IP Library Granted Patent US 12,299,508
Granted Patent B2
US 12,299,508 · App. 18/641,089 · Granted May 13, 2025

Indexing data at a data intake and query system based on a node capacity threshold

Inventors: Shalabh Goyal (Fremont, CA); Anish Shrigondekar (Sunnyvale, CA); Bhavin Thaker (Sunnyvale, CA); Zhenghui Xie (Cupertino, CA); Ruochen Zhang (Milpitas, CA)
G06F9/546G06F11/3006G06F11/3409G06F2201/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,508
App. No.
18/641,089
Granted
May 13, 2025
Kind
B2
Abstract

As an indexer indexes and groups events, it can generate data slices that include events. Based on a slice rollover policy, the indexer can add a particular slice to an aggregate slice. Based on an aggregate slice backup policy, the indexer can store a copy of the aggregate slice to a shared storage system. The aggregate slice can be used for restore purposes in the event the indexer fails or becomes unresponsive.

Claims (45)

1. A method, comprising:

receiving, at an indexing node of a data intake and query system, a message payload including a first plurality of events;

extracting the first plurality of events from the message payload;

adding two or more events of the first plurality of events to a first editable data slice, wherein the first editable data slice is associated with a hot bucket, the hot bucket including at least one index file, and a plurality of aggregate data slices;

based on a slice rollover policy, converting the first editable data slice to a first non-editable data slice and adding the first non-editable data slice to a first aggregate data slice of the plurality of aggregate data slices, wherein the first aggregate data slice comprises a plurality of non-editable data slices, each of the plurality of non-editable data slices comprising a second plurality of events;

concurrent to at least one of adding the two or more events to the first editable data slice or adding the first non-editable data slice to the first aggregate data slice, modifying one or more files of the hot bucket using the two or more events;

based on an aggregate slice backup policy and a determination that a warm bucket corresponding to the hot bucket has not been stored on a remote shared storage system, communicating a copy of the first aggregate data slice to the remote shared storage system for storage, wherein the copy of the first aggregate data slice is communicated independent of the hot bucket; and

based on a bucket rollover policy, converting the hot bucket to a first warm bucket and communicating a copy of the first warm bucket to the remote shared storage system for storage, wherein the copy of the first warm bucket includes a second copy of the first aggregate data slice.

2. The method of claim 1 , wherein each event of the first plurality of events includes raw machine data associated with a timestamp.

3. The method of claim 1 , wherein extracting the first plurality of events comprises decoding the first plurality of events.

4. The method of claim 1 , wherein the two or more events of the first plurality of events are added to the first editable data slice based on an association between the first plurality of events with a particular index, wherein the particular index is associated with the first editable data slice and the hot bucket.

5. The method of claim 1 , wherein adding the first non-editable data slice to the first aggregate data slice includes compressing the first non-editable data slice, and wherein the first non-editable data slice is added to the first aggregate data slice as a compressed first non-editable data slice.

6. The method of claim 1 , wherein the slice rollover policy includes a slice size threshold, and wherein the first non-editable data slice is added to the first aggregate data slice based on a determination that a size of the first non-editable data slice satisfies the slice size threshold.

7. The method of claim 1 , wherein the slice rollover policy includes a slice time threshold, and wherein the first non-editable data slice is added to the first aggregate data slice based on a determination that an amount of time since the first non-editable data slice was generated satisfies the slice time threshold.

8. The method of claim 1 , wherein the aggregate slice backup policy includes a slice size threshold, and wherein the copy of the first aggregate data slice is stored to the remote shared storage system based on a determination that a size of the first aggregate data slice satisfies the slice size threshold.

9. The method of claim 1 , wherein the aggregate slice backup policy includes a slice time threshold, and wherein the copy of the first aggregate data slice is stored to the remote shared storage system based on a determination that an amount of time since the first aggregate data slice was generated satisfies the slice time threshold.

10. The method of claim 1 , further comprising based on the bucket rollover policy, generating a second hot bucket.

11. The method of claim 1 , wherein the bucket rollover policy includes a bucket size threshold, wherein converting the hot bucket to a first warm bucket and communicating a copy of the first warm bucket to the remote shared storage system for storage is further based on a determination that a size of the hot bucket satisfies the bucket size threshold.

12. The method of claim 1 , wherein the bucket rollover policy includes a bucket timing threshold, wherein converting the hot bucket to a first warm bucket and communicating a copy of the first warm bucket to the remote shared storage system for storage is further based on a determination that an amount of time since the hot bucket was generated satisfies the bucket timing threshold.

13. The method of claim 1 , further comprising, based on a determination that the copy of the first warm bucket is stored on the remote shared storage system, removing the copy of the first aggregate data slice from the remote shared storage system.

14. The method of claim 1 , wherein the message payload is received from a remote message bus, and wherein the method further comprises:

identifying for each event of the first plurality of events, a particular bucket that includes the event; and

based on a determination that a copy of each bucket that includes at least one event of the first plurality of events was stored to the remote shared storage system, communicating an acknowledgement to the remote message bus, wherein the remote message bus deletes the message payload in response to the acknowledgement.

15. The method of claim 1 , further comprising, based at least in part on communicating the copy of the first aggregate data slice, generating an additional aggregate data slice, wherein the additional aggregate data slice is associated with the hot bucket.

16. A computing device, comprising:

memory; and

one or more processing devices communicatively coupled to the memory and configured to:

receive, at an indexing node of a data intake and query system, a message payload including a first plurality of events;

extract the first plurality of events from the message payload;

add two or more events of the first plurality of events to a first editable data slice, wherein the first editable data slice is associated with a hot bucket, the hot bucket including at least one index file, and a plurality of aggregate data slices;

based on a slice rollover policy, convert the first editable data slice to a first non-editable data slice and adding the first non-editable data slice to a first aggregate data slice of the plurality of aggregate data slices, wherein the first aggregate data slice comprises a plurality of non-editable data slices, each of the plurality of non-editable data slices comprising a second plurality of events;

concurrent to at least one of addition of the two or more events to the first editable data slice or addition of the first non-editable data slice to the first aggregate data slice, modify one or more files of the hot bucket using the two or more events;

based on an aggregate slice backup policy and a determination that a warm bucket corresponding to the hot bucket has not been stored on a remote shared storage system, communicate a copy of the first aggregate data slice to the remote shared storage system for storage, wherein the copy of the first aggregate data slice is communicated independent of the hot bucket; and

based on a bucket rollover policy, convert the hot bucket to a first warm bucket and communicate a copy of the first warm bucket to the remote shared storage system for storage, wherein the copy of the first warm bucket includes a second copy of the first aggregate data slice.

17. The computing device of claim 16 , wherein each event of the first plurality of events includes raw machine data associated with a timestamp.

18. The computing device of claim 16 , wherein the two or more events of the first plurality of events are added to the first editable data slice based on an association between the first plurality of events with a particular index, wherein the particular index is associated with the first editable data slice and the hot bucket.

19. The computing device of claim 16 , wherein the slice rollover policy includes a slice size threshold, and wherein the first non-editable data slice is added to the first aggregate data slice based on a determination that a size of the first non-editable data slice satisfies the slice size threshold.

20. Non-transitory computer-readable media comprising computer-executable instructions that when executed by one or more processing devices, causes the one or more processing devices to:

receive, at an indexing node of a data intake and query system, a message payload including a first plurality of events;

extract the first plurality of events from the message payload;

add two or more events of the first plurality of events to a first editable data slice, wherein the first editable data slice is associated with a hot bucket, the hot bucket including at least one index file, and a plurality of aggregate data slices;

based on a slice rollover policy, convert the first editable data slice to a first non-editable data slice and adding the first non-editable data slice to a first aggregate data slice of the plurality of aggregate data slices, wherein the first aggregate data slice comprises a plurality of non-editable data slices, each of the plurality of non-editable data slices comprising a second plurality of events;

concurrent to at least one of addition of the two or more events to the first editable data slice or addition of the first non-editable data slice to the first aggregate data slice, modify one or more files of the hot bucket using the two or more events;

based on an aggregate slice backup policy and a determination that a warm bucket corresponding to the hot bucket has not been stored on a remote shared storage system, communicate a copy of the first aggregate data slice to the remote shared storage system for storage, wherein the copy of the first aggregate data slice is communicated independent of the hot bucket; and

based on a bucket rollover policy, convert the hot bucket to a first warm bucket and communicate a copy of the first warm bucket to the remote shared storage system for storage, wherein the copy of the first warm bucket includes a second copy of the first aggregate data slice.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: SHRIGONDEKAR, ANISH; ZHANG, RUOCHEN; XIE, ZHENGHUI; GOYAL, SHALABH; THAKER, BHAVIN
To: SPLUNK INC.
Reel/Frame 070754/0141 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
Continuity (3)
Continuation 17933455 · Sep 19, 2022
Continuation 16945645 · Jul 31, 2020
Related Publication 20250094253A1 · Mar 20, 2025
References Cited (179)
US 5566171A · Levinson · 1996 [cited by applicant]
US 5914874A · Nohara · 1999 [cited by applicant]
US 7401132B1 · Krumel et al. · 2008 [cited by applicant]
US 7917495B1 · Chapman et al. · 2011 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8312037B1 · Bacthavachalu et al. · 2012 [cited by applicant]
US 8504521B2 · Okamoto · 2013 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8776086B1 · Chhabra et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9063939B2 · Dalton · 2015 [cited by applicant]
US 9092502B1 · Cannaliato et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9356995B1 · Schaeffer, III · 2016 [cited by applicant]
US 9451025B2 · Kazi et al. · 2016 [cited by applicant]
US 9785480B2 · Kamawat et al. · 2017 [cited by applicant]
US 9917888B1 · Bonagiri et al. · 2018 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10129118B1 · Ghare et al. · 2018 [cited by applicant]
US 10162875B2 · Hattori · 2018 [cited by applicant]
US 10194001B1 · Gardiner et al. · 2019 [cited by applicant]
US 10325032B2 · Dageville et al. · 2019 [cited by applicant]
US 10474544B1 · Li et al. · 2019 [cited by applicant]
US 10474656B1 · Bronnikov · 2019 [cited by applicant]
US 10585755B2 · Yamamoto · 2020 [cited by applicant]
US 10616314B1 · Plenderleith et al. · 2020 [cited by applicant]
US 10620883B1 · Cai et al. · 2020 [cited by applicant]
US 10657061B1 · Marriner · 2020 [cited by applicant]
US 10684888B1 · Sethuramalingam et al. · 2020 [cited by applicant]
US 10685041B2 · Hattori · 2020 [cited by applicant]
US 10740009B2 · Chen et al. · 2020 [cited by applicant]
US 10795735B1 · Potnis et al. · 2020 [cited by applicant]
US 10924548B1 · Karumbunathan et al. · 2021 [cited by applicant]
US 10936589B1 · Beitchman et al. · 2021 [cited by applicant]
US 10963189B1 · Neelakantam et al. · 2021 [cited by applicant]
US 10990480B1 · Bernat et al. · 2021 [cited by applicant]
US 11003714B1 · Batsakis et al. · 2021 [cited by applicant]
US 11089105B1 · Karumbunathan et al. · 2021 [cited by applicant]
US 11119989B1 · Dance · 2021 [cited by applicant]
US 11120800B1 · Cheng et al. · 2021 [cited by applicant]
US 11157497B1 · Batsakis et al. · 2021 [cited by applicant]
US 11275733B1 · Batsakis et al. · 2022 [cited by applicant]
US 11294916B2 · Kondiles et al. · 2022 [cited by applicant]
US 11327992B1 · Batakis et al. · 2022 [cited by applicant]
US 11334543B1 · Anwar et al. · 2022 [cited by applicant]
US 11416465B1 · Anwar et al. · 2022 [cited by applicant]
US 11436116B1 · Batsakis et al. · 2022 [cited by applicant]
US 11449371B1 · Goyal et al. · 2022 [cited by applicant]
US 11609913B1 · Anwar et al. · 2023 [cited by applicant]
US 11615082B1 · Shrigondekar et al. · 2023 [cited by applicant]
US 11620288B2 · Batsakis et al. · 2023 [cited by applicant]
US 11809395B1 · Fan et al. · 2023 [cited by applicant]
US 11892996B1 · Anwar et al. · 2024 [cited by applicant]
US 11966797B2 · Goyal et al. · 2024 [cited by applicant]
US 12019634B1 · Anwar et al. · 2024 [cited by applicant]
US 20040153528A1 · Suzuki · 2004 [cited by applicant]
US 20060015773A1 · Singh et al. · 2006 [cited by applicant]
US 20060114903A1 · Duffy, IV et al. · 2006 [cited by applicant]
US 20070037563A1 · Yang et al. · 2007 [cited by applicant]
US 20080013566A1 · Smith et al. · 2008 [cited by applicant]
US 20080215546A1 · Baum et al. · 2008 [cited by applicant]
US 20080294661A1 · Garza et al. · 2008 [cited by applicant]
US 20100005055A1 · An et al. · 2010 [cited by applicant]
US 20100063950A1 · Joshi et al. · 2010 [cited by applicant]
US 20100106767A1 · Livshits et al. · 2010 [cited by applicant]
US 20100107158A1 · Chen et al. · 2010 [cited by applicant]
US 20100122184A1 · Vonog et al. · 2010 [cited by applicant]
US 20100293555A1 · Vepsalainen · 2010 [cited by applicant]
US 20100318650A1 · Nielsen · 2010 [cited by applicant]
US 20110041136A1 · Messier et al. · 2011 [cited by applicant]
US 20110199899A1 · Lemaire et al. · 2011 [cited by applicant]
US 20110298596A1 · Warrick · 2011 [cited by applicant]
US 20120078975A1 · Chen et al. · 2012 [cited by applicant]
US 20120317579A1 · Liu · 2012 [cited by applicant]
US 20130091251A1 · Walker et al. · 2013 [cited by applicant]
US 20130151535A1 · Dusberger et al. · 2013 [cited by applicant]
US 20130311735A1 · Sivakumar et al. · 2013 [cited by applicant]
US 20140071290A1 · Collen et al. · 2014 [cited by applicant]
US 20140108633A1 · Dai et al. · 2014 [cited by applicant]
US 20140136255A1 · Grabovski et al. · 2014 [cited by applicant]
US 20140149783A1 · Georgiev · 2014 [cited by applicant]
US 20140189062A1 · Yan et al. · 2014 [cited by applicant]
US 20140236889A1 · Vasan et al. · 2014 [cited by applicant]
US 20140236890A1 · Vasan et al. · 2014 [cited by applicant]
US 20140366020A1 · Lee et al. · 2014 [cited by applicant]
US 20140372616A1 · Arisoylu et al. · 2014 [cited by applicant]
US 20150067097A1 · Hsia et al. · 2015 [cited by applicant]
US 20150095457A1 · Goda et al. · 2015 [cited by applicant]
US 20150120928A1 · Gummaraju et al. · 2015 [cited by applicant]
US 20150347523A1 · Patel · 2015 [cited by examiner]
US 20160036903A1 · Pal et al. · 2016 [cited by applicant]
US 20160055225A1 · Xu et al. · 2016 [cited by applicant]
US 20160087855A1 · Vlachogiannis et al. · 2016 [cited by applicant]
US 20160117318A1 · Helland · 2016 [cited by applicant]
US 20160210071A1 · Kawahara · 2016 [cited by applicant]
US 20160224570A1 · Sharp et al. · 2016 [cited by applicant]
US 20160224660A1 · Munk et al. · 2016 [cited by applicant]
US 20160226731A1 · Maroulis · 2016 [cited by applicant]
US 20160261716A1 · Khalaf et al. · 2016 [cited by applicant]
US 20160314163A1 · Marquardt et al. · 2016 [cited by applicant]
US 20160314211A1 · Kerai et al. · 2016 [cited by applicant]
US 20160321352A1 · Patel et al. · 2016 [cited by applicant]
US 20160323193A1 · Zhou et al. · 2016 [cited by applicant]
US 20170055916A1 · Bhattacharya et al. · 2017 [cited by applicant]
US 20170139996A1 · Marquardt et al. · 2017 [cited by applicant]
US 20170163724A1 · Puri et al. · 2017 [cited by applicant]
US 20170220651A1 · Mathew et al. · 2017 [cited by applicant]
US 20170262551A1 · Cho et al. · 2017 [cited by applicant]
US 20170286038A1 · Li et al. · 2017 [cited by applicant]
US 20170329390A1 · Shah et al. · 2017 [cited by applicant]
US 20170346887A1 · Kaguma et al. · 2017 [cited by applicant]
US 20170371568A1 · Aravot et al. · 2017 [cited by applicant]
US 20180032478A1 · Felderman et al. · 2018 [cited by applicant]
US 20180089278A1 · Bhattacharjee et al. · 2018 [cited by applicant]
US 20180089328A1 · Bath et al. · 2018 [cited by applicant]
US 20180241802A1 · Bernat et al. · 2018 [cited by applicant]
US 20180255121A1 · Hiltunen et al. · 2018 [cited by applicant]
US 20180285418A1 · Petropoulos et al. · 2018 [cited by applicant]
US 20180314746A1 · Gujarathi · 2018 [cited by applicant]
US 20180322157A1 · Lee et al. · 2018 [cited by applicant]
US 20190005067A1 · Bao et al. · 2019 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190155714A1 · Zhang et al. · 2019 [cited by applicant]
US 20190155806A1 · Mathew et al. · 2019 [cited by applicant]
US 20190171748A1 · Duffield · 2019 [cited by applicant]
US 20190188315A1 · Hsieh et al. · 2019 [cited by applicant]
US 20200044927A1 · Apostolopoulos et al. · 2020 [cited by applicant]
US 20200050372A1 · Venkatesh et al. · 2020 [cited by applicant]
US 20200050607A1 · Pal et al. · 2020 [cited by applicant]
US 20200068010A1 · Xing et al. · 2020 [cited by applicant]
US 20200073876A1 · Lopez et al. · 2020 [cited by applicant]
US 20200082015A1 · Watts et al. · 2020 [cited by applicant]
US 20200104864A1 · Mohanlal et al. · 2020 [cited by applicant]
US 20200128094A1 · De Lavarene et al. · 2020 [cited by applicant]
US 20200177333A1 · Liu · 2020 [cited by applicant]
US 20200195501A1 · Shenoy et al. · 2020 [cited by applicant]
US 20200265087A1 · Verma · 2020 [cited by applicant]
US 20200310884A1 · Villalobos et al. · 2020 [cited by applicant]
US 20200327953A1 · Fleming et al. · 2020 [cited by applicant]
US 20200364223A1 · Pal et al. · 2020 [cited by applicant]
US 20200394225A1 · Nair et al. · 2020 [cited by applicant]
US 20200403822A1 · Pompelio · 2020 [cited by applicant]
US 20210034571A1 · Bedadala et al. · 2021 [cited by applicant]
US 20210173748A1 · Mukku · 2021 [cited by applicant]
US 20230014346A1 · Goyal et al. · 2023 [cited by applicant]
US 20240111606A1 · Chanler et al. · 2024 [cited by applicant]
US 20240118905A1 · Kondiles et al. · 2024 [cited by applicant]
US 20240202006A1 · Krijger et al. · 2024 [cited by applicant]
WO WO2013170041A2 · 2013 [cited by examiner]
WO WO2019245445A1 · 2019 [cited by examiner]
Alfred, “What we do,” URL: https://helloalfred.com/what-we-do/, in 4 pages, captured Aug. 27, 2019. [cited by applicant]
Balazinska, et al., Fault-tolerance and high availability in data stream management systes; https://homes.cs.washington.edu/-magda/encyclopedia-short.pdf; Publication Date Provided by WayBack Machine: Aug. 12, 2017 at 1… [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Google Scholar/Patents—text refined (Year: 2021). [cited by applicant]
SLAML 10 Reports, Workshop On Managing Systems via Log Analysis and Machine Learning Techniques, ;login: Feb. 2011 Conference Reports. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
U.S. Appl. No. 16/513,365, filed Jul. 16, 2019. [cited by applicant]
U.S. Appl. No. 16/778,427, filed Jan. 31, 2020. [cited by applicant]
U.S. Appl. No. 16/778,498, filed Jan. 31, 2020. [cited by applicant]
U.S. Appl. No. 17/162,477, filed Jan. 29, 2021. [cited by applicant]
U.S. Appl. No. 17/162,491, filed Jan. 29, 2021. [cited by applicant]
U.S. Appl. No. 16/945,578, filed Jul. 31, 2020, Sajja et al. [cited by applicant]
U.S. Appl. No. 16/945,631, filed Jul. 31, 2020, Shrigondekar et al. [cited by applicant]
U.S. Appl. No. 16/945,645, filed Jul. 31, 2020, Goyal et al. [cited by applicant]
U.S. Appl. No. 16/945,646, filed Jul. 31, 2020, Shrigondekar et al. [cited by applicant]
U.S. Appl. No. 17/901,586, filed Sep. 1, 2022, Batsakis et al. [cited by applicant]
U.S. Appl. No. 17/933,455, filed Sep. 19, 2022, Goyal et al. [cited by applicant]
U.S. Appl. No. 18/123,758, filed Mar. 20, 2023, Anwar et al. [cited by applicant]
U.S. Appl. No. 18/295,123, filed Apr. 3, 2023, Batsakis et al. [cited by applicant]
U.S. Appl. No. 18/329,874, filed Jun. 6, 2023, Anwar et al. [cited by applicant]
U.S. Appl. No. 18/542,468, filed Dec. 15, 2023, Anwar et al. [cited by applicant]
U.S. Appl. No. 18/162,480, filed Jan. 31, 2023, Xie et al. [cited by applicant]
U.S. Appl. No. 18/162,273, filed Jan. 31, 2023, Xie et al. [cited by applicant]
U.S. Appl. No. 18/735,936, filed Jun. 6, 2024, Anwar et al. [cited by applicant]