Monitoring IT services at an individual overall level from machine data

US9762455B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9762455-B2
Application numberUS-201615296030-A
CountryUS
Kind codeB2
Filing dateOct 17, 2016
Priority dateOct 9, 2014
Publication dateSep 12, 2017
Grant dateSep 12, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One or more processing devices derive values indicative of various aspects of how a particular service in an information technology (IT) environment is performing at a point in time or for a period of time. The values are derived by a search query over machine data associated with the one or more entities that provide the service. The one or more processing devices determine a value for an aggregate key performance indicator (KPI) for the service to indicate or characterize the service overall from values for each of the various aspects.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: deriving a value for each of a plurality of key performance indicators (KPIs), each KPI indicating a different aspect of how a same service provided by one or more entities is performing at a point in time or during a period of time, each KPI defined by a search query that derives the value for that KPI from machine data associated with the one or more entities that provide the same service, each of the one or more entities having a respective entity definition including information to identify the machine data associated with the respective entity, and the same service having a service definition associating each of the entity definitions; and determining a value for an aggregate KPI for the same service from the values for each of the plurality of KPIs, wherein the machine data is produced by one or more components within an information technology environment and reflects activity within the information technology environment; wherein the method is performed by a computer system comprising one or more processing devices. 2. The method of claim 1 wherein the machine data includes segments of machine data each associated with a respective timestamped event. 3. The method of claim 1 wherein the machine data associated with a particular one of the entities comes from two or more sources. 4. The method of claim 1 wherein the machine data associated with a particular one of the entities comes from a first source in accordance with a first data representation and from a second source in accordance with a second data representation. 5. The method of claim 1 wherein the machine data associated with a particular one of the entities comes from the particular entity and at least one other source. 6. The method of claim 1 , further comprising: comparing the value for the aggregate KPI to a threshold; and indicating an alert based on the comparison. 7. The method of claim 1 , further comprising: comparing the value for the aggregate KPI to a threshold; and generating a notable event based on the comparison. 8. The method of claim 1 , further comprising: comparing the value for the aggregate KPI to a threshold; and causing display of an entry in an incident-review dashboard based on the comparison. 9. The method of claim 1 wherein the search query defining a KPI derives the value for that KPI in part by applying a late-binding schema to machine data. 10. The method of claim 1 wherein the search query defining a KPI derives the value for that KPI in part by applying a late-binding schema to events containing portions of the machine data. 11. The method of claim 1 wherein deriving a value for each of a plurality of key performance indicators (KPIs) comprises executing the search query defining each KPI in accordance with a user-specified frequency. 12. The method of claim 1 wherein deriving a value for each of a plurality of key performance indicators (KPIs) comprises executing the search query defining each KPI in accordance with a user-specified schedule. 13. The method of claim 1 wherein determining the value for the aggregate KPI includes applying a weighting associated with at least one of the KPIs. 14. The method of claim 1 wherein determining the value for the aggregate KPI includes applying a user-specified weighting associated with at least one of the KPIs. 15. The method of claim 1 wherein determining the value for the aggregate KPI includes, for each KPI, applying a corresponding weighting to the value derived for the KPI. 16. The method of claim 1 wherein determining a value for an aggregate KPI is based at least in part on mapping the value for each of the plurality of KPIs to one of a plurality of states, each state defined by a range of values. 17. A system comprising: a memory; and a processing device coupled with the memory to: derive a value for each of a plurality of key performance indicators (KPIs), each KPI indicating a different aspect of how a same service provided by one or more entities is performing at a point in time or during a period of time, each KPI defined by a search query that derives the value for that KPI from machine data associated with the one or more entities that provide the same service, each of the one or more entities having a respective entity definition including information to identify the machine data associated with the respective entity, and the same service having a service definition associating each of the entity definitions; and determine a value for an aggregate KPI for the same service from the values for each of the plurality of KPIs; wherein the machine data is produced by one or more components within an information technology environment and reflects activity within the information technology environment. 18. The system of claim 17 wherein the machine data includes segments of machine data each associated with a respective timestamped event. 19. The system of claim 17 wherein the machine data associated with a particular one of the entities comes from two or more sources. 20. The system of claim 17 wherein the machine data associated with a particular one of the entities comes from a first source in accordance with a first data representation and from a second source in accordance with a second data representation. 21. The system of claim 17 wherein the machine data associated with a particular one of the entities comes from the particular entity and at least one other source. 22. The system of claim 17 further to: compare the value for the aggregate KPI to a threshold; and indicate an alert based on the comparison. 23. The system of claim 17 further to: compare the value for the aggregate KPI to a threshold; and generate a notable event based on the comparison. 24. The system of claim 17 further to: compare the value for the aggregate KPI to a threshold; and cause display of an entry in an incident-review dashboard based on the comparison. 25. The system of claim 17 wherein the search query defining a KPI derives the value for that KPI in part by applying a late-binding schema to machine data. 26. The system of claim 17 wherein the search query defining a KPI derives the value for that KPI in part by applying a late-binding schema to events containing portions of the machine data. 27. The system of claim 17 wherein to derive a value for each of a plurality of key performance indicators (KPIs) comprises executing the search query defining each KPI in accordance with a user-specified frequency. 28. The system of claim 17 wherein to derive a value for each of a plurality of key performance indicators (KPIs) comprises executing the search query defining each KPI in accordance with a user-specified schedule. 29. The system of claim 17 wherein to determine the value for the aggregate KPI includes applying a user-specified weighting associated with at least one of the KPIs. 30. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the processing device to perform operations comprising: deriving a value for each of a plurality of key performance indicators (KPIs), each KPI indicating a different aspect of how a same service provided by one or more entities is performing at a point in ti

Assignees

Inventors

Classifications

  • for graphical visualisation of monitoring data · CPC title

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • Standardised network management protocols, e.g. simple network management protocol [SNMP] · CPC title

  • Electricity · mapped topic

  • Interaction with lists of selectable items, e.g. menus · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9762455B2 cover?
One or more processing devices derive values indicative of various aspects of how a particular service in an information technology (IT) environment is performing at a point in time or for a period of time. The values are derived by a search query over machine data associated with the one or more entities that provide the service. The one or more processing devices determine a value for an aggr…
Who is the assignee on this patent?
Splunk Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/5032. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 12 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).