Providing an extraction rule associated with a selected portion of an event

    公开(公告)号:US10802797B2

    公开(公告)日:2020-10-13

    申请号:US16003998

    申请日:2018-06-08

    Applicant: Splunk Inc.

    Abstract: Embodiments are directed towards real time display of event records with an indication of previously provided extraction rules. A plurality of extraction rules may be provided to the system, such as automatically generated and/or user created extraction rules. These extraction rules may include regular expressions. A plurality of event records may be displayed to the user, such that text in a field defined by an extraction rule is emphasized in the display of the event record. The same emphasis may be provided for text in overlapping fields, or the emphasis may be somewhat different for different fields. The user interface may enable a user to select a portion of text of an event record, such as by rolling-over or clicking on an emphasized part of the event record. By selecting the portion of the event record, the interface may display each extraction rule associated with the selected portion.

    Determining events having a value
    53.
    发明授权

    公开(公告)号:US10585919B2

    公开(公告)日:2020-03-10

    申请号:US15582667

    申请日:2017-04-29

    Applicant: SPLUNK, Inc.

    Abstract: Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.

    AUTOMATED EXTRACTION RULE GENERATION USING A TIMESTAMP SELECTOR

    公开(公告)号:US20190251086A1

    公开(公告)日:2019-08-15

    申请号:US16394754

    申请日:2019-04-25

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/2477 G06F16/9014 G06F17/277

    Abstract: Embodiments are directed towards a graphical user interface identify locations within event records with splittable timestamp information. A display of event records is provided using any of a variety of formats. A splittable timestamp selector allows a user to select one or more locations within event records as having time related information that may be split across the one or more locations, including, information based on date, time of day, day of the week, or other time information. Any of a plurality of mechanisms is used to associate the selected locations with the split timestamp information, including tags, labels, or header information within the event records. In other embodiments, a separate table, list, index, or the like may be generated that associates the selected locations with the split timestamp information. The split timestamp information may be used within extraction rules for selecting subsets or the event records.

Patent Agency Ranking