IP Library Granted Patent US 12,657,185
Granted Patent B1
US 12,657,185 · App. 18/772,809 · Granted Jun 16, 2026

Analyzing a modified query to determine data on which to execute the modified query

Inventors: Jesse Brandau Miller (San Francisco, CA); Marc V. Robichaud (San Francisco, CA); Cory Eugene Burke (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/2425G06F16/2428G06F16/2455G06F16/248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,185
App. No.
18/772,809
Granted
Jun 16, 2026
Kind
B1
Abstract

A method includes causing display to a user of at least one event of a first result set from a first pipelined search on events at an event source. Each event comprises a time stamp and a portion of machine data. A selection of a command is received from the user. The selection is to extend the first pipelined search with the selected command in a second pipelined search. The system selects between the first result set and the event source for execution of the second pipelined search based on an analysis of the selected command and at least one command of the first pipelined search. Based on the selecting being of the first result set, display to the user is caused of at least one event of a second result set from the execution of the second pipelined search on the first result set.

Claims (43)

1 . A computer-implemented method for executing search queries, the method comprising:

identifying an indication of a command selected to modify a query comprising a pipeline query language;

analyzing at least one command of the modified query to determine whether to execute the modified query on an event source having a set of events and whether to execute the modified query on a result set from a previous search performed on the set of events at the event source using the query, wherein each event of the set of events comprises a portion of raw machine data;

based on the determination, executing, by at least one processor, the modified query on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the modified query.

2 . The computer-implemented method of claim 1 , wherein the query corresponds with a plurality of commands represented in a command entry list, and the determining is based on metadata of at least one command entry in the command entry list.

3 . The computer-implemented method of claim 1 , further comprising receiving a selection of the command to use to modify the query, wherein the selection of the command is of an option of a plurality of selectable options in an option menu, each selectable option corresponding to one or more of a plurality of selectable commands.

4 . The computer-implemented method of claim 1 , further comprising:

assigning the result set as a search point prior to identifying the indication of the command selected to modify the query;

determining to retain the result set as the search point, wherein the determining is of the result set based on the determining to retain the result set as the search point.

5 . The computer-implemented method of claim 1 , further comprising:

receiving a selection of the command, the selection being to extend the query with the selected command to generate the modified query;

selecting between the result set and the set of events of the event source for execution of the modified query based on an analysis of at least the selected command; and

based on the selecting being of the result set, causing display of at least one event of a new result set from the execution of the modified query on the result set.

6 . The computer-implemented method of claim 1 , wherein at a time of the execution of the modified query on the result set, the event source includes at least one more event incorporated into the set of events than at a time of execution of the previous search performed using the query.

7 . The computer-implemented method of claim 1 , wherein each event of the set of events comprises a time stamp and the portion of machine data reflects security-related information of at least one computing system.

8 . The computer-implemented method of claim 1 , wherein the modified query comprises the pipeline query language.

9 . The computer-implemented method of claim 1 further comprising generating the modified query based on the command selected.

10 . The computer-implemented method of claim 1 , wherein the at least one command analyzed comprises the command selected to modify the query.

11 . One or more non-transitory computer-readable media having instructions stored thereon, the instructions, when executed by at least one processor of a computing device, to cause the computing device to perform a method comprising:

identifying an indication of a command selected to modify a query comprising a pipeline query language;

analyzing at least one command of the modified query to determine whether to execute the modified query on an event source having a set of events and whether to execute the modified query on a result set from a previous search performed on the set of events at the event source using the query, wherein each event of the set of events comprises a portion of raw machine data;

based on the determination, executing, by at least one processor, the modified query on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the modified query.

12 . The one or more computer-readable media of claim 11 , further comprising receiving a selection of the command to use to modify the query, wherein the selection of the command is of an option of a plurality of selectable options in an option menu, each selectable option corresponding to one or more of a plurality of selectable commands.

13 . The one or more computer-readable media of claim 11 , further comprising:

assigning the result set as a search point prior to identifying the indication of the command selected to modify the query;

determining to retain the result set as the search point, wherein the determining is of the result set based on the determining to retain the result set as the search point.

14 . The one or more computer-readable media of claim 11 , further comprising:

receiving a selection of the command, the selection being to extend the query with the selected command in the modified query;

selecting between the result set and the set of events of the event source for execution of the modified query based on an analysis of the selected command; and

based on the selecting being of the result set, causing display of at least one event of a new result set from the execution of the modified query on the result set.

15 . The one or more computer-readable media of claim 11 , wherein at a time of the execution of the modified query on the result set, the event source includes at least one more event incorporated into the set of events than at a time of execution of the previous search performed using the query.

16 . The one or more computer-readable media of claim 11 , wherein the modified query comprises the pipeline query language.

17 . A system comprising:

at least one processor; and

memory having instructions stored thereon, the instructions, executable by the at least one processor to cause the system to perform a method comprising:

identifying an indication of a command selected to modify a query comprising a pipeline query language;

analyzing at least one command of the modified query to determine whether to execute the modified query on an event source having a set of events and whether to execute the modified query on a result set from a previous search performed on the set of events at the event source using the query, wherein each event of the set of events comprises a portion of raw machine data;

based on the determination, executing, by at least one processor, the modified query on the set of events of the event source or the result set from the previous search performed on the set of events at the event source; and

causing display of at least one event of a second result set from the execution of the modified query.

18 . The system of claim 17 , wherein modified query applies a late-binding schema.

19 . The system of claim 17 , wherein the at least one command analyzed comprises the command selected to modify the query.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
Continuity (3)
Continuation 17874024 · Jul 26, 2022
Continuation 16776317 · Jan 29, 2020
Continuation 15221392 · Jul 27, 2016
References Cited (16)
US 12067007B1 · Miller · 2024 [cited by examiner]
US 20050289109A1 · Arrouye · 2005 [cited by examiner]
US 20090063206A1 · Payne · 2009 [cited by examiner]
US 20090193009A1 · Naick et al. · 2009 [cited by applicant]
US 20090198675A1 · Mihalik et al. · 2009 [cited by applicant]
US 20140053088A1 · Civelli · 2014 [cited by examiner]
US 20150019537A1 · Neels et al. · 2015 [cited by applicant]
US 20150026167A1 · Neels · 2015 [cited by examiner]
US 20150081356A1 · Olson et al. · 2015 [cited by applicant]
US 20160012111A1 · Pattabhiraman et al. · 2016 [cited by applicant]
US 20160034827A1 · Morris · 2016 [cited by applicant]
US 20160335303A1 · Madhalam et al. · 2016 [cited by applicant]
US 20180039638A1 · Krivokon · 2018 [cited by examiner]
U.S. Appl. No. 15/221,392, filed Jul. 27, 2016, Granted. [cited by applicant]
U.S. Appl. No. 16/776,317, filed Jan. 29, 2020, Granted. [cited by applicant]
U.S. Appl. No. 17/874,024, filed Jul. 26, 2022, Granted. [cited by applicant]