IP Library › Granted Patent US 9,594,789
Granted Patent B2
US 9,594,789 · App. 14/611,170 · Granted Mar 14, 2017

Time series search in primary and secondary memory

Inventors: Michael Joseph Baum (Ross, CA); R. David Carasso (San Rafael, CA); Robin Kumar Das (Redwood City, CA); Rory Greene (San Francisco, CA); Bradley Hall (San Francisco, CA); Nicholas Christian Mealy (Oakland, CA); Brian Philip Murphy (San Francisco, CA); Stephen Phillip Sorkin (San Francisco, CA); Andre David Stechert (Brooklyn, NY); Erik M. Swan (Piedmont, CA)
Assignee: Splunk Inc.
G06F17/30342G06F17/3053G06F17/30321G06F17/30353G06F17/30516G06F17/30528G06F17/30551G06F17/30554G06F17/30864
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,594,789
App. No.
14/611,170
Filed
Jan 30, 2015
Granted
Mar 14, 2017
Kind
B2
Art Unit
2167
USPC
707/746
Abstract

Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is organized into discrete events with normalized time stamps and the events are indexed by time and keyword. A search is received and relevant event information is retrieved based in whole or in part on the time indexing mechanism, keyword indexing mechanism, or statistical indices calculated at the time of the search.

Claims (46)

1. A method for building a searchable data store, comprising:

electronically receiving machine data produced by devices in an information processing environment;

segmenting the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the machine data;

associating a time stamp with each event in the plurality of events by applying an extraction rule to the machine data segmented for each event in order to extract time information to use as the time stamp for that event;

repeatedly generating buckets in volatile, random access memory;

designating a time span for each bucket of the generated buckets;

inserting a time stamped event in the plurality of events into a particular bucket in the generated buckets based at least in part on the associated time stamp and the time span of the particular bucket;

advancing a full bucket to full bucket status that does not accept further events;

transferring the full bucket into non-volatile storage, the full bucket is available for searching;

determining that a full bucket in non-volatile storage has expired; and

based on determining that the full bucket has expired, moving the full bucket out of active status.

2. The method of claim 1 , further comprising indexing events in the particular bucket.

3. The method of claim 1 , further comprising creating a speculative index for the events in at least one of the generated buckets based on the full bucket.

4. The method of claim 1 , further comprising indexing keywords in the events in the particular bucket.

5. The method of claim 1 , further comprising indexing keywords in the events in the full bucket.

6. A system that builds a searchable data store, comprising:

a processor and memory coupled to the processor, the memory storing program instructions that when executed cause:

electronically receiving machine data produced by devices in an information processing environment;

segmenting the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the machine data;

associating a time stamp with each event in the plurality of events by applying an extraction rule to the machine data segmented for each event in order to extract time information to use as the time stamp for that event;

repeatedly generating buckets in volatile, random access memory;

designating a time span for each bucket of the generated buckets;

inserting a time stamped event in the plurality of events into a particular bucket in the generated buckets based at least in part on the associated time stamp and the time span of the particular bucket;

advancing a full bucket to full bucket status that does not accept further events;

transferring the full bucket into non-volatile storage, the full bucket is available for searching;

determining that a full bucket in non-volatile storage has expired; and

based on determining that the full bucket has expired, moving the full bucket out of active status.

7. The system of claim 6 , further configured to index events in the particular bucket.

8. The system of claim 6 , further configured to create a speculative index for the events in at least one of the generated buckets based on the full bucket.

9. The system of claim 6 , further configured to index keywords in the events in the particular bucket.

10. The system of claim 6 , further configured to index keywords in the events in the full bucket.

11. A computer program product including memory that stores program instructions that, when executed on a computer, cause:

electronically receiving machine data produced by devices in an information processing environment;

segmenting the machine data into a plurality of events by determining a beginning and ending of each event in the plurality of events in the machine data;

associating a time stamp with each event in the plurality of events by applying an extraction rule to the machine data segmented for each event in order to extract time information to use as the time stamp for that event;

repeatedly generating buckets in volatile, random access memory;

designating a time span for each bucket of the generated buckets;

inserting a time stamped event in the plurality of events into a particular bucket in the generated buckets based at least in part on the associated time stamp and the time span of the particular bucket;

advancing a full bucket to full bucket status that does not accept further events;

transferring the full bucket into non-volatile storage, the full bucket is available for searching;

determining that a full bucket in non-volatile storage has expired; and

based on determining that the full bucket has expired, moving the full bucket out of active status.

12. The computer program product of claim 11 , further configured to index events in the particular bucket.

13. The computer program product of claim 11 , further configured to create a speculative index for the events in at least one of the generated buckets based on the full bucket.

14. The computer program product of claim 11 , further configured to index keywords in the events in the particular bucket.

15. The computer program product of claim 11 , further configured to index keywords in the events in the full bucket.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: BAUM, MICHAEL J.; CARASSO, DAVID; DAS, ROBIN K.; GREENE, RORY; HALL, BRAD; MEALY, NICK; MURPHY, BRIAN; SORKIN, STEPHEN; STECHERT, ANDRE; SWAN, ERIC M.
To: SPLUNK INC.
Reel/Frame 040344/0797 →
Continuity (4)
Continuation 13353135 · Jan 18, 2012
Continuation 11868370 · Oct 5, 2007
Provisional Application 60828283 · Oct 5, 2006
Related Publication 20150149480A1 · May 28, 2015