IP Library Granted Patent US 12,566,710
Granted Patent B2
US 12,566,710 · App. 18/884,821 · Granted Mar 3, 2026

Cache aware searching

Inventors: Ledion Bitincka (San Francisco, CA); Alexandros Batsakis (San Francisco, CA); Paul J. Lucas (San Francisco, CA); Nicholas Robert Romito (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F12/0875G06F3/061G06F3/0611G06F12/0802G06F12/0862G06F12/0866G06F12/0868G06F12/0871G06F12/0873G06F16/148G06F16/172G06F16/951G06F16/9574G06F2212/1021G06F2212/45G06F2212/6024G06F2212/6026G06F2212/6028
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,566,710
App. No.
18/884,821
Granted
Mar 3, 2026
Kind
B2
Abstract

Embodiments are disclosed for performing cache aware searching. In response to a search query, a first bucket and a second bucket in remote storage for processing the search query. A determination is made that a first file in the first bucket is present in a cache when the search query is received. In response to the search query, a search is performed using the first file based on the determination that the first file is present in the cache when the search query is received, and the search is performed using a second file from the second bucket once the second file is stored in the cache.

Claims (38)

1 . A method comprising:

obtaining, at a cache and from remote storage, a metadata file associated with a bucket of data, wherein the bucket of data stored at the remote storage includes the metadata file, an index file, and a journal file;

determining that the index file of the bucket of data is predicted to contain data relevant to a search query;

based on the determination that the index file of the bucket of data is predicted to contain data relevant to the search query, obtaining, at the cache and from the remote storage, the index file associated with the bucket of data;

determining that the journal file of the bucket of data is predicted to include data relevant to the search query; and

based on the determination that the journal file of the bucket of data is predicted to include data relevant to the search query, obtaining, at the cache and from the remote storage, the journal file associated with the bucket of data.

2 . The method of claim 1 , further comprising updating a location of the index file of the bucket of data in a cache map to indicate a cache address corresponding to a location of the metadata file in the cache.

3 . The method of claim 2 , further comprising communicating the cache address of the index file of the bucket of data to a search process.

4 . The method of claim 3 , further comprising assigning a usage status to the index file of the bucket of data.

5 . The method of claim 1 , further comprising generating a result of evaluating a query using the index file of the bucket of data.

6 . The method of claim 1 , wherein the metadata file is obtained based on a prediction that the metadata file will be used during execution of a query relative to the bucket of data.

7 . The method of claim 6 , wherein the prediction is based on a lack of any usage status in a file usage history for one or more metadata files in previously processed buckets of data.

8 . The method of claim 6 , wherein the prediction is based on a usage status in at least one of an immediately preceding bucket of data of a same file type.

9 . The method of claim 1 , further comprising updating a location of the metadata file in a cache map to indicate a cache address corresponding to a location of the metadata file in the cache.

10 . The method of claim 1 , wherein the determining that the journal file of the bucket of data is predicted to include data relevant to the search query is based on a usage status in a file usage history for index files in one or more buckets of data.

11 . The method of claim 1 , further comprising using at least one of the metadata file, the index file, and the journal file to execute the search query.

12 . The method of claim 1 , wherein the bucket of data comprises at least one event, each event in the at least one event comprises a portion of raw machine data associated with a timestamp.

13 . The method of claim 1 , wherein the bucket of data is associated with a first time frame.

14 . The method of claim 1 , wherein the remote storage is located in a cloud storage or a storage in an on-premises environment.

15 . A computer system, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

obtaining, at a cache and from remote storage, a metadata file associated with a bucket of data, wherein the bucket of data stored at the remote storage includes the metadata file, an index file, and a journal file;

determining that the index file of the bucket of data is predicted to contain data relevant to a search query;

based on the determination that the index file of the bucket of data is predicted to contain data relevant to the search query, obtaining, at the cache and from the remote storage, the index file associated with the bucket of data;

determining that the journal file of the bucket of data is predicted to include data relevant to the search query; and

based on the determination that the journal file of the bucket of data is predicted to include data relevant to the search query, obtaining, at the cache and from the remote storage, the journal file associated with the bucket of data.

16 . The computer system of claim 15 , wherein the bucket of data comprises at least one event, each event in the at least one event comprises a portion of raw machine data associated with a timestamp.

17 . The computer system of claim 15 , wherein the determining that the journal file of the bucket of data is predicted to include data relevant to the search query is based on a usage status in a file usage history for index files in one or more buckets of data.

18 . The computer system of claim 15 , wherein the metadata file is obtained based on a prediction that the metadata file will be used during execution of a query relative to the bucket of data.

19 . The non-transitory computer-readable medium of claim 15 , wherein the determining that the journal file of the bucket of data is predicted to include data relevant to the search query is based on a usage status in a file usage history for index files in one or more buckets of data.

20 . The computer system of claim 15 , wherein the bucket of data is associated with a first time frame.

21 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

obtaining, at a cache and from remote storage, a metadata file associated with a bucket of data, wherein the bucket of data stored at the remote storage includes the metadata file, an index file, and a journal file;

determining that the index file of the bucket of data is predicted to contain data relevant to a search query;

based on the determination that the index file of the bucket of data is predicted to contain data relevant to the search query, obtaining, at the cache and from the remote storage, the index file associated with the bucket of data;

determining that the journal file of the bucket of data is predicted to include data relevant to the search query; and

based on the determination that the journal file of the bucket of data is predicted to include data relevant to the search query, obtaining, at the cache and from the remote storage, the journal file associated with the bucket of data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2025
From: BITINCKA, LEDION; BATSAKIS, ALEXANDROS; LUCAS, PAUL J.; ROMITO, NICHOLAS ROBERT
To: SPLUNK INC.
Reel/Frame 070997/0015 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
Continuity (7)
Continuation 18313239 · May 5, 2023
Continuation 17652635 · Feb 25, 2022
Continuation 16888320 · May 29, 2020
Continuation 16049609 · Jul 30, 2018
Continuation 15402105 · Jan 9, 2017
Continuation 15402119 · Jan 9, 2017
Related Publication 20250190353A1 · Jun 12, 2025
References Cited (2)
US 9323680B1 · Salli · 2016 [cited by examiner]
US 20100082672A1 · Kottomtharayil · 2010 [cited by examiner]