IP Library Granted Patent US 12,326,875
Granted Patent B2
US 12,326,875 · App. 18/675,896 · Granted Jun 10, 2025

Disaster recovery in a clustered environment using generation identifiers

Inventors: Da Xu (San Francisco, CA); Sundar Vasan (San Francisco, CA); Dhruva Kumar Bhagi (Union City, CA)
Assignee: Cisco Technology, Inc.
G06F16/27G06F11/2094G06F11/3006G06F11/3072G06F11/32G06F11/3409G06F11/3476G06F16/2272H04L67/1097G06F3/0617G06F2201/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,326,875
App. No.
18/675,896
Filed
May 28, 2024
Granted
Jun 10, 2025
Kind
B2
Art Unit
2159
USPC
707/624
Abstract

A method for performing disaster recovery in a clustered environment comprises identifying, at a master device, a first indexer from a set of indexers to serve as a primary indexer for responding to queries pertaining to a subset of data. The method also comprises assigning, at the master device, a generation identifier indicating that the first indexer is the primary indexer for the subset of data. Responsive to an event prompting a change in a primary indexer designation for the subset of data, the method comprises identifying, at the master device, a second indexer from the set of indexers to serve as the primary indexer for responding to queries pertaining to the subset of data. Further, the method comprises assigning, at the master device, a new generation identifier indicating that the second indexer is the primary indexer for the subset of data.

Claims (44)

1. A method comprising:

receiving, at an indexer, a generation identifier, wherein the generation identifier indicates that the indexer has primary responsibility for responding to search queries for a first grouped subset of data, wherein the indexer is one of a plurality of indexers included in a cluster, and wherein a master node coordinates searches against data indexed by the plurality of indexers in the cluster;

generating, at the indexer, summary data corresponding to the first grouped subset of data based on instructions received by the indexer;

receiving, at the indexer, a search query;

determining, based on the generation identifier, that the indexer has primary responsibility for responding to the search query; and

generating results for the search query based upon the summary data and the first grouped subset of data.

2. The method of claim 1 , wherein the summary data is associated with a report, and wherein the search query is a recurring search used to generate the report.

3. The method of claim 1 , wherein the summary data is associated with a data model for data stored by the cluster, and wherein the results correspond to fields included in the data model.

4. The method of claim 1 , wherein the summary data is generated prior to receiving the search query at the indexer.

5. The method of claim 1 , further comprising generating results for a subsequent instance of the search query based upon the summary data.

6. The method of claim 1 , further comprising generating results of a subsequent search query based upon the summary data, wherein the subsequent search query is different from the search query.

7. The method of claim 1 , wherein the data is transformed using at least one of an aggregation operation, a filtering operation, or a data conversion.

8. The method of claim 1 , further comprising:

receiving a new generation identifier at the indexer indicating that a new indexer has primary responsibility for the search query;

replicating the summary data; and

transmitting the summary data to the new indexer.

9. The method of claim 1 , further comprising:

determining that the summary data corresponding to the search query is not stored by the indexer; and

generating the summary data.

10. The method of claim 1 , further comprising:

identifying a replication factor that indicates a number of times that the first grouped subset of data is to be replicated; and

transmitting the first subset of data to a number of other indexers, wherein the number corresponds to the replication factor.

11. A non-transitory computer-readable medium storing computer-executable instructions which, when executed by a processor, cause the processor to perform operations comprising:

receiving, at an indexer, a generation identifier, wherein the generation identifier indicates that the indexer has primary responsibility for responding to search queries for a first grouped subset of data, wherein the indexer is one of a plurality of indexers included in a cluster, and wherein a master node coordinates searches against data indexed by the plurality of indexers in the cluster;

generating, at the indexer, summary data corresponding to the first grouped subset of data based on instructions received by the indexer;

receiving, at the indexer, a search query;

determining, based on the generation identifier, that the indexer has primary responsibility for responding to the search query; and

generating results for the search query based upon the summary data and the first grouped subset of data.

12. The non-transitory computer-readable medium of claim 11 , wherein the generation identifier is generated by the master node of the cluster.

13. The non-transitory computer-readable medium of claim 11 , further comprising sending, by a master node of the cluster, summary data replication instructions to the indexer, the summary data replication instructions causing the indexer to send the summary data to a second indexer in the cluster.

14. The non-transitory computer-readable medium of claim 11 , wherein the grouped subset of data includes a plurality of events, and wherein the plurality of events are associated with a time span.

15. The non-transitory computer-readable medium of claim 11 , wherein the summary data is associated with a report, and wherein the search query is a recurring search used to generate the report.

16. The non-transitory computer-readable medium of claim 11 , wherein the summary data is associated with a data model for data stored by the group of indexers, and wherein the results correspond to fields included in the data model.

17. The non-transitory computer-readable medium of claim 11 , wherein the summary data is generated prior to receiving the search query at the indexer.

18. The non-transitory computer-readable medium of claim 11 , further comprising generating results for a subsequent instance of the search query based upon the summary data.

19. The non-transitory computer-readable medium of claim 11 , wherein the data is transformed using at least one of an aggregation operation, a filtering operation, or a data conversion.

20. A system comprising:

one or more memories; and

one or more processors for:

receiving, at an indexer, a generation identifier, wherein the generation identifier indicates that the indexer has primary responsibility for responding to search queries for a first grouped subset of data, wherein the indexer is one of a plurality of indexers included in a cluster, and wherein a master node coordinates searches against data indexed by the plurality of indexers in the cluster;

generating, at the indexer, summary data corresponding to the first grouped subset of data based on instructions received by the indexer;

receiving, at the indexer, a search query;

determining, based on the generation identifier, that the indexer has primary responsibility for responding to the search query; and

generating results for the search query based upon the summary data and the first grouped subset of data.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2024
From: XU, DA; VASAN, SUNDAR; BHAGI, DHRUVA KUMAR
To: SPLUNK INC.
Reel/Frame 068248/0530 →
Continuity (9)
Continuation 18313240 · May 5, 2023
Continuation 17228429 · Apr 12, 2021
Continuation 16451582 · Jun 25, 2019
Continuation 14929089 · Oct 30, 2015
Continuation In Part 14815880 · Jul 31, 2015
Continuation 14266812 · Apr 30, 2014
Continuation In Part 13648116 · Oct 9, 2012
Provisional Application 61647245 · May 15, 2012
Related Publication 20240362252A1 · Oct 31, 2024
References Cited (92)
US 5717911A · Madrid et al. · 1998 [cited by applicant]
US 5975738A · DeKoning et al. · 1999 [cited by applicant]
US 6334124B1 · Bouchard et al. · 2001 [cited by applicant]
US 6353831B1 · Gustman · 2002 [cited by applicant]
US 6823336B1 · Srinivasan et al. · 2004 [cited by applicant]
US 6839819B2 · Martin · 2005 [cited by applicant]
US 7085904B2 · Mizuno et al. · 2006 [cited by applicant]
US 7162601B2 · Yamagami · 2007 [cited by applicant]
US 7167880B2 · Amano et al. · 2007 [cited by applicant]
US 7243197B2 · Yamagami · 2007 [cited by applicant]
US 7693885B2 · Okada et al. · 2010 [cited by applicant]
US 7792897B2 · Foss et al. · 2010 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8195153B1 · Frencel et al. · 2012 [cited by applicant]
US 8438277B1 · Chepuri et al. · 2013 [cited by applicant]
US 8560886B1 · Kekre et al. · 2013 [cited by applicant]
US 8732162B2 · Harris · 2014 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788459B2 · Patel et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9124612B2 · Vasan et al. · 2015 [cited by applicant]
US 9130971B2 · Vasan et al. · 2015 [cited by applicant]
US 9160798B2 · Patel et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20020062336A1 · Teodosiu et al. · 2002 [cited by applicant]
US 20020107934A1 · Lowery et al. · 2002 [cited by applicant]
US 20030070044A1 · Jeddeloh · 2003 [cited by applicant]
US 20030120751A1 · Husain et al. · 2003 [cited by applicant]
US 20040199553A1 · Byrne et al. · 2004 [cited by applicant]
US 20040268067A1 · Yamagami · 2004 [cited by applicant]
US 20050015416A1 · Yamagami · 2005 [cited by applicant]
US 20050027685A1 · Kamwar et al. · 2005 [cited by applicant]
US 20050235016A1 · Amano et al. · 2005 [cited by applicant]
US 20050268145A1 · Hufferd et al. · 2005 [cited by applicant]
US 20060101045A1 · Chen et al. · 2006 [cited by applicant]
US 20060149798A1 · Yamagami · 2006 [cited by applicant]
US 20060168154A1 · Zhang et al. · 2006 [cited by applicant]
US 20060179129A1 · Clayton et al. · 2006 [cited by applicant]
US 20070083567A1 · Arai et al. · 2007 [cited by applicant]
US 20070094312A1 · Sim-Tang · 2007 [cited by applicant]
US 20070100917A1 · Amano et al. · 2007 [cited by applicant]
US 20070112893A1 · Okada et al. · 2007 [cited by applicant]
US 20070112894A1 · Okada et al. · 2007 [cited by applicant]
US 20070115738A1 · Emaru et al. · 2007 [cited by applicant]
US 20070174246A1 · Sigurdsson et al. · 2007 [cited by applicant]
US 20070185923A1 · Nishikawa et al. · 2007 [cited by applicant]
US 20070198604A1 · Okada et al. · 2007 [cited by applicant]
US 20070220309A1 · Andre et al. · 2007 [cited by applicant]
US 20080199155A1 · Hagens et al. · 2008 [cited by applicant]
US 20090271412A1 · Lacapra et al. · 2009 [cited by applicant]
US 20100005151A1 · Gokhale · 2010 [cited by applicant]
US 20100191922A1 · Dickey et al. · 2010 [cited by applicant]
US 20100318538A1 · Wyman et al. · 2010 [cited by applicant]
US 20110055231A1 · Huck et al. · 2011 [cited by applicant]
US 20110060716A1 · Forman et al. · 2011 [cited by applicant]
US 20110161335A1 · Dash et al. · 2011 [cited by applicant]
US 20120110015A1 · Nath et al. · 2012 [cited by applicant]
US 20120144033A1 · Daude et al. · 2012 [cited by applicant]
US 20120278344A1 · Berg et al. · 2012 [cited by applicant]
US 20120297236A1 · Ziskind et al. · 2012 [cited by applicant]
US 20120310912A1 · Shah et al. · 2012 [cited by applicant]
US 20130311428A1 · Patel et al. · 2013 [cited by applicant]
US 20140236889A1 · Vasan et al. · 2014 [cited by applicant]
US 20140236890A1 · Vasan et al. · 2014 [cited by applicant]
US 20150339308A1 · Vasan et al. · 2015 [cited by applicant]
US 20150347523A1 · Patel et al. · 2015 [cited by applicant]
US 20160055225A1 · Xu et al. · 2016 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
EP 1804167A2 · 2007 [cited by applicant]
Splunk Answers, “What is a search head?”, Apr. 14, 2010, 2 pages. [cited by applicant]
Wikipedia, “High-Availability Cluster”, Wikipedia, Free Encyclopedia, http://en.wikipedia.org/wiki/High-availability-cluster, Oct. 24, 2012, 4 pages. [cited by applicant]
Wikipedia, “Raid”, Wikipedia, the free encyclopedia, http://en.wikipedia.org/wiki/RAID, Nov. 2, 2012, 23 pages. [cited by applicant]
Adams, Michael, “How Snapshot Technology Will Change the Future of Backup and Recovery”, Technology information, Computer Technology Review, Jan. 2001, 4 pages. [cited by applicant]
Carasso, David, “Exploring Splunk”, Search Processing Language {SPL) Primer and Cookbook, Splunk, Apr. 2012, 156 pages. [cited by applicant]
Kaczmarski et al., “Beyond Backup Toward Storage Management”, IBM Systems Journal , vol. 42, No. 2, Apr. 2003, 4 pages. [cited by applicant]
Brain, Marshall., “How Domain Servers Work”, Feb. 1, 2009, 4 pages. [cited by applicant]
IEEE, “The Authoritative Dictionary of IEEE Standards Terms”, Seventh Edition, 2000, 3 pages. [cited by applicant]
Searchstorage.com, “Common Information Model (CIM)”, Sep. 21, 2005, 1 page. [cited by applicant]
Splunk Wiki, “Community: Forwarder Best Practice”, Splunk Wiki, Nov. 19, 2009, 1 page. [cited by applicant]
Splunk Wiki, “Community: Understanding Buckets”, Splunk Wiki, May 3, 2011, 3 pages. [cited by applicant]
Splunk Wiki, “Community: MultipleIndex Server Deployment Options”, Splunk Wiki, Apr. 26, 2011, 2 pages. [cited by applicant]
Fairhust, “IPv4 Packet Header”, 2008, 2 pages. [cited by applicant]
XGC, “Metanode Organized Prototype Hierarchy Specification (Morph)”, Version 0.9b, Mar. 7, 2006, 48 pages. [cited by applicant]
Jackson, Joab., “NPR Deploys Splunk for Web Analytics”, Mar. 24, 2011, 3 pages. [cited by applicant]
Sinofsky, Steven., “Designing The Windows 8 File Name Collision Experience”, Aug. 26, 2011, 2 Pages. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved on May 20, 2020 from docs.splunk.com, 17 pages. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved on May 20, 2020 from docs.splunk.com, 66 pages. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved on May 20, 2020, 6 pages. [cited by applicant]
Bitincka et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”, Vancou… [cited by applicant]