PROVIDING AN EXTRACTION RULE ASSOCIATED WITH A SELECTED PORTION OF AN EVENT

    公开(公告)号:US20180293051A1

    公开(公告)日:2018-10-11

    申请号:US16003998

    申请日:2018-06-08

    Applicant: Splunk Inc.

    CPC classification number: G06F7/24 G06F16/2477

    Abstract: Embodiments are directed towards real time display of event records with an indication of previously provided extraction rules. A plurality of extraction rules may be provided to the system, such as automatically generated and/or user created extraction rules. These extraction rules may include regular expressions. A plurality of event records may be displayed to the user, such that text in a field defined by an extraction rule is emphasized in the display of the event record. The same emphasis may be provided for text in overlapping fields, or the emphasis may be somewhat different for different fields. The user interface may enable a user to select a portion of text of an event record, such as by rolling-over or clicking on an emphasized part of the event record. By selecting the portion of the event record, the interface may display each extraction rule associated with the selected portion.

Patent Agency Ranking