IP Library Granted Patent US 12,222,840
Granted Patent B1
US 12,222,840 · App. 17/974,262 · Granted Feb 11, 2025

Generating span related metric data streams by an analytic engine

Inventors: Steven Karis (Redwood City, CA); Maxime Petazzoni (San Mateo, CA); Matthew William Pound (Palo Alto, CA); Joseph Ari Ross (Redwood City, CA); Charles Smith (Morrisville, NC); Scott Stewart (Pflugerville, TX)
Assignee: SPLUNK Inc.
G06F11/3636G06F9/547G06F11/3612G06F11/3644G06F16/24568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,222,840
App. No.
17/974,262
Filed
Oct 26, 2022
Granted
Feb 11, 2025
Kind
B1
Examiner
WU, DAXIN
Art Unit
2191
USPC
717/128
Abstract

A method of generating metrics data associated with a microservices-based application comprises ingesting a plurality of spans and mapping an ingested span of the plurality of spans to a span identity, wherein the span identity comprises a tuple of information identifying a type of span associated with the span identity, wherein the tuple of information comprises user-configured dimensions. The method further comprises grouping the ingested span by the span identity, wherein the ingested span is grouped with other spans from the plurality of spans comprising a same span identity. The method also comprises computing metrics associated with the span identity and using the metrics to generate a stream of metric data associated with the span identity.

Claims (54)

1. A method of generating metrics data associated with a microservices-based application, the method comprising:

ingesting a plurality of spans associated with one or more applications executing in a distributed computing environment;

mapping each span of the plurality of spans to a span identity that corresponds to a type of span;

grouping the plurality of spans based on the span identity associated with each span of the plurality of spans;

computing metrics associated with the span identity by aggregating information extracted from spans associated with the span identity;

generating, based on the metrics, a stream of metric data associated with the span identity;

generating an alert signal based on values associated with the stream of metric data satisfying a condition; and

responsive to generating the alert signal, extending the span identity with user-configured tags to extract information regarding an operation associated with the span identity.

2. The method of claim 1 , wherein each of the plurality of spans includes a plurality of attributes and one or more user-configured tags.

3. The method of claim 1 , wherein the condition corresponds to at least one value of the stream of metric data exceeding a predetermined threshold.

4. The method of claim 2 , wherein the plurality of attributes includes:

an operation name,

a service name,

a kind tag,

an error flag, or

a flag indicating if the span is part of a service mesh.

5. The method of claim 1 , wherein the metrics computed are selected from one or more of a minimum span duration, a median span duration, a maximum span duration, a p90 latency value, a p99 latency value, and a count of spans associated with the span identity.

6. The method of claim 1 , wherein an analytic engine computes the metrics periodically for a given number of time-periods, and wherein the analytic engine resets the metrics at an end of each time-period.

7. The method of claim 6 , wherein the analytic engine resides in a cloud network.

8. The method of claim 1 , wherein the step of computing metrics further comprises:

generating a fixed size bin histogram for the span identity;

inserting values associated with each span corresponding to the span identity in respective bins of the fixed size bin histogram; and

computing the metrics by tracking counts associated with each bin in the fixed size bin histogram.

9. The method of claim 1 , further comprising:

determining whether the span identity is associated with a cross-service call; and

responsive to a determination that the span identity is associated with a cross-service call, extending the span identity with user-configured tags to extract information regarding the cross-service call.

10. The method of claim 1 , further comprising:

rendering, in a user interface, an application topology graph depicting metrics corresponding to a plurality of services associated with one or more applications executing in the distributed computing environment.

11. A non-transitory computer-readable medium having computer-readable program code embodied therein for causing a computer system to perform a method of generating metrics data associated with a microservices-based application, the method comprising:

ingesting a plurality of spans associated with one or more applications executing in a distributed computing environment;

mapping each span of the plurality of spans to a span identity that corresponds to a type of span;

grouping the plurality of spans based on the span identity associated with each span of the plurality of spans;

computing metrics associated with the span identity by aggregating information extracted from spans associated with the span identity;

generating, based on the metrics, a stream of metric data associated with the span identity;

generating an alert signal based on values associated with the stream of metric data satisfying a condition; and

responsive to generating the alert signal, extending the span identity with user-configured tags to extract information regarding an operation associated with the span identity.

12. The non-transitory computer-readable medium of claim 11 , wherein each of the plurality of spans includes a plurality of attributes and one or more user-configured tags.

13. The non-transitory computer-readable medium of claim 11 , wherein the condition corresponds to at least one value of the stream of metric data exceeding a predetermined threshold.

14. The non-transitory computer-readable medium of claim 11 , wherein the metrics computed are selected from one or more of a minimum span duration, a median span duration, a maximum span duration, a p90 latency value, a p99 latency value, and a count of spans associated with the span identity.

15. The non-transitory computer-readable medium of claim 11 , wherein an analytic engine computes the metrics periodically for a given number of time-periods, and wherein the analytic engine resets the metrics at an end of each time-period.

16. The non-transitory computer-readable medium of claim 11 , wherein the step of computing metrics further comprises:

generating a fixed size bin histogram for the span identity;

inserting values associated with each span corresponding to the span identity in respective bins of the fixed size bin histogram; and

computing the metrics by tracking counts associated with each bin in the fixed size bin histogram.

17. A system for performing a method of generating metrics data associated with a microservices-based application, the system comprising:

a processing device communicatively coupled with a memory and configured to:

ingest a plurality of spans associated with one or more applications executing in a distributed computing environment;

map each span of the plurality of spans to a span identity that corresponds to a type of span;

group the plurality of spans based on the span identity associated with each span of the plurality of spans;

compute metrics associated with the span identity by aggregating information extracted from spans associated with the span identity;

generate, based on the metrics, a stream of metric data associated with the span identity;

generate an alert signal based on values associated with the stream of metric data satisfying a condition; and

extend the span identity with user-configured tags to extract information regarding an operation associated with the span identity in response to the alert signal being generated.

18. The system of claim 17 , wherein the metrics computed are selected from one or more of a minimum span duration, a median span duration, a maximum span duration, a p90 latency value, a p99 latency value, and a count of spans associated with the span identity.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2022
From: KARIS, STEVEN; PETAZZONI, MAXIME; POUND, MATTHEW WILLIAM; ROSS, JOSEPH ARI; SMITH, CHARLES; STEWART, SCOTT
To: SPLUNK INC.
Reel/Frame 062059/0714 →
Continuity (1)
Continuation 16835179 · Mar 30, 2020
References Cited (24)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10880191B1 · Kant · 2020 [cited by examiner]
US 11516269B1 · Chang, Jr. et al. · 2022 [cited by applicant]
US 11526425B1 · Karis et al. · 2022 [cited by applicant]
US 20130283281A1 · Krajec · 2013 [cited by examiner]
US 20140019879A1 · Krajec · 2014 [cited by examiner]
US 20180088813A1 · Agrawal · 2018 [cited by examiner]
US 20200257670A1 · Masson · 2020 [cited by examiner]
US 20200328952A1 · Makwarth · 2020 [cited by examiner]
WO WO2020087082A1 · 2020 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Henschen , “Why all the Hadoopla”, InformationWeek, 2011. [cited by applicant]
Hua , et al., “Correlated Data Gathering in Wireless Sensor Networks Based on Distributed Source Coding”, International Journal of Sensor Networks, vol. 4, Issue 1/2, 2008. [cited by applicant]
Kefalakis , et al., “A Configurable Distributed Data Analytics Infrastructure for the Industrial Internet of Things”, 15th International Conference on Distributed Computing in Sensor Systems, 2019. [cited by applicant]
Morshed , et al., “Open Source Initiatives and Frameworks Addressing Distributed Real-time Data Analytics”, IEEE International Parallel and Distributed Processing Symposium Workshops, 2016, pp. 1481-1484. [cited by applicant]
Cited By (1)
US 12,568,031