Generating and Storing Summarization Tables for Searchable Events
    501.
    发明申请
    Generating and Storing Summarization Tables for Searchable Events 有权
    生成和存储可搜索事件的汇总表

    公开(公告)号:US20160154832A1

    公开(公告)日:2016-06-02

    申请号:US15007185

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed are towards the transparent summarization of events. Queries directed towards summarizing and reporting on event records may be received at a search head. Search heads may be associated with one more indexers containing event records. The search head may forward the query to the indexers the can resolve the query for concurrent execution. If a query is a collection query, indexers may generate summarization information based on event records located on the indexers. Event record fields included in the summarization information may be determined based on terms included in the collection query. If a query is a stats query, each indexer may generate a partial result set from previously generated summarization information, returning the partial result sets to the search head. Collection queries may be saved and scheduled to run and periodically update the summarization information.

    Abstract translation: 实施例针对事件的透明总结。 可以在搜索头收到针对事件记录的总结和报告的查询。 搜索头可能与一个包含事件记录的索引器相关联。 搜索头可以将查询转发给索引器,可以解析用于并发执行的查询。 如果查询是集合查询,则索引器可以基于位于索引器上的事件记录生成摘要信息。 包含在汇总信息中的事件记录字段可以基于收集查询中包含的项来确定。 如果查询是统计查询,则每个索引器可以从先前生成的摘要信息生成部分结果集,将部分结果集返回到搜索头。 收集查询可以保存并计划运行,并定期更新摘要信息。

    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS
    504.
    发明申请
    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS 审中-公开
    基于协议的网络数据捕获的构建由远程捕获代理

    公开(公告)号:US20160127180A1

    公开(公告)日:2016-05-05

    申请号:US14528932

    申请日:2014-10-30

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system provides, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets. The system then includes the one or more event attributes specified through the first set of user-interface elements in the configuration information.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统提供图形用户界面(GUI),用于获得用于配置由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息。 接下来,系统在GUI中提供用于在与网络分组的协议分类相关联的事件流的时间序列事件数据中包括一个或多个事件属性的第一组用户界面元素。 然后,该系统包括通过配置信息中的第一组用户界面元素指定的一个或多个事件属性。

    DEFINING A SERVICE-MONITORING DASHBOARD USING KEY PERFORMANCE INDICATORS DERIVED FROM MACHINE DATA
    506.
    发明申请
    DEFINING A SERVICE-MONITORING DASHBOARD USING KEY PERFORMANCE INDICATORS DERIVED FROM MACHINE DATA 审中-公开
    使用从机器数据获取的主要性能指标来定义服务监控台

    公开(公告)号:US20160105329A1

    公开(公告)日:2016-04-14

    申请号:US14528926

    申请日:2014-10-30

    Applicant: Splunk Inc.

    Abstract: Processing device(s) cause display of a dashboard-creation graphical interface that includes a modifiable dashboard template and a key performance indicator (KPI)-selection interface for selecting a KPI indicating how a service provided by one or more entities is performing at one or more points in time. Each entity is associated with machine data. A KPI is defined by a search query that derives value(s) for the KPI from the machine data associated with the entities that provide the service. The processing device(s) receive through the KPI-selection interface a selection of a particular KPI and a selection of a location in the dashboard template corresponding to a location for displaying a KPI widget in a dashboard based on the dashboard template. The KPI widget provides a representation of value(s) for the particular KPI. The processing device(s) cause display of an identifier for the particular KPI at the location in the dashboard template.

    Abstract translation: 处理设备引起显示仪表板创建图形界面,其包括可修改的仪表板模板和关键性能指标(KPI)选择界面,用于选择指示如何由一个或多个实体提供的服务在一个或多个实体上执行的KPI 更多时间点 每个实体与机器数据相关联。 KPI由搜索查询定义,该搜索查询从与提供服务的实体相关联的机器数据中获取KPI的值。 处理设备通过KPI选择界面接收对基于仪表板模板在仪表板中显示KPI小部件的位置的对应于仪表板模板中的特定KPI的选择和选择。 KPI小部件提供特定KPI的值的表示。 处理设备导致在仪表板模板中的位置显示特定KPI的标识符。

    Event Segment Search Drill Down
    509.
    发明申请
    Event Segment Search Drill Down 审中-公开
    事件段搜索向下钻取

    公开(公告)号:US20160098463A1

    公开(公告)日:2016-04-07

    申请号:US14526380

    申请日:2014-10-28

    Applicant: Splunk Inc.

    Abstract: In embodiments of event segment search drill down, a search system exposes a search interface that displays multiple events returned as a search result set. A segment can be emphasized in event raw data of an event that is one of multiple events displayed in the search interface, and a menu is displayed with search options that are selectable to operate on the emphasized segment. The menu includes the search options to add the emphasized segment as a keyword to a search command in a search bar of the search interface, exclude the keyword that represents the emphasized segment from a search, or create a new data search based on the highlighted segment. A selection of one of the search options in the menu can be received, and the search command in the search bar is updated based on the search option that is selected.

    Abstract translation: 在事件段搜索向下钻取的实施例中,搜索系统公开了显示作为搜索结果集返回的多个事件的搜索界面。 可以在事件的原始数据中突出显示分段,该事件是在搜索界面中显示的多个事件中的一个,并且显示具有可选择以在被强调的段上操作的搜索选项的菜单。 该菜单包括搜索选项,将强调段作为关键字添加到搜索接口的搜索栏中的搜索命令,从搜索中排除表示强调段的关键字,或者基于突出显示的段创建新的数据搜索 。 可以接收菜单中的一个搜索选项的选择,并且基于所选择的搜索选项来更新搜索栏中的搜索命令。

    Custom Communication Alerts
    510.
    发明申请
    Custom Communication Alerts 审中-公开
    自定义通信警报

    公开(公告)号:US20160098402A1

    公开(公告)日:2016-04-07

    申请号:US14528905

    申请日:2014-10-30

    Applicant: Splunk Inc.

    Abstract: Custom communication alert techniques are described. In one or more implementations, a triggering condition is detected by one or more computing devices that is found by searching data using one or more extraction rules of a late-binding schema. Responsive to the detection of the triggering condition of the alert, a communication is formed by the one or more computing devices that corresponds to the alert and that includes one or more tokens based on one or more values of the data taken from fields defined by the one or more extraction rules. The communication is caused to be transmitted by the one or more computing device via a network for receipt by at least one computing device of an intended recipient of the communication.

    Abstract translation: 描述自定义通信警报技术。 在一个或多个实现中,通过使用后期绑定模式的一个或多个提取规则通过搜索数据而发现的一个或多个计算设备来检测触发条件。 响应于警报的触发条件的检测,由与警报对应的一个或多个计算设备形成通信,并且基于从由所述警报定义的字段取得的数据的一个或多个值来包括一个或多个令牌 一个或多个提取规则。 该通信被一个或多个计算设备经由网络发送,以由通信的预期接收者的至少一个计算设备接收。

Patent Agency Ranking