IP Library › Granted Patent US 12,130,829
Granted Patent B2
US 12,130,829 · App. 18/051,458 · Granted Oct 29, 2024

Generation of modified queries using a field value for different fields

Inventors: Nasim Bigdelu (North Vancouver, CA); Margaret Kelley (Boulder, CO); Mirjana Tesic (Pacifica, CA); Rebecca Tortell (Los Altos, CA); Rajesh Raman (Palo Alto, CA)
Assignee: Splunk Inc.
G06F16/248G06F16/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,130,829
App. No.
18/051,458
Filed
Oct 31, 2022
Granted
Oct 29, 2024
Kind
B2
Art Unit
2161
USPC
707/722
Abstract

Systems and methods are described for generation and execution of modified queries. An input can be received via a visualization of a user interface. The input may identify a first field value and a first field for execution of a query. A set of data for execution of the query can be identified based on the input. Alias data may identify a second field that is associated with the first field. Using the alias data, a modified query can be generated based on the query and the second field. The modified query can be executed to generate query results. The query results can be displayed via a visualization of the user interface based on the first field.

Claims (59)

1. A method comprising:

obtaining a user input via a first visualization of a user interface, wherein the user input defines a first field-value pair for execution of a query, wherein the first field-value pair associates a first field and a first field value;

identifying a set of data for execution of the query based at least in part on the user input;

determining the first field is mapped to a second field based on mapping data, wherein a second field-value pair associates the second field and the first field value;

generating a modified query using the query and the second field-value pair based at least in part on determining the first field is mapped to the second field;

executing the modified query on the set of data using the second field-value pair to generate query results; and

causing display of the query results via a second visualization of the user interface based at least in part on the first field.

2. The method of claim 1 , further comprising determining that the set of data is associated with the second field, wherein generating the modified query is further based at least in part on determining that the set of data is associated with the second field.

3. The method of claim 1 , wherein the second field comprises a modified version of the first field.

4. The method of claim 1 , further comprising:

obtaining a second user input via the first visualization of the user interface, wherein the second user input defines a third field-value pair for execution of a second query, wherein the third field-value pair associates a third field associated and a second field value;

identifying a second set of data for execution of the second query based at least in part on the second user input;

determining the third field is not associated with an alias mapping;

executing the second query on the second set of data using the third field-value pair to generate second query results based at least in part on determining the third field is not associated with the alias mapping; and

causing display of the second query results.

5. The method of claim 1 , further comprising:

obtaining a second user input; and

defining the mapping data based on the second user input.

6. The method of claim 1 , further comprising:

obtaining the mapping data, wherein the mapping data comprises one or more alias mappings, wherein the one or more alias mappings indicate one or more fields associated with a shared mapping.

7. The method of claim 1 , wherein determining the first field is mapped to a second field comprises:

determining the first field corresponds to a plurality of fields, the plurality of fields comprising the second field, wherein generating the modified query is further based at least in part on determining the first field corresponds to the plurality of fields.

8. The method of claim 1 , wherein the query and the modified query correspond to different query languages.

9. The method of claim 1 , wherein causing display of the query results comprising causing display of the query results according to the first field.

10. The method of claim 1 , further comprising translating the query results to generate translated query results, wherein the query results are associated with the second field and the translated query results are associated with the first field, wherein causing display of the query results comprises causing display of the translated query results.

11. The method of claim 1 , further comprising translating the query to generate the modified query.

12. The method of claim 1 , wherein the first field and the second field comprise different fields.

13. The method of claim 1 , wherein the modified query defines a query operation according to the second field and the query defines the query operation according to the first field.

14. The method of claim 1 , wherein the modified query defines a query operation according to the second field and not according to the first field, wherein the query defines the query operation according to the first field.

15. The method of claim 1 , wherein first field value is defined via one or more selectable parameters of the user interface.

16. The method of claim 1 , wherein first field value and the first field are defined via one or more selectable parameters of the user interface.

17. A system comprising:

a data store; and

one or more processors configured to:

obtain a user input via a first visualization of a user interface, wherein the user input defines a first field-value pair for execution of a query, wherein the first field-value pair associates a first field and a first field value;

identify a set of data for execution of the query based at least in part on the user input;

determine the first field is mapped to a second field based on mapping data, wherein a second field-value pair associates the second field and the first field value;

generate a modified query using the query and the second field-value pair based at least in part on determining the first field is mapped to the second field;

execute the modified query on the set of data using the second field-value pair to generate query results; and

cause display of the query results via a second visualization of the user interface based at least in part on the first field.

18. The system of claim 17 , wherein the one or more processors are further configured to:

obtain a second user input via the first visualization of the user interface, wherein the second user input defines a third field-value pair for execution of a second query, wherein the third field-value pair associates a third field associated and a second field value;

identify a second set of data for execution of the second query based at least in part on the second user input;

determine the third field is not associated with an alias mapping;

execute the second query on the second set of data using the third field-value pair to generate second query results based at least in part on determining the third field is not associated with the alias mapping; and

cause display of the second query results.

19. Non-transitory computer-readable media including computer-executable instructions that, when executed by a computing system, cause the computing system to:

obtain a user input via a first visualization of a user interface, wherein the user input defines a first field-value pair for execution of a query, wherein the first field-value pair associates a first field and a first field value;

identify a set of data for execution of the query based at least in part on the user input;

determine the first field is mapped to a second field based on mapping data, wherein a second field-value pair associates the second field and the first field value;

generate a modified query using the query and the second field-value pair based at least in part on determining the first field is mapped to the second field;

execute the modified query on the set of data using the second field-value pair to generate query results; and

cause display of the query results via a second visualization of the user interface based at least in part on the first field.

20. The non-transitory computer-readable media of claim 19 , wherein execution of the computer-executable instructions by the computing system further causes the computing system to:

obtain a second user input via the first visualization of the user interface, wherein the second user input defines a third field-value pair for execution of a second query, wherein the third field-value pair associates a third field associated and a second field value;

identify a second set of data for execution of the second query based at least in part on the second user input;

determine the third field is not associated with an alias mapping;

execute the second query on the second set of data using the third field-value pair to generate second query results based at least in part on determining the third field is not associated with the alias mapping; and

cause display of the second query results.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: BIGDELU, NASIM; KELLEY, MARGARET; TESIC, MIRJANA; TORTELL, REBECCA; RAMAN, RAJESH
To: SPLUNK INC.
Reel/Frame 062674/0791 →
Continuity (1)
Related Publication 20240143612A1 · May 2, 2024
Cited By (3)
US 12,271,428 US 12,298,981 US 12,670,152