Graphical display of field values extracted from machine data
First Claim
1. A computer-implemented method comprising:
- receiving a search query entered by a user in textual form into a query box;
creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including unstructured raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment;
determining a set of fields that have each been defined for one or more events in the set of events, each field included in the set of fields associated with a different extraction rule that is used to identify occurrences of the field in the unstructured raw data in each of the one or more events and extract values from the occurrences of the field;
calculating a relevance score for each field in the set of fields;
selecting one or more fields included in the set of fields based on the relevance scores; and
causing display of one or more graphical controls, each graphical control corresponding to a field in the one or more fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields.
1 Assignment
0 Petitions
Accused Products
Abstract
The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.
180 Citations
21 Claims
-
1. A computer-implemented method comprising:
-
receiving a search query entered by a user in textual form into a query box; creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including unstructured raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment; determining a set of fields that have each been defined for one or more events in the set of events, each field included in the set of fields associated with a different extraction rule that is used to identify occurrences of the field in the unstructured raw data in each of the one or more events and extract values from the occurrences of the field; calculating a relevance score for each field in the set of fields; selecting one or more fields included in the set of fields based on the relevance scores; and causing display of one or more graphical controls, each graphical control corresponding to a field in the one or more fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 21)
-
-
20. One or more non-transitory computer readable storage media storing instructions which, when executed by one or more computing devices, cause:
-
receiving a search query entered by a user in textual form into a query box; creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including unstructured raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment; determining a set of fields that have each been defined for one or more events in the set of events, each field included in the set of fields associated with a different extraction rule that is used to identify occurrences of the field in the unstructured raw data in each of the one or more events and extract values from the occurrences of the field; calculating a relevance score for each field in the set of fields; selecting one or more fields included in the set of fields based on the relevance scores; and causing display of one or more graphical controls, each graphical control corresponding to a field in the one or more fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields.
-
Specification