Custom communication alerts
First Claim
1. A computer-implemented method, comprising:
- executing a search query on events in a data store, each event comprising a portion of raw data in textual form, wherein a field specified in the search query is mapped to an extraction rule that defines the field, the extraction rule identifying a location within the portion of raw data in an event containing a value for the field for the event;
detecting a triggering condition of an alert by one or more computing devices, the triggering condition found by determining search results of the search query satisfy the triggering condition; and
responsive to the detecting of the triggering condition of the alert, forming a communication corresponding to the alert by one or more computing devices, the communication including one or more tokens based on one or more values of the field defined by the extraction rule.
1 Assignment
0 Petitions
Accused Products
Abstract
Custom communication alert techniques are described where a triggering condition is detected by one or more computing devices that is found by searching data using one or more extraction rules of a late-binding schema. Responsive to the detection of the triggering condition of the alert, a communication is formed by the one or more computing devices that corresponds to the alert and that includes one or more tokens based on one or more values of the data taken from fields defined by the one or more extraction rules. The communication is caused to be transmitted by the one or more computing device via a network for receipt by at least one computing device of an intended recipient of the communication.
-
Citations
30 Claims
-
1. A computer-implemented method, comprising:
-
executing a search query on events in a data store, each event comprising a portion of raw data in textual form, wherein a field specified in the search query is mapped to an extraction rule that defines the field, the extraction rule identifying a location within the portion of raw data in an event containing a value for the field for the event; detecting a triggering condition of an alert by one or more computing devices, the triggering condition found by determining search results of the search query satisfy the triggering condition; and responsive to the detecting of the triggering condition of the alert, forming a communication corresponding to the alert by one or more computing devices, the communication including one or more tokens based on one or more values of the field defined by the extraction rule. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. A computer-implemented system comprising:
-
one or more processors, and one or more computer memory to store instructions, the instructions when executed by the one or more processors to perform operations comprising; executing a search query on events in a data store, each event comprising a portion of raw data in textual form, wherein a field specified in the search query is mapped to an extraction rule that defines the field, the extraction rule identifying a location within the portion of raw data in an event containing a value for the field for the event; detecting a triggering condition of an alert by one or more computing devices, the triggering condition found by determining search results of the search query satisfy the triggering condition; and responsive to the detecting of the triggering condition of the alert, forming a communication corresponding to the alert by one or more computing devices, the communication including one or more tokens based on one or more values of the field defined by the extraction rule. - View Dependent Claims (19, 20, 21, 22, 23)
-
-
24. One or more computer-readable storage media comprising instructions stored thereon that, responsive to execution by one or more computing devices, causes the one or more computing devices to perform operations comprising:
-
executing a search query on events in a data store, each event comprising a portion of raw data in textual form, wherein a field specified in the search query is mapped to an extraction rule that defines the field, the extraction rule identifying a location within the portion of raw data in an event containing a value for the field for the event; detecting a triggering condition of an alert by one or more computing devices, the triggering condition found by determining search results of the search query satisfy the triggering condition; and responsive to the detecting of the triggering condition of the alert, forming a communication corresponding to the alert by one or more computing devices, the communication including one or more tokens based on one or more values of the field defined by the extraction rule. - View Dependent Claims (25, 26, 27, 28, 29, 30)
-
Specification