PROVIDING EXTRACTION RESULTS FOR A PARTICULAR FIELD

    公开(公告)号:US20210174009A1

    公开(公告)日:2021-06-10

    申请号:US17169254

    申请日:2021-02-05

    Applicant: SPLUNK Inc.

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

    PREVIEWING AN EXTRACTION RULE FOR A FIELD IN EXEMPLARY EVENTS AND MODIFYING THE RULE THROUGH COUNTER-EXAMPLE
    2.
    发明申请
    PREVIEWING AN EXTRACTION RULE FOR A FIELD IN EXEMPLARY EVENTS AND MODIFYING THE RULE THROUGH COUNTER-EXAMPLE 审中-公开
    通过对比例来预测一个场景中的抽象规则并修改规则

    公开(公告)号:US20140208245A1

    公开(公告)日:2014-07-24

    申请号:US14169268

    申请日:2014-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.

    Abstract translation: 实施例涉及基于诸如正则表达式的至少一个提取规则来实时显示事件记录和提取的值。 可以使用用户界面来使用户能够自动生成提取规则和/或手动输入提取规则。 可以使用户手动编辑先前提供的提取规则,这可以导致更新的提取值的实时显示。 提取规则可以用于从多个记录中的每一个提取值,包括非结构化机器数据的事件记录。 可以针对每个唯一提取的值确定统计量,并且可以实时地向用户显示。 用户界面还可以使用户能够选择至少一个唯一的提取值来显示包括与所选择的值匹配的提取值的那些事件记录。

    DETERMINING AN EXTRACTION RULE FROM POSITIVE AND NEGATIVE EXAMPLES

    公开(公告)号:US20200034414A1

    公开(公告)日:2020-01-30

    申请号:US16589445

    申请日:2019-10-01

    Applicant: SPLUNK INC.

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

    PREVIEWING AN EXTRACTION RULE FOR RAW MACHINE DATA AND MODIFYING THE RULE THROUGH COUNTER-EXAMPLE
    4.
    发明申请
    PREVIEWING AN EXTRACTION RULE FOR RAW MACHINE DATA AND MODIFYING THE RULE THROUGH COUNTER-EXAMPLE 审中-公开
    检查原始机器数据的提取规则并通过反例来修改规则

    公开(公告)号:US20150143220A1

    公开(公告)日:2015-05-21

    申请号:US14611093

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.

    Abstract translation: 实施例涉及基于诸如正则表达式的至少一个提取规则来实时显示事件记录和提取的值。 可以使用用户界面来使用户能够自动生成提取规则和/或手动输入提取规则。 可以使用户手动编辑先前提供的提取规则,这可以导致更新的提取值的实时显示。 提取规则可以用于从多个记录中的每一个提取值,包括非结构化机器数据的事件记录。 可以针对每个唯一提取的值确定统计量,并且可以实时地向用户显示。 用户界面还可以使用户能够选择至少一个唯一的提取值来显示包括与所选择的值匹配的提取值的那些事件记录。

Patent Agency Ranking