IP Library Patent Application 19184991
Patent Application
App. No. 19/184,991

SEARCH RESULT REPLICATION MANAGEMENT IN A SEARCH HEAD CLUSTER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/184,991
Abstract

Systems and methods for search result replication in a search head cluster of a data aggregation and analysis system. An example method may include receiving, by a search head leader of a search head cluster including multiple search heads, from a first search head of the plurality of search heads, a search result in response to a search query. The search head leader parses a registry comprising a set of replicas of the search result in the search head cluster to determine a replication count corresponding to a number of replicas of the search result. A determination is made that the replication count is greater than a target replication count. Based on the determination, a least-recently-accessed replica from the set of replicas is identified and a deletion of the least-recently-accessed replica is initiated.

Claims (41)

1 . (canceled)

2 . A method comprising:

determining, by a search head leader of a search head cluster comprising a plurality of search heads, a failed search head of the plurality of search heads;

based on determining the failed search head, updating a cluster search results registry maintained by the search head leader by removing references to the failed search head from the cluster search results registry; and

in accordance with the updated cluster search results registry, managing compliance of a replication policy in association with a search result corresponding with the failed search head.

3 . The method of claim 2 , wherein the failed search head is determined based on an expiration of a period of time without the search head leader receiving a heartbeat message from the failed search head.

4 . The method of claim 2 , further comprising:

communicating, from the search head leader, periodic heartbeat messages to the failed search head; and

determining, by the search head leader, an expiration of a period of time during which the search head leader fails to receive a heartbeat message from the failed search head.

5 . The method of claim 2 , wherein the references to the failed search head comprise an identifier associated with the failed search head.

6 . The method of claim 2 , wherein removing the references to the failed search head from the cluster search results registry modifies one or more search results included in the cluster search results registry.

7 . The method of claim 2 , wherein the replication policy comprises a replication count configured in association with the search head cluster.

8 . The method of claim 2 , wherein the retention policy indicates a number of locations in the search head cluster at which the search result is to be replicated.

9 . The method of claim 2 , wherein managing compliance of the replication policy in association with the search result corresponding with the failed search head comprises determining that a replication count associated with the search result is not in compliance with the replication policy.

10 . The method of claim 2 , wherein managing compliance of the replication policy in association with the search result corresponding with the failed search head comprises:

determining that a replication count associated with the search result is below the replication policy; and

based on the determination that the replication count is below the replication policy, scheduling a replication of the search result to at least one search head of the plurality of search heads.

11 . The method of claim 2 , wherein managing compliance of the replication policy in association with the search result corresponding with the failed search head comprises:

determining that a replication count associated with the search result is above the replication policy; and

based on the determination that the replication count is below the replication policy, scheduling a removal of the search result from at least one search head of the plurality of search heads.

12 . A system comprising:

a memory; and one or more processing devices coupled with the memory, the one or more processing devices configured to:

determine, by a search head leader of a search head cluster comprising a plurality of search heads, a failed search head of the plurality of search heads;

based on determining the failed search head, update a cluster search results registry maintained by the search head leader by removing references to the failed search head from the cluster search results registry; and

in accordance with the updated cluster search results registry, manage compliance of a replication policy in association with a search result corresponding with the failed search head.

13 . The system of claim 12 , wherein the failed search head is determined based on an expiration of a period of time without the search head leader receiving a heartbeat message from the failed search head.

14 . The system of claim 12 , wherein the one or more processing devices are further configured to:

communicate, from the search head leader, periodic heartbeat messages to the failed search head; and

determine, by the search head leader, an expiration of a period of time during which the search head leader fails to receive a heartbeat message from the failed search head.

15 . The system of claim 12 , wherein the references to the failed search head comprise an identifier associated with the failed search head.

16 . The system of claim 12 , wherein removing the references to the failed search head from the cluster search results registry modifies one or more search results included in the cluster search results registry.

17 . A non-transitory computer-readable storage medium encoding executable instructions thereon that, in response to execution by one or more processing devices, cause the one or more processing devices to:

determine, by a search head leader of a search head cluster comprising a plurality of search heads, a failed search head of the plurality of search heads;

based on determining the failed search head, update a cluster search results registry maintained by the search head leader by removing references to the failed search head from the cluster search results registry; and

in accordance with the updated cluster search results registry, manage compliance of a replication policy in association with a search result corresponding with the failed search head.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the replication policy comprises a replication count configured in association with the search head cluster.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the retention policy indicates a number of locations in the search head cluster at which the search result is to be replicated.

20 . The non-transitory computer-readable storage medium of claim 17 , wherein managing compliance of the replication policy in association with the search result corresponding with the failed search head comprises determining that a replication count associated with the search result is not in compliance with the replication policy.

21 . The non-transitory computer-readable storage medium of claim 17 , wherein managing compliance of the replication policy in association with the search result corresponding with the failed search head comprises:

determining that a replication count associated with the search result is below the replication policy; and

based on the determination that the replication count is below the replication policy, scheduling a replication of the search result to at least one search head of the plurality of search heads.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2026
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 074735/0375 →
CHANGE OF NAME Recorded Feb 11, 2026
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 074768/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 074331/0001 →
CHANGE OF NAME Recorded Jan 13, 2026
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 074331/0875 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2025
From: VASAN, SUNDAR; RAHUT, ANIRBAN
To: SPLUNK INC.
Reel/Frame 070945/0522 →