SEARCH-TIME FIELD EXTRACTION IN A DATA INTAKE AND QUERY SYSTEM

    公开(公告)号:US20230134578A1

    公开(公告)日:2023-05-04

    申请号:US18078876

    申请日:2022-12-09

    申请人: Splunk Inc.

    摘要: An improved data intake and query system that can perform and display ingest-time and search-time field extraction, redaction, copy, and/or categorization is described herein. As described herein, ingest-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by a log observer system of the data intake and query system on raw machine data as the raw machine data is ingested or received from a publisher. As described herein, search-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by the log observer system and/or other components of the improved data intake and query system on historical raw machine data that has already been ingested and indexed by the improved data intake and query system.

    Search-time field extraction in a data intake and query system

    公开(公告)号:US11526504B1

    公开(公告)日:2022-12-13

    申请号:US17246154

    申请日:2021-04-30

    申请人: Splunk Inc.

    摘要: An improved data intake and query system that can perform and display ingest-time and search-time field extraction, redaction, copy, and/or categorization is described herein. As described herein, ingest-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by a log observer system of the data intake and query system on raw machine data as the raw machine data is ingested or received from a publisher. As described herein, search-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by the log observer system and/or other components of the improved data intake and query system on historical raw machine data that has already been ingested and indexed by the improved data intake and query system.

    Generating metric data from log data using metricization rules

    公开(公告)号:US11714823B1

    公开(公告)日:2023-08-01

    申请号:US17246229

    申请日:2021-04-30

    申请人: Splunk Inc.

    IPC分类号: G06F16/25 G06F16/2455

    CPC分类号: G06F16/254 G06F16/24556

    摘要: Systems and methods are described for generating metrics from real-time streaming log data. In order to generate the metrics, a metricization rule associated with the log data can be obtained. For example, the metricization rule may be obtained from a user. The metricization rule may include one or more field-value pairs that define how the metrics are generated from the log data. Preview metric data can be generated by applying the metricization rule to the log data. For example, the preview metric data may be displayed via a user interface. Further, the metricization rule can be accepted or approved by the user. Further, the additional log data can be ingested and based on determining that the metricization rule has been accepted, metric data may be generated by applying the metricization rule to the additional log data.