IP Library Granted Patent US 12,430,356
Granted Patent B2
US 12,430,356 · App. 18/494,312 · Granted Sep 30, 2025

Data source visualizations

Inventors: Glenn Block (Seattle, WA); Patrick Ogdin (Ann Arbor, MI)
Assignee: Splunk Inc.
G06F16/26G06F16/2228G06F16/248G06F16/254G06F16/951
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,356
App. No.
18/494,312
Granted
Sep 30, 2025
Kind
B2
Abstract

A data intake and query system processes and stores events, which are associated with token identifiers for tokens corresponding to data sources for the messages that the events are generated from. Thus, the data intake and query system can receive a request to provide analyses and visualizations regarding stored events associated with a particular component associated with a plurality of events, such as a data source for the messages from which the plurality of events are generated from. These requests and the resulting visualizations can be customized based on selected tokens and selected components.

Claims (40)

1. A computer-implemented method, comprising:

identifying a plurality of events associated with a token identifier, wherein event data of the plurality of events is obtained from data included within a plurality of messages output by one or more computing components, wherein the token identifier corresponds to a token authenticating the plurality of messages and raw machine data output by the one or more computing components;

generating visualization data for a graphical visualization, the visualization data indicating one or more metrics associated with the plurality of events, wherein the token identifier and the one of more metrics and indicative of a same component; and

causing display of the graphical visualization.

2. The computer-implemented method of claim 1 , wherein the one or more metrics comprise at least one of one or more metrics of the one or more computing components or one or more metrics of one or more components of a data intake and query system that processes the plurality of events.

3. The computer-implemented method of claim 1 , wherein the token identifier is associated with at least one of the one or more computing components or one or more components of a data intake and query system that processes the plurality of events.

4. The computer-implemented method of claim 1 , further comprising:

identifying one or more components, of a data intake and query system, that process the plurality of events, wherein the one or more metrics comprise one or more metrics of the one or more components.

5. The computer-implemented method of claim 1 , wherein the token comprises metadata for the one or more computing components.

6. The computer-implemented method of claim 1 , wherein each of the plurality of messages comprises a token corresponding to the token identifier, raw machine data, and event metadata.

7. The computer-implemented method of claim 1 , further comprising:

calculating values associated with the visualization data;

comparing the values to a threshold; and

invoking a process based on comparing the values to the threshold.

8. The computer-implemented method of claim 1 , wherein the one or more computing components provide the plurality of messages to a data intake and query system that processes the plurality of events.

9. The computer-implemented method of claim 1 , wherein a data intake and query system processes the plurality of events, wherein the data intake and query system comprises at least one of:

a plurality of event collectors, wherein the plurality of event collectors are configured to receive the plurality of events and manage storage of the plurality of events; a plurality of indexers, wherein the plurality of indexers are configured to store the

plurality of events; or

a plurality of forwarders, wherein the plurality of forwarders are configured to receive the plurality of events and forward the plurality of events for storage.

10. The computer-implemented method of claim 1 , wherein the visualization data indicates a number of the plurality of events.

11. The computer-implemented method of claim 1 , further comprising:

obtaining an input indicating one or more components of a data intake and query system that processes the plurality of events, wherein the visualization data is based on the input.

12. The computer-implemented method of claim 1 , further comprising:

obtaining an input indicating the token corresponding to the token identifier, wherein identifying the plurality of events is based on obtaining the input.

13. The computer-implemented method of claim 1 , wherein the token comprises timestamps for data in the plurality of messages.

14. The computer-implemented method of claim 1 , wherein each event of the plurality of events comprises a portion of raw machine data associated with a timestamp.

15. A computing system, comprising:

memory; and

one or more processing devices coupled to the memory and configured to:

identify a plurality of events associated with a token identifier, wherein event data of the plurality of events is obtained from data included within a plurality of messages output by one or more computing components, wherein the token identifier corresponds to a token authenticating the plurality of messages and raw machine data output by the one or more computing components;

generate visualization data for a graphical visualization, the visualization data indicating one or more metrics associated with the plurality of events, wherein the token identifier and the one or more metrics are indicative of a same component; and

cause display of the graphical visualization.

16. The computing system of claim 15 , wherein the one or more metrics comprise at least one of one or more metrics of the one or more computing components or one or more metrics of one or more components of a data intake and query system that processes the plurality of events.

17. The computing system of claim 15 , wherein the token identifier is associated with at least one of the one or more computing components or one or more components of a data intake and query system that processes the plurality of events.

18. Non-transitory, computer readable media comprising computer-executable instructions that, when executed by a computing system, cause the computing system to:

identify a plurality of events associated with a token identifier, wherein event data of the plurality of events is obtained from data included within a plurality of messages output by one or more computing components, wherein the token identifier corresponds to a token authenticating the plurality of messages and raw machine data output by the one or more computing components;

generate visualization data for a graphical visualization, the visualization data indicating one or more metrics associated with the plurality of events, wherein the token identifier and the one or more metrics are indictive of a same component; and

cause display of the graphical visualization.

19. The non-transitory computer readable media of claim 18 , wherein the one or more metrics comprise at least one of one or more metrics of the one or more computing components or one or more metrics of one or more components of a data intake and query system that processes the plurality of events.

20. The non-transitory computer readable media of claim 18 , wherein the token identifier is associated with at least one of the one or more computing components or one or more components of a data intake and query system that processes the plurality of events.

Assignments (2)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
Continuity (5)
Continuation 17861046 · Jul 8, 2022
Continuation 16698810 · Nov 27, 2019
Continuation 15011652 · Jan 31, 2016
Related Publication 20240134877A1 · Apr 25, 2024
Related Publication 20240232219A9 · Jul 11, 2024
References Cited (138)
US 5796952A · Davis · 1998 [cited by examiner]
US 6446135B1 · Koppolu · 2002 [cited by examiner]
US 7653742B1 · Bhargava · 2010 [cited by examiner]
US 7849502B1 · Bloch · 2010 [cited by examiner]
US 7873710B2 · Kiley · 2011 [cited by examiner]
US 7908397B1 · Chen · 2011 [cited by examiner]
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8682925B1 · Marquardt · 2014 [cited by examiner]
US 8751529B2 · Zhang · 2014 [cited by examiner]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9026674B1 · Kanna · 2015 [cited by examiner]
US 9128779B1 · Gladkikh · 2015 [cited by examiner]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates · 2016 [cited by examiner]
US 9397861B1 · Tovino · 2016 [cited by examiner]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 9596150B2 · Kalus · 2017 [cited by examiner]
US 9635011B1 · Wu et al. · 2017 [cited by applicant]
US 9686159B2 · Poe · 2017 [cited by examiner]
US RE46852E · Petrovykh · 2018 [cited by examiner]
US 10127258B2 · Lamas · 2018 [cited by examiner]
US 10169651B2 · Gu · 2019 [cited by examiner]
US 10257059B2 · Dickey · 2019 [cited by examiner]
US 10331677B1 · Horowitz · 2019 [cited by applicant]
US 10534791B1 · Block et al. · 2020 [cited by applicant]
US 10880366B1 · Chen · 2020 [cited by examiner]
US 10984013B1 · Block et al. · 2021 [cited by applicant]
US 11093476B1 · Neeman · 2021 [cited by examiner]
US 11386113B2 · Block et al. · 2022 [cited by applicant]
US 11829381B2 · Block et al. · 2023 [cited by applicant]
US 11921693B1 · Neeman et al. · 2024 [cited by applicant]
US 12105724B1 · Block et al. · 2024 [cited by applicant]
US 20020048269A1 · Hong · 2002 [cited by examiner]
US 20020053033A1 · Cooper · 2002 [cited by examiner]
US 20020138566A1 · Leach · 2002 [cited by examiner]
US 20020138582A1 · Chandra · 2002 [cited by examiner]
US 20030217162A1 · Fu · 2003 [cited by examiner]
US 20030225924A1 · Jung · 2003 [cited by examiner]
US 20040044912A1 · Connary · 2004 [cited by examiner]
US 20040088423A1 · Miller · 2004 [cited by examiner]
US 20040181693A1 · Milliot · 2004 [cited by examiner]
US 20040186918A1 · Lonnfors · 2004 [cited by examiner]
US 20060036644A1 · Cheslow · 2006 [cited by examiner]
US 20060036720A1 · Faulk · 2006 [cited by examiner]
US 20070064680A1 · Savchenko · 2007 [cited by examiner]
US 20070067383A1 · Savchenko · 2007 [cited by examiner]
US 20070067479A1 · Angelov · 2007 [cited by examiner]
US 20070067494A1 · Savchenko · 2007 [cited by examiner]
US 20070074169A1 · Chess · 2007 [cited by examiner]
US 20070094671A1 · Stephens · 2007 [cited by examiner]
US 20070118491A1 · Baum · 2007 [cited by examiner]
US 20070124577A1 · Nielsen · 2007 [cited by examiner]
US 20070156756A1 · Stoyanova · 2007 [cited by examiner]
US 20070156859A1 · Savchenko · 2007 [cited by examiner]
US 20070240208A1 · Yu · 2007 [cited by examiner]
US 20070265947A1 · Schimpf · 2007 [cited by examiner]
US 20080063154A1 · Tamari · 2008 [cited by examiner]
US 20080127149A1 · Kosche · 2008 [cited by examiner]
US 20080215546A1 · Baum · 2008 [cited by examiner]
US 20080222248A1 · Eberlein · 2008 [cited by examiner]
US 20080307056A1 · Videlov · 2008 [cited by examiner]
US 20100029308A1 · Tims · 2010 [cited by examiner]
US 20100070620A1 · Awadallah · 2010 [cited by examiner]
US 20100106562A1 · Taylor · 2010 [cited by examiner]
US 20100235762A1 · Laiho · 2010 [cited by examiner]
US 20110113048A1 · Njemanze · 2011 [cited by examiner]
US 20110124319A1 · Fu · 2011 [cited by examiner]
US 20110125847A1 · Cocheu · 2011 [cited by examiner]
US 20110138052A1 · Caplan · 2011 [cited by examiner]
US 20110276408A1 · Toole · 2011 [cited by examiner]
US 20110302653A1 · Frantz · 2011 [cited by examiner]
US 20110307580A1 · Fullett · 2011 [cited by examiner]
US 20120136926A1 · Dillon · 2012 [cited by examiner]
US 20120197928A1 · Zhang · 2012 [cited by examiner]
US 20120197934A1 · Zhang · 2012 [cited by examiner]
US 20120198057A1 · Ennis, Jr. · 2012 [cited by examiner]
US 20120271902A1 · Baliga · 2012 [cited by examiner]
US 20130145222A1 · Birdsall · 2013 [cited by examiner]
US 20130191500A1 · Shafi · 2013 [cited by examiner]
US 20130219397A1 · Adams · 2013 [cited by examiner]
US 20130232164A1 · Bigney · 2013 [cited by examiner]
US 20130318236A1 · Coates · 2013 [cited by examiner]
US 20130318603A1 · Merza · 2013 [cited by examiner]
US 20130318604A1 · Coates · 2013 [cited by examiner]
US 20130326620A1 · Merza · 2013 [cited by examiner]
US 20130332445A1 · Opalinski · 2013 [cited by examiner]
US 20140074889A1 · Neels · 2014 [cited by examiner]
US 20140101134A1 · Bohrer · 2014 [cited by examiner]
US 20140201838A1 · Varsanyi · 2014 [cited by examiner]
US 20140223011A1 · Smith · 2014 [cited by examiner]
US 20140304407A1 · Moon · 2014 [cited by examiner]
US 20150067185A1 · Tamblin · 2015 [cited by examiner]
US 20150149879A1 · Miller · 2015 [cited by examiner]
US 20150180891A1 · Seward · 2015 [cited by examiner]
US 20150213631A1 · Vander Broek · 2015 [cited by examiner]
US 20150215177A1 · Pietrowicz · 2015 [cited by examiner]
US 20150293954A1 · Hsiao · 2015 [cited by examiner]
US 20150341212A1 · Hsiao · 2015 [cited by examiner]
US 20150372855A1 · Kushmerick · 2015 [cited by examiner]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160196131A1 · Searle et al. · 2016 [cited by applicant]
US 20160224577A1 · Miller · 2016 [cited by examiner]
US 20160248644A1 · Dontcheva · 2016 [cited by examiner]
US 20160275593A1 · Cosano-Martinez · 2016 [cited by examiner]
US 20160294614A1 · Searle et al. · 2016 [cited by applicant]
US 20160321352A1 · Patel · 2016 [cited by examiner]
US 20160350091A1 · Khot · 2016 [cited by applicant]
US 20160350093A1 · Walker et al. · 2016 [cited by applicant]
US 20160350153A1 · Khot et al. · 2016 [cited by applicant]
US 20160350303A1 · Fischer et al. · 2016 [cited by applicant]
US 20160350367A1 · Fischer · 2016 [cited by examiner]
US 20160359872A1 · Yadav · 2016 [cited by examiner]
US 20160373293A1 · Kushmerick · 2016 [cited by examiner]
US 20170069043A1 · Doyle · 2017 [cited by examiner]
US 20170199727A1 · Lau · 2017 [cited by examiner]
US 20170201495A1 · Cooley · 2017 [cited by examiner]
US 20170371568A1 · Aravot · 2017 [cited by examiner]
US 20180004820A1 · Hao · 2018 [cited by examiner]
US 20180041500A1 · Menhem et al. · 2018 [cited by applicant]
US 20190098106A1 · Mungel · 2019 [cited by examiner]
US 20200097484A1 · Block et al. · 2020 [cited by applicant]
US 20200220875A1 · Harguindeguy et al. · 2020 [cited by applicant]
US 20220414119A1 · Block et al. · 2022 [cited by applicant]
U.S. Appl. No. 15/011,651, filed Jan. 31, 2016, Block et al. [cited by applicant]
U.S. Appl. No. 15/011,652, filed Jan. 31, 2016, Block et al. [cited by applicant]
U.S. Appl. No. 16/189,124, filed Nov. 12, 2018, Block et al. [cited by applicant]
U.S. Appl. No. 17/225,900, filed Apr. 8, 2021, Block et al. [cited by applicant]
U.S. Appl. No. 17/861,046, filed Jul. 8, 2022, Block et al. [cited by applicant]
Vaid, Workshop on Managing Systems via log Analysis and Machine Learning Techniques (SLAML '10), ;login: vol. 36, No. 1, Oct. 3, 2010, Vancouver, BC, Canada. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
SLAML 10 Reports, Workshop On Managing Systems via Log Analysis and Machine Learning Techniques, ;login: Feb. 2011 Conference Reports. [cited by applicant]
Schmidt et al., “The Enterprise Service Bus: Making service-oriented architecture real,” IMB Systems Journal (Year: 2005). [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
U.S. Appl. No. 18/806,379, filed Aug. 15, 2024, Block et al. [cited by applicant]