IP Library Granted Patent US 11,768,836
Granted Patent B2
US 11,768,836 · App. 16/582,205 · Granted Sep 26, 2023

Automatic entity definitions based on derived content

Inventors: Arun Ramani (Redmond, WA); Anupadmaja Raghavan (Cupertino, CA); Tristan Antonio Fletcher (Pacifica, CA); Marc Chene (Seattle, WA)
Assignee: Splunk Inc.
G06F16/24573G06Q10/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,768,836
App. No.
16/582,205
Filed
Sep 25, 2019
Granted
Sep 26, 2023
Kind
B2
Art Unit
2163
USPC
707/725
Abstract

A service monitoring system (SMS) produces key performance indicator (KPI) scores that indicate the performance of a service. To produce the KPI scores, the SMS may process the data for a large number of machine entities that perform the service. This data can be processed on a per-entity basis to produce a per-entity KPI score representing the contribution of a particular machine to the overall KPI. The per-entity KPI scores can be transformed to statistical representations which can be visualized as a distribution stream graph. The visualization may be presented with interactive aspects. Automatic entity definitions may also be generated based on content derived from the processed data.

Claims (54)

1. A method implemented by one or more processing devices, the method comprising:

identifying an undefined entity by applying, to machine data, a data selection query specifying a relationship between two or more data items in the machine data, wherein the entity generates particular data items included in the machine data as part of performing a service, and wherein the entity is identified by the data selection query as a result of the entity having generated particular two or more data items that have the relationship;

determining, using the particular two or more data items, that a plurality of stored entity definitions does not include a definition for the entity such that the entity is an undefined entity;

executing a search query on the machine data to determine content descriptive of the undefined entity;

generating an entity definition for the undefined entity using the content descriptive of the entity;

identifying the service performed by the entity based on the entity definition matching an association rule specified by a service definition of the service, wherein the service definition specifies one or more entity definitions of entities providing the service and defines relationships between one or more entities referenced by the one or more entity definitions;

associating the entity definition with the service definition; and

storing the entity definition with the plurality of stored entity definitions.

2. The method of claim 1 , wherein the machine data comprises data generated by a machine other than the undefined entity.

3. The method of claim 1 , wherein the machine data comprises data generated by the undefined entity and a machine other than the undefined entity.

4. The method of claim 1 , wherein the entity definition includes an identifier.

5. The method of claim 1 , wherein the entity definition includes an alias.

6. The method of claim 1 , wherein the entity definition includes at least one of: a network address, a host name, or an identifier number.

7. The method of claim 1 , wherein the machine data is received from multiple sources.

8. The method of claim 1 , wherein executing the search query on the machine data comprises accessing the machine data using a late-binding schema.

9. The method of claim 1 , wherein the machine data comprises a plurality of timestamped events.

10. The method of claim 1 , wherein the machine data comprises a plurality of timestamped events each having a segment of raw machine data.

11. The method of claim 1 , wherein executing the search query produces the result set in a tabular form.

12. The method of claim 1 , wherein generating the entity definition includes processing the result set as an input.

13. The method of claim 1 , further comprising: causing display of a graphical user interface (GUI) visually rendering the entity definition including at least one of: a name, an alias, or an information field.

14. The method of claim 1 , wherein identifying the undefined entity is performed automatically in accordance with a frequency or schedule.

15. A system comprising:

a memory; and

a processing device coupled with the memory to:

identify an undefined entity by applying, to machine data, a data selection query specifying a relationship between two or more data items in the machine data, wherein the entity generates particular data items included in the machine data as part of performing a service, and wherein the entity is identified by the data selection query as a result of the entity having generated particular two or more data items that have the relationship;

determine, using the particular two or more data items, that a plurality of stored entity definitions does not include a definition for the entity such that the entity is an undefined entity;

execute a search query on the machine data to determine content descriptive of the undefined entity;

generate an entity definition for the undefined entity using the content descriptive of the entity;

identify the service performed by the undefined entity based on the entity definition matching an association rule specified by a service definition of the service, wherein the service definition specifies one or more entity definitions of entities providing the service and defines relationships between one or more entities referenced by the one or more entity definitions;

associate the entity definition with the service definition; and

store the entity definition with the plurality of stored entity definitions.

16. The system of claim 15 , wherein the machine data is received from multiple sources.

17. The system of claim 15 , wherein executing the search query on the machine data comprises accessing the machine data using a late-binding schema.

18. The system of claim 15 , wherein the machine data comprises a plurality of timestamped events each having a segment of raw machine data.

19. The system of claim 15 , further comprising to:

make a determination whether the entity definition satisfies filter criteria for identifying entities associated with the service; and

associate the entity definition with the service definition for the service.

20. The system of claim 15 , wherein executing the search query produces a search result set in a tabular form.

21. The system of claim 15 , wherein generating the entity definition includes processing the result set as an input.

22. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the processing devices to perform operations comprising:

identifying an undefined entity by applying, to machine data, a data selection query specifying a relationship between two or more data items in the machine data, wherein the entity generates particular data items included in the machine data as part of performing a service, and wherein the entity is identified by the data selection query as a result of the entity having generated particular two or more data items that have the relationship;

determining, using the particular two or more data items, that a plurality of stored entity definitions does not include a definition for the entity such that the entity is an undefined entity;

executing a search query on the machine data to determine content descriptive of the undefined entity;

generating an entity definition for the undefined entity using the content descriptive of the entity;

identifying the service performed by the undefined entity based on the entity definition matching an association rule specified by a service definition of the service, wherein the service definition specifies one or more entity definitions of entities providing the service and defines relationships between one or more entities referenced by the one or more entity definitions;

associating the entity definition with the service definition; and

storing the entity definition with the plurality of stored entity definitions.

23. The non-transitory computer readable storage medium of claim 22 , wherein the machine data is received from multiple sources.

24. The non-transitory computer readable storage medium of claim 22 , wherein executing the search query on the machine data comprises accessing the machine data using a late-binding schema.

25. The non-transitory computer readable storage medium of claim 22 , further comprising:

determining whether the entity definition satisfies filter criteria for identifying entities associated with the service; and

associating the entity definition with the service definition for the service.

26. The non-transitory computer readable storage medium of claim 22 , wherein executing the search query produces the result set in tabular form.

27. The non-transitory computer readable storage medium of claim 22 , wherein generating the entity definition includes processing the result set as an input.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2019
From: RAMANI, ARUN; RAGHAVAN, ANUPADMAJA; FLETCHER, TRISTAN ANTONIO; CHENE, MARC
To: SPLUNK INC.
Reel/Frame 050486/0546 →
Continuity (7)
Continuation 14859243 · Sep 18, 2015
Continuation In Part 14800675 · Jul 15, 2015
Continuation In Part 14700110 · Apr 29, 2015
Continuation In Part 14611200 · Jan 31, 2015
Continuation In Part 14528858 · Oct 30, 2014
Provisional Application 62062104 · Oct 9, 2014
Related Publication 20200019555A1 · Jan 16, 2020