Event selector to generate alternate views
First Claim
1. A computer-implemented method comprising:
- receiving, from input to a search screen, a search query on events in a data store, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system and is associated with one or more fields, wherein a field is defined by an extraction rule for extracting a sub-portion of text from the portion of machine data in an event by identifying a pattern in the portion of machine data to produce a field value and a field name for the field for the event;
causing display in the search screen of a search results set that is responsive to the receiving of the search query using a raw view of one or more events of a plurality of the events of the search results set in a first display format that displays for at least a first event of the one or more events, the portion of machine data of the first event in a cell, the displayed portion of machine data corresponding to a plurality of field values of the fields of the first event without displaying field names in the cell, wherein the raw view comprises a list of the plurality of the events;
causing display of a graphical display element, that when selected, causes display of the search results set using an alternate view of the one or more events in a second display format, the second display format being a list format or a table format; and
causing a transition in the displayed list in the search screen from the display of the search results set using the raw view of the one or more events in the first display format to the display of the search results set using the alternate view of the one or more events in the second display format based on a user selection of the graphical display element,wherein the transition causes display of the field values and field names of the fields associated with the first event produced using the extraction rule in the cell in the list of the plurality of the events.
1 Assignment
0 Petitions
Accused Products
Abstract
An event view selector for a search user interface is described. In one or more implementations, a service may operate to collect and store data as events and apply a late binding schema to extract events that match the search criteria and provide search results for display via the search user interface. The search user interface exposes an event view selector operable to enable transitions between multiple different views of the events associated with different levels of detail. The views may include at least a raw view, a list view, and a table view. Responsive to receiving an indication of a view selected via the event view selector, the selected view may be exposed via the search user interface.
144 Citations
30 Claims
-
1. A computer-implemented method comprising:
-
receiving, from input to a search screen, a search query on events in a data store, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system and is associated with one or more fields, wherein a field is defined by an extraction rule for extracting a sub-portion of text from the portion of machine data in an event by identifying a pattern in the portion of machine data to produce a field value and a field name for the field for the event; causing display in the search screen of a search results set that is responsive to the receiving of the search query using a raw view of one or more events of a plurality of the events of the search results set in a first display format that displays for at least a first event of the one or more events, the portion of machine data of the first event in a cell, the displayed portion of machine data corresponding to a plurality of field values of the fields of the first event without displaying field names in the cell, wherein the raw view comprises a list of the plurality of the events; causing display of a graphical display element, that when selected, causes display of the search results set using an alternate view of the one or more events in a second display format, the second display format being a list format or a table format; and causing a transition in the displayed list in the search screen from the display of the search results set using the raw view of the one or more events in the first display format to the display of the search results set using the alternate view of the one or more events in the second display format based on a user selection of the graphical display element, wherein the transition causes display of the field values and field names of the fields associated with the first event produced using the extraction rule in the cell in the list of the plurality of the events. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. One or more non-transitory computer-readable storage media comprising instructions that are stored thereon that, responsive to execution by one or more processors, cause the one or more processors to perform operations comprising:
-
receiving, from input to a search screen, a search query on events in a data store, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system and is associated with one or more fields, wherein a field is defined by an extraction rule for extracting a subportion of text from the portion of machine data in an event by identifying a pattern in the portion of machine data to produce a field value and a field name for the field for the event; causing display in the search screen of a search results set that is responsive to the receiving of the search query using a raw view of one or more events of a plurality of the events of the search results set in a first display format that displays for at least a first event of the one or more events, the portion of machine data of the first event in a cell, the displayed portion of machine data corresponding to a plurality of field values of the fields of the first event without displaying field names in the cell, wherein the raw view comprises a list of the plurality of the events; causing display of a graphical display element, that when selected, causes display of the search results set using an alternate view of the one or more events in a second display format, the second display format being a list format or a table format; and causing a transition in the displayed list in the search screen from the display of the search results set using the raw view of the one or more events in the first display format to the display of the search results set using the alternate view of the one or more events in the second display format based on a user selection of the graphical display element, wherein the transition causes display of the field values and field names of the fields associated with the first event produced using the extraction rule in the cell in the list of the plurality of the events. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23)
-
-
24. A computer-implemented system comprising:
- one or more processors; and
one or more computer-readable storage media comprising instructions that are stored thereon that, responsive to execution by the one or more processors, cause the one or more processors to perform operations comprising;receiving, from input to a search screen, a search query on events in a data store, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system and is associated with one or more fields, wherein a field is defined by an extraction rule for extracting a subportion of text from the portion of machine data in an event by identifying a pattern in the portion of machine data to produce a field value and a field name for the field for the event; causing display in the search screen of a search results set that is responsive to the receiving of the search query using a raw view of one or more events of a plurality of the events of the search results set in a first display format that displays for at least a first event of the one or more events, the portion of machine data of the first event in a cell, the displayed portion of machine data corresponding to a plurality of field values of the fields of the first event without displaying field names in the cell, wherein the raw view comprises a list of the plurality of the events; causing display of a graphical display element, that when selected, causes display of the search results set using an alternate view of the one or more events in a second display format, the second display format being a list format or a table format; and causing a transition in the displayed list in the search screen from the display of the search results set using the raw view of the one or more events in the first display format to the display of the search results set using the alternate view of the one or more events in the second display format based on a user selection of the graphical display element, wherein the transition causes display of the field values and field names of the fields associated with the first event produced using the extraction rule in the cell in the list of the plurality of the events. - View Dependent Claims (25, 26, 27, 28, 29, 30)
- one or more processors; and
Specification