Patents by Inventor Eric Tschetter
Eric Tschetter has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12001426Abstract: Systems and methods are disclosed for supporting transformations of a graph generated from a query to event data. The event data may be unstructured event data, from which instances of a journey can be identified that represent sequences of related events describing actions performed in a computing environment. When evaluating journey instances, it can be helpful to visualize the instances as a graph. Depending on the instances viewed, a user may desire different modifications to the graph. While such modifications can be made when initially building instances from the unstructured event data, this can limit reuse of the resulting instances (since the modification would also be present when evaluating other subsets). To address this, embodiments of the present disclosure enable graph modifications to be applied to subsets of journey instances after building those instances from unstructured event data, increasing reuse of instances built from a query against the unstructured data.Type: GrantFiled: April 4, 2023Date of Patent: June 4, 2024Assignee: Splunk Inc.Inventors: Chandrashekar Basavaiah, Elizabeth Li, Eric Tschetter, Joshua Walters
-
Publication number: 20240020311Abstract: A system and method for implementing an iterative query mechanism to facilitate query-time sessionization and analysis of data is disclosed. At least, the method includes determining a table of independent events, determining a query, the query including a parameter specifying a size limit on a sample of sessions, executing the query against the table of independent events, at the time of query execution, processing the table of independent events to reconstruct the sample of sessions approaching the size limit, and at the time of query execution, analyzing the sample of reconstructed sessions to generate a result.Type: ApplicationFiled: July 17, 2023Publication date: January 18, 2024Inventors: Eric Tschetter, Rohan Garg
-
Patent number: 11829746Abstract: Systems and methods are disclosed for providing a multi-component application, including a first and second component. Functionality of the application may be easily and rapidly modified by modification to the first component, without requiring modification to the second component. The first component may be implemented locally at a client device, while the second component is implemented remotely. While modification of the second component may require privileges of a remote location, a user of a client device may modify the first component while maintaining interoperability and compatibility with the second component, thereby enabling the end user to modify functionality of the multi-component application. In some instances, different versions of a first component are provided, and an end user of a client device is enabled to specify which version of the first component should be used.Type: GrantFiled: January 31, 2022Date of Patent: November 28, 2023Assignee: Splunk Inc.Inventors: Akash Dwivedi, Simon Foster Fishel, Isabelle Park, Vivian Shen, Eric Tschetter, Joshua Walters
-
Patent number: 11809497Abstract: Systems and methods are disclosed for processing events having raw machine data associated with a timestamp using one or more pivot identifiers and one or more step identifiers to generate one or more journey instances. Based on the one or more pivot identifier field, the system can relate events that have a common field value for the pivot identifier field. Based on the one or more step identifiers, the system can group the related events into a subset of events. Using the subset of events, the system can build a journey instance.Type: GrantFiled: January 6, 2023Date of Patent: November 7, 2023Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Foster Fishel
-
Patent number: 11741131Abstract: Systems and methods are disclosed for efficiently uploading event data of a data intake and processing system and building journey instances using the uploaded event data in a distributed manner. Each journey instance is illustratively associated with a series of events within the event data occurring over a journey duration. For example, a cloud-based hosting system can implement a cloud-based distributed system that receives fragmented uploads of event data from the data intake and query system. Once received, the cloud-based hosting system can combine the event data from one or more uploads and re-stitch portions of the uploaded event data using a set of worker nodes to build journey instances.Type: GrantFiled: January 29, 2021Date of Patent: August 29, 2023Assignee: Splunk Inc.Inventors: Akash Dwivedi, Himanshu Gupta, Eric Tschetter, Rahul Gidwani
-
Patent number: 11726990Abstract: Systems and methods are disclosed for efficiently storing information identifying journey instances within unstructured event data of a data intake and processing system. Each journey instance is illustratively associated with a series of events within the unstructured event data occurring over a journey duration. Because the unstructured event data may be constantly updated, any given inspection of the event data may yield both complete and incomplete instances. Storage of instance data over time can require updating of prior incomplete journey instances with complete versions of such instance detected at a later point in time. However, a data store of the unstructured event data may be unsuited for such updating, as the store may maintain version information for deleted data to reduce possibility of data loss. To address this issue, a separate structured data store, such as a columnar time series data store, is provided to efficiently store instance information.Type: GrantFiled: October 18, 2021Date of Patent: August 15, 2023Assignee: Splunk Inc.Inventors: Akash Dwivedi, Himanshu Gupta, Eric Tschetter
-
Publication number: 20230118230Abstract: A system and method for implementing an iterative query mechanism to facilitate distributed aggregation and interactive visualization of data is disclosed. At least, the method includes receiving user interaction in association with rendering a visualization of hierarchical data, determining a query based on the user interaction, distributing the query in parallel to a cluster of computing devices, wherein each computing device in the cluster locally generates and prunes a tree based on processing the query, receiving a plurality of trees from the cluster of computing devices responsive to distributing the query, merging the plurality of trees into an aggregated tree, and rendering the visualization of hierarchical data based on the aggregated tree.Type: ApplicationFiled: October 3, 2022Publication date: April 20, 2023Inventors: Eric Tschetter, Vadim Ogievetsky
-
Patent number: 11625394Abstract: Systems and methods are disclosed for supporting transformations of a graph generated from a query to event data. The event data may be unstructured event data, from which instances of a journey can be identified that represent sequences of related events describing actions performed in a computing environment. When evaluating journey instances, it can be helpful to visualize the instances as a graph. Depending on the instances viewed, a user may desire different modifications to the graph. While such modifications can be made when initially building instances from the unstructured event data, this can limit reuse of the resulting instances (since the modification would also be present when evaluating other subsets). To address this, embodiments of the present disclosure enable graph modifications to be applied to subsets of journey instances after building those instances from unstructured event data, increasing reuse of instances built from a query against the unstructured data.Type: GrantFiled: March 4, 2022Date of Patent: April 11, 2023Assignee: Splunk Inc.Inventors: Chandrashekar Basavaiah, Elizabeth Li, Eric Tschetter, Joshua Walters
-
Patent number: 11550849Abstract: Systems and methods are disclosed for processing events having raw machine data associated with a timestamp using one or more pivot identifiers and one or more step identifiers to generate one or more journey instances. Based on the one or more pivot identifier field, the system can relate events that have a common field value for the pivot identifier field. Based on the one or more step identifiers, the system can group the related events into a subset of events. Using the subset of events, the system can build a journey instance.Type: GrantFiled: January 28, 2021Date of Patent: January 10, 2023Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Foster Fishel
-
Patent number: 11269876Abstract: Systems and methods are disclosed for supporting transformations of a graph generated from a query to event data. The event data may be unstructured event data, from which instances of a journey can be identified that represent sequences of related events describing actions performed in a computing environment. When evaluating journey instances, it can be helpful to visualize the instances as a graph. Depending on the instances viewed, a user may desire different modifications to the graph. While such modifications can be made when initially building instances from the unstructured event data, this can limit reuse of the resulting instances (since the modification would also be present when evaluating other subsets). To address this, embodiments of the present disclosure enable graph modifications to be applied to subsets of journey instances after building those instances from unstructured event data, increasing reuse of instances built from a query against the unstructured data.Type: GrantFiled: April 30, 2020Date of Patent: March 8, 2022Assignee: Splunk Inc.Inventors: Chandrashekar Basavaiah, Elizabeth Li, Eric Tschetter, Joshua Walters
-
Patent number: 11263229Abstract: Systems and methods are disclosed for efficiently detecting alert states within unstructured event data. Alert states are illustratively defined as occurring when a threshold number of journey instances are present within the unstructured event data, each journey instance representing a series of events within the event data representing steps within a pre-defined journey. Detecting journey instances within unstructured event data can require significant computational resources, and thus attempting to detect alert states directly from unstructured event data can lead to inefficiencies. Embodiments of this disclosure enable a structured data set of journey instances to be generated from unstructured event data, and for the structured data set to be evaluated based on criteria of multiple alert states. By utilizing a single structured data set to support evaluation based on multiple alert states, detecting alert states from unstructured event data is rendered more efficient.Type: GrantFiled: October 18, 2019Date of Patent: March 1, 2022Assignee: Splunk Inc.Inventors: Chandrashekar Basavaiah, Jindrich Dinga, Elizabeth Li, Cary Glen Noel, Isabelle Park, Eric Tschetter, Joshua Walters, Mei Chun Yeh
-
Patent number: 11256497Abstract: Systems and methods are disclosed for providing a multi-component application, including a first and second component. Functionality of the application may be easily and rapidly modified by modification to the first component, without requiring modification to the second component. The first component may be implemented locally at a client device, while the second component is implemented remotely. While modification of the second component may require privileges of a remote location, a user of a client device may modify the first component while maintaining interoperability and compatibility with the second component, thereby enabling the end user to modify functionality of the multi-component application. In some instances, different versions of a first component are provided, and an end user of a client device is enabled to specify which version of the first component should be used.Type: GrantFiled: July 22, 2020Date of Patent: February 22, 2022Assignee: Splunk Inc.Inventors: Akash Dwivedi, Simon Foster Fishel, Isabelle Park, Vivian Shen, Eric Tschetter, Joshua Walters
-
Publication number: 20220043807Abstract: Systems and methods are disclosed for efficiently storing information identifying journey instances within unstructured event data of a data intake and processing system. Each journey instance is illustratively associated with a series of events within the unstructured event data occurring over a journey duration. Because the unstructured event data may be constantly updated, any given inspection of the event data may yield both complete and incomplete instances. Storage of instance data over time can require updating of prior incomplete journey instances with complete versions of such instance detected at a later point in time. However, a data store of the unstructured event data may be unsuited for such updating, as the store may maintain version information for deleted data to reduce possibility of data loss. To address this issue, a separate structured data store, such as a columnar time series data store, is provided to efficiently store instance information.Type: ApplicationFiled: October 18, 2021Publication date: February 10, 2022Inventors: Akash Dwivedi, Himanshu Gupta, Eric Tschetter
-
Patent number: 11194564Abstract: Systems and methods are disclosed for providing a multi-component application, including a first and second component. Functionality of the application may be modified by modification of the first component, potentially without requiring modification of the second component. However, some functionalities added to application may require modifications to both the first and second component. To maintain compatibility between components, the first component can be configured to detect versioning information of a second component, and adjust its functionality to disable functions unavailable due to lack of compatibility with a current version of the second component. The first component can notify an end user of any such lack of compatibility, and potentially instruct the end user in updating the second component.Type: GrantFiled: April 29, 2019Date of Patent: December 7, 2021Assignee: Splunk Inc.Inventors: Akash Dwivedi, Simon Foster Fishel, Eric Tschetter, Joshua Walters
-
Patent number: 11151125Abstract: Systems and methods are disclosed for efficiently storing information identifying journey instances within unstructured event data of a data intake and processing system. Each journey instance is illustratively associated with a series of events within the unstructured event data occurring over a journey duration. Because the unstructured event data may be constantly updated, any given inspection of the event data may yield both complete and incomplete instances. Storage of instance data over time can require updating of prior incomplete journey instances with complete versions of such instance detected at a later point in time. However, a data store of the unstructured event data may be unsuited for such updating, as the store may maintain version information for deleted data to reduce possibility of data loss. To address this issue, a separate structured data store, such as a columnar time series data store, is provided to efficiently store instance information.Type: GrantFiled: January 6, 2020Date of Patent: October 19, 2021Assignee: Splunk Inc.Inventors: Akash Dwivedi, Himanshu Gupta, Eric Tschetter
-
Publication number: 20210224331Abstract: Systems and methods are disclosed for processing events having raw machine data associated with a timestamp using one or more pivot identifiers and one or more step identifiers to generate one or more journey instances. Based on the one or more pivot identifier field, the system can relate events that have a common field value for the pivot identifier field. Based on the one or more step identifiers, the system can group the related events into a subset of events. Using the subset of events, the system can build a journey instance.Type: ApplicationFiled: January 28, 2021Publication date: July 22, 2021Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Foster Fishel
-
Patent number: 10909182Abstract: Systems and methods are disclosed for processing events having raw machine data associated with a timestamp using one or more pivot identifiers and one or more step identifiers to generate one or more journey instances. Based on the one or more pivot identifier field, the system can relate events that have a common field value for the pivot identifier field. Based on the one or more step identifiers, the system can group the related events into a subset of events. Using the subset of events, the system can build a journey instance.Type: GrantFiled: March 26, 2018Date of Patent: February 2, 2021Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Fishel
-
Patent number: 10909128Abstract: Systems and methods are disclosed for processing events having raw machine data associated with a timestamp using one or more pivot identifiers and one or more step identifiers to generate one or more journey instances. Based on the one or more pivot identifier field, the system can relate events that have a common field value for the pivot identifier field. Based on the one or more step identifiers, the system can group the related events into a subset of events. Using the subset of events the system can build a journey instance.Type: GrantFiled: March 26, 2018Date of Patent: February 2, 2021Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Fishel, Horst Werner
-
Patent number: 10885049Abstract: Systems and methods are disclosed for generating a user interface to enable identification of one or more pivot identifiers and one or more step identifiers. The system executes a query on events having raw machine data associated with a timestamp and obtains fields associated with the events. The system further populates a graphical user interface with field identifiers associated with the obtained fields and enables identification of one or more fields as one or more pivot identifiers and one or more step identifiers.Type: GrantFiled: March 26, 2018Date of Patent: January 5, 2021Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Fishel
-
Patent number: 10776377Abstract: Systems and methods are disclosed for generating one or more journey instances from events having raw machine data associated with a timestamp. The system generates a user interface that includes field identifiers associated with the plurality events for selection as one or more pivot identifiers and one or more step identifiers. Based on the one or more pivot identifiers, the system identifies related events that share a common field value, and based on the one or more step identifiers, the system groups the related events into a subset of events. Using the subset of events the system builds a journey instance.Type: GrantFiled: March 26, 2018Date of Patent: September 15, 2020Assignee: Splunk Inc.Inventors: Joerg Beringer, Isabelle Park, Joshua Walters, Eric Tschetter, Simon Fishel