Real Time Indication Of Previously Extracted Data Fields For Regular Expressions
    105.
    发明申请
    Real Time Indication Of Previously Extracted Data Fields For Regular Expressions 有权
    以前提取的正则表达式数据字段的实时指示

    公开(公告)号:US20140236971A1

    公开(公告)日:2014-08-21

    申请号:US14266839

    申请日:2014-05-01

    Applicant: Splunk Inc.

    CPC classification number: G06F7/24 G06F17/30551

    Abstract: Embodiments are directed towards real time display of event records with an indication of previously provided extraction rules. A plurality of extraction rules may be provided to the system, such as automatically generated and/or user created extraction rules. These extraction rules may include regular expressions. A plurality of event records may be displayed to the user, such that text in a field defined by an extraction rule is emphasized in the display of the event record. The same emphasis may be provided for text in overlapping fields, or the emphasis may be somewhat different for different fields. The user interface may enable a user to select a portion of text of an event record, such as by rolling-over or clicking on an emphasized part of the event record. By selecting the portion of the event record, the interface may display each extraction rule associated with the selected portion.

    Abstract translation: 实施例针对具有先前提供的提取规则的指示的事件记录的实时显示。 可以向系统提供多个提取规则,诸如自动生成和/或用户创建的提取规则。 这些提取规则可以包括正则表达式。 可以向用户显示多个事件记录,使得在事件记录的显示中强调由提取规则定义的字段中的文本。 对于重叠字段中的文本可以提供相同的重点,或者对于不同领域的重点可能有些不同。 用户界面可以使得用户能够选择事件记录的文本的一部分,例如通过滚动或点击事件记录的被强调部分。 通过选择事件记录的部分,界面可以显示与所选部分相关联的每个提取规则。

    Graphical user interface for extraction rules

    公开(公告)号:US11782678B1

    公开(公告)日:2023-10-10

    申请号:US17384467

    申请日:2021-07-23

    Applicant: Splunk Inc.

    CPC classification number: G06F7/24 G06F16/2477

    Abstract: Embodiments are directed towards real time display of event records with an indication of previously provided extraction rules. A plurality of extraction rules may be provided to the system, such as automatically generated and/or user created extraction rules. These extraction rules may include regular expressions. A plurality of event records may be displayed to the user, such that text in a field defined by an extraction rule is emphasized in the display of the event record. The same emphasis may be provided for text in overlapping fields, or the emphasis may be somewhat different for different fields. The user interface may enable a user to select a portion of text of an event record, such as by rolling-over or clicking on an emphasized part of the event record. By selecting the portion of the event record, the interface may display each extraction rule associated with the selected portion.

    Using a timestamp selector to select a time information and a type of time information

    公开(公告)号:US11709850B1

    公开(公告)日:2023-07-25

    申请号:US17443892

    申请日:2021-07-28

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/2477 G06F16/9014 G06F40/284

    Abstract: Embodiments are directed towards a graphical user interface identify locations within event records with splittable timestamp information. A display of event records is provided using any of a variety of formats. A splittable timestamp selector allows a user to select one or more locations within event records as having time related information that may be split across the one or more locations, including, information based on date, time of day, day of the week, or other time information. Any of a plurality of mechanisms is used to associate the selected locations with the split timestamp information, including tags, labels, or header information within the event records. In other embodiments, a separate table, list, index, or the like may be generated that associates the selected locations with the split timestamp information. The split timestamp information may be used within extraction rules for selecting subsets or the event records.

Patent Agency Ranking