发明名称 MANAGING DATASETS PRODUCED BY ALERT-TRIGGERING SEARCH QUERIES
摘要 Systems and methods for managing datasets produced by alert-triggering search queries in data aggregation and analysis systems. An example method may comprise: executing, by one or more processing devices, a search query on a portion of searchable data associated with a time window to produce a dataset comprising one or more results; responsive to determining that at least a portion of the dataset satisfies a triggering condition defining an alert associated with the search query, generating an instance of the alert; associating, by a memory data structure, the instance of the alert with an identifier of the search query and a time parameter specifying the time window; receiving, from a client computing device, a request for the portion of the dataset; and responsive to determining that the portion of the dataset is not stored in the memory in a manner associating it with the instance of the alert, reproducing the portion of the dataset by re-executing the search query in view of the time parameter.
申请公布号 US2016147830(A1) 申请公布日期 2016.05.26
申请号 US201414396367 申请日期 2014.07.09
申请人 SPLUNK INC. 发明人 Zhong Qianjie;Wang Ting;Lee Margaret;Li Dawei;Filippi Nick;Ni Yue;Yuan Shiming
分类号 G06F17/30;G08B21/18 主分类号 G06F17/30
代理机构 代理人
主权项 1. A method, comprising: executing, by one or more processing devices, a search query on a portion of searchable data associated with a time window to produce a dataset comprising one or more results; responsive to determining that at least a portion of the dataset satisfies a triggering condition defining an alert associated with the search query, generating an instance of the alert; associating, by a memory data structure, the instance of the alert with an identifier of the search query and a time parameter specifying the time window; receiving, from a client computing device, a request for the portion of the dataset; and responsive to determining that the portion of the dataset is not stored in the memory in a manner associating it with the instance of the alert, reproducing the portion of the dataset by re-executing the search query in view of the time parameter.
地址 San Francisco CA US