IP Library › Granted Patent US 11,500,783
Granted Patent B1
US 11,500,783 · App. 17/382,043 · Granted Nov 15, 2022

Evicting data associated with a data intake and query system from a local storage

Inventors: Bharath Aleti (San Ramon, CA); Alexandros Batsakis (San Francisco, CA); Paul J. Lucas (San Francisco, CA); Igor Stojanovski (San Francisco, CA)
Assignee: Splunk Inc.
G06F12/121G06F16/2282G06F16/24553G06F2212/1044
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,500,783
App. No.
17/382,043
Filed
Jul 21, 2021
Granted
Nov 15, 2022
Kind
B1
Art Unit
2137
USPC
711/133
Abstract

Systems and methods are disclosed for making space available in a local storage of a data intake and query system. A cache manager of the data intake and query system may determine an amount of storage space of a local data store that is available for use to perform a query. The cache manager may then use one or more eviction policies associated with content stored at the local data store to purge content items to evict from the local storage. The system may then retrieve content for performing the query from a remote storage and store the retrieved content at the local storage.

Claims (51)

1. A method, comprising:

receiving, by a data intake and query system, a query identifying a set of data to be processed and a manner of processing the set of data;

identifying content of a set of buckets for retrieval from a remote data store based on the query;

determining, based at least in part on the content of the set of buckets for retrieval, that storage available on a local data store does not satisfy an available storage threshold;

identifying, from a plurality of eviction policies, a first eviction policy and a second eviction policy associated with a first bucket of a plurality of buckets stored on the local data store, wherein the first eviction policy associated with the first bucket comprises a first eviction criterion used to evaluate a first portion of content of the first bucket for potential eviction, and wherein the second eviction policy associated with the first bucket comprises a second eviction criterion used to evaluate a second portion of the content of the first bucket for potential eviction; and

evicting one of the first portion of the content or the second portion of the content of the first bucket based on the first eviction policy or the second eviction policy.

2. The method of claim 1 , wherein determining that the storage available on the local data store does not satisfy the available storage threshold comprises excluding reserved unused storage space from a determination of the storage available.

3. The method of claim 1 , further comprising determining a total size of the content of the set of buckets for retrieval, wherein the available storage threshold is determined based at least in part on the total size of the content.

4. The method of claim 1 , wherein the available storage threshold exceeds a total size of the content of the set of buckets for retrieval by a reserved buffer size.

5. The method of claim 1 , further comprising retrieving the content of the set of buckets from the remote data store and executing the query using the content of the set of buckets.

6. The method of claim 1 , wherein the first eviction policy and the second eviction policy are performed in succession.

7. The method of claim 1 , wherein the first eviction policy is selected from the plurality of eviction policies based on the first portion of content.

8. The method of claim 1 , further comprising excluding from eviction at least some content from the first bucket determined to be included in the set of data identified by the query.

9. The method of claim 1 , wherein the plurality of eviction policies further includes a third eviction policy comprising a third eviction criterion useable to evaluate at least one of the first portion and the second portion of the content of the first bucket for potential eviction.

10. The method of claim 1 , further comprising:

determining that a second bucket of the plurality of buckets satisfies at least one query parameter of the query; and

identifying the content of the second bucket for retention on the local data store based on said determining that the second bucket satisfies at least one query parameter of the query.

11. The method of claim 1 , wherein identifying the first eviction policy comprises:

determining an index associated with the first bucket; and

identifying the first eviction policy associated with the first bucket based on the index associated with the first bucket.

12. The method of claim 1 , further comprising identifying the first eviction policy used to evaluate the first portion of the content based on a field-value pair or metadata of the first portion of the content.

13. The method of claim 1 , wherein the set of data comprises raw machine data.

14. The method of claim 1 , further comprising:

determining an aggregate size of the content of the set of buckets for retrieval; and

determining the available storage threshold based on the aggregate size.

15. The method of claim 1 , further comprising:

determining an aggregate size of the content of the set of buckets for retrieval;

determining a size of a buffer for processing the query; and

determining the available storage threshold based on the aggregate size and the size of the buffer.

16. The method of claim 1 , wherein, subsequent to evicting one of the first portion of the content or the second portion of the content, the method further comprises:

determining that the storage available on the local data store satisfies the available storage threshold; and

ceasing to evict additional content from the plurality of buckets stored on the local data store.

17. The method of claim 1 , wherein, subsequent to evicting one of the first portion of the content or the second portion of the content, the method further comprises:

determining that the storage available on the local data store does not satisfy the available storage threshold;

identifying a third eviction policy associated with a second bucket; and

evicting at least a portion of the second bucket based on the third eviction policy.

18. The method of claim 1 , wherein, subsequent to evicting one of the first portion of the content or the second portion of the content, the method further comprises storing the content of the set of buckets at the local data store.

19. A computing system of a data intake and query system, the computing system comprising:

memory; and

one or more processing devices coupled to the memory and configured to:

receive a query identifying a set of data to be processed and a manner of processing the set of data;

identify content of a set of buckets for retrieval from a remote data store based on the query;

determine, based at least in part on the content of the set of buckets for retrieval, that storage available on a local data store does not satisfy an available storage threshold;

identify, from a plurality of eviction policies, a first eviction policy and a second eviction policy associated with a first bucket of a plurality of buckets stored on the local data store, wherein the first eviction policy associated with the first bucket comprises a first eviction criterion used to evaluate a first portion of content of the first bucket for potential eviction, and wherein the second eviction policy associated with the first bucket comprises a second eviction criterion used to evaluate a second portion of the content of the first bucket for potential eviction; and

evict one of the first portion of the content or the second portion of the content of the first bucket based on the first eviction policy or the second eviction policy.

20. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system of a data intake and query system, cause the computing system to:

receive a query identifying a set of data to be processed and a manner of processing the set of data;

identify content of a set of buckets for retrieval from a remote data store based on the query;

determine, based at least in part on the content of the set of buckets for retrieval, that storage available on a local data store does not satisfy an available storage threshold;

identify, from a plurality of eviction policies, a first eviction policy and a second eviction policy associated with a first bucket of a plurality of buckets stored on the local data store, wherein the first eviction policy associated with the first bucket comprises a first eviction criterion used to evaluate a first portion of content of the first bucket for potential eviction, and wherein the second eviction policy associated with the first bucket comprises a second eviction criterion used to evaluate a second portion of the content of the first bucket for potential eviction; and

evict one of the first portion of the content or the second portion of the content of the first bucket based on the first eviction policy or the second eviction policy.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2025
From: ALETI, BHARATH; BATSAKIS, ALEXANDROS; LUCAS, PAUL J.; STOJANOVSKI, IGOR
To: SPLUNK INC.
Reel/Frame 071926/0163 →
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
Continuity (1)
Continuation 16147103 · Sep 28, 2018
Cited By (1)
US 12,585,684