Generating new visualizations based on prior journey definitions

    公开(公告)号:US12019858B1

    公开(公告)日:2024-06-25

    申请号:US17474833

    申请日:2021-09-14

    申请人: SPLUNK Inc.

    摘要: Systems, methods, and computer readable media are disclosed for generating and providing concurrent journey visualizations associated with different journey definitions. In computer-implemented embodiments, a data intake and query system, or a journey visualization computing tool, can be used to generate and provide concurrent representations corresponding with different journey definitions. In operation, a set of journey instances associated with a journey having a set of steps is obtained. Each step may be associated with at least one event that includes raw machine data produced by a component of an information technology environment. Upon obtaining different journey definitions specifying filters to apply to the set of journey instances, the data intake and query system can generate journey visualizations in accordance with the journey definitions. Thereafter, the journey visualizations corresponding with the journey definitions can be concurrently displayed by a computing device via a graphical user interface.

    Coding commands using syntax templates

    公开(公告)号:US11010412B2

    公开(公告)日:2021-05-18

    申请号:US16735055

    申请日:2020-01-06

    申请人: SPLUNK INC.

    摘要: A method includes in response to a user selection of a command of a coding language, causing display of a set of argument blocks in a text input region based on syntax of the command. Each argument block allows the user to input a value of an argument of the command to the argument block. In response to a user selection to modify the set of argument blocks, an argument block is added to the set of argument blocks displayed in the text input region based on the syntax of the command. In response to receiving from the user the input of the value of the argument to the added argument block, the command is caused to be coded in the text input region with at least the argument having the value from the input to the added argument block.

    CONTROL INTERFACE FOR METRIC DEFINITION SPECIFICATION FOR ASSETS DRIVEN BY SEARCH-DERIVED ASSET TREE HIERARCHY

    公开(公告)号:US20200150621A1

    公开(公告)日:2020-05-14

    申请号:US16743549

    申请日:2020-01-15

    申请人: Splunk Inc.

    摘要: An asset monitoring and reporting system (AMRS) implements an interface to establish an asset hierarchy to be monitored and reported against. The interface employs a search query of extant asset data from which definitional aspects of the asset hierarchy can be identified, and therefrom the interface automatically determines control information reflective of the asset hierarchy to direct the ongoing operation of the AMRS. The interface further allows for configuration of a metric definition for a metric of an asset node of the asset hierarchy, the metric representing a point in time or a period of time and derived from a metric-time search of machine data produced by or about the asset node and receives an identification of a metric determination specification for the metric definition, the metric determination specification comprising at least identification of a metric component and identification of a calculation operation to apply to the metric component.

    Supplementing extraction rules based on event clustering

    公开(公告)号:US12099517B1

    公开(公告)日:2024-09-24

    申请号:US18300936

    申请日:2023-04-14

    申请人: Splunk Inc.

    IPC分类号: G06F16/00 G06F16/26

    CPC分类号: G06F16/26

    摘要: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.