IP Library › Granted Patent US 12,197,442
Granted Patent B1
US 12,197,442 · App. 17/937,902 · Granted Jan 14, 2025

Integration of cloud-based and non-cloud-based data in a data intake and query system

Inventors: Kyle Champlin (Castro Valley, CA); Cory Chen (Oakland, CA); Patrick Schulz (Pulheim, DE); Jason Szeto (Belmont, CA)
Assignee: Cisco Technology, Inc
G06F16/2455G06F3/14G06F16/248
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,442
App. No.
17/937,902
Filed
Oct 4, 2022
Granted
Jan 14, 2025
Kind
B1
Art Unit
2169
USPC
707/769
Abstract

A software module ingests data into a data intake and query system. At least a portion of the data is cloud data. The software module includes an event type definition that specifies a type of data to be ingested by the software module, a first tag that associates ingested data of the event type with a data model, and a second tag that designates ingested data of the event type as cloud data. The ingested data is stored in a data repository, and subsequently a search query that includes the first tag and the second tag is executed against the data repository, to identify ingested cloud data that satisfies the search query and a first search constraint specified in the data model. A display device is caused to display a visualization based on the identified ingested cloud data that satisfies the search query.

Claims (70)

1. A computer-implemented method comprising:

accessing a first tag and a second tag stored in association with each other in a metadata storage, the first tag for associating ingested data of a particular class of data with a data model that contains semantic knowledge about the particular class of data, the second tag for designating ingested data as cloud data;

ingesting data by a data intake and query system, a portion of the ingested data being cloud data;

in response to determining that the portion of the ingested data satisfies one or more criteria associated with the first tag, determining that the portion of the ingested data should be tagged with the first tag;

determining that the portion of the ingested data should be tagged with the second tag based on the first tag being associated with the second tag in the metadata storage;

storing the portion of the ingested data in a data repository in association with the first tag and the second tag, the first tag associating the portion of the ingested data with the data model that contains semantic knowledge about the particular class of data, the second tag designating the portion of the ingested data as cloud data;

executing a search query against the data repository, to identify ingested cloud data that satisfies the search query, the search query including the first tag and the second tag; and

causing a display device to display a visualization based on a result of the search query, the result including the portion of the ingested data.

2. The computer-implemented method of claim 1 , wherein the ingesting is performed by a software module of the data intake and query system, and wherein the software module includes an event type definition that specifies a type of data to be ingested by the software module and further includes the first tag and the second tag.

3. The computer-implemented method of claim 1 , wherein the data model includes a search constraint, and wherein executing the search query comprises identifying ingested cloud data that satisfies the search query and the search constraint.

4. The computer-implemented method of claim 1 , wherein the data model includes a search constraint, wherein executing the search query comprises identifying ingested cloud data that satisfies the search query and the search constraint, and wherein the search constraint is not expressly set forth in the search query.

5. The computer-implemented method of claim 1 , wherein executing the search query comprises:

ascertaining that the search query is to apply a data model based on a presence of the first tag in the search query; and

ascertaining that the search query is to retrieve cloud data based on a presence of the second tag in the search query.

6. The computer-implemented method of claim 1 , wherein the ingesting is performed by a software module of the data intake and query system, and wherein the software module includes a first event type definition that specifies a type of data to be ingested by the software module, the method further comprising maintaining a configuration file that includes the event type definition and at least one additional event type definition.

7. The computer-implemented method of claim 1 , wherein the ingesting is performed by a software module of the data intake and query system, and wherein the software module includes a first event type definition that specifies a type of data to be ingested by the software module;

the method further comprising:

maintaining a first configuration file that includes the first event type definition and a second event type definition; and

maintaining a second configuration file that associates the first tag and the second tag with the first event type definition.

8. The computer-implemented method of claim 1 , wherein the ingesting is performed by a software module of the data intake and query system, and wherein the software module includes a first event type definition that specifies a type of data to be ingested by the software module:

the software module further includes a first configuration file that includes the first event type definition and a second event type definition;

the software module further includes a second configuration file that associates the first tag and the second tag with the first event type definition; and

the first configuration file further includes a second event type definition, and wherein the second configuration file further includes the second tag in association with the second event type definition.

9. The computer-implemented method of claim 1 , wherein the ingesting is performed by a software module of the data intake and query system, and wherein the software module includes an event type definition that specifies a type of data to be ingested by the software module and a set of parameters for identifying data to be ingested into the data intake and query system by the software module.

10. The computer-implemented method of claim 1 , wherein the data model specifies a dataset, including a search constraint and a set of fields associated with the dataset.

11. The computer-implemented method of claim 1 , wherein the ingested data comprises a plurality of different fields, and wherein said ingesting data comprises:

ingesting data from a plurality of different source types, wherein a field of the plurality of fields has different field names for at least two of the plurality of different source types; and

normalizing the different field names of the field across the plurality of different source types.

12. The computer-implemented method of claim 1 , wherein the ingested data comprises a plurality of different fields, and wherein said ingesting data comprises:

ingesting data from a plurality of different source types, wherein a field of the plurality of fields has different field names for at least two of the plurality of different source types; and

normalizing the different field names of the field across the plurality of different source types, by accessing a configuration file containing a list of field name aliases.

13. The computer-implemented method of claim 1 , wherein the data model specifies a dataset, including a set of fields associated with the dataset;

the method further comprising:

receiving user input defining a plurality of aliases for a field name of a field of the set of fields; and

in response to the user input defining the plurality of aliases, storing the plurality of aliases in a configuration file, for use in normalizing the field name across different data source types.

14. A computing device comprising:

a processor; and

a non-transitory computer-readable medium, accessible to the processor, having stored thereon instructions, execution of which by the processor causes the computing device to perform operations including:

accessing a first tag and a second tag stored in association with each other in a metadata storage, the first tag for associating ingested data of a particular class of data with a data model that contains semantic knowledge about the particular class of data, the second tag for designating ingested data as cloud data;

ingesting data into a data intake and query system, at least a portion of the ingested data being cloud data;

in response to determining that the portion of the ingested data satisfies one or more criteria associated with the first tag, determining that the portion of the ingested data should be tagged with the first tag;

determining that the portion of the ingested data should be tagged with the second tag based on the first tag being associated with the second tag in the metadata storage;

storing the portion of the ingested data in a data repository in association with the first tag and the second tag, the first tag associating the portion of the ingested data with the data model that contains semantic knowledge about the particular class of data, the second tag designating the portion of the ingested data as cloud data;

executing a search query that includes the first tag and the second tag against the data repository, to identify ingested cloud data that satisfies the search query; and

causing a display device to display a visualization based on a result of the search query, the result including the portion of the ingested data.

15. The computing device of claim 14 , wherein executing the search query comprises:

ascertaining that the search query is to apply the data model based on a presence of the first tag in the search query; and

ascertaining that the search query is to retrieve cloud data based on a presence of the second tag in the search query.

16. The computing device of claim 14 , wherein computing device comprises a software module configured to perform the ingesting;

wherein the software module includes a first configuration file that includes a first event type definition and a second event type definition;

the software module further includes a second configuration file that associates the first tag and the second tag with the first event type definition; and

the first configuration file further includes the second event type definition, and wherein the second configuration file further includes the second tag in association with the second event type definition.

17. The computing device of claim 14 , wherein the data comprises first data representing a first plurality of events from a first data source, the first data source being of a first source type, and wherein the ingesting is performed by a software module customized to ingest only data from sources of the first source type into the data intake and query system;

said operations further including:

ingesting second data, by a second software module, into the data intake and query system, at least a portion of the second data being cloud data, the second software module including an event type definition that specifies a type of data to be ingested by the second software module, the second software module further including the second tag to designate ingested data from a source of a second source type as cloud data and a third tag to associate ingested data from the source of the second source type with a second data model.

18. A non-transitory computer-readable medium having stored thereon instructions, execution of which by one or more processors in a data intake and query system causes the data intake and query system to perform operations including:

accessing a first tag and a second tag stored in association with each other in a metadata storage, the first tag for associating ingested data of a particular class of data with a data model that contains semantic knowledge about the particular class of data, the second tag for designating ingested data as cloud data;

ingesting data, at least a portion of which is cloud data;

in response to determining that the portion of the ingested data satisfies one or more criteria associated with the first tag, determining that the portion of the ingested data should be tagged with the first tag;

determining that the portion of the ingested data should be tagged with the second tag based on the first tag being associated with the second tag in the metadata storage;

storing the portion of the ingested data in a data repository in association with the first tag and the second tag, the first tag associating the portion of the ingested data with the data model that contains semantic knowledge about the particular class of data, the second tag designating the portion of the ingested data as cloud data;

executing a search query that includes the first tag and the second tag against the data repository, to identify ingested cloud data that satisfies the search query; and

causing a display device to display a visualization based on a result of the search query, the result including the portion of the ingested data.

19. The non-transitory computer-readable medium of claim 18 , wherein executing the search query comprises:

ascertaining that the search query is to apply the data model based on a presence of the first tag in the search query; and

ascertaining that the search query is to retrieve cloud data based on a presence of the second tag in the search query.

20. The non-transitory computer-readable medium of claim 18 , such that:

the ingesting is performed by a software module that includes a first configuration file that includes a first event type definition and at least one additional event type definition;

the software module further includes a second configuration file that associates the first tag and the second tag with the first event type definition; and

the first configuration file further includes a second event type definition, and wherein the second configuration file further includes the second tag in association with the second event type definition.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2022
From: CHAMPLIN, KYLE; CHEN, CORY; SCHULZ, PATRICK; SZETO, JASON
To: SPLUNK INC.
Reel/Frame 061305/0631 →
Continuity (1)
Continuation 17163308 · Jan 29, 2021
References Cited (29)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20170220651A1 · Mathew et al. · 2017 [cited by applicant]
US 20180089328A1 · Bath et al. · 2018 [cited by applicant]
US 20180196864A1 · Xu · 2018 [cited by applicant]
US 20180293304A1 · Miller et al. · 2018 [cited by applicant]
US 20180314601A1 · Jain · 2018 [cited by examiner]
US 20190095478A1 · Tankersley · 2019 [cited by examiner]
US 20190098106A1 · Mungel · 2019 [cited by examiner]
US 20190163841A1 · Bhattacharjee · 2019 [cited by examiner]
US 20190236149A1 · Kuruvada · 2019 [cited by examiner]
US 20190347334A1 · Sundaramoorthy et al. · 2019 [cited by applicant]
US 20220221585A1 · Miao · 2022 [cited by examiner]
“Splunk Enterprise, Knowledge Manager Manual 8.1.1, About data models,” generated Jan. 25, 2021, available online at https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Aboutdatamodels; 9 pages. [cited by applicant]
“Splunk Enterprise, Knowledge Manager Manual 8.1.1, Tag event types,” generated Jan. 26, 2021, https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Tageventtypes; 2 pages. [cited by applicant]
“Splunk Supported Add-ons, Splunk Add-0ns released, About Splunk add-ons,” generated Jun. 22, 2020, available online at https://docs.splunk.com/Documentation/AddOns/released/Overview/AboutSplunkAdd-ons; 2 pages. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
“Splunk Common Information Model Add-on, Common Information Model Add-on Manual 4.18.0, Overview of the Splunk Common Information Model,” generated Dec. 2, 2020, available online at https://docs.splunk.com/Documentation… [cited by applicant]
“Splunk Enterprise Knowledge Manager Manual 8.1.1, About event types,” generated Jan. 27, 2021, available online at https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Abouteventtypes, 4 pages. [cited by applicant]
Bitincka, Ledion , et al., “Optimizing Data Analysis with a Semi-structured Time Series Database”, self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML… [cited by applicant]