DISCOVERING FIELDS TO FILTER DATA RETURNED IN RESPONSE TO A SEARCH
    1.
    发明申请
    DISCOVERING FIELDS TO FILTER DATA RETURNED IN RESPONSE TO A SEARCH 有权
    发现过滤数据返回到搜索

    公开(公告)号:US20150026167A1

    公开(公告)日:2015-01-22

    申请号:US14448937

    申请日:2014-07-31

    Applicant: Splunk Inc.

    Abstract: Fields may be discovered in events that are returned in response to an initial search. The events may comprise portions of raw data. Furthermore, the fields may be defined by extraction rules for extracting values from corresponding portions of raw data. The displaying of a graphical user interface (GUI) may be caused where the GUI enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar. At least one criterion for at least one field from the subset of the discovered fields may be received through a portion of the GUI that does not include a search bar for entering a search query. The events returned in response to the initial search query may be caused to be filtered based on the received criterion.

    Abstract translation: 可以在响应初始搜索返回的事件中发现字段。 事件可以包括原始数据的部分。 此外,这些字段可以由用于从原始数据的相应部分提取值的提取规则来定义。 图形用户界面(GUI)的显示可能是在GUI允许用户选择或输入所发现的字段的子集的标准而不在搜索栏中输入搜索查询的情况下引起的。 可以通过不包括用于输入搜索查询的搜索栏的GUI的一部分来接收来自所发现字段的子集的至少一个字段的至少一个标准。 响应于初始搜索查询而返回的事件可能被导致根据接收到的标准进行过滤。

    Graphically Selectable Filter Parameters for Field Data in a Set of Machine Data
    3.
    发明申请
    Graphically Selectable Filter Parameters for Field Data in a Set of Machine Data 审中-公开
    一组机器数据中的场数据的图形可选滤波器参数

    公开(公告)号:US20160321369A1

    公开(公告)日:2016-11-03

    申请号:US15143579

    申请日:2016-04-30

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Graphically Selectable Aggregate Functions for Field Data in a Set of Machine Data
    4.
    发明申请
    Graphically Selectable Aggregate Functions for Field Data in a Set of Machine Data 审中-公开
    一组机器数据中的字段数据的图形可选聚合函数

    公开(公告)号:US20160246495A1

    公开(公告)日:2016-08-25

    申请号:US15143582

    申请日:2016-04-30

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Displaying Pie Charts of Event Data Using Pull-Down Menus
    5.
    发明申请
    Displaying Pie Charts of Event Data Using Pull-Down Menus 审中-公开
    使用下拉菜单显示事件数据的饼图

    公开(公告)号:US20160217599A1

    公开(公告)日:2016-07-28

    申请号:US15007182

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Graphical Display of Event Data Using Pull-Down Menus
    7.
    发明申请
    Graphical Display of Event Data Using Pull-Down Menus 审中-公开
    使用下拉菜单图形显示事件数据

    公开(公告)号:US20160140743A1

    公开(公告)日:2016-05-19

    申请号:US15007180

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    GENERATION OF A SEARCH QUERY TO APPROXIMATE REPLICATION OF A CLUSTER OF EVENTS
    8.
    发明申请
    GENERATION OF A SEARCH QUERY TO APPROXIMATE REPLICATION OF A CLUSTER OF EVENTS 审中-公开
    搜索查询的生成大大增加了一系列事件的复制

    公开(公告)号:US20160034525A1

    公开(公告)日:2016-02-04

    申请号:US14449051

    申请日:2014-07-31

    Applicant: Splunk Inc.

    CPC classification number: G06F17/30389 G06F17/30598

    Abstract: A processing device performs a preliminary grouping of data items in a dataset to define one or more clusters and for each cluster, identifies a set of search terms for a search query that would retrieve data items in the cluster upon execution of the search query against the dataset.

    Abstract translation: 处理设备执行数据集中的数据项的初步分组以定义一个或多个集群,并且对于每个集群,识别搜索查询的搜索项集合,该搜索查询将在针对所述集群执行搜索查询时检索集群中的数据项。 数据集

Patent Agency Ranking