发明名称 |
MANAGING DATASETS PRODUCED BY ALERT-TRIGGERING SEARCH QUERIES |
摘要 |
Systems and methods for managing datasets produced by alert-triggering search queries in data aggregation and analysis systems. An example method may comprise: executing, by one or more processing devices, a search query on a portion of searchable data associated with a time window to produce a dataset comprising one or more results; responsive to determining that at least a portion of the dataset satisfies a triggering condition defining an alert associated with the search query, generating an instance of the alert; associating, by a memory data structure, the instance of the alert with an identifier of the search query and a time parameter specifying the time window; receiving, from a client computing device, a request for the portion of the dataset; and responsive to determining that the portion of the dataset is not stored in the memory in a manner associating it with the instance of the alert, reproducing the portion of the dataset by re-executing the search query in view of the time parameter. |
申请公布号 |
US2016147830(A1) |
申请公布日期 |
2016.05.26 |
申请号 |
US201414396367 |
申请日期 |
2014.07.09 |
申请人 |
SPLUNK INC. |
发明人 |
Zhong Qianjie;Wang Ting;Lee Margaret;Li Dawei;Filippi Nick;Ni Yue;Yuan Shiming |
分类号 |
G06F17/30;G08B21/18 |
主分类号 |
G06F17/30 |
代理机构 |
|
代理人 |
|
主权项 |
1. A method, comprising:
executing, by one or more processing devices, a search query on a portion of searchable data associated with a time window to produce a dataset comprising one or more results; responsive to determining that at least a portion of the dataset satisfies a triggering condition defining an alert associated with the search query, generating an instance of the alert; associating, by a memory data structure, the instance of the alert with an identifier of the search query and a time parameter specifying the time window; receiving, from a client computing device, a request for the portion of the dataset; and responsive to determining that the portion of the dataset is not stored in the memory in a manner associating it with the instance of the alert, reproducing the portion of the dataset by re-executing the search query in view of the time parameter. |
地址 |
San Francisco CA US |