IP Library Granted Patent US 12,505,099
Granted Patent B1
US 12,505,099 · App. 18/771,534 · Granted Dec 23, 2025

Efficient management of data storage and retrieval

Inventors: Brent Davis (San Francisco, CA); Ryan Russell Delanoy (San Francisco, CA); Karol Julian Olko (Cracow, PL); Tomasz Maciej Sikora (Makow Podhalanski, PL)
Assignee: Cisco Technology, Inc.
G06F16/2453G06F16/2228
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,099
App. No.
18/771,534
Granted
Dec 23, 2025
Kind
B1
Abstract

Embodiments described herein are directed to facilitating efficient management of data storage and retrieval. In one embodiment, filter data associated with a bucket of data is obtained at a local data store from a remote data store. Based on analysis of the filter data, it is determined that the bucket of data is a candidate to contain data relevant to a search query. Based on such a determination, the index data associated with the bucket of data is obtained at the local data store from the remote data store. Thereafter, it may be determined that the bucket of data includes data relevant to the search query based on analysis of the index data. Based on the determination that the bucket of data includes data relevant to the search query, the journal data associated with the bucket of data is obtained at the local data store from the remote data store.

Claims (42)

1 . A computer-implemented method, comprising:

obtaining, at a local data store and from a remote data store, filter data associated with a bucket of data, wherein the bucket of data stored at the remote data store includes the filter data, index data, and journal data;

determining that the bucket of data is a candidate to contain data relevant to a search query based on analysis of the filter data associated with the bucket of data;

based on the determination that the bucket of data is the candidate to contain data relevant to the search query, obtaining, at the local data store and from the remote data store, the index data associated with the bucket of data;

determining that the bucket of data includes data relevant to the search query based on analysis of the index data associated with the bucket of data;

based on the determination that the bucket of data includes data relevant to the search query, obtaining, at the local data store and from the remote data store, the journal data associated with the bucket of data; and

in accordance with completing the analysis of the index data associated with the bucket of data, analyzing a subsequent bucket of data to determine whether the subsequent bucket of data is a new candidate to contain data relevant to the search query.

2 . The computer-implemented method of claim 1 further comprising prefetching filter data associated with a set of buckets of data, including the bucket of data, in association with obtaining the search query.

3 . The computer-implemented method of claim 1 , wherein the analysis of the index data associated with the bucket of data is performed upon analyzing filter data associated with a predetermined number of buckets.

4 . The computer-implemented method of claim 1 , wherein the analysis of the index data associated with the bucket of data is performed upon determining that index data is downloaded to the local data store in association with a predetermined number of unread buckets.

5 . The computer-implemented method of claim 1 , wherein

analyzing the subsequent bucket of data determines that the subsequent bucket of data is eliminated as the new candidate to contain data relevant to the search query; and

based on the subsequent bucket of data being eliminated, analyzing a new subsequent bucket without downloading index data associated with the subsequent bucket of data to the local data store.

6 . The computer-implemented method of claim 1 further comprising analyzing the journal data associated with the bucket of data to extract data relevant to the search query.

7 . The computer-implemented method of claim 1 further comprising extracting data relevant to the search query from the journal data associated with the bucket of data and providing the extracted data relevant to the search query to a search head for providing a set of search results to a user device in response to the search query.

8 . The computer-implemented method of claim 1 , wherein upon the analysis of the index data associated with the bucket of data, initiating downloading of the journal data associated with the bucket of data to the local data store, initiating downloading of filter data associated with a first subsequent bucket of data, and analyzing filter data associated with a second subsequent bucket of data.

9 . The computer-implemented method of claim 1 , wherein the filter data comprises metadata and bloom filter data.

10 . The computer-implemented method of claim 1 , wherein the index data comprises time-series index file data.

11 . The computer-implemented method of claim 1 , wherein the journal data comprises raw event data.

12 . The computer-implemented method of claim 1 , wherein the remote data store comprises a third-party data store accessible over a network.

13 . A computing device, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions when executed by the processor, cause the processor to perform operations including:

obtaining, at a local data store and from a remote data store, filter data associated with a bucket of data, wherein the bucket of data stored at the remote data store includes the filter data, index data, and journal data;

determining that the bucket of data is a candidate to contain data relevant to a search query based on analysis of the filter data associated with the bucket of data;

based on the determination that the bucket of data is the candidate to contain data relevant to the search query, obtaining, at the local data store and from the remote data store, the index data associated with the bucket of data;

determining that the bucket of data includes data relevant to the search query based on analysis of the index data associated with the bucket of data;

based on the determination that bucket of data includes data relevant to the search query, obtaining, at the local data store and from the remote data store, the journal data associated with the bucket of data; and

in accordance with completing the analysis of the index data associated with the bucket of data, analyzing a subsequent bucket of data to determine whether the subsequent bucket of data is a new candidate to contain data relevant to the search query.

14 . The computing device of claim 13 , wherein the analysis of the index data associated with the bucket of data is performed upon analyzing filter data associated with a predetermined number of buckets.

15 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

obtaining, at a local data store and from a remote data store, filter data associated with a bucket of data, wherein the bucket of data stored at the remote data store includes the filter data, index data, and journal data;

determining that the bucket of data is a candidate to contain data relevant to a search query based on analysis of the filter data associated with the bucket of data;

based on the determination that the bucket of data is the candidate to contain data relevant to the search query, obtaining, at the local data store and from the remote data store, the index data associated with the bucket of data;

determining that the bucket of data includes data relevant to the search query based on analysis of the index data associated with the bucket of data; and

based on the determination that bucket of data includes data relevant to the search query, obtaining, at the local data store and from the remote data store, the journal data associated with the bucket of data; and

in accordance with completing the analysis of the index data associated with the bucket of data, analyzing a subsequent bucket of data to determine whether the subsequent bucket of data is a new candidate to contain data relevant to the search query.

16 . The medium of claim 15 , wherein the analysis of the index data associated with the bucket of data is performed upon determining that index data is downloaded to the local data store in association with a predetermined number of unread buckets.

17 . The medium of claim 15 , wherein

analyzing the subsequent bucket of data determines that the subsequent bucket of data is eliminated as the new candidate to contain data relevant to the search query; and

based on the subsequent bucket of data being eliminated, analyzing a new subsequent bucket without downloading index data associated with the subsequent bucket of data to the local data store.

18 . The medium of claim 15 , wherein upon the analysis of the index data associated with the bucket of data, initiating downloading of the journal data associated with the bucket of data to the local data store, initiating downloading of filter data associated with a first subsequent bucket of data, and analyzing filter data associated with a second subsequent bucket of data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: DAVIS, BRENT; DELANOY, RYAN RUSSELL; OLKO, KAROL JULIAN; SIKORA, TOMASZ MACIEJ
To: SPLUNK INC.
Reel/Frame 067978/0667 →
Continuity (1)
Provisional Application 63658335 · Jun 10, 2024
References Cited (23)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8589403B2 · Marquardt · 2013 [cited by examiner]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11074196B1 · Aleti · 2021 [cited by examiner]
US 11567993B1 · Batsakis · 2023 [cited by examiner]
US 11874691B1 · Batsakis · 2024 [cited by examiner]
US 20070027929A1 · Whelan · 2007 [cited by examiner]
US 20070130370A1 · Akaezuwa · 2007 [cited by examiner]
US 20140344391A1 · Varney · 2014 [cited by examiner]
US 20180196824A1 · Bitincka · 2018 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190208013A1 · Lai · 2019 [cited by examiner]
US 20250103229A1 · Wu · 2025 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, First presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]