Search query processing using operational parameters
First Claim
Patent Images
1. A method, comprising:
- creating a set of searchable, time stamped events by segmenting raw time series machine data received from at least one data source in an information technology environment into searchable, time stamped events;
processing, by a device, a time-based search phrase by parsing the time-based search phrase having at least two command line portions, a first portion of the at least two command line portions having at least one search phrase to be executed across the set of searchable, time stamped events, and a second portion of the at least two command line portions having at least one data modification operation that specifies processing to be performed by the device on a result data set resulting from executing the search phrase across the set of searchable, time stamped events;
wherein processing the time-based search phrase further comprises;
creating, by the device, the result data set by searching at least a portion of the set of searchable, time stamped events using the at least one search phrase;
creating, by the device, a data modification result by applying the at least one data modification operation to data in the result data set; and
causing display of information relating to the data modification result.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus consistent with the invention provide the ability to search and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is organized into discrete events with normalized time stamps and the events are indexed by time and keyword. A search is received and relevant event information is retrieved based in whole or in part on the time indexing mechanism, keyword indexing mechanism, or statistical indices calculated at the time of the search.
-
Citations
30 Claims
-
1. A method, comprising:
-
creating a set of searchable, time stamped events by segmenting raw time series machine data received from at least one data source in an information technology environment into searchable, time stamped events; processing, by a device, a time-based search phrase by parsing the time-based search phrase having at least two command line portions, a first portion of the at least two command line portions having at least one search phrase to be executed across the set of searchable, time stamped events, and a second portion of the at least two command line portions having at least one data modification operation that specifies processing to be performed by the device on a result data set resulting from executing the search phrase across the set of searchable, time stamped events; wherein processing the time-based search phrase further comprises; creating, by the device, the result data set by searching at least a portion of the set of searchable, time stamped events using the at least one search phrase; creating, by the device, a data modification result by applying the at least one data modification operation to data in the result data set; and causing display of information relating to the data modification result. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. An apparatus, comprising:
-
one or more processors; and a memory storing instructions, which when executed by the one or more processors, causes the one or more processors to; create a set of searchable, time stamped events by segmenting raw time series machine data received from at least one data source in an information technology environment into searchable, time stamped events; process a time-based search phrase by parsing the time-based search phrase having at least two command line portions, a first portion of the at least two command line portions having at least one search phrase to be executed across the set of searchable, time stamped events, and a second portion of the at least two command line portions having at least one data modification operation that specifies processing to be performed on a result data set resulting from executing the search phrase across the set of searchable, time stamped events; wherein process the time-based search phrase further comprises; create the result data set by searching at least a portion of the set of searchable, time stamped events using the at least one search phrase; create a data modification result by applying the at least one data modification operation to data in the result data set; and cause display of information relating to the data modification result. - View Dependent Claims (14, 15, 16, 17, 18, 19, 20, 21)
-
-
22. One or more non-transitory computer-readable storage media, storing software instructions, which when executed by one or more processors cause performance of:
-
creating a set of searchable, time stamped events by segmenting raw time series machine data received from at least one data source in an information technology environment into searchable, time stamped events; processing, by a device, a time-based search phrase by parsing the time-based search phrase having at least two command line portions, a first portion of the at least two command line portions having at least one search phrase to be executed across the set of searchable, time stamped events, and a second portion of the at least two command line portions having at least one data modification operation that specifies processing to be performed by the device on a result data set resulting from executing the search phrase across the set of searchable, time stamped events; wherein processing the time-based search phrase further comprises; creating, by the device, the result data set by searching at least a portion of the set of searchable, time stamped events using the at least one search phrase; creating, by the device, a data modification result by applying the at least one data modification operation to data in the result data set; and causing display of information relating to the data modification result. - View Dependent Claims (23, 24, 25, 26, 27, 28, 29, 30)
-
Specification