IP Library › Granted Patent US 11,829,330
Granted Patent B2
US 11,829,330 · App. 17/646,372 · Granted Nov 28, 2023

Log data extraction from data chunks of an isolated execution environment

Inventors: Zhimin Liang (West Vancouver, CA); Matthew Modestino (Toronto, CA); David Christopher Baldwin (Dublin, CA); Marc Andre Chéné (Seattle, WA); Blaine Wastell (Woodinville, WA)
Assignee: Splunk Inc.
G06F16/1734G06F8/427G06F9/45533G06F16/901G06F16/907G06F16/9038G06F2009/45587G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,829,330
App. No.
17/646,372
Filed
Dec 29, 2021
Granted
Nov 28, 2023
Kind
B2
Art Unit
2159
USPC
707/672
Abstract

Systems and methods are disclosed for processing data associated with isolated execution environments. A chunk of data associated with an isolated execution environment can include log data and non-log data. At least a portion of the log data can include log data generated by the isolated execution environment. The system can parse the chunk of data to identify the log data and the non-log data and extract at least a portion of the log data from the chunk of data. The extracted data can be further processed to generate one or more events.

Claims (45)

1. A method, comprising:

obtaining a chunk of data from a data store in a hosted computing environment, the hosted computing environment comprising:

a host computing device associated with the data store, and

a plurality of isolated execution environments instantiated on the host computing device, wherein the plurality of isolated execution environments share compute resources of the host computing device;

obtaining location information of the chunk of data, wherein the location information includes a storage location of the chunk of data in the data store;

parsing the location information to determine an identity of a particular isolated execution environment of the plurality of isolated execution environments that generated at least a portion of the chunk of data;

generating metadata using the determined identity of the particular isolated execution environment; and

communicating the chunk of data and the generated metadata to a computing device of a distributed processing system, wherein the computing device generates an event using the chunk of data and associates the generated metadata with the generated event.

2. The method of claim 1 , wherein said obtaining the location information comprises identifying a directory path to a file that includes the chunk of data.

3. The method of claim 1 , further comprising identifying one or more regex rules associated with an isolated execution environment manager of the plurality of isolated execution environments and parsing the location information using the one or more regex rules.

4. The method of claim 1 , further comprising identifying one or more regex rules associated with the particular isolated execution environment and parsing the location information using the one or more regex rules.

5. The method of claim 1 , wherein the determined identity of the particular isolated execution environment includes at least one of a container name, a container ID, a pod name, a pod ID, a namespace name or a namespace identifier.

6. The method of claim 1 , further comprising determining a source of the chunk of data based on the location information.

7. The method of claim 1 , further comprising determining a sourcetype of the chunk of data based on the location information, wherein the sourcetype corresponds to at least one identifier of the particular isolated execution environment extracted from the location information.

8. The method of claim 1 , further comprising parsing the chunk of data based on the determined identity of the particular isolated execution environment.

9. The method of claim 1 , further comprising determining a source of the at least a portion of the chunk of data based on the location information, wherein the source of the at least a portion of the chunk of data is different from a source of the chunk of data.

10. The method of claim 1 , further comprising determining a sourcetype of the at least a portion of the chunk of data based on the location information, wherein the sourcetype of the at least a portion of the chunk of data is different from a sourcetype of the chunk of data.

11. The method of claim 1 , further comprising:

identifying a regex rule based on the determined identity of the particular isolated execution environment; and

processing the at least a portion of the chunk of data based on the regex rule.

12. The method of claim 1 , wherein the particular isolated execution environment is a software container.

13. The method of claim 1 , wherein the at least a portion of the chunk of data is log data generated by the particular isolated execution environment.

14. The method of claim 1 , wherein the at least a portion of the chunk of data is raw machine data generated by the particular isolated execution environment.

15. A computing system, comprising:

memory; and

one or more first processing devices coupled to the memory and configured to:

obtain a chunk of data from a data store in a hosted computing environment, the hosted computing environment comprising:

a host computing device associated with the data store, and

a plurality of isolated execution environments instantiated on the host computing device, wherein the plurality of isolated execution environments share compute resources of the host computing device;

obtain location information of the chunk of data, wherein the location information includes a storage location of the chunk of data in the data store;

parse the location information to determine an identity of a particular isolated execution environment of the plurality of isolated execution environments that generated at least a portion of the chunk of data;

generate metadata using the determined identity of the particular isolated execution environment; and

communicate the chunk of data and the generated metadata to a computing device of a distributed processing system, wherein the computing device generates an event using the chunk of data and associates the generated metadata with the generated event.

16. The computing system of claim 15 , wherein the location information comprises a directory path to a file that includes the chunk of data.

17. The computing system of claim 15 , wherein the one or more first processing devices are further configured to identify one or more regex rules associated with an isolated execution environment manager of the plurality of isolated execution environments and parse the location information using the one or more regex rules.

18. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system of a data intake and query system, cause the computing system to:

obtain a chunk of data from a data store in a hosted computing environment, the hosted computing environment comprising:

a host computing device associated with the data store, and

a plurality of isolated execution environments instantiated on the host computing device, wherein the plurality of isolated execution environments share compute resources of the host computing device;

obtain location information of the chunk of data, wherein the location information includes a storage location of the chunk of data in the data store;

parse the location information to determine an identity of a particular isolated execution environment of the plurality of isolated execution environments that generated at least a portion of the chunk of data;

generate metadata using the determined identity of the particular isolated execution environment; and

communicate the chunk of data and the generated metadata to a computing device of a distributed processing system, wherein the computing device generates an event using the chunk of data and associates the generated metadata with the generated event.

19. The non-transitory computer readable media of claim 18 , wherein the location information comprises a directory path to a file that includes the chunk of data.

20. The non-transitory computer readable media of claim 18 , wherein the determined identity of the particular isolated execution environment includes at least one of a container name, a container ID, a pod name, a pod ID, a namespace name or a namespace identifier.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2023
From: LIANG, ZHIMIN; MODESTINO, MATTHEW; BALDWIN, DAVID CHRISTOPHER; CHÉNÉ, MARC ANDRE; WASTELL, BLAINE
To: SPLUNK INC.
Reel/Frame 065135/0896 →
Continuity (2)
Continuation 15979933 · May 15, 2018
Related Publication 20220300464A1 · Sep 22, 2022
Cited By (2)
US 12,417,210 US 12,556,565