Locating and categorizing data using inverted indexes

    公开(公告)号:US11061918B2

    公开(公告)日:2021-07-13

    申请号:US15479823

    申请日:2017-04-05

    申请人: Splunk Inc.

    IPC分类号: G06F16/2458 G06F16/26

    摘要: Systems and methods are disclosed for locating data and categorizing a set of data using inverted indexes. The inverted indexes include token entries and field-value pair entries, as well as event references that correspond to events that include raw machine data. Using filter criteria, the inverted indexes are identified. In turn, the inverted indexes are used to identify a set of events that satisfy the filter criteria. The identified set of events are categorized based on categorization criteria and provided for display to a user.

    LOCATING AND CATEGORIZING DATA USING INVERTED INDEXES

    公开(公告)号:US20180293327A1

    公开(公告)日:2018-10-11

    申请号:US15479823

    申请日:2017-04-05

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    摘要: Systems and methods are disclosed for locating data and categorizing a set of data using inverted indexes. The inverted indexes include token entries and field-value pair entries, as well as event references that correspond to events that include raw machine data. Using filter criteria, the inverted indexes are identified. In turn, the inverted indexes are used to identify a set of events that satisfy the filter criteria. The identified set of events are categorized based on categorization criteria and provided for display to a user.

    CLUSTERING EVENTS BASED ON EXTRACTION RULES
    3.
    发明申请

    公开(公告)号:US20180089303A1

    公开(公告)日:2018-03-29

    申请号:US15276693

    申请日:2016-09-26

    申请人: SPLUNK INC.

    IPC分类号: G06F17/30

    CPC分类号: G06F16/26

    摘要: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    Automated generation of metrics from log data

    公开(公告)号:US11226964B1

    公开(公告)日:2022-01-18

    申请号:US16147438

    申请日:2018-09-28

    申请人: Splunk Inc.

    摘要: A log-to-metrics transformation system includes a log-to-metrics application executing on a processor. The log-to-metrics transformation system receives a format associated with machine data, and further receives, via a first graphical control, a first set of metric identifiers corresponding to a first set of metrics associated with the machine data. The log-to-metrics transformation system generates a first set of mappings between the first set of metric identifiers and a first set of field values included in the machine data. The log-to-metrics transformation system stores the first set of mappings and an association with the format of the machine data. The log-to-metrics transformation system, based on the first set of mappings, causes the first set of field values to be extracted from the machine data. Further, a first metric included in the first set of metrics is determined based on at least a portion of the first set of field values.

    SAMPLING DATA USING INVERTED INDEXES IN RESPONSE TO GROUPING SELECTION

    公开(公告)号:US20180293304A1

    公开(公告)日:2018-10-11

    申请号:US15479852

    申请日:2017-04-05

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    摘要: Systems and methods are disclosed for sampling a set of data using inverted indexes in response to a user interaction with a user interface. Based on the user interaction with a displayed grouping of a summarization of a set of data, the system uses filter criteria corresponding to the grouping to review one or more inverted indexes and identify a sample of events for analysis. The system then accesses the sample of events and provides the results for display to a user.

    Coding commands using syntax templates

    公开(公告)号:US11010412B2

    公开(公告)日:2021-05-18

    申请号:US16735055

    申请日:2020-01-06

    申请人: SPLUNK INC.

    摘要: A method includes in response to a user selection of a command of a coding language, causing display of a set of argument blocks in a text input region based on syntax of the command. Each argument block allows the user to input a value of an argument of the command to the argument block. In response to a user selection to modify the set of argument blocks, an argument block is added to the set of argument blocks displayed in the text input region based on the syntax of the command. In response to receiving from the user the input of the value of the argument to the added argument block, the command is caused to be coded in the text input region with at least the argument having the value from the input to the added argument block.

    CONTROL INTERFACE FOR METRIC DEFINITION SPECIFICATION FOR ASSETS DRIVEN BY SEARCH-DERIVED ASSET TREE HIERARCHY

    公开(公告)号:US20200150621A1

    公开(公告)日:2020-05-14

    申请号:US16743549

    申请日:2020-01-15

    申请人: Splunk Inc.

    摘要: An asset monitoring and reporting system (AMRS) implements an interface to establish an asset hierarchy to be monitored and reported against. The interface employs a search query of extant asset data from which definitional aspects of the asset hierarchy can be identified, and therefrom the interface automatically determines control information reflective of the asset hierarchy to direct the ongoing operation of the AMRS. The interface further allows for configuration of a metric definition for a metric of an asset node of the asset hierarchy, the metric representing a point in time or a period of time and derived from a metric-time search of machine data produced by or about the asset node and receives an identification of a metric determination specification for the metric definition, the metric determination specification comprising at least identification of a metric component and identification of a calculation operation to apply to the metric component.