IP Library Granted Patent US 12,443,656
Granted Patent B1
US 12,443,656 · App. 18/545,844 · Granted Oct 14, 2025

Processing index data based on generation of index data

Inventors: Mitchell Neuman Blank, Jr. (San Francisco, CA); Leonid Budchenko (San Jose, CA); David Carasso (San Rafael, CA); Micah James Delfino (San Francisco, CA); Johnvey Hwang (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA); Eric Timothy Woo (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/901G06F3/0482G06F3/04842G06F3/0485G06F16/2228G06F16/24564G06F16/2477G06F16/248G06F16/252G06F16/316G06F16/951G06F16/9535G06F40/205G06V10/245G06V40/161
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,656
App. No.
18/545,844
Granted
Oct 14, 2025
Kind
B1
Abstract

Embodiments are directed towards previewing results generated from indexing data raw data before the corresponding index data is added to an index store. Raw data may be received from a preview data source. After an initial set of configuration information may be established, the preview data may be submitted to an index processing pipeline. A previewing application may generate preview results based on the preview index data and the configuration information. The preview results may enable previewing how the data is being processed by the indexing application. If the preview results are not acceptable, the configuration information may be modified. The preview application enables modification of the configuration information until the generated preview results may be acceptable. If the configuration information is acceptable, the preview data may be processed and indexed in one or more index stores.

Claims (33)

1. A computer-implemented method comprising:

generating a first set of index data and a second set of index data;

determining that the first set of index data is not generated from preview data;

based on the determination that the first set of index data is not generated from the preview data, adding the first set of index data to the index data store;

determining that the second set of index data is generated from the preview data;

based on the determination that the second set of index data is generated from the preview data, generating preview search result data from the second set of index data, storing the preview search result data in a preview data store separate from the index data store, and presenting the preview search result data, via a user interface, to indicate an effectiveness of candidate configuration information used to generate the preview search result data, wherein the preview data store also stores the second set of index data generated from the preview data to prevent an improper index data generated from preview data from being stored in the index data store prior to approval of the candidate configuration information; and

monitoring progress of a preview process by tracking a number of index data generated from the preview data and a number of the preview search result data stored in the preview data store.

2. The method of claim 1 , wherein the first set of index data is generated from raw data in a pipeline.

3. The method of claim 1 , wherein the first set of index data is generated from raw data based on configuration information corresponding to a source of the raw data or a type of results expected to be included in an index.

4. The method of claim 1 , wherein the second set of index data is generated from the preview data from a preview data source.

5. The method of claim 1 , wherein the preview search result data is generated by executing one or more search commands.

6. The method of claim 1 , wherein determining that the second set of index data is generated from the preview data comprises determining that the index data is generated from data originating from a preview data source.

7. A non-transitory storage medium storing instructions which, when executed by a computing device, cause the computing device to:

generate a first set of index data and a second set of index data;

determine that the first set of index data is not generated from preview data;

based on the determination that the first set of index data is not generated from the preview data, adding the first set of index data to the index data store;

determining that the second set of index data is generated from the preview data;

based on the determination that the second set of index data is generated from the preview data, generating preview search result data from the second set of index data, storing the preview search result data in a preview data store separate from the index data store, and presenting the preview search result data, via a user interface, to indicate an effectiveness of candidate configuration information used to generate the preview search result data, wherein the preview data store also stores the second set of index data generated from the preview data to prevent an improper index data generated from preview data from being stored in the index data store prior to approval of the candidate configuration information; and

monitoring progress of a preview process by tracking a number of index data generated from the preview data and a number of the preview search result data stored in the preview data store.

8. The non-transitory storage medium of claim 7 , wherein the first set of index data is generated from raw data in a pipeline.

9. The non-transitory storage medium of claim 7 , wherein the first set of index data is generated from raw data based on configuration information corresponding to a source of the raw data or a type of results expected to be included in an index.

10. The non-transitory storage medium of claim 7 , wherein the second set of index data is generated from the preview data from a preview data source.

11. A computing system comprising:

a processor; and

computer storage memory having computer-executable instructions stored thereon which, when executed by the processor, configure the computing system to:

generate a first set of index data and a second set of index data;

determine that the first set of index data is not generated from preview data;

based on the determination that the first set of index data is not generated from the preview data, adding the first set of index data to the index data store;

determining that the second set of index data is generated from the preview data;

based on the determination that the second set of index data is generated from the preview data, generating preview search result data from the second set of index data, storing the preview search result data in a preview data store separate from the index data store, and presenting the preview search result data, via a user interface, to indicate an effectiveness of candidate configuration information used to generate the preview search result data, wherein the preview data store also stores the second set of index data generated from the preview data to prevent an improper index data generated from preview data from being stored in the index data store prior to approval of the candidate configuration information; and

monitoring progress of a preview process by tracking a number of index data generated from the preview data and a number of the preview search result data stored in the preview data store.

12. The system of claim 11 , wherein determining that the second set of index data is generated from the preview data comprises determining that the index data is generated from data originating from a preview data source.

13. The system of claim 11 , wherein the preview search result data is generated by executing one or more search commands.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2023
From: BLANK, MITCHELL NEUMAN, JR.; BUDCHENKO, LEONID; CARASSO, DAVID; DELFINO, MICAH JAMES; HWANG, JOHNVEY; SORKIN, STEPHEN PHILLIP; WOO, ERIC TIMOTHY
To: SPLUNK INC.
Reel/Frame 065915/0396 →
Continuity (6)
Continuation 16870233 · May 8, 2020
Continuation 15642062 · Jul 5, 2017
Continuation 15224655 · Jul 31, 2016
Continuation 14929332 · Oct 31, 2015
Continuation 14445001 · Jul 28, 2014
Continuation 13588939 · Aug 17, 2012
References Cited (78)
US 4571700A · Emry, Jr. · 1986 [cited by examiner]
US 5781772A · Wilkinson et al. · 1998 [cited by applicant]
US 6011795A · Varghese et al. · 2000 [cited by applicant]
US 6052683A · Irwin · 2000 [cited by applicant]
US 6067574A · Tzeng · 2000 [cited by applicant]
US 6147976A · Shand et al. · 2000 [cited by applicant]
US 6212184B1 · Venkatachary et al. · 2001 [cited by applicant]
US 6275822B1 · Consens · 2001 [cited by examiner]
US 6446081B1 · Preston · 2002 [cited by applicant]
US 6567408B1 · Li et al. · 2003 [cited by applicant]
US 6718535B1 · Underwood · 2004 [cited by applicant]
US 6836894B1 · Hellerstein et al. · 2004 [cited by applicant]
US 7272589B1 · Guay et al. · 2007 [cited by applicant]
US 7539685B2 · Mosescu · 2009 [cited by examiner]
US 7743060B2 · Fontoura et al. · 2010 [cited by applicant]
US 8055646B2 · Augenstein · 2011 [cited by examiner]
US 8102869B2 · Brown et al. · 2012 [cited by applicant]
US 8380752B2 · Botros et al. · 2013 [cited by applicant]
US 8572483B1 · Dilorenzo · 2013 [cited by applicant]
US 20020128996A1 · Reed · 2002 [cited by applicant]
US 20030050805A1 · Gouyet et al. · 2003 [cited by applicant]
US 20040230667A1 · Wookey · 2004 [cited by applicant]
US 20050022207A1 · Grabarnik et al. · 2005 [cited by applicant]
US 20050049924A1 · Debettencourt et al. · 2005 [cited by applicant]
US 20050060340A1 · Sommerfield et al. · 2005 [cited by applicant]
US 20060124738A1 · Wang et al. · 2006 [cited by applicant]
US 20070011353A1 · Hicks et al. · 2007 [cited by applicant]
US 20070118491A1 · Baum et al. · 2007 [cited by applicant]
US 20070185859A1 · Flowers et al. · 2007 [cited by applicant]
US 20080039121A1 · Muller et al. · 2008 [cited by applicant]
US 20080172376A1 · Yu · 2008 [cited by examiner]
US 20080172409A1 · Botros et al. · 2008 [cited by applicant]
US 20080215546A1 · Baum et al. · 2008 [cited by applicant]
US 20080294588A1 · Morris et al. · 2008 [cited by applicant]
US 20080294657A1 · Leung · 2008 [cited by examiner]
US 20090119416A1 · Sirdevan et al. · 2009 [cited by applicant]
US 20090150769A1 · Konnola et al. · 2009 [cited by applicant]
US 20090157513A1 · Bonev et al. · 2009 [cited by applicant]
US 20090182779A1 · Johnson · 2009 [cited by applicant]
US 20100057556A1 · Rousso et al. · 2010 [cited by applicant]
US 20100064026A1 · Brown et al. · 2010 [cited by applicant]
US 20100115443A1 · Richstein · 2010 [cited by applicant]
US 20100228650A1 · Shacham et al. · 2010 [cited by applicant]
US 20100250566A1 · Paul · 2010 [cited by applicant]
US 20100318858A1 · Essawi et al. · 2010 [cited by applicant]
US 20110035390A1 · Whitehouse · 2011 [cited by applicant]
US 20110110515A1 · Tidwell et al. · 2011 [cited by applicant]
US 20110113466A1 · Stringham · 2011 [cited by examiner]
US 20110173180A1 · Gurumurthy et al. · 2011 [cited by applicant]
US 20110191679A1 · Lin et al. · 2011 [cited by applicant]
US 20110296244A1 · Fu et al. · 2011 [cited by applicant]
US 20110314148A1 · Petersen et al. · 2011 [cited by applicant]
US 20120005542A1 · Petersen et al. · 2012 [cited by applicant]
US 20120023116A1 · Wilkes et al. · 2012 [cited by applicant]
US 20120050778A1 · Shiohara · 2012 [cited by applicant]
US 20120072204A1 · Nasri et al. · 2012 [cited by applicant]
US 20120078951A1 · Hsu et al. · 2012 [cited by applicant]
US 20120109637A1 · Merugu et al. · 2012 [cited by applicant]
US 20120117015A1 · Sathish · 2012 [cited by applicant]
US 20120131185A1 · Petersen et al. · 2012 [cited by applicant]
US 20120197914A1 · Harnett et al. · 2012 [cited by applicant]
US 20120197928A1 · Zhang et al. · 2012 [cited by applicant]
US 20120197934A1 · Zhang et al. · 2012 [cited by applicant]
US 20120203757A1 · Ravindran · 2012 [cited by applicant]
US 20120246303A1 · Petersen et al. · 2012 [cited by applicant]
US 20120265726A1 · Padmanabhan et al. · 2012 [cited by applicant]
US 20120303561A1 · Sathish · 2012 [cited by applicant]
US 20130166332A1 · Hammad · 2013 [cited by applicant]
US 20130204894A1 · Faith et al. · 2013 [cited by applicant]
US 20130246438A1 · Gestrelius · 2013 [cited by examiner]
US 20130290106A1 · Bradley et al. · 2013 [cited by applicant]
US 20140040287A1 · Frome · 2014 [cited by applicant]
US 20140149477A1 · Abramovitz et al. · 2014 [cited by applicant]
Carasso, D., “Exploring Splunk,” Search Processing Language (SPL) Primerand Cookbook, pp. 156 (Apr. 2012). [cited by applicant]
Kalet, I. J., et al., “A declarative implementation of the DICOM-3 network protocol”, Journal of Biomedical Informatics, vol. 36, Issue 3, pp. 159-176 (Jun. 2003). [cited by applicant]
Ramage, D., and Adam J. Oliner, A. J., “RA: ResearchAssistant for the computational sciences”, Stanford University Department of Computer Science, ExpCS '07: Proceedings of the 2007 workshop on Experimental computer sci… [cited by applicant]
Shabtai, A., et al.,“A distributed architecture for efficient parallelization and computation of knowledge-based temporal abstractions” Journal of Intelligent Information Systems vol. 39, Issue 1, pp. 249-286 (Dec. 24, … [cited by applicant]
Xu, W., et al., “Detecting Large-Scale System Problems by Mining Console Logs”, SOSP '09: Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles, pp. 117-132 (Oct. 11, 2009). [cited by applicant]