×

Displaying events based on user selections within an event limited field picker

  • US 10,372,722 B2
  • Filed: 01/31/2018
  • Issued: 08/06/2019
  • Est. Priority Date: 09/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, the method comprising:

  • in response to receiving a first query, accessing a set of events in a data store, wherein each event in the accessed set of events includes raw machine data that reflects the activity in the information technology environment associated with the event and the raw data of each event is produced by the component of the information technology environment;

    within a first interface, causing display of first search results that are based on the received first query, wherein the first search results include a first plurality of events that includes a first subset of the accessed set of events;

    in response to receiving a first user selection that indicates a first event included in the first plurality of events, causing display of a field information panel that displays fields having corresponding values for the first event, wherein each field is defined by an extraction rule that when applied to the first event, extracts a portion of a character string that represents the raw machine data of the first event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string; and

    in response to receiving a second user selection, displaying a second plurality of events that includes a second subset of the accessed set of events, wherein the second user selection indicates a first field included in the fields displayed in the field information panel and the second subset of the accessed set of events is based on first field.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×