-
公开(公告)号:US11907244B2
公开(公告)日:2024-02-20
申请号:US17809837
申请日:2022-06-29
Applicant: SPLUNK INC.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
CPC classification number: G06F16/254
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
-
公开(公告)号:US20180157724A1
公开(公告)日:2018-06-07
申请号:US15885809
申请日:2018-01-31
Applicant: Splunk Inc.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
IPC: G06F17/30
CPC classification number: G06F16/254
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
-
公开(公告)号:US20220327137A1
公开(公告)日:2022-10-13
申请号:US17809837
申请日:2022-06-29
Applicant: SPLUNK INC.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
IPC: G06F16/25
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
-
公开(公告)号:US09922102B2
公开(公告)日:2018-03-20
申请号:US14266797
申请日:2014-04-30
Applicant: Splunk Inc.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
CPC classification number: G06F17/30563
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
-
公开(公告)号:US20150039651A1
公开(公告)日:2015-02-05
申请号:US14266797
申请日:2014-04-30
Applicant: Splunk Inc.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
IPC: G06F17/30
CPC classification number: G06F17/30563
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
Abstract translation: 字段提取模板通过向用户提供通常分配给某种类型的数据的一组字段名称,以及如何提取这些字段的值的指导,简化了字段提取规则的创建。 这些字段提取规则反过来便于通过命名字段访问数据的某些“块”或从这些块导出的信息。 字段提取模板至少包括一组字段名称和字段名称的排序数据。 排序数据表示与至少一些字段名称相关联的索引位置。 指定了一个分隔符,用于将数据项分割成块数组。 属于给定字段名称的数据项的块是在该组件数组中的位置等于与给定字段名称关联的索引位置的块。
-
-
-
-