Interactive display of aggregated search result information
First Claim
1. A method, comprising:
- causing graphical display, on a client device, of a user interface;
sending, to a plurality of computing systems, a search request to search a set of time stamped events, wherein the search request was received from the client device via the user interface;
receiving, from two or more computing systems among the plurality of computing systems, at least two sets of search results and event references, wherein each set of search results of the at least two sets of search results includes information associated with one or more time stamped events that satisfy the search request, and each of the event references includes an event identifier and an order value corresponding to each of the one or more time stamped events that satisfy the search request;
aggregating the at least two sets of search results into an aggregated search result by merging the event references into a global ordered list of the event references based on the order values of the event references;
causing graphical display, within the user interface, of information based on the global ordered list of the event references of the aggregated search result;
in response to receiving input requesting additional information from at least a portion of the aggregated search result, determining a set of event identifiers corresponding to time stamped events included in the at least a portion of the aggregated search result;
sending, to the two or more computing systems, a request for time stamped events corresponding to the set of event identifiers;
receiving, from the two or more computing systems, the requested time stamped events; and
causing display, within the user interface, of the requested additional information using the received requested time stamped events.
1 Assignment
0 Petitions
Accused Products
Abstract
A method, system, and processor-readable storage medium are directed towards generating a report derived from data, such as event data, stored on a plurality of distributed nodes. In one embodiment the analysis is generated using a “divide and conquer” algorithm, such that each distributed node analyzes locally stored event data while an aggregating node combines these analysis results to generate the report. In one embodiment, each distributed node also transmits a list of event data references associated with the analysis result to the aggregating node. The aggregating node may then generate a global ordered list of data references based on the list of event data references received from each distributed node. Subsequently, in response to a user selection of a range of global event data, the report may dynamically retrieve event data from one or more distributed nodes for display according to the global order.
-
Citations
24 Claims
-
1. A method, comprising:
-
causing graphical display, on a client device, of a user interface; sending, to a plurality of computing systems, a search request to search a set of time stamped events, wherein the search request was received from the client device via the user interface; receiving, from two or more computing systems among the plurality of computing systems, at least two sets of search results and event references, wherein each set of search results of the at least two sets of search results includes information associated with one or more time stamped events that satisfy the search request, and each of the event references includes an event identifier and an order value corresponding to each of the one or more time stamped events that satisfy the search request; aggregating the at least two sets of search results into an aggregated search result by merging the event references into a global ordered list of the event references based on the order values of the event references; causing graphical display, within the user interface, of information based on the global ordered list of the event references of the aggregated search result; in response to receiving input requesting additional information from at least a portion of the aggregated search result, determining a set of event identifiers corresponding to time stamped events included in the at least a portion of the aggregated search result; sending, to the two or more computing systems, a request for time stamped events corresponding to the set of event identifiers; receiving, from the two or more computing systems, the requested time stamped events; and causing display, within the user interface, of the requested additional information using the received requested time stamped events. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. An apparatus, comprising:
-
one or more data processors; and one or more computer-readable storage media containing instructions which when executed on the one or more data processors, implement a plurality of subsystems including; a subsystem that sends, to a plurality of computing systems, a search request to search a set of time stamped events, wherein the search request was received via a user interface; a subsystem that receives, from two or more computing systems among the plurality of computing systems, at least two sets of search results and event references, wherein each set of search results of the at least two sets of search results includes information associated with one or more time stamped events that satisfy the search request and each of the event references includes an event identifier and an order value corresponding to each of the one or more time stamped events that satisfy the search request; a subsystem that aggregates the at least two sets of search results into an aggregated search result by merging the event references into a global ordered list of the event references based on the order values of the event references; a subsystem that causes graphical display, within the user interface, of information based on the global ordered list of the event references of the aggregated search result; a subsystem that in response to receiving input requesting additional information from at least a portion of the aggregated search result, determines a set of event identifiers corresponding to time stamped events included in the at least a portion of the aggregated search result; a subsystem that sends, to the two or more computing systems, a request for time stamped events corresponding to the set of event identifiers; a subsystem that receives, from the two or more computing systems, the requested time stamped events; and a subsystem that causes display, within the user interface, of the requested additional information using the received requested time stamped events. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16)
-
-
17. A non-transitory computer-readable medium storing one or more sequences of instructions, wherein execution of the one or more sequences of instructions by one or more processors causes the one or more processors to perform:
-
causing graphical display, on a client device, of a user interface; sending, to a plurality of computing systems, a search request to search a set of time stamped events, wherein the search request was received from the client device via the user interface; receiving, from two or more computing systems among the plurality of computing systems, at least two sets of search results and event references, wherein each set of search results of the at least two sets of search results includes information associated with one or more time stamped events that satisfy the search request and each of the event references includes an event identifier and an order value corresponding to each of the one or more time stamped events that satisfy the search request; aggregating the at least two sets of search results into an aggregated search result by merging the event references into a global ordered list of the event references based on the order values of the event references; causing graphical display, within the user interface, of information based on the global ordered list of the event references of the aggregated search result; in response to receiving input requesting additional information from at least a portion of the aggregated search result, determining a set of event identifiers corresponding to time stamped events included in the at least a portion of the aggregated search result; sending, to the two or more computing systems, a request for time stamped events corresponding to the set of event identifiers; receiving, from the two or more computing systems, the requested time stamped events; and
causing display, within the user interface, of the requested additional information using the received requested time stamped events. - View Dependent Claims (18, 19, 20, 21, 22, 23, 24)
-
Specification