IP Library Granted Patent US 9,055,075
Granted Patent B2
US 9,055,075 · App. 14/449,135 · Granted Jun 9, 2015

Project resource access control

Inventors: Robin Kumar Das (Healdsburg, CA); Ledio Ago (San Leandro, CA); Declan Gerard Shanaghy (Benicia, CA); Gaurav Gupta (San Francisco, CA)
Assignee: Splunk Inc.
H04L63/10G06F17/30896G06F17/30321G06F17/3087G06F17/30091G06F17/30094G06F17/30117G06Q20/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,055,075
App. No.
14/449,135
Filed
Jul 31, 2014
Granted
Jun 9, 2015
Kind
B2
Art Unit
2162
USPC
707/783
Abstract

Embodiments are directed towards a system and method for a cloud-based front end that may abstract and enable access to the underlying cloud-hosted elements and objects that may be part of a multi-tenant application, such as a search application. Search objects may be employed to access indexed objects. An amount of indexed data accessible to a user may be based on an index storage limit selected by the user, such that data that exceeds the index storage limit may continue to be indexed. Also, one or more projects can be elastically scaled for a user to provide resources that may meet the specific needs of each project.

Claims (52)

1. A method, comprising:

determining at least one role for each project of a plurality of projects, wherein a role describes permissions for a user for interacting with resources associated with a project;

receiving a request from a first user to search indexed data in a data store for a particular project;

determining a role of the first user for the particular project;

determining whether the first user has permission to search indexed data in the data store based on the role determined for the first user, wherein the role of the first user for the particular project grants the first user permission to search indexed data in the data store for the particular project;

allowing the first user to search indexed data in the data store for the particular project when the role indicates that the first user has permission to search indexed data in the data store for the particular project;

wherein the method is performed by one or more computing devices.

2. The method of claim 1 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store.

3. The method of claim 1 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store and grants the first user permission to search indexed data in the index store.

4. The method of claim 1 , wherein the role of the first user for the particular project grants the first user permission to access cloud-based resources.

5. The method of claim 1 , wherein the search is performed by a cloud-based search application.

6. The method of claim 1 , wherein the particular project comprises: receiving raw data.

7. The method of claim 1 , wherein the particular project comprises: storing indexed data.

8. The method of claim 1 , wherein the particular project comprises: dividing raw data into time stamped searchable events, storing the time-stamped searchable events, and searching the time-stamped searchable events.

9. The method of claim 1 , further comprising:

receiving input corresponding to an invitation to provide access to the particular project to a second user;

wherein the second user inherits the role for the particular project from the first user.

10. The method of claim 1 , wherein the plurality of projects reside in a cloud-based, multi-tenant environment sharing a common application program.

11. An apparatus, comprising:

a subsystem, implemented at least partially in hardware, that determines at least one role for each project of a plurality of projects, wherein a role describes permissions for a user for interacting with resources associated with a project;

a subsystem, implemented at least partially in hardware, that receives a request from a first user to search indexed data in a data store for a particular project;

a subsystem, implemented at least partially in hardware, that determines a role of the first user for the particular project;

a subsystem, implemented at least partially in hardware, that determines whether the first user has permission to search indexed data in the data store based on the role determined for the first user, wherein the role of the first user for the particular project grants the first user permission to search indexed data in the data store for the particular project;

a subsystem, implemented at least partially in hardware, that allows the first user to search indexed data in the data store for the particular project when the role indicates that the first user has permission to search indexed data in the data store for the particular project.

12. The apparatus of claim 11 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store.

13. The apparatus of claim 11 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store and grants the first user permission to search indexed data in the index store.

14. The apparatus of claim 11 , wherein the role of the first user for the particular project grants the first user permission to access cloud-based resources.

15. The apparatus of claim 11 , wherein the search is performed by a cloud-based search application.

16. The apparatus of claim 11 , wherein the particular project comprises: receiving raw data.

17. The apparatus of claim 11 , wherein the particular project comprises: storing indexed data.

18. The apparatus of claim 11 , wherein the particular project comprises: dividing raw data into time stamped searchable events, storing the time-stamped searchable events, and searching the time-stamped searchable events.

19. The apparatus of claim 11 , further comprising:

a subsystem, implemented at least partially in hardware, that receives input corresponding to an invitation to provide access to the particular project to a second user;

wherein the second user inherits the role for the particular project from the first user.

20. The apparatus of claim 11 , wherein the plurality of projects reside in a cloud-based, multi-tenant environment sharing a common application program.

21. A non-transitory computer-readable medium storing one or more sequences of instructions, wherein execution of the one or more sequences of instructions by one or more processors causes the one or more processors to perform:

determining at least one role for each project of a plurality of projects, wherein a role describes permissions for a user for interacting with resources associated with a project;

receiving a request from a first user to search indexed data in a data store for a particular project;

determining a role of the first user for the particular project;

determining whether the first user has permission to search indexed data in the data store based on the role determined for the first user, wherein the role of the first user for the particular project grants the first user permission to search indexed data in the data store for the particular project;

allowing the first user to search indexed data in the data store for the particular project access to the resource when the role indicates that the first user has permission to search indexed data in the data store for the particular project.

22. The non-transitory computer-readable medium of claim 21 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store.

23. The non-transitory computer-readable medium of claim 21 , wherein the role of the first user for the particular project grants the first user permission to provide data to be indexed in an index store and grants the first user permission to search indexed data in the index store.

24. The non-transitory computer-readable medium of claim 21 , wherein the role of the first user for the particular project grants the first user permission to access cloud-based resources.

25. The non-transitory computer-readable medium of claim 21 , wherein the search is performed by a cloud-based search application.

26. The non-transitory computer-readable medium of claim 21 , wherein the particular project comprises: receiving raw data.

27. The non-transitory computer-readable medium of claim 21 , wherein the particular project comprises: storing indexed data.

28. The non-transitory computer-readable medium of claim 21 , wherein the particular project comprises: dividing raw data into time stamped searchable events, storing the time-stamped searchable events, and searching the time-stamped searchable events.

29. The non-transitory computer-readable medium of claim 21 , wherein execution of the one or more sequences of instructions by the one or more processors causes the one or more processors to further perform:

receiving input corresponding to an invitation to provide access to the particular project to a second user;

wherein the second user inherits the role for the particular project from the first user.

30. The non-transitory computer-readable medium of claim 21 , wherein the plurality of projects reside in a cloud-based, multi-tenant environment sharing a common application program.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAMES PREVIOUSLY RECORDED AT REEL: 036524 FRAME: 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 11, 2015
From: DAS, ROBIN KUMAR; AGO, LEDIO; SHANAGHY, DECLAN GERARD; GUPTA, GAURAV
To: SPLUNK INC.
Reel/Frame 036587/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2015
From: BAUM, MICHAEL JOSEPH; CARASSO, R. DAVID; DAS, ROBIN KUMAR; HALL, BRADLEY; MURPHY, BRIAN PHILIP; SORKIN, STEPHEN PHILLIP; STECHERT, ANDRE DAVID; SWAN, ERIK M.; GREENE, RORY; MEALY, NICHOLAS CHRISTIAN; NOREN, CHRISTINA
To: SPLUNK INC.
Reel/Frame 036524/0517 →
Continuity (5)
Continuation 14068445 · Oct 31, 2013
Continuation 13662356 · Oct 26, 2012
Continuation 13572434 · Aug 10, 2012
Provisional Application 61523063 · Aug 12, 2011
Related Publication 20140344900A1 · Nov 20, 2014