IP Library › Granted Patent US 11,507,562
Granted Patent B1
US 11,507,562 · App. 16/419,941 · Granted Nov 22, 2022

Associating data from different nodes of a distributed ledger system

Inventors: Stephen Robert Luedtke (Denver, CO); Nathaniel Gerard McKervey (Tallahassee, FL); Ryan Russell Moore (St. Augustine, FL); Jeffrey Yung Wu (Berkeley, CA)
Assignee: Splunk Inc.
G06F16/2365G06F16/2228G06F16/2477G06F16/27
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,507,562
App. No.
16/419,941
Filed
May 22, 2019
Granted
Nov 22, 2022
Kind
B1
Art Unit
2165
USPC
707/690
Abstract

Systems and methods are described to associate data from different nodes of a distributed ledger system. The nodes can generate transaction notifications, log data, and/or metrics data. At least some of the data generated by the nodes can be obtained by a data intake and query system via a distributed ledger system monitor. The data from the distributed ledger system can be stored in the data intake and query system and correlated. Based on an association between at least some of the data of the first node and at least some of the data of the second node, the data intake and query system can determine at least a partial history of a transaction in the distributed ledger system, relationships between components of the distributed ledger system, and/or an architecture of the distributed ledger system.

Claims (45)

1. A computer-implemented method, comprising:

receiving a query at a computing device of a data intake and query system, the query identifying a set of data associated with a distributed ledger system, wherein the distributed ledger system is different from the data intake and query system; identifying as a portion of the set of data, a set of events stored by the data intake and query system, wherein the set of events correspond to log data generated by a plurality of nodes of the distributed ledger system; identifying a first event of the set of events, wherein the first event corresponds to first log data generated by a first node of the distributed ledger system, wherein the first event identifies a first task performed by the first node as part of the distributed ledger system storing a transaction to a particular distributed ledger of the distributed ledger system; identifying a second event of the set of events associated with the transaction, wherein the second event corresponds to second log data generated by a second node of the distributed ledger system, the second log data being generated at a different time than the first log data, wherein the second event identifies a second task performed by the second node as part of the distributed ledger system storing the transaction to the particular distributed ledger; ordering, in response to the query, the first event and the second event to determine a partial history of the transaction as it is processed for storage by the distributed ledger system; determining, based on the ordering, that the transaction is an invalidated transaction; and outputting a result as a response to the query, wherein the result includes the partial history of the transaction and an indication of the invalidated transaction.

2. The computer-implemented method of claim 1 , wherein the first event includes the first log data associated with a timestamp.

3. The computer-implemented method of claim 1 , wherein the second event includes the second log data associated with a timestamp.

4. The computer-implemented method of claim 1 , wherein the first node is a first isolated execution environment and the second node is a second isolated execution environment.

5. The computer-implemented method of claim 1 , wherein the first node is a peer node configured to endorse and validate the transaction and the second node is an ordering node configured to order the transaction relative to other transactions.

6. The computer-implemented method of claim 1 , wherein the first node and the second node are peer nodes configured to endorse and validate the transaction and store the transaction as part of a block of a blockchain.

7. The computer-implemented method of claim 1 , wherein the first node and the second node are ordering nodes configured to order the transaction and generate blocks that include the transaction for validation and storage on a blockchain.

8. The computer-implemented method of claim 1 , wherein the ordering the first event with the second event is based on a transaction identifier associated with the first event and the second event.

9. The computer-implemented method of claim 1 , further comprising:

extracting a transaction identifier from at least one of the first log data or the second log data using a regular expression rule.

10. The computer-implemented method of claim 1 , further comprising:

reading a transaction identifier from an inverted index, wherein the transaction identifier is associated with the first event and the second event.

11. The computer-implemented method of claim 1 , further comprising correlating the first log data and the second log data with metrics data.

12. The computer-implemented method of claim 1 , further comprising correlating the first log data and the second log data with metrics data based on a first timestamp associated with at least one of the first log data or the second log data and a second timestamp associated with the metrics data.

13. The computer-implemented method of claim 1 , further comprising correlating the first log data and the second log data with one or more transaction notifications.

14. The computer-implemented method of claim 1 , further comprising correlating the first log data and the second log data with one or more transaction notifications based on a transaction identifier associated with the first log data, the second log data, and the one or more transaction notifications.

15. The computer-implemented method of claim 1 , further comprising correlating the first log data and the second log data with metrics data and one or more transaction notifications.

16. The computer-implemented method of claim 1 , wherein at least one of the first log data or the second log data is obtained via a data adapter.

17. The computer-implemented method of claim 1 , further comprising generating a visualization of the result.

18. The computer-implemented method of claim 1 , further comprising identifying one or more relationships between components of the distributed ledger system based on the ordering.

19. The computer-implemented method of claim 1 , further comprising identifying a node type of at least one of the first node or the second node.

20. The computer-implemented method of claim 1 , wherein the partial history includes one or more stages of the transaction in the distributed ledger system.

21. A computing system of a data intake and query system, the computing system comprising:

memory; and

one or more processing devices coupled to the memory and configured to:

receive a query, the query identifying a set of data associated with a distributed ledger system, wherein the distributed ledger system is different from the data intake and query system;

identify as at least a portion of the set of data, a set of events stored by the data intake and query system, wherein the set of events correspond to log data generated by a plurality of nodes of the distributed ledger system;

identify a first event of the set of events, wherein the first event corresponds to first log data generated by a first node of the distributed ledger system, wherein the first event identifies a first task performed by the first node as part of the distributed ledger system storing a transaction to a particular distributed ledger of the distributed ledger system;

identify a second event of the set of events associated with the transaction, wherein the second event corresponds to second log data generated by a second node of the distributed ledger system, the second log data being generated at a different time than the first log data, wherein the second event identifies a second task performed by the second node as part of the distributed ledger system storing the transaction to the particular distributed ledger;

order, in response to the query, the first event and the second event to determine a partial history of the transaction as it is processed for storage by the distributed ledger system;

determine, based on the order, that the transaction is an invalidated transaction; and

output a result in response to the query, wherein the result includes the partial history of the transaction and an indication of the invalidated transaction.

22. The computing system of claim 21 , wherein to order the first event and the second event, the one or more processing devices are configured to order the first event and the second event based on a transaction identifier stored in an inverted index, wherein the transaction identifier is associated with the first event and the second event.

23. The computing system of claim 21 , further comprising correlating the first log data and the second log data with metrics data and one or more transaction notifications.

24. Non-transitory computer-readable media comprising computer-executable instructions that, when executed by a computing system of a data intake and query system, cause the computing system to:

receive a query, the query identifying a set of data associated with a distributed ledger system, wherein the distributed ledger system is different from the data intake and query system;

identify as at least a portion of the set of data, a set of events stored by the data intake and query system, wherein the set of events correspond to log data generated by a plurality of nodes of the distributed ledger system;

identify a first event of the set of events, wherein the first event corresponds to first log data generated by a first node of the distributed ledger system, wherein the first event identifies a first task performed by the first node as part of the distributed ledger system storing a transaction to a particular distributed ledger of the distributed ledger system;

identify a second event of the set of events associated with the transaction, wherein the second event corresponds to second log data generated by a second node of the distributed ledger system, the second log data being generated at a different time than the first log data, wherein the second event identifies a second task performed by the second node as part of the distributed ledger system storing the transaction to the particular distributed ledger;

order, in response to the query, the first event and the second event to determine a partial history of the transaction as it is processed for storage by the distributed ledger system;

determine, based on the order, that the transaction is an invalidated transaction; and

output a result in response to the query, wherein the result includes the partial history of the transaction and an indication of the invalidated transaction.

25. The non-transitory computer-readable media of claim 24 , wherein to order the first event and the second event is, the computer-executable instructions that cause the computing system to order the first event and the second event based on a transaction identifier associated with the first event and the second event.

26. The non-transitory computer-readable media of claim 24 , wherein to order the first event and the second event is, the computer-executable instructions that cause the computing system to order the first event and the second event based on a transaction identifier associated with the first event and the second event, wherein the transaction identifier is extracted from at least one of the first log data or the second log data using a regex rule.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2019
From: LUEDTKE, STEPHEN ROBERT; MCKERVEY, NATHANIEL GERARD; MOORE, RYAN RUSSELL; WU, JEFFREY YUNG
To: SPLUNK INC.
Reel/Frame 049331/0084 →
Cited By (14)
US 12,206,805 US 12,229,764 US 12,238,168 US 12,238,220 US 12,273,414 US 12,306,983 US 12,316,663 US 12,316,758 US 12,335,109 US 12,339,833 US 12,399,913 US 12,417,074 US 12,443,589 US 12,750,240