Previewing raw data parsing
First Claim
1. A method, comprising:
- accessing a portion of raw data from at least one data source;
causing display of one or more selectable parsing rules;
receiving a first user input, from a graphical user interface, selecting a parsing rule among the one or more selectable parsing rules, the parsing rule to be applied to the portion of raw data;
parsing the portion of raw data into one or more sets of parsed data using the parsing rule, each set of parsed data including raw data from the portion of raw data;
causing display of at least a portion of the one or more sets of parsed data;
receiving a second user input, from the graphical user interface, indicating a user preference to use a different parsing rule;
accessing a second parsing rule;
processing raw data from the at least one data source using the second parsing rule, to create searchable, time-stamped events, the processed raw data including the portion of raw data and additional raw data different from the portion of raw data; and
storing the searchable, time-stamped events in an index store, wherein the searchable, time-stamped events in the index store are used to service search queries received from a search engine;
wherein the method is performed by one or more computing devices.
1 Assignment
0 Petitions
Accused Products
Abstract
Embodiments are directed towards previewing results generated from indexing data raw data before the corresponding index data is added to an index store. Raw data may be received from a preview data source. After an initial set of configuration information may be established, the preview data may be submitted to an index processing pipeline. A previewing application may generate preview results based on the preview index data and the configuration information. The preview results may enable previewing how the data is being processed by the indexing application. If the preview results are not acceptable, the configuration information may be modified. The preview application enables modification of the configuration information until the generated preview results may be acceptable. If the configuration information is acceptable, the preview data may be processed and indexed in one or more index stores.
61 Citations
20 Claims
-
1. A method, comprising:
-
accessing a portion of raw data from at least one data source; causing display of one or more selectable parsing rules; receiving a first user input, from a graphical user interface, selecting a parsing rule among the one or more selectable parsing rules, the parsing rule to be applied to the portion of raw data; parsing the portion of raw data into one or more sets of parsed data using the parsing rule, each set of parsed data including raw data from the portion of raw data; causing display of at least a portion of the one or more sets of parsed data; receiving a second user input, from the graphical user interface, indicating a user preference to use a different parsing rule; accessing a second parsing rule; processing raw data from the at least one data source using the second parsing rule, to create searchable, time-stamped events, the processed raw data including the portion of raw data and additional raw data different from the portion of raw data; and storing the searchable, time-stamped events in an index store, wherein the searchable, time-stamped events in the index store are used to service search queries received from a search engine; wherein the method is performed by one or more computing devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. One or more non-transitory storage media storing instructions which, when executed by one or more computing devices, cause operations comprising:
-
accessing a portion of raw data from at least one data source; causing display of one or more selectable parsing rules; receiving a first user input, from a graphical user interface, selecting a parsing rule among the one or more selectable parsing rules, the parsing rule to be applied to the portion of raw data; parsing the portion of raw data into one or more sets of parsed data using the parsing rule, each set of parsed data including raw data from the portion of raw data; causing display of at least a portion of the one or more sets of parsed data; receiving a second user input, from the graphical user interface, indicating a user preference to use a different parsing rule; accessing a second parsing rule; processing raw data from the at least one data source using the second parsing rule, to create searchable, time-stamped events, the processed raw data including the portion of raw data and additional raw data different from the portion of raw data; and storing the searchable, time-stamped events in an index store, wherein the searchable, time-stamped events in the index store are used to service search queries received from a search engine. - View Dependent Claims (10, 11, 12, 13, 14)
-
-
15. An apparatus, comprising:
-
a raw data selector, implemented at least partially in hardware, configured to access a portion of raw data from at least one data source; a display subsystem, implemented at least partially in hardware, configured to cause display of one or more selectable parsing rules; a user input receiver, implemented at least partially in hardware, configured to receive a first user input from a graphical user interface, selecting a parsing rule among the one or more selectable parsing rules, the parsing rule to be applied to the portion of raw data; a raw data parser, implemented at least partially in hardware, configured to parse the portion of raw data into one or more sets of parsed data using the parsing rule, each set of parsed data including raw data from the portion of raw data; wherein the display subsystem is configured to cause display of at least a portion of the one or more sets of parsed data; wherein the user input receiver is configured to receive a second user input, from the graphical user interface, indicating a user preference to use a different parsing rule; a parsing rule selector, implemented at least partially in hardware, configured to access a second parsing rule; wherein the raw data parser is configured to process, in response to receiving a second user input, raw data from the at least one data source using the second parsing rule, to create searchable, time-stamped events, the processed raw data including the portion of raw data and additional raw data different from the portion of raw data; and an event storage device, implemented at least partially in hardware, configured to store the searchable, time-stamped events in an index store, wherein the searchable, time-stamped events in the index store are usable to service search queries received from a search engine. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification