IP Library Granted Patent US 12,657,196
Granted Patent B1
US 12,657,196 · App. 17/965,618 · Granted Jun 16, 2026

Creating a time series based on event data

Inventors: Jeremy Hicks (Ellsworth, ME); Todd Leonard DeCapua (Wilmington, DE); Adam James Schalock (Beaverton, OR); Neil Douglas Erkkila (Cherry Valley, MA); Samuel Halpern (Chicago, IL); Chad Tripod (Livermore, CA); Joel Schoenberg (Vashon, WA); David Connett (Lake Orion, MI)
Assignee: Cisco Technology, Inc.
G06F16/2471G06F16/244G06F16/24561
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,196
App. No.
17/965,618
Granted
Jun 16, 2026
Kind
B1
Abstract

Field-based enterprise events created within an enterprise platform are compared to criteria to determine enterprise events of interest. These enterprise events of interest are used to create key-value based observability events which are sent from the enterprise platform to an observability platform. At the observability platform, the observability events are used to create a time series, and the observability platform analyzes the time series to create one or more reports and/or events. This may enable a compatibility between the log-based enterprise platform and the time-series based observability platform. This may also enable the automatic analysis of log-based data using a (real-time) time-series based approach, which may result in a faster response to log-based issues, which may in turn reduce an amount of damage resulting from such log-based issues (and may improve a performance of computing hardware experiencing the issues reported using log data).

Claims (51)

1 . A computer-implemented method, comprising:

receiving, at an observability computer system from an enterprise computer system, a set of observability events that are key-value based and are created, by an observability component, from field-based enterprise events created by an enterprise component of the enterprise computer system that is separate from the observability component, wherein the enterprise events include structured fields and associated values that are created from log data that includes unstructured data and raw machine data obtained by the enterprise computer system and wherein the observability events created by the observability component are more compact compared to the enterprise events, wherein at least a portion of the log data is generated by one or more applications that enable a sharing of computing resources between isolated execution environments;

creating, by the observability computer system, a time series based on the set of observability events;

identifying, by the observability computer system, a component of a cloud computing system that is a source of data within the time series;

obtaining, by the observability computer system, additional observability events based on data related to real-time monitoring of the component, wherein the additional observability events have values for one or more fields that match values for corresponding fields within the set of observability events utilized to create the time series;

correlating, by the observability computer system, the additional observability events with the time series; and

performing, by the observability computer system, one or more actions based on the time series.

2 . The computer-implemented method of claim 1 , comprising:

receiving, at the enterprise computer system, the log data from one or more host devices;

creating, by the enterprise computer system, a set of enterprise events based on the log data, wherein each of the set of enterprise events includes time value data;

identifying, by the enterprise computer system, enterprise events of interest within the set of enterprise events; and

creating, by the enterprise computer system, the set of observability events utilizing data extracted from the enterprise events of interest, the data including the time value data.

3 . The computer-implemented method of claim 1 , wherein creating, by the observability computer system, the time series based on the set of observability events includes:

determining, by the observability computer system, a time window having a start time and an end time;

determining, by the observability computer system, a time interval within the time window;

creating, by the observability computer system, a set of data points within the time window that correspond to the time interval; and

assigning, by the observability computer system, a value to each data point within the set of data points within the time window to create the time series, wherein the value for each data point indicates a number of the observability events that occur at a time represented by that data point.

4 . The computer-implemented method of claim 1 , wherein performing, by the observability computer system, one or more actions based on the time series includes displaying, by the observability computer system, the time series utilizing a graphical user interface (GUI).

5 . The computer-implemented method of claim 1 , wherein performing, by the observability computer system, one or more actions based on the time series includes generating, by the observability computer system, one or more alerts based on the time series.

6 . The computer-implemented method of claim 1 , wherein performing, by the observability computer system, one or more actions based on the time series includes redirecting, by the observability computer system, one or more workloads.

7 . The computer-implemented method of claim 1 , wherein the observability computer system includes a computer system that creates, analyzes, and manages time series metrics.

8 . The computer-implemented method of claim 1 , wherein the enterprise computer system includes a computer system that creates events based on the log data.

9 . A system comprising:

one or more processors configured to:

receive, at an observability computer system from an enterprise computer system, a set of observability events that are created, by an observability component, from enterprise events created by an enterprise component of the enterprise computer system that is separate from the observability component, wherein the enterprise events include structured fields and associated values that are created from log data that includes unstructured data and raw machine data obtained by the enterprise computer system and wherein the observability events created by the observability component are more compact compared to the enterprise events, wherein at least a portion of the log data is generated by one or more applications that enable a sharing of computing resources between isolated execution environments;

create, by the observability computer system, a time series based on the set of observability events;

identify, by the observability computer system, a component of a cloud computing system that is a source of data within the time series;

obtain, by the observability computer system, additional observability events based on data related to real-time monitoring of the component, wherein the additional observability events have values for one or more fields that match values for corresponding fields within the set of observability events utilized to create the time series;

correlate, by the observability computer system, the additional observability events with the time series; and

perform, by the observability computer system, one or more actions based on the time series.

10 . The system of claim 9 , wherein the one or more processors are further configured to:

receive, at the enterprise computer system, the log data from one or more host devices;

create, by the enterprise computer system, a set of enterprise events based on the log data, wherein each of the set of enterprise events includes time value data;

identify, by the enterprise computer system, enterprise events of interest within the set of enterprise events; and

create, by the enterprise computer system, the set of observability events utilizing data extracted from the enterprise events of interest, the data including the time value data.

11 . The system of claim 9 , wherein creating, by the observability computer system, the time series based on the set of observability events includes:

determining, by the observability computer system, a time window having a start time and an end time;

determining, by the observability computer system, a time interval within the time window;

creating, by the observability computer system, a set of data points within the time window that correspond to the time interval; and

assigning, by the observability computer system, a value to each data point within the set of data points within the time window to create the time series, wherein the value for each data point indicates a number of the observability events that occur at a time represented by that data point.

12 . The system of claim 9 , wherein performing, by the observability computer system, one or more actions based on the time series includes displaying, by the observability computer system, the time series utilizing a graphical user interface (GUI).

13 . The system of claim 9 , wherein performing, by the observability computer system, one or more actions based on the time series includes generating, by the observability computer system, one or more alerts based on the time series.

14 . The system of claim 9 , wherein performing, by the observability computer system, one or more actions based on the time series includes redirecting, by the observability computer system, one or more workloads.

15 . The system of claim 9 , wherein the observability computer system includes a computer system that creates, analyzes, and manages time series metrics.

16 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions when executed by one or more processors cause processing to be performed comprising:

receiving, at an observability computer system from an enterprise computer system, a set of observability events that are created, by an observability component, from enterprise events created by an enterprise component of the enterprise computer system that is separate from the observability component, wherein the enterprise events include structured fields and associated values that are created from log data that includes unstructured data and raw machine data obtained by the enterprise computer system and wherein the observability events created by the observability component are more compact compared to the enterprise events, wherein at least a portion of the log data is generated by one or more applications that enable a sharing of computing resources between isolated execution environments;

creating, by the observability computer system, a time series based on the set of observability events;

identifying, by the observability computer system, a component of a cloud computing system that is a source of data within the time series;

obtaining, by the observability computer system, additional observability events based on data related to real-time monitoring of the component, wherein the additional observability events have values for one or more fields that match values for corresponding fields within the set of observability events utilized to create the time series;

correlating, by the observability computer system, the additional observability events with the time series; and

performing, by the observability computer system, one or more actions based on the time series.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2022
From: HICKS, JEREMY; DECAPUA, TODD LEONARD; SCHALOCK, ADAM JAMES; ERKKILA, NEIL DOUGLAS; HALPERN, SAMUEL; TRIPOD, CHAD; SCHOENBERG, JOEL; CONNETT, DAVID
To: SPLUNK INC.
Reel/Frame 061427/0287 →
References Cited (18)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10885167B1 · Lador · 2021 [cited by examiner]
US 20140380478A1 · Canning · 2014 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20230016199A1 · Jividen · 2023 [cited by examiner]
US 20230075065A1 · Ivenso · 2023 [cited by examiner]
US 20230164156A1 · Grossman · 2023 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]