Data summary view with filtering
    31.
    发明授权

    公开(公告)号:US10204093B2

    公开(公告)日:2019-02-12

    申请号:US14815932

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: In some embodiments, a method may include display of a data summary view of a set of events that correspond to query results of a query. Each event of the set of events may include data items of a plurality of event attributes. In embodiments, the data summary view can include various summary reports. Each summary report can include summary entries and a summary graph that each present a summary of data items of a selected event attribute, of the plurality of event attributes. At least one summary report can include summary entries that are selectable by a user. The method may further include filtering the set of event, in response to, and based on, selection of one or more of the selectable summary entries by the user and updating of at least the first and second summary graphs to correspond to the filtered set of events.

    Data summary view
    32.
    发明授权

    公开(公告)号:US10185708B2

    公开(公告)日:2019-01-22

    申请号:US14815928

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention provide methods, computer-readable media, and systems directed at providing a data summary view. In some embodiments, a method may include receiving a request to display a data summary view of search results of a search query. The request may be received while the search results are displayed in a table format. The method may further include causing display of the data summary view. The data summary view can include a summary report for a selected event attribute of a plurality of event attributes that are represented in the table format. The summary report can include summary entries that present a summary of data items of the selected event attribute and a summary graph of the data items. The summary graph may depict a distribution of at least a subset of the data items of the selected event attribute over a period of time.

    Source type management
    33.
    发明授权

    公开(公告)号:US10037331B2

    公开(公告)日:2018-07-31

    申请号:US14611010

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: A data intake and query system provides interfaces that enable users to configure source type definitions used by the system. A data intake and query system generally refers to a system for collecting and analyzing data including machine-generated data. Such a system may be configured to consume many different types of machine data generated by any number of different data sources including various servers, network devices, applications, etc. At a high level, a source type definition comprises one or more properties that define how various components of a data intake and query system collect, index, store, search and otherwise interact with particular types of data consumed by the system. The interfaces provided by the system generally comprise one or more interface components for configuring various attributes of a source type definition.

    RUNTIME PERMISSIONS OF QUERIES
    35.
    发明申请
    RUNTIME PERMISSIONS OF QUERIES 审中-公开
    QUY的允许时间

    公开(公告)号:US20160224631A1

    公开(公告)日:2016-08-04

    申请号:US14815929

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: A method includes assigning an access permission of a first user to a query object that represents a first query, the access permission granting are first user access rights to one or more data sources of the first query, the access permission being assigned as a runtime permission of the first query, granting a request from a second user to execute a second query, the first query being a subquery of the second query, and allowing the second user to execute the first query on the one or more data sources of the first query using the runtime permission assigned to the first query in executing the second query using the first query as the subquery.

    Abstract translation: 一种方法包括将第一用户的访问许可分配给表示第一查询的查询对象,访问许可授予是对第一查询的一个或多个数据源的第一用户访问权限,访问许可被分配为运行时权限 所述第一查询授予来自第二用户的请求以执行第二查询,所述第一查询是所述第二查询的子查询,并且允许所述第二用户对所述第一查询的所述一个或多个数据源执行所述第一查询 使用第一个查询作为子查询执行第二个查询时分配给第一个查询的运行时权限。

    Source Type Management
    36.
    发明申请
    Source Type Management 审中-公开
    源类型管理

    公开(公告)号:US20160224576A1

    公开(公告)日:2016-08-04

    申请号:US14611010

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: A data intake and query system provides interfaces that enable users to configure source type definitions used by the system. A data intake and query system generally refers to a system for collecting and analyzing data including machine-generated data. Such a system may be configured to consume many different types of machine data generated by any number of different data sources including various servers, network devices, applications, etc. At a high level, a source type definition comprises one or more properties that define how various components of a data intake and query system collect, index, store, search and otherwise interact with particular types of data consumed by the system. The interfaces provided by the system generally comprise one or more interface components for configuring various attributes of a source type definition.

    Abstract translation: 数据采集​​和查询系统提供使用户能够配置系统使用的源类型定义的接口。 数据采集​​和查询系统通常是指用于收集和分析包括机器生成数据的数据的系统。 这样的系统可以被配置为消耗由包括各种服务器,网络设备,应用等的任何数量的不同数据源生成的许多不同类型的机器数据。在高级别,源类型定义包括一个或多个属性,其定义如何 数据采集​​和查询系统的各种组件收集,索引,存储,搜索和以其他方式与系统消耗的特定类型的数据进行交互。 由系统提供的接口通常包括用于配置源类型定义的各种属性的一个或多个接口组件。

    Using anchors to generate extraction rules

    公开(公告)号:US11972203B1

    公开(公告)日:2024-04-30

    申请号:US18306863

    申请日:2023-04-25

    Applicant: Splunk Inc.

    CPC classification number: G06F40/174 G06F16/2477

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

Patent Agency Ranking