IP Library Granted Patent US 9,160,798
Granted Patent B2
US 9,160,798 · App. 13/662,358 · Granted Oct 13, 2015

Clustering for high availability and disaster recovery

Inventors: Vishal Patel (San Francisco, CA); Mitchell Neuman Blank, Jr. (San Francisco, CA); Sundar Rengarajan Vasan (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA)
Assignee: Splunk, Inc.
H04L67/1097G06F11/2097G06F17/30312
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,160,798
App. No.
13/662,358
Granted
Oct 13, 2015
Kind
B2
Abstract

Embodiments are directed towards managing within a cluster environment having a plurality of indexers for data storage using redundancy the data being managed using a generation identifier, such that a primary indexer is designated for a given generation of data. When a master device for the cluster fails, data may continue to be stored using redundancy, and data searches performed may still be performed.

Claims (65)

1. A computer-implemented method comprising:

identifying, at the master device, a first indexer from a set of indexers to serve as a primary indexer for responding to queries pertaining to certain data, and wherein the first indexer is configured to determine whether to search the certain data based on a time range associated with one of the queries pertaining to the certain data;

assigning, at the master device, a generation identifier indicating that the first indexer is the primary indexer for the certain data, the first indexer receiving information that the generation identifier designates the first indexer as the primary indexer for the certain data;

in response to an event prompting a change in a primary indexer designation for the certain data:

identifying, at the master device, a second indexer from the set of indexers to serve as the primary indexer for responding to queries pertaining to the certain data; and

assigning, at the master device, a new generation identifier indicating that the second indexer is the primary indexer for the certain data, the second indexer receiving information that the new generation identifier designates the second indexer as the primary indexer for the certain data;

receiving, at the master device, a request for a current generation identifier; and

responding, at the master device, to the request query with the new generation identifier.

2. The method of claim 1 , wherein the event prompting the change includes a determination that the first indexer was non-responsive to a communication.

3. The method of claim 1 , wherein the event prompting the change includes a determination that the first indexer has responsibility for a high processing load relative to other indexers in the set of indexers.

4. The method of claim 1 , further comprising responding, at the master device, to the request with an identification of at least one indexer storing the certain data.

5. The method of claim 1 , wherein the first indexer and the second indexer each concurrently store copies of the certain data.

6. The method of claim 1 , wherein creating the new generation identifier includes incrementing the generation identifier.

7. The method of claim 1 , wherein the certain data includes two or more events, and wherein an indexer in the set of indexers is configured to:

receive raw data;

separate the raw data into the two or more events;

determine, for each of the two or more events, a time stamp; and

store the two or more events in a data store that it can search in response to a query.

8. The method of claim 1 , wherein, while the first indexer is serving as the primary indexer for the certain data, the first indexer concurrently stores other data for which it is not designated as the primary indexer.

9. The method of claim 1 , wherein the certain data is stored in one of several buckets maintained by the first indexer.

10. The method of claim 1 , wherein a particular query pertaining at least to the certain data is associated with a particular generation identifier, and wherein a particular indexer responds to the particular query associated with the particular generation identifier based on the particular indexer having received information that the particular generation identifier designates the particular indexer as the primary indexer for the certain data.

11. A system comprising:

one or more data processors; and

a non-transitory computer-readable storage medium containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including:

identifying, at the master device, a first indexer from a set of indexers to serve as a primary indexer for responding to queries pertaining to certain data, and wherein the first indexer is configured to determine whether to search the certain data based on a time range associated with one of the queries pertaining to the certain data;

assigning, at the master device, a generation identifier indicating that the first indexer is the primary indexer for the certain data, the first indexer receiving information that the generation identifier designates the first indexer as the primary indexer for the certain data;

in response to an event prompting a change in a primary indexer designation for the certain data:

identifying, at the master device, a second indexer from the set of indexers to serve as the primary indexer for responding to queries pertaining to the certain data; and

assigning, at the master device, a new generation identifier indicating that the second indexer is the primary indexer for the certain data, the second indexer receiving information that the new generation identifier designates the second indexer as the primary indexer for the certain data;

receiving, at the master device, a request for a current generation identifier; and

responding, at the master device, to the request with the new generation identifier.

12. The system of claim 11 , wherein the event prompting the change includes a determination that the first indexer was non-responsive to a communication.

13. The system of claim 11 , wherein the event prompting the change includes a determination that the first indexer has responsibility for a high processing load relative to other indexers in the set of indexers.

14. The system of claim 11 , further comprising responding, at the master device, to the request with an identification of at least one indexer storing the certain data.

15. The system of claim 11 , wherein the first indexer and the second indexer each concurrently store copies of the certain data.

16. The system of claim 11 , wherein creating the new generation identifier includes incrementing the generation identifier.

17. The system of claim 11 , wherein the certain data includes two or more events, and wherein an indexer in the set of indexers is configured to:

receive raw data;

separate the raw data into the two or more events;

determine, for each of the two or more events, a time stamp; and

store the two or more events in a data store that it can search in response to a query.

18. The system of claim 11 , wherein, while the first indexer is serving as the primary indexer for the certain data, the first indexer concurrently stores other data for which it is not designated as the primary indexer.

19. The system of claim 11 , wherein the certain data is stored in one of several buckets maintained by the first indexer.

20. The system of claim 11 , wherein a particular query pertaining at least to the certain data is associated with a particular generation identifier, and wherein a particular indexer responds to the particular query associated with the particular generation identifier based on the particular indexer having received information that the particular generation identifier designates the particular indexer as the primary indexer for the certain data.

21. A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions to cause one or more data processors to perform operations comprising:

identifying, at the master device, a first indexer from a set of indexers to serve as a primary indexer for responding to queries pertaining to certain data, and wherein the first indexer is configured to determine whether to search the certain data based on a time range associated with one of the queries pertaining to the certain data;

assigning, at the master device, a generation identifier indicating that the first indexer is the primary indexer for the certain data, the first indexer receiving information that the generation identifier designates the first indexer as the primary indexer for the certain data;

in response to an event prompting a change in a primary indexer designation for the certain data:

identifying, at the master device, a second indexer from the set of indexers to serve as the primary indexer for responding to queries pertaining to the certain data; and

assigning, at the master device, a new generation identifier indicating that the second indexer is the primary indexer for the certain data, the second indexer receiving information that the new generation identifier designates the second indexer as the primary indexer for the certain data;

receiving, at the master device, a request for a current generation identifier; and

responding, at the master device, to the request query with the new generation identifier.

22. The product of claim 21 , wherein the event prompting the change includes a determination that the first indexer was non-responsive to a communication.

23. The product of claim 21 , wherein the event prompting the change includes a determination that the first indexer has responsibility for a high processing load relative to other indexers in the set of indexers.

24. The product of claim 21 , further comprising responding, at the master device, to the request with an identification of at least one indexer storing the certain data.

25. The product of claim 21 , wherein the first indexer and the second indexer each concurrently store copies of the certain data.

26. The product of claim 21 , wherein creating the new generation identifier includes incrementing the generation identifier.

27. The product of claim 21 , wherein the certain data includes two or more events, and wherein an indexer in the set of indexers is configured to:

receive raw data;

separate the raw data into the two or more events;

determine, for each of the two or more events, a time stamp; and

store the two or more events in a data store that it can search in response to a query.

28. The product of claim 21 , wherein, while the first indexer is serving as the primary indexer for the certain data, the first indexer concurrently stores other data for which it is not designated as the primary indexer.

29. The product of claim 21 , wherein the certain data is stored in one of several buckets maintained by the first indexer.

30. The product of claim 21 , wherein a particular query pertaining at least to the certain data is associated with a particular generation identifier, and wherein a particular indexer responds to the particular query associated with the particular generation identifier based on the particular indexer having received information that the particular generation identifier designates the particular indexer as the primary indexer for the certain data.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2012
From: PATEL, VISHAL; BLANK, MITCHELL NEUMAN, JR.; VASAN, SUNDAR RENGARAJAN; SORKIN, STEPHEN PHILLIP
To: SPLUNK INC.
Reel/Frame 029202/0860 →
Continuity (3)
Continuation 13648116 · Oct 9, 2012
Provisional Application 61647245 · May 15, 2012
Related Publication 20130311428A1 · Nov 21, 2013