IP Library › Granted Patent US 10,698,895
Granted Patent B2
US 10,698,895 · App. 15/494,419 · Granted Jun 30, 2020

Skewing of scheduled search queries

Inventors: Paul J. Lucas (San Francisco, CA); Eric Woo (San Francisco, CA)
Assignee: SPLUNK INC.
G06F16/24545G06F16/24549G06F16/24553G06F16/9014
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,698,895
App. No.
15/494,419
Filed
Apr 21, 2017
Granted
Jun 30, 2020
Kind
B2
Art Unit
2166
USPC
707/720
Abstract

Techniques for scheduling search queries in a computing environment are disclosed. A search query scheduling system associates a first set of queries with a first skew tolerance, the first set of queries scheduled to be performed during a first period, where the first skew tolerance is based on a duration of the first period. The search query scheduling system reschedules a first subset of search queries included in the first set of queries by skewing the first subset of search queries over a first portion of the first period based on the first skew tolerance.

Claims (48)

1. A computer-implemented method, comprising:

associating a first set of queries with a first skew tolerance, wherein the first set of queries is scheduled to be performed during each occurrence of a first period; and

rescheduling a first subset of search queries included in the first set of queries by skewing the first subset of search queries over a first portion of the first period, wherein the first portion of the first period is determined based on a maximum skew amount associated with the first subset of search queries, wherein the maximum skew amount is based on the first skew tolerance, wherein the maximum skew amount is modified by multiplying the maximum skew amount by a percentage value specified by a skew setting associated with the first subset of search queries, and wherein the percentage value specified in the skew setting indicates a percent of the first period during which the first subset of search queries is to be executed,

wherein the first subset of search queries is executed via one or more processors based on the skewing of the first subset of search queries over the first portion of the first period.

2. The computer-implemented method of claim 1 , further comprising:

associating a second set of queries with a second skew tolerance, the second set of queries scheduled to be performed during each occurrence of a second period, wherein the second skew tolerance is based on a duration of the second period; and

rescheduling a second subset of search queries included in the second set of queries by skewing the second subset of search queries over a second portion of the second period, wherein the second portion of the second period is determined based on the second skew tolerance.

3. The computer-implemented method of claim 1 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries.

4. The computer-implemented method of claim 1 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and further comprising modifying the maximum skew amount based on an allow skew setting.

5. The computer-implemented method of claim 1 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and further comprising setting the maximum skew amount to a fixed value associated with an allow skew setting.

6. The computer-implemented method of claim 1 , further comprising computing a hash value for a first search query included in the first subset of search queries based on parameters associated with the first search query.

7. The computer-implemented method of claim 1 , further comprising computing a hash value for a first search query included in the first subset of search queries based on parameters associated with the first search query, wherein the parameters associated with the first search query include at least one of a title associated with the first search query, a description associated with the first search query, and a search string associated with the first search query.

8. The computer-implemented method of claim 1 , further comprising computing a skew value associated with a first search query included in the first subset of search queries.

9. The computer-implemented method of claim 1 , further comprising computing a hash value for a first search query included in the first subset of search queries based on one or more parameters associated with the first search query, and computing a skew value associated with the first search query included in the first subset of search queries, wherein the skew value is computed as the hash value associated with the first search query modulo the maximum skew amount associated with the first search query, wherein the maximum skew amount is based on the first skew tolerance.

10. The computer-implemented method of claim 1 , further comprising adjusting a priority associated with a first search query included in the first subset of search queries.

11. The computer-implemented method of claim 1 , further comprising adjusting a priority associated with a first search query included in the first subset of search queries, wherein the priority associated with the first search query is adjusted based on a schedule window that indicates an allowable deferral period associated with the first search query.

12. The computer-implemented method of claim 1 , wherein a first search query included in the first subset of search queries is directed to a set of events, and each event included in the set of events includes raw machine data and an associated time stamp timestamp derived from the raw machine data.

13. The computer-implemented method of claim 1 , wherein a first search query included in the first subset of search queries is directed to a set of events, and each event included in the set of events includes raw machine data from sources associated with a first component in an information technology (IT) environment.

14. The computer-implemented method of claim 1 , further comprising:

executing a first search query included in the first subset of search queries, wherein the first search query is directed to a set of events; and

during execution of the first search query, applying a late-binding schema to event data associated with the set of events.

15. The computer-implemented method of claim 1 , further comprising:

executing a first search query included in the first subset of search queries, wherein the first search query is directed to a set of events; and

during execution of the first search query, applying an extraction rule to extract a value for a first field associated with the event data.

16. One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of:

associating a first set of queries with a first skew tolerance, wherein the first set of queries is scheduled to be performed during each occurrence of a first period; and

rescheduling a first subset of search queries included in the first set of queries by skewing the first subset of search queries over a first portion of the first period, wherein the first portion of the first period is determined based on a maximum skew amount associated with the first subset of search queries, wherein the maximum skew amount is based on the first skew tolerance, wherein the maximum skew amount is modified by multiplying the maximum skew amount by a percentage value specified by a skew setting associated with the first subset of search queries, and wherein the percentage value specified in the skew setting indicates a percent of the first period during which the first subset of search queries is to be executed,

wherein the first subset of search queries is executed via the one or more processors based on the skewing of the first subset of search queries over the first portion of the first period.

17. The one or more non-transitory computer-readable storage media of claim 16 , further comprising:

associating a second set of queries with a second skew tolerance, the second set of queries scheduled to be performed during each occurrence of a second period, wherein the second skew tolerance is based on a duration of the second period; and

rescheduling a second subset of search queries included in the second set of queries by skewing the second subset of search queries over a second portion of the second period, wherein the second portion of the second period is determined based on the second skew tolerance.

18. The one or more non-transitory computer-readable storage media of claim 16 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries.

19. The one or more non-transitory computer-readable storage media of claim 16 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and further comprising modifying the maximum skew amount based on an allow skew setting.

20. The one or more non-transitory computer-readable storage media of claim 16 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and further comprising setting the maximum skew amount to a fixed value associated with an allow skew setting.

21. The one or more non-transitory computer-readable storage media of claim 16 , further comprising computing a hash value for a first search query included in the first subset of search queries based on parameters associated with the first search query.

22. A computing device, comprising:

one or more memories that include a search query scheduling program; and

one or more processors that are coupled to the one or more memories and, when executing the search query scheduling program, are configured to:

associate a first set of queries with a first skew tolerance, wherein the first set of queries is scheduled to be performed during each occurrence of a first period; and

reschedule a first subset of search queries included in the first set of queries by skewing the first subset of search queries over a first portion of the first period, wherein the first portion of the first period is determined based on a maximum skew amount associated with the first subset of search queries, wherein the maximum skew amount is based on the first skew tolerance, wherein the maximum skew amount is modified by multiplying the maximum skew amount by a percentage value specified by a skew setting associated with the first subset of search queries, and wherein the percentage value specified in the skew setting indicates a percent of the first period during which the first subset of search queries is to be executed,

wherein the first subset of search queries is executed via the one or more processors based on the skewing of the first subset of search queries over the first portion of the first period.

23. The computing device of claim 22 , wherein the processor is further configured to:

associate a second set of queries with a second skew tolerance, the second set of queries scheduled to be performed during each occurrence of a second period, wherein the second skew tolerance is based on a duration of the second period; and

reschedule a second subset of search queries included in the second set of queries by skewing the second subset of search queries over a second portion of the second period, wherein the second portion of the second period is determined based on the second skew tolerance.

24. The computing device of claim 22 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries.

25. The computing device of claim 22 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and wherein the processor is further configured to modify the maximum skew amount based on an allow skew setting.

26. The computing device of claim 22 , wherein the first portion of the first period is based on the maximum skew amount associated with the first subset of search queries, and wherein the processor is further configured to set the maximum skew amount to a fixed value associated with an allow skew setting.

27. The computing device of claim 22 , wherein the processor is further configured to compute a hash value for a first search query included in the first subset of search queries based on parameters associated with the first search query.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE STREET ADDRESS OF ASSIGNEE SPLUNK INC. PREVIOUSLY RECORDED ON REEL 042119 FRAME 0529. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 28, 2017
From: LUCAS, PAUL J.; WOO, ERIC
To: SPLUNK INC.
Reel/Frame 042368/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2017
From: LUCAS, PAUL J.; WOO, ERIC
To: SPLUNK INC.
Reel/Frame 042119/0529 →
Continuity (1)
Related Publication 20180307727A1 · Oct 25, 2018