IP Library Granted Patent US 12,197,394
Granted Patent B1
US 12,197,394 · App. 18/516,834 · Granted Jan 14, 2025

Method and apparatus for efficient synchronization of search heads in a cluster using digests

Inventor: Yuan Xu (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/178G06F16/188G06F16/273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,394
App. No.
18/516,834
Granted
Jan 14, 2025
Kind
B1
Abstract

Embodiments of the present disclosure provide techniques for efficiently and accurately performing propagation of search-head specific configuration customizations across multiple individual configuration files of search heads of a cluster for a consistent user experience. The cluster of search heads may be synchronized such that the search heads operate to receive the configuration or knowledge object customizations from one or more clients from a central or lead search head. To reduce the amount of data that is transferred during propagation, the list of configuration or knowledge object customizations maintained in each search head is filtered from the list of the lead search head until a divergence point is determined. Once determined and communicated to the lead search head, the lead search head sends the configuration and knowledge object customization data that is absent from the internal list of the member search head.

Claims (39)

1. A method comprising:

receiving, by one or more processing devices corresponding to a first search head of a cluster comprising a plurality of search heads of a data aggregation and analysis system, a journal entry associated with a knowledge object customization from a second search head in the cluster, wherein the first search head is configured in a leader state and the second search head is configured in a follower state, wherein each search head comprises a configuration file comprising information associated with knowledge objects and knowledge object customizations, and wherein each search head further comprises a journal comprising a history of knowledge object customizations;

adding the journal entry associated with the knowledge object customization to a local data store of the first search head;

updating a first configuration file corresponding to the first search head with the journal entry associated with the knowledge object customization;

updating the journal entry in the first configuration file; and

synchronizing the journal entry with other search heads in the plurality of search heads.

2. The method of claim 1 , wherein the knowledge object customization comprises a customization of a configuration that is one of: a search-related, a visualization-related, or a system-activity-related configuration.

3. The method of claim 1 , wherein the knowledge object customization comprises a customization of a configuration that is one of a search-related configuration or a visualization-related configuration, and wherein the customization may be selected from a group including a deletion, a creation, a modification, a change, or an update of a knowledge object.

4. The method of claim 1 , wherein the knowledge object customization comprises a customization of a knowledge object, and wherein the knowledge object is selected from a group including a saved search, an event type, a transaction, a tag, a field extraction, a field transform, a lookup, a workflow action, a search command, a view, and late-binding schema.

5. The method of claim 1 , wherein receiving the journal entry associated with the knowledge object customization from the second search head in the cluster comprises confirming that a change associated with the journal entry is a latest commit in a respective journal associated with the first search head.

6. The method of claim 1 , wherein adding the journal entry associated with the knowledge object customization to a local data store comprises marking the journal entry to indicate that the journal entry is replicated but not applied to the first configuration file.

7. The method of claim 1 , wherein updating the journal entry in the first configuration file comprises marking the journal entry to indicate that the journal entry is replicated and applied to the first configuration file.

8. The method of claim 1 , further comprising:

transmitting a notification to the second search head that the journal entry was applied at the first search head.

9. The method of claim 1 , wherein synchronizing the journal entry with other search heads in the plurality of search heads comprises performing the synchronizing with the other search heads concurrently.

10. The method of claim 1 , wherein synchronizing the journal entry with other search heads in the plurality of search heads comprises performing the synchronizing with one or more of the other search heads at different times.

11. The method of claim 1 , wherein synchronizing the journal entry with other search heads in the plurality of search heads comprises one or more of the other search heads initializing a synchronization request to retrieve the journal entry from the first search head.

12. A system comprising:

a local data store comprising a first configuration file comprising information associated with knowledge objects and knowledge object customizations, and a first journal comprising a history of knowledge object customizations; and

one or more processing devices coupled with the local data store, the processing devices being configured to:

receive, by the one or more processing devices corresponding to a first search head of a cluster comprising a plurality of search heads of a data aggregation and analysis system, a journal entry associated with a knowledge object customization from a second search head in the cluster, wherein the first search head is configured in a leader state and the second search head is configured in a follower state, wherein each search head comprises a configuration file comprising information associated with knowledge objects and knowledge object customizations, and wherein each search head further comprises a journal comprising a history of knowledge object customizations;

add the journal entry associated with the knowledge object customization to the local data store of the first search head;

update the first configuration file with the journal entry associated with the knowledge object customization;

update the journal entry in the first configuration file; and

synchronize the journal entry with other search heads in the plurality of search heads.

13. The system of claim 12 , wherein the knowledge object customization comprises a customization of a configuration that is one of: a search-related, a visualization-related, or a system-activity-related configuration.

14. The system of claim 12 , wherein the knowledge object customization comprises a customization of a configuration that is one of a search-related configuration or a visualization-related configuration, and wherein the customization may be selected from a group including a deletion, a creation, a modification, a change, or an update of a knowledge object.

15. The system of claim 12 , wherein the knowledge object customization comprises a customization of a knowledge object, and wherein the knowledge object is selected from a group including a saved search, an event type, a transaction, a tag, a field extraction, a field transform, a lookup, a workflow action, a search command, a view, and late-binding schema.

16. The system of claim 12 , wherein receiving the journal entry associated with the knowledge object customization from the second search head in the cluster comprises confirming that a change associated with the journal entry is a latest commit in a respective journal associated with the first search head.

17. The system of claim 12 , wherein adding the journal entry associated with the knowledge object customization to a local data store comprises marking the journal entry to indicate that the journal entry is replicated but not applied to the first configuration file.

18. A non-transitory computer readable medium having instructions stored thereon which, when executed by a processing device, causes the processing device to perform configuration propagation, the instructions comprising:

instructions to receive, by one or more processing devices corresponding to a first search head of a cluster comprising a plurality of search heads of a data aggregation and analysis system, a journal entry associated with a knowledge object customization from a second search head in the cluster, wherein the first search head is configured in a leader state and the second search head is configured in a follower state, wherein each search head comprises a configuration file comprising information associated with knowledge objects and knowledge object customizations, and wherein each search head further comprises a journal comprising a history of knowledge object customizations;

instructions to add the journal entry associated with the knowledge object customization to a local data store of the first search head;

instructions to update a first configuration file corresponding to the first search head with the journal entry associated with the knowledge object customization;

instructions to update the journal entry in the first configuration file; and

instructions to synchronize the journal entry with other search heads in the plurality of search heads.

19. The non-transitory computer readable media of claim 18 , wherein the instructions further comprise:

Instructions to transmit a notification to the second search head that the journal entry was applied at the first search head.

20. The non-transitory computer readable media of claim 18 , wherein instructions to synchronize the journal entry with other search heads in the plurality of search heads comprises instructions to perform the synchronizing with the other search heads concurrently.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2023
From: XU, YUAN
To: SPLUNK INC.
Reel/Frame 065656/0357 →
Continuity (3)
Continuation 17725132 · Apr 20, 2022
Continuation 16793845 · Feb 18, 2020
Continuation 15401427 · Jan 9, 2017
References Cited (40)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 7984043B1 · Waas · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8682925B1 · Marquardt · 2014 [cited by examiner]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9047246B1 · Rahut · 2015 [cited by examiner]
US 9069607B1 · Gopalakrishna Alevoor · 2015 [cited by examiner]
US 9128779B1 · Gladkikh · 2015 [cited by examiner]
US 9130832B1 · Boe · 2015 [cited by examiner]
US 9158811B1 · Choudhary · 2015 [cited by examiner]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10606810B2 · Xu · 2020 [cited by applicant]
US 11347695B2 · Xu · 2022 [cited by applicant]
US 20050165827A1 · Schmitt · 2005 [cited by examiner]
US 20060047798A1 · Feinleib · 2006 [cited by examiner]
US 20090049010A1 · Bodapati · 2009 [cited by examiner]
US 20090112780A1 · Chen et al. · 2009 [cited by applicant]
US 20090282000A1 · Bennett · 2009 [cited by examiner]
US 20100030840A1 · O'Shea · 2010 [cited by examiner]
US 20110072338A1 · Caldwell · 2011 [cited by examiner]
US 20120059823A1 · Barber et al. · 2012 [cited by applicant]
US 20140236890A1 · Vasan · 2014 [cited by examiner]
US 20160092558A1 · Ago et al. · 2016 [cited by applicant]
US 20170091183A1 · Kenchammana-Hosekote · 2017 [cited by examiner]
US 20170091215A1 · Beard · 2017 [cited by examiner]
US 20170228661A1 · Chien · 2017 [cited by examiner]
US 20180095966A1 · Fourney · 2018 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20200334304A1 · Reddy Vennapusa · 2020 [cited by examiner]
Felfernig et al., “Standardized Configuration Knowledge Representations as Technological Foundation for Mass Customization”, 2007, IEEE, vol. 54, pp. 41-56 (Year: 2007). [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]
Carasso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012, 156 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]
Splunk, Splunk Documentation 6.3 .3 Web.archive.org/web/20160305094905/http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/Whatisdistributedsearch, 2016, 134 pages. [cited by applicant]
Loughran, Steve A., “Hadoop and Kerberos: The Madness Beyond the Gate”, http://wwwfreetechbooks.com/hadoop-and-kerberos-themadness-beyond-the-gale-t921.html, Mar. 1, 2016, 98 pages. [cited by applicant]