IP Library Granted Patent US 12,602,397
Granted Patent B1
US 12,602,397 · App. 18/887,869 · Granted Apr 14, 2026

Clustering in association with extraction rules

Inventors: Jesse Brandau Miller (San Francisco, CA); Katherine Kyle Feeney (Oakland, CA); Yuan Xie (San Francisco, CA); Steve Zhang (San Francisco, CA); Adam Jamison Oliner (San Francisco, CA); Jindrich Dinga (San Francisco, CA); Jacob Leverich (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,397
App. No.
18/887,869
Granted
Apr 14, 2026
Kind
B1
Abstract

Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

Claims (31)

1 . A computer-implemented method, comprising:

causing display, via a user interface, of a first set of clusters of events, each event of the set of events comprises a time stamp and a portion of raw machine data;

obtaining, via the user interface, an indication of an extraction rule; and

causing display, via the user interface, of a second set of clusters of events based on comparisons between the portions of raw machine data of the events, wherein the portions of raw machine data that correspond to values identified using the extraction rule are excluded from the comparisons, thereby improving clustering of the events to efficiently facilitate field identification and/or extraction rule generation.

2 . The computer-implemented method of claim 1 , wherein the first set of clusters of events are clustered in accordance with a source type.

3 . The computer-implemented method of claim 1 , wherein the first set of clusters of events are clustered in accordance with a field.

4 . The computer-implemented method of claim 1 , wherein the first set of clusters of events are clustered based on identical matches between raw machine data or based on a similarity between raw machine data.

5 . The computer-implemented method of claim 1 , wherein the first set of clusters of events are clustered in accordance with unmasked portions of the raw machine data.

6 . The computer-implemented method of claim 1 , wherein the extraction rule is generated based on a selected portion of the raw machine data.

7 . The computer-implemented method of claim 1 , wherein the extraction rule is generated based on modifications applied to an initial extraction rule.

8 . The computer-implemented method of claim 1 further comprising causing display of a visualization that indicates relationships between the first set of clusters of events and the second set of clusters of events.

9 . The computer-implemented method of claim 1 further comprising causing display of a visualization that indicates progression of the first set of clusters of events to the second set of clusters of events.

10 . The computer-implemented method of claim 1 further comprising causing display of a visualization that includes event data for each cluster of the second set of clusters of events.

11 . The computer-implemented method of claim 1 further comprising assigning the extraction rule to a field based on a user selection.

12 . The computer-implemented method of claim 1 , wherein each cluster of the second set of clusters of events is represented by a particular event.

13 . The computer-implemented method of claim 1 , wherein, based on a user selection of a particular cluster of the second set of clusters of events, corresponding events associated with the particular cluster are presented for display.

14 . The computer-implemented method of claim 1 , wherein the excluding comprises masking text corresponding to the values from the events, wherein the comparison is between the masked events.

15 . The computer-implemented method of claim 1 , wherein the excluding comprises tokenizing text portions of the events that correspond to the values, wherein the comparison is between the tokenized text portions.

16 . A system comprising:

one or more processors; and

computer memory having instructions stored thereon, the instructions, when executed by the one or more processors causing the system to perform a method comprising:

causing display, via a user interface, of a first set of clusters of events, each event of the set of events comprises a time stamp and a portion of raw machine data;

obtaining, via the user interface, an indication of an extraction rule; and

causing display, via the user interface, of a second set of clusters of events based on comparisons between the portions of raw machine data of the events, wherein the portions of raw machine data that correspond to values identified using the extraction rule are excluded from the comparisons, thereby improving clustering of the events to efficiently facilitate field identification and/or extraction rule generation.

17 . The system of claim 16 , wherein the excluding comprises masking text corresponding to the values from the events, wherein the comparison is between the masked events.

18 . One or more computer-readable media having instructions stored thereon, the instructions, when executed by a processor of a computing device, to cause the computing device to perform a method comprising:

causing display, via a user interface, of a first set of clusters of events, each event of the set of events comprises a time stamp and a portion of raw machine data;

obtaining, via the user interface, an indication of an extraction rule; and

causing display, via the user interface, of a second set of clusters of events based on comparisons between the portions of raw machine data of the events, wherein the portions of raw machine data that correspond to values identified using the extraction rule are excluded from the comparisons, thereby improving clustering of the events to efficiently facilitate field identification and/or extraction rule generation.

19 . The one or more computer-readable media of claim 18 , wherein the excluding comprises tokenizing text portions of the events that correspond to the values, wherein the comparison is between the tokenized text portions.

20 . The one or more computer-readable media of claim 18 , wherein, based on a user selection of a particular cluster of the second set of clusters of events, corresponding events associated with the particular cluster are presented for display.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0060 →
Continuity (3)
Continuation 18300936 · Apr 14, 2023
Continuation 17158880 · Jan 26, 2021
Continuation 15276693 · Sep 26, 2016
References Cited (48)
US 5542006A · Shustorovich et al. · 1996 [cited by applicant]
US 5841946A · Naito et al. · 1998 [cited by applicant]
US 7577098B2 · Tamura et al. · 2009 [cited by applicant]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751499B1 · Carasso et al. · 2014 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 8909642B2 · Carasso · 2014 [cited by examiner]
US 9021304B2 · Tonouchi · 2015 [cited by applicant]
US 9146962B1 · Boe et al. · 2015 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 9596252B2 · Coates et al. · 2017 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10193775B2 · Fletcher et al. · 2019 [cited by applicant]
US 10310615B2 · Lee et al. · 2019 [cited by applicant]
US 10331720B2 · Neels et al. · 2019 [cited by applicant]
US 11100150B2 · Carasso et al. · 2021 [cited by applicant]
US 11216491B2 · Li et al. · 2022 [cited by applicant]
US 20040024773A1 · Stoffel et al. · 2004 [cited by applicant]
US 20050015624A1 · Ginter et al. · 2005 [cited by applicant]
US 20050226512A1 · Napper · 2005 [cited by applicant]
US 20070198565A1 · Ivanov · 2007 [cited by examiner]
US 20090030860A1 · Leitheiser · 2009 [cited by applicant]
US 20110066585A1 · Subrahmanyam et al. · 2011 [cited by applicant]
US 20140207792A1 · Carasso et al. · 2014 [cited by applicant]
US 20140222750A1 · Uchiumi et al. · 2014 [cited by applicant]
US 20150039651A1 · Kinsely et al. · 2015 [cited by applicant]
US 20150293976A1 · Guo et al. · 2015 [cited by applicant]
US 20150347859A1 · Dixon et al. · 2015 [cited by applicant]
US 20160350655A1 · Weiss et al. · 2016 [cited by applicant]
US 20170091168A1 · Bellegarda et al. · 2017 [cited by applicant]
US 20180067918A1 · Bellegarda et al. · 2018 [cited by applicant]
US 20180275967A1 · Mohamed et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20190310715A1 · Lee et al. · 2019 [cited by applicant]
“Cluster events extraction rules timestamps”, Google Patents, Retrieved from Internet URL: https://patents.google.com/q=cluster+events+extraction+rules+timestamps&oq=cluster+events+extraction+rules+timestamps., accessed… [cited by applicant]
Bitincka, L., et al., “Optimizing Data Analysis With a Semi-Structured Time Series Database,” pp. 1-9 (2010). [cited by applicant]
Carasso, D., “Exploring Splunk: Search Processing Language (SPL) Primer and Coockbook,” Splunk, pp. 156 (Apr. 2012). [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com, pp. 17. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020, pp. 6. [cited by applicant]
U.S. Appl. No. 15/276,693, filed Sep. 26, 2016. [cited by applicant]
U.S. Appl. No. 15/420,754, filed Jan. 31, 2017. [cited by applicant]
U.S. Appl. No. 16/901,985, filed Jun. 15, 2020. [cited by applicant]
U.S. Appl. No. 17/158,880, filed Jan. 26, 2021. [cited by applicant]
U.S. Appl. No. 18/300,936, filed Apr. 14, 2023. [cited by applicant]