Displaying events based on user selections within an event limited field picker
First Claim
1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, the method comprising:
- in response to receiving a first query, accessing a set of events in a data store, wherein each event in the accessed set of events includes raw machine data that reflects the activity in the information technology environment associated with the event and the raw data of each event is produced by the component of the information technology environment;
within a first interface, causing display of first search results that are based on the received first query, wherein the first search results include a first plurality of events that includes a first subset of the accessed set of events;
in response to receiving a first user selection that indicates a first event included in the first plurality of events, causing display of a field information panel that displays fields having corresponding values for the first event, wherein each field is defined by an extraction rule that when applied to the first event, extracts a portion of a character string that represents the raw machine data of the first event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string; and
in response to receiving a second user selection, displaying a second plurality of events that includes a second subset of the accessed set of events, wherein the second user selection indicates a first field included in the fields displayed in the field information panel and the second subset of the accessed set of events is based on first field.
1 Assignment
0 Petitions
Accused Products
Abstract
An event limited field picker for a search user interface is described. In one or more implementations, a service may operate to collect and store data as events each of which includes a portion of the data correlated with a point in time. Clients may use a search user interface perform searches by input of search criteria. Responsive to receiving search criteria, the service may operate to apply a late binding schema to extract events that match the search criteria and provide search results for display via the search user interface. The search user interface exposes an event limited field picker operable to make selections of fields with respect to individual events in a view of the search results. In response to receiving an indication of a fields selected via the picker, visibility of selected fields may be updated to control which field and values are included in different views.
59 Citations
30 Claims
-
1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, the method comprising:
-
in response to receiving a first query, accessing a set of events in a data store, wherein each event in the accessed set of events includes raw machine data that reflects the activity in the information technology environment associated with the event and the raw data of each event is produced by the component of the information technology environment; within a first interface, causing display of first search results that are based on the received first query, wherein the first search results include a first plurality of events that includes a first subset of the accessed set of events; in response to receiving a first user selection that indicates a first event included in the first plurality of events, causing display of a field information panel that displays fields having corresponding values for the first event, wherein each field is defined by an extraction rule that when applied to the first event, extracts a portion of a character string that represents the raw machine data of the first event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string; and in response to receiving a second user selection, displaying a second plurality of events that includes a second subset of the accessed set of events, wherein the second user selection indicates a first field included in the fields displayed in the field information panel and the second subset of the accessed set of events is based on first field. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24)
-
-
25. A system comprising:
-
one or more processors; and one or more computer-readable storage media containing instructions which, in response to execution by the one or more processors, cause the one or more processors to perform a method comprising; in response to receiving a first query, accessing a set of events in a data store, wherein each event in the accessed set of events includes raw machine data that reflects the activity in the information technology environment associated with the event and the raw data of each event is produced by the component of the information technology environment; within a first interface, causing display of first search results that are based on the received first query, wherein the first search results include a first plurality of events that includes a first subset of the accessed set of events; in response to receiving a first user selection that indicates a first event included in the first plurality of events, causing display of a field information panel that displays fields having corresponding values for the first event, wherein each field is defined by an extraction rule that when applied to the first event, extracts a portion of a character string that represents the raw machine data of the first event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string; and in response to receiving a second user selection, displaying a second plurality of events that includes a second subset of the accessed set of events, wherein the second user selection indicates a first field included in the fields displayed in the field information panel and the second subset of the accessed set of events is based on first field. - View Dependent Claims (26, 27)
-
-
28. One or more non-transitory computer-storage media having executable instructions, which, when executed by a computing device, cause the computing device to perform a method comprising:
-
in response to receiving a first query, accessing a set of events in a data store, wherein each event in the accessed set of events includes raw machine data that reflects the activity in the information technology environment associated with the event and the raw data of each event is produced by the component of the information technology environment; within a first interface, causing display of first search results that are based on the received first query, wherein the first search results include a first plurality of events that includes a first subset of the accessed set of events; in response to receiving a first user selection that indicates a first event included in the first plurality of events, causing display of a field information panel that displays fields having corresponding values for the first event, wherein each field is defined by an extraction rule that when applied to the first event, extracts a portion of a character string that represents the raw machine data of the first event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string; and in response to receiving a second user selection, displaying a second plurality of events that includes a second subset of the accessed set of events, wherein the second user selection indicates a first field included in the fields displayed in the field information panel and the second subset of the accessed set of events is based on first field. - View Dependent Claims (29, 30)
-
Specification