IP Library Granted Patent US 12,468,660
Granted Patent B1
US 12,468,660 · App. 18/585,781 · Granted Nov 11, 2025

Dynamically scheduling items for re-evaluation for a possible change based on an evaluation backlog

Inventors: Amritpal Singh Bath (El Sobrante, CA); Mitchell Neuman Blank, Jr. (San Francisco, CA); Vishal Patel (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA)
G06F16/1734G06F16/174G06F16/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,660
App. No.
18/585,781
Granted
Nov 11, 2025
Kind
B1
Abstract

Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.

Claims (31)

1 . A computer-implemented method comprising:

obtaining, via a computing device, a time to wait for an item to be analyzed to detect a possible change based on an evaluation backlog indicator;

determining, via the computing device, that the time to wait is above a maximum threshold value that is based on a previous expiration time of the item or below a minimum threshold value based on the previous expiration time of the item, the previous expiration time indicates when the item is available for scheduling analysis of the item; and

assigning, via the computing device, the item a new expiration time, wherein the new expiration time is greater than the previous expiration time when the time to wait is above the maximum threshold value or the new expiration time is less than the previous expiration time when the time to wait is below the minimum threshold value.

2 . The computer-implemented method of claim 1 , wherein a start time associated with the evaluation backlog indicator is a system time when the item is identified as being in a TIMEOUT state, and a stop time associated with the evaluation backlog indicator is the system time when the item is analyzed for a possible change in a STAT state.

3 . The computer-implemented method of claim 1 , wherein the evaluation backlog indicator is based on an incrementing time counter that is started when the item is identified as being in a TIMEOUT state and stopped when the item is analyzed for a possible change in a STAT state.

4 . The computer-implemented method of claim 1 , wherein the time to wait is a difference between a start time associated with the evaluation backlog indicator and a stop time associated with the evaluation backlog indicator.

5 . The computer-implemented method of claim 1 , wherein the maximum threshold value is selected based on a percentage of the previous expiration time for the item.

6 . The computer-implemented method of claim 1 , wherein the new expiration time is determined based on an increase of the previous expiration time or the time to wait.

7 . The computer-implemented method of claim 1 , further comprising identifying the item to be in a TIMEOUT state with the new expiration time.

8 . The computer-implemented method of claim 1 , wherein the minimum threshold value is determined based on a percentage of the previous expiration time for the item.

9 . The computer-implemented method of claim 1 , wherein the time to wait is obtained in response to identifying that there is not a possible change to the item based on an evaluation of metadata associated with the item.

10 . The computer-implemented method of claim 1 , wherein the evaluation backlog indicator is assigned to the item and identifies a duration for which the item is delayed for evaluation based on a backlog of other items to be evaluated prior to the item.

11 . One or more computer-readable storage media having instructions stored thereon, wherein the instructions, when executed by a computing device, cause the computing device to:

obtain a time to wait for an item to be analyzed to detect a possible change based on an evaluation backlog indicator;

determine that the time to wait is above a maximum threshold value that is based on a previous expiration time of the item or below a minimum threshold value based on the previous expiration time of the item, the previous expiration time indicates when the item is available for scheduling analysis of the item; and

assign the item a new expiration time, wherein the new expiration time is greater than the previous expiration time when the time to wait is above the maximum threshold value or the new expiration time is less than the previous expiration time when the time to wait is below the minimum threshold value.

12 . The one or more computer-readable storage media of claim 11 , wherein a start time associated with the evaluation backlog indicator is a system time when the item is identified as being in a TIMEOUT state and a stop time associated with evaluation backlog indicator is a system time when the item is analyzed for a possible change in a STAT state.

13 . The one or more computer-readable storage media of claim 11 , wherein the evaluation backlog indicator is based on an incrementing time counter that is started when the item is identified as being in a TIMEOUT state and stopped when the item is analyzed for a possible change in a STAT state.

14 . The one or more computer-readable storage media of claim 11 , wherein the time to wait is a difference between a start time associated with the evaluation backlog indicator and a stop time associated with the evaluation backlog indicator.

15 . The one or more computer-readable storage media of claim 11 , wherein the maximum threshold value is selected based on a percentage of the previous expiration time for the item.

16 . The one or more computer-readable storage media of claim 11 , wherein the new expiration time is determined based on an increase of the previous expiration time or the time to wait.

17 . A computing system comprising:

one or more processors; and

a memory coupled with the one or more processors, the memory having instructions stored thereon, wherein the instructions, when executed by the one or more processors, cause the computing system to:

obtain a time to wait for an item to be analyzed to detect a possible change based on an evaluation backlog indicator;

determine that the time to wait is above a maximum threshold value that is based on a previous expiration time of the item or below a minimum threshold value based on the previous expiration time of the item, the previous expiration time indicates when the item is available for scheduling analysis of the item; and

assign the item a new expiration time, wherein the new expiration time is greater than the previous expiration time when the time to wait is above the maximum threshold value or the new expiration time is less than the previous expiration time when the time to wait is below the minimum threshold value.

18 . The computing system of claim 17 , wherein the minimum threshold value is determined based on a percentage of the previous expiration time for the item.

19 . The computing system of claim 17 , wherein the time to wait is obtained in response to identifying that there is not a possible change to the item based on an evaluation of metadata associated with the item.

20 . The computing system of claim 17 , wherein the evaluation backlog indicator is assigned to the item and identifies a duration for which the item is delayed for evaluation based on a backlog of other items to be evaluated prior to the item.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2024
From: BATH, AMRITPAL SINGH; BLANK, MITCHELL NEUMAN, JR.; PATEL, VISHAL; SORKIN, STEPHEN PHILLIP
To: SPLUNK INC.
Reel/Frame 066589/0701 →
Continuity (7)
Continuation 18160123 · Jan 26, 2023
Continuation 17080416 · Oct 26, 2020
Continuation 15663652 · Jul 28, 2017
Continuation 15224649 · Jul 31, 2016
Continuation 14611156 · Jan 30, 2015
Continuation 14034220 · Sep 23, 2013
Continuation 13076296 · Mar 30, 2011
References Cited (182)
US 5778395A · Whiting et al. · 1998 [cited by applicant]
US 5898836A · Freivald et al. · 1999 [cited by applicant]
US 5902352A · Chou et al. · 1999 [cited by applicant]
US 5918013A · Mighdoll et al. · 1999 [cited by applicant]
US 6067541A · Raju et al. · 2000 [cited by applicant]
US 6101507A · Cane et al. · 2000 [cited by applicant]
US 6236993B1 · Fanberg · 2001 [cited by applicant]
US 6256712B1 · Challenger et al. · 2001 [cited by applicant]
US 6311197B2 · Mighdoll et al. · 2001 [cited by applicant]
US 6922781B1 · Shuster · 2005 [cited by applicant]
US 7171616B1 · Berstis · 2007 [cited by applicant]
US 7203711B2 · Borden et al. · 2007 [cited by applicant]
US 7228319B1 · Fuchs · 2007 [cited by applicant]
US 7320007B1 · Chang · 2008 [cited by applicant]
US 7320009B1 · Srivastava et al. · 2008 [cited by applicant]
US 7328217B2 · Borthakur et al. · 2008 [cited by applicant]
US 7653624B1 · Reitmeyer et al. · 2010 [cited by applicant]
US 7653654B1 · Sundaresan · 2010 [cited by applicant]
US 7779021B1 · Smith et al. · 2010 [cited by applicant]
US 7814134B2 · Leonardos · 2010 [cited by applicant]
US 7844580B2 · Srivastava et al. · 2010 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 7986298B1 · Dulaney et al. · 2011 [cited by applicant]
US 8015117B1 · Lillibridge et al. · 2011 [cited by applicant]
US 8055613B1 · Mu et al. · 2011 [cited by applicant]
US 8103718B2 · O'Shea et al. · 2012 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8131691B1 · Nagaralu et al. · 2012 [cited by applicant]
US 8239421B1 · Marwah et al. · 2012 [cited by applicant]
US 8306954B2 · Srivastava et al. · 2012 [cited by applicant]
US 8326803B1 · Stringham · 2012 [cited by applicant]
US 8346803B2 · Chang · 2013 [cited by applicant]
US 8407191B1 · Nanda · 2013 [cited by applicant]
US 8443354B1 · Satish et al. · 2013 [cited by applicant]
US 8504517B2 · Agrawal · 2013 [cited by applicant]
US 8505101B1 · Lee · 2013 [cited by applicant]
US 8516050B1 · Chapweske et al. · 2013 [cited by applicant]
US 8555157B1 · Fu · 2013 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8768984B2 · Priddle et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9002854B2 · Baum et al. · 2015 [cited by applicant]
US 9020987B1 · Nanda et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9424266B2 · Perlin et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11550829B2 · Patel et al. · 2023 [cited by applicant]
US 20010003823A1 · Mighdoll et al. · 2001 [cited by applicant]
US 20020059245A1 · Zakharov et al. · 2002 [cited by applicant]
US 20020133325A1 · Hoare et al. · 2002 [cited by applicant]
US 20030041093A1 · Yamane et al. · 2003 [cited by applicant]
US 20030041094A1 · Lara et al. · 2003 [cited by applicant]
US 20030144985A1 · Ebert · 2003 [cited by examiner]
US 20030187809A1 · Suermondt et al. · 2003 [cited by applicant]
US 20040068664A1 · Nachenberg et al. · 2004 [cited by applicant]
US 20040098599A1 · Bentley · 2004 [cited by applicant]
US 20040105331A1 · Kanai et al. · 2004 [cited by applicant]
US 20040210551A1 · Jones et al. · 2004 [cited by applicant]
US 20040233286A1 · Kawabe et al. · 2004 [cited by applicant]
US 20040259633A1 · Gentles et al. · 2004 [cited by applicant]
US 20050021994A1 · Barton et al. · 2005 [cited by applicant]
US 20050166094A1 · Blackwell et al. · 2005 [cited by applicant]
US 20050188086A1 · Mighdoll et al. · 2005 [cited by applicant]
US 20050273486A1 · Keith, Jr. · 2005 [cited by applicant]
US 20050273674A1 · Shinn et al. · 2005 [cited by applicant]
US 20060004858A1 · Tran et al. · 2006 [cited by applicant]
US 20060009213A1 · Sturniolo et al. · 2006 [cited by applicant]
US 20060020936A1 · Wyatt · 2006 [cited by applicant]
US 20060047620A1 · Branson et al. · 2006 [cited by applicant]
US 20060053182A1 · Sen et al. · 2006 [cited by applicant]
US 20060159098A1 · Munson et al. · 2006 [cited by applicant]
US 20060200936A1 · Gardner · 2006 [cited by applicant]
US 20060277223A1 · Gupta et al. · 2006 [cited by applicant]
US 20060288300A1 · Chambers et al. · 2006 [cited by applicant]
US 20070011211A1 · Reeves et al. · 2007 [cited by applicant]
US 20070028303A1 · Brennan · 2007 [cited by applicant]
US 20070039053A1 · Dvir · 2007 [cited by applicant]
US 20070050777A1 · Hutchinson et al. · 2007 [cited by applicant]
US 20070078941A1 · Dun et al. · 2007 [cited by applicant]
US 20070124816A1 · Abigail · 2007 [cited by applicant]
US 20070168286A1 · Nishioka · 2007 [cited by examiner]
US 20070168320A1 · Borthakur et al. · 2007 [cited by applicant]
US 20070179995A1 · Prahlad et al. · 2007 [cited by applicant]
US 20070250517A1 · Bestgen et al. · 2007 [cited by applicant]
US 20070271177A1 · April et al. · 2007 [cited by applicant]
US 20070276823A1 · Borden et al. · 2007 [cited by applicant]
US 20070282462A1 · Sourov et al. · 2007 [cited by applicant]
US 20070286071A1 · Cormode et al. · 2007 [cited by applicant]
US 20080040388A1 · Petri et al. · 2008 [cited by applicant]
US 20080077634A1 · Quakenbush · 2008 [cited by applicant]
US 20080228574A1 · Stewart et al. · 2008 [cited by applicant]
US 20080243936A1 · Li et al. · 2008 [cited by applicant]
US 20080281874A1 · Koga · 2008 [cited by applicant]
US 20090070373A1 · Jeong et al. · 2009 [cited by applicant]
US 20090119669A1 · Norman et al. · 2009 [cited by applicant]
US 20090171990A1 · Naef, III · 2009 [cited by applicant]
US 20090192978A1 · Hewett et al. · 2009 [cited by applicant]
US 20090198744A1 · Nakamura · 2009 [cited by applicant]
US 20090228533A1 · Reddy et al. · 2009 [cited by applicant]
US 20090271412A1 · Lacapra et al. · 2009 [cited by applicant]
US 20090303160A1 · Chew et al. · 2009 [cited by applicant]
US 20090327288A1 · Silverman et al. · 2009 [cited by applicant]
US 20100070475A1 · Chen · 2010 [cited by applicant]
US 20100083085A1 · Tow et al. · 2010 [cited by applicant]
US 20100083300A1 · Lyou · 2010 [cited by examiner]
US 20100100774A1 · Ding et al. · 2010 [cited by applicant]
US 20100114948A1 · Shrivastava et al. · 2010 [cited by applicant]
US 20100169287A1 · Klose · 2010 [cited by applicant]
US 20100211595A1 · Yamamoto et al. · 2010 [cited by applicant]
US 20100250480A1 · Cherkasova et al. · 2010 [cited by applicant]
US 20100274772A1 · Samuels · 2010 [cited by applicant]
US 20100325352A1 · Schuette et al. · 2010 [cited by applicant]
US 20100332513A1 · Azar et al. · 2010 [cited by applicant]
US 20110022566A1 · Beaverson et al. · 2011 [cited by applicant]
US 20110022840A1 · Stefan et al. · 2011 [cited by applicant]
US 20110047594A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20110107053A1 · Beckmann et al. · 2011 [cited by applicant]
US 20110145216A1 · Subramanya · 2011 [cited by applicant]
US 20110161207A1 · Moussavi · 2011 [cited by examiner]
US 20110161327A1 · Pawar · 2011 [cited by applicant]
US 20110225177A1 · Farber et al. · 2011 [cited by applicant]
US 20110321166A1 · Capalik et al. · 2011 [cited by applicant]
US 20120023065A1 · Deweese et al. · 2012 [cited by applicant]
US 20120059799A1 · Oliveira et al. · 2012 [cited by applicant]
US 20120117096A1 · Massand · 2012 [cited by applicant]
US 20120124014A1 · Provenzano · 2012 [cited by applicant]
US 20120143824A1 · Doshi et al. · 2012 [cited by applicant]
US 20120185445A1 · Borden et al. · 2012 [cited by applicant]
US 20120198346A1 · Clemm · 2012 [cited by examiner]
US 20120246567A1 · Brahms et al. · 2012 [cited by applicant]
US 20120272115A1 · Munson et al. · 2012 [cited by applicant]
US 20120317188A1 · Fredricksen · 2012 [cited by examiner]
US 20130124472A1 · Srivastava et al. · 2013 [cited by applicant]
US 20140012949A1 · Meyers et al. · 2014 [cited by applicant]
US 20140019809A1 · Nagaoka · 2014 [cited by applicant]
US 20140074777A1 · Agrawal · 2014 [cited by applicant]
US 20160063281A1 · Kahana et al. · 2016 [cited by applicant]
US 20160350017A1 · Amir et al. · 2016 [cited by applicant]
US 20170098095A1 · Gilpin · 2017 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190260595A1 · Walton et al. · 2019 [cited by applicant]
US 20200409967A1 · Caldwell et al. · 2020 [cited by applicant]
US 20240028725A1 · Segal et al. · 2024 [cited by applicant]
WO PCTUS2012031242 · 2012 [cited by applicant]
WO PCTUS2012031246 · 2012 [cited by applicant]
WO 2012135516A2 · 2012 [cited by applicant]
WO 2012135518A2 · 2012 [cited by applicant]
“Coreutils—GNU core utilities”, gnu.org, http://www.gnu.org/software/coreutils, accessed Mar. 31, 2011, 3 pages. [cited by applicant]
“Cryptographic has function,” Wikipedia.org, 8 pages http://en.wikipedia.org/wiki/Cryptographic_hash_function, accessed Apr. 4, 2011. [cited by applicant]
“MultiTail,” vanheusden.com, 2 pages http://www.vanheusden.com/multitail, accessed Mar. 31, 2011. [cited by applicant]
“SGI—Developer Central Open Source | FAM,” sgi.com, 7 pages http://oss.sgi.com/projects/fam/faq.html, accessed Mar. 31, 2011. [cited by applicant]
“Simple file verification,” Wikipedia.org, 2 pages http://en.wikipedia.org/wiki/Simple_file_verificaiton, accessed Mar. 31, 2011. [cited by applicant]
“Splunk Cloud 8.0.2004 User Manual”, available online, retrieved on May 20, 2020 from docs.splunk.com, pp. 66. [cited by applicant]
“Splunk Enterprise 8.0.0 Overview”, available online, retrieved on May 20, 2020 from docs.splunk.com, pp. 17. [cited by applicant]
“Splunk Quick Reference Guide”, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, pp. 6. [cited by applicant]
“Tripwire Enterprise Delivers IT Compliance and Data Protection,” Tripwire, Inc., 2 pages http://www.tripwire.com/it-compliance-products/te, accessed Mar. 31, 2011. [cited by applicant]
“Tripwire Essential Customer Service Offerings”, Tripwire, Inc., http://www.tripwire.com/services/essential, accessed Apr. 1, 2011, 2 pages. [cited by applicant]
“Tripwire IT Compliance Automation Makes IT Security and Compliance Easy,” Tripwire, Inc., 2 pages http://www.tripwire.com/it-compliance-products, accessed Apr. 1, 2011. [cited by applicant]
“Tripwire Log & Event Management for Next Generation SIEM,” Tripwire, Inc. 1 page http://www.tripwire.com/it-compliance-products/log-event-management, accessed Mar. 31, 2011. [cited by applicant]
“Tripwire Services Shortens the Path to IT Security and Compliance,” Tripwire, Inc., 2 pages http://www.tripwire.com/services, accessed Apr. 1, 2011. [cited by applicant]
“UNIX man pages : tail ( )” unixhelp.ed.ac.uk, http://unixhelp.ed.ac.uk/CGI/man.about.cgi?tail, accessed Mar. 31, 2011, 3 pages. [cited by applicant]
Allman, M, et al. “TCP Congestion Control,” Network Working Groups RFC 2581, The Internet Society, Apr. 1999, 14 pages http://www.rfc-editor.org/rfc/rfc2581.txt, accessed Apr. 1, 2011. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-Structured Time Series Database”, Splunk Inc., 2010, pp. 1-9. [cited by applicant]
Brakmo, L. et a!., “TCP Vegas: End to End Congestion Avoidance on a Global Internet,” IEEE Journal on Selected Areas in Communications, vol. 13, No. 8, Oct. 1995, pp. 1465-1480. [cited by applicant]
Carasso, D., “Exploring Splunk Search Processing Language (SPL) Primer and Cookbook”, CITO Research, pp. 1-156 (2012). [cited by applicant]
Floyd, S. et al., “The NewReno Modification to TCP's Fast Recovery Algorithm,” Network Working Groups RFC 3782, The Internet Society, Apr. 2004, 18 pages http://www.rfc-editor.org/rfc/rfc3782.txt, accessed Apr. 1, 2011. [cited by applicant]
Floyd, S., “Limited Slow-Start for TCP with Large Congestion Windows”, Network Working Groups RFC 3742, The ntemet Society, https://www.rfc-editor.org/rfc/rfc3742.txt, accessed on Apr. 1, 2011, pp. 1-7 (Mar. 2004). [cited by applicant]
McCallum, E., “The Watchful Eye of FAM”, O'Reilly Media, http://linuxdevcenter.com/pub/a/linux/2004/12/16/fam.html,accessed Mar. 31, 2011 pp. 1-7 (Dec. 16, 2004). [cited by applicant]
Veillard, D., “Gamin the File Alteration Monitor—Overview,” 2 pages http://people.gnome.org/˜veillard/gamin/overview.html, accessed Mar. 31, 2011. [cited by applicant]
U.S. Appl. No. 13/076,296, filed Mar. 30, 2011, Granted. [cited by applicant]
U.S. Appl. No. 13/076,263, filed Mar. 30, 2011, Granted. [cited by applicant]
U.S. Appl. No. 13/662,315, filed Oct. 26, 2012, Abandoned. [cited by applicant]
U.S. Appl. No. 14/014,059, filed Aug. 29, 2013, Granted. [cited by applicant]
U.S. Appl. No. 14/034,220, filed Sep. 23, 2013, Granted. [cited by applicant]
U.S. Appl. No. 14/611,156, filed Jan. 30, 2015, Granted. [cited by applicant]
U.S. Appl. No. 15/224,649, filed Jul. 31, 2016, Granted. [cited by applicant]
U.S. Appl. No. 15/663,652, filed Jul. 28, 2017, Granted. [cited by applicant]
U.S. Appl. No. 16/141,913, filed Sep. 25, 2018, Granted. [cited by applicant]
U.S. Appl. No. 17/080,416, filed Oct. 26, 2020, Granted. [cited by applicant]
U.S. Appl. No. 17/339,117, filed Jun. 4, 2021, Pending. [cited by applicant]
U.S. Appl. No. 18/160,123, filed Jan. 26, 2023, Granted. [cited by applicant]