Event selection via graphical user interface control

    公开(公告)号:US11651149B1

    公开(公告)日:2023-05-16

    申请号:US17874046

    申请日:2022-07-26

    Applicant: SPLUNK Inc.

    CPC classification number: G06F40/174 G06F16/2477

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

    Determining an extraction rule from positive and negative examples

    公开(公告)号:US11042697B2

    公开(公告)日:2021-06-22

    申请号:US16589445

    申请日:2019-10-01

    Applicant: SPLUNK INC.

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

    Graphically Selectable Aggregate Functions for Field Data in a Set of Machine Data
    3.
    发明申请
    Graphically Selectable Aggregate Functions for Field Data in a Set of Machine Data 审中-公开
    一组机器数据中的字段数据的图形可选聚合函数

    公开(公告)号:US20160246495A1

    公开(公告)日:2016-08-25

    申请号:US15143582

    申请日:2016-04-30

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    Displaying Pie Charts of Event Data Using Pull-Down Menus
    4.
    发明申请
    Displaying Pie Charts of Event Data Using Pull-Down Menus 审中-公开
    使用下拉菜单显示事件数据的饼图

    公开(公告)号:US20160217599A1

    公开(公告)日:2016-07-28

    申请号:US15007182

    申请日:2016-01-26

    Applicant: Splunk Inc.

    Abstract: The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.

    Abstract translation: 本公开涉及用于从非结构化数据生成报告的某些系统和方法实施例。 在一个实施例中,一种方法可以包括识别匹配初始搜索查询的标准的事件(每个事件包括与时间相关联的原始机器数据的一部分),标识一组字段,每个字段被定义为一个或多个 识别的事件,导致显示包括一个或多个交互元件的交互式图形用户界面(GUI),使得用户能够定义用于提供与匹配事件有关的信息的报告(每个交互元件能够处理或呈现在 通过GUI接收指示如何报告与匹配事件有关的信息的报告定义,以及基于报告定义生成包括与所述事件相关的信息的报告的报告 匹配事件。

    System and Method for Displaying an Interface
    5.
    发明申请
    System and Method for Displaying an Interface 审中-公开
    用于显示接口的系统和方法

    公开(公告)号:US20130239047A1

    公开(公告)日:2013-09-12

    申请号:US13874223

    申请日:2013-04-30

    Applicant: SPLUNK INC.

    Inventor: Marc Robichaud

    CPC classification number: G06F3/0485

    Abstract: Systems and methods for displaying an interface are provided. A system and method can be configured to display a scrollable viewing region. The viewing region can be a fixed size and the viewing region can facilitate displaying underlying content. Underlying content can be divided into multiple sectioned viewing areas, and each sectioned viewing area can have a corresponding heading. Headings can be docked or undocked. Input corresponding to a scroll movement can be received, and the viewing region can be adjusted according to the scroll movement. Adjusting a viewing region can include shifting the display of the underlying content by docking or undocking headings. Headings can be docked or undocked as they occur in the underlying content.

    Abstract translation: 提供了显示界面的系统和方法。 可以将系统和方法配置为显示可滚动的观看区域。 观看区域可以是固定大小,并且观看区域可以便于显示底层内容。 基础内容可以分为多个分段的观看区域,每个分段的观看区域可以具有相应的标题。 标题可以停靠或停靠。 可以接收对应于滚动运动的输入,并且可以根据滚动运动来调整观看区域。 调整观看区域可以包括通过对接或取消标题来移动底层内容的显示。 标题可以在基础内容中停靠或停靠。

    Providing extraction results for a particular field

    公开(公告)号:US11423216B2

    公开(公告)日:2022-08-23

    申请号:US17169254

    申请日:2021-02-05

    Applicant: SPLUNK Inc.

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

Patent Agency Ranking