×

Displaying a number of events that have a particular value for a field in a set of events

  • US 10,282,463 B2
  • Filed: 08/02/2015
  • Issued: 05/07/2019
  • Est. Priority Date: 01/23/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • accessing a set of events in a field-searchable data store that acts as a persistent repository for the events, wherein each event in the set includes a portion of raw machine data in textual form, and wherein the raw machine data is produced by a component within an information technology environment and reflects activity within the information technology environment;

    receiving a user selection of a first portion of raw machine data in a particular event presented in a first portion of a display screen;

    applying an extraction rule, which specifies how to extract a subportion of text from a larger portion of text, to the portion of raw machine data in textual form in each event in the accessed set of events to extract a set of values, wherein the extraction rule comprises a regular expression rule updated and presented in a second portion of the display screen in real-time to correspond with the user-selected first portion of raw machine data;

    for one or more particular values in the extracted set of values, determining a count of events that include the particular value at a location corresponding to the extraction rule;

    updating, in real-time in a third portion of the display screen, a display of the one or more particular values and its associated count;

    andwherein the method is performed by one or more computing devices.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×