×

Displaying drill-down event information using event identifiers

  • US 10,318,535 B2
  • Filed: 01/25/2016
  • Issued: 06/11/2019
  • Est. Priority Date: 03/14/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • receiving, at a user interface of a first device, a search query to be performed on a set of event records accessible by a second device;

    sending, by the first device, at least a portion of the search query to the second device;

    receiving, by the first device, a search result from the second device, the search result including one or more event identifiers that are transmitted to the second device by a plurality of distributed nodes, each event identifier of the one or more event identifiers is associated with a specific event record of a set of event records accessible by the second device that satisfied the search query, each event identifier enables locating an associated specific event record that is stored by a corresponding specific distributed node of the plurality of distributed nodes and the specific event record is accessible by the second device, at the corresponding specific distributed node, without searching the set of event records;

    causing, within the user interface of the first device, display of information associated with at least a portion of the search result;

    receiving, based on a user selection of at least a portion of the information displayed within the user interface of the first device, a request to view underlying data associated with the at least a portion of the search result;

    determining, by the first device, at least one event identifier in the search result associated with the request, wherein the at least one event identifier was transmitted to the second device by a first distributed node of the plurality of nodes;

    sending, by the first device, a request for event records, the request including the at least one event identifier;

    receiving from the second device, by the first device, at least one event record associated with the at least one event identifier, wherein the at least one event record was accessed by the second device, at the first distributed node, and comprises raw data that relates to operations or activities in an information technology environment; and

    causing, within the user interface of the first device, display of the requested underlying data based on at least the raw data of the received at least one event record.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×