-
公开(公告)号:US20150039651A1
公开(公告)日:2015-02-05
申请号:US14266797
申请日:2014-04-30
Applicant: Splunk Inc.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
IPC: G06F17/30
CPC classification number: G06F17/30563
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
Abstract translation: 字段提取模板通过向用户提供通常分配给某种类型的数据的一组字段名称,以及如何提取这些字段的值的指导,简化了字段提取规则的创建。 这些字段提取规则反过来便于通过命名字段访问数据的某些“块”或从这些块导出的信息。 字段提取模板至少包括一组字段名称和字段名称的排序数据。 排序数据表示与至少一些字段名称相关联的索引位置。 指定了一个分隔符,用于将数据项分割成块数组。 属于给定字段名称的数据项的块是在该组件数组中的位置等于与给定字段名称关联的索引位置的块。
-
公开(公告)号:US20200257582A1
公开(公告)日:2020-08-13
申请号:US16864111
申请日:2020-04-30
Applicant: Splunk Inc.
Inventor: Cary Glen Noel , Kirubakaran Pakkirisamy , Alex Raitz , Pierre Tsai
Abstract: Embodiments are directed towards the visualization of machine data received from computing clusters. Embodiments may enable improved analysis of computing cluster performance, error detection, troubleshooting, error prediction, or the like. Individual cluster nodes may generate machine data that includes information and data regarding the operation and status of the cluster node. The machine data is received from each cluster node for indexing by one or more indexing applications. The indexed machine data including the complete data set may be stored in one or more index stores. A visualization application enables a user to select one or more analysis lenses that may be used to generate visualizations of the machine data. The visualization application employs the analysis lens to produce visualizations of the computing cluster machine data.
-
公开(公告)号:US10691523B2
公开(公告)日:2020-06-23
申请号:US15224654
申请日:2016-07-31
Applicant: Splunk Inc.
Inventor: Cary Glen Noel , Kirubakaran Pakkirisamy , Alex Raitz , Pierre Tsai
Abstract: Embodiments are directed towards the visualization of machine data received from computing clusters. Embodiments may enable improved analysis of computing cluster performance, error detection, troubleshooting, error prediction, or the like. Individual cluster nodes may generate machine data that includes information and data regarding the operation and status of the cluster node. The machine data is received from each cluster node for indexing by one or more indexing applications. The indexed machine data including the complete data set may be stored in one or more index stores. A visualization application enables a user to select one or more analysis lenses that may be used to generate visualizations of the machine data. The visualization application employs the analysis lens to produce visualizations of the computing cluster machine data.
-
公开(公告)号:US20180157724A1
公开(公告)日:2018-06-07
申请号:US15885809
申请日:2018-01-31
Applicant: Splunk Inc.
Inventor: Michael Kinsely , Alex Raitz , John Robert Coates , Shirley Wu
IPC: G06F17/30
CPC classification number: G06F16/254
Abstract: A field extraction template simplifies the creation of field extraction rules by providing a user with a set of field names commonly assigned to a certain type of data, as well as guidance on how to extract values for those fields. These field extraction rules, in turn, facilitate access to certain “chunks” of the data, or to information derived from those chunks, through named fields. A field extraction template comprises at least a set of field names and ordering data for the field names. The ordering data indicates index positions that are associated with at least some of the field names. A delimiter is specified for splitting data items into arrays of chunks. The chunk of a data item that belongs to a given field name is the chunk whose position within the item's array of chunks is equivalent to the index position associated with the given field name.
-
公开(公告)号:US09442789B2
公开(公告)日:2016-09-13
申请号:US15011623
申请日:2016-01-31
Applicant: Splunk Inc.
Inventor: Cary Glen Noel , Kirubakaran Pakkirisamy , Alex Raitz , Pierre Tsai
CPC classification number: G06F11/079 , G06F9/542 , G06F11/0709 , G06F11/0712 , G06F11/0721 , G06F11/0751 , G06F11/0769 , G06F11/0787 , G06N5/022 , G06N5/048
Abstract: Embodiments are directed towards the visualization of machine data received from computing clusters. Embodiments may enable improved analysis of computing cluster performance, error detection, troubleshooting, error prediction, or the like. Individual cluster nodes may generate machine data that includes information and data regarding the operation and status of the cluster node. The machine data is received from each cluster node for indexing by one or more indexing applications. The indexed machine data including the complete data set may be stored in one or more index stores. A visualization application enables a user to select one or more analysis lenses that may be used to generate visualizations of the machine data. The visualization application employs the analysis lens to produce visualizations of the computing cluster machine data.
Abstract translation: 实施例针对从计算群集接收的机器数据的可视化。 实施例可以实现对计算集群性能,错误检测,故障排除,错误预测等的改进的分析。 单个集群节点可以生成包含关于集群节点的操作和状态的信息和数据的机器数据。 从每个集群节点接收机器数据,用于由一个或多个索引应用程序进行索引。 包括完整数据集的索引机器数据可以存储在一个或多个索引存储器中。 可视化应用程序使用户能够选择可用于生成机器数据可视化的一个或多个分析镜头。 可视化应用程序使用分析镜头来产生计算集群机器数据的可视化。
-
-
-
-