Cross-system journey monitoring based on relation of machine data
First Claim
1. A method comprising:
- obtaining information describing a user journey, the user journey comprising a plurality of steps,wherein each step of the plurality of steps corresponds to a query to be applied to one or more field-searchable data stores storing a plurality of events, wherein each event of the plurality of events includes a portion of machine data that reflects activity in an information technology environment and that is produced by a component of that information technology environment;
relating, based on the obtained information, a set of events returned as a result of the plurality of queries, wherein relating the set of events is based on one or more stitching schemes, wherein a stitching scheme indicates a relation between information included in a first event and information included in a second event, and wherein relating the set of events based on a particular stitching scheme comprises;
identifying that a same entity is associated with a first particular event of the set of events and a second particular event of the set of events, the first particular event being associated with a first data source and the second particular event being associated with a second data source; and
causing display of results of the relating.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems and methods are disclosed for cross-system journey modeling based on relation of machine data. An example method includes obtaining information describing a user journey that includes multiple steps, each step corresponding to a query to be applied to one or more field-searchable data stores storing events, each event including a portion of machine data that reflects activity in an information technology environment and that is produced by a component of that information technology environment, and each event being associated with a timestamp extracted from the portion of machine data of that event. Events returned as a result of the query of each step are related. The results of the relating are displayed.
-
Citations
29 Claims
-
1. A method comprising:
-
obtaining information describing a user journey, the user journey comprising a plurality of steps, wherein each step of the plurality of steps corresponds to a query to be applied to one or more field-searchable data stores storing a plurality of events, wherein each event of the plurality of events includes a portion of machine data that reflects activity in an information technology environment and that is produced by a component of that information technology environment; relating, based on the obtained information, a set of events returned as a result of the plurality of queries, wherein relating the set of events is based on one or more stitching schemes, wherein a stitching scheme indicates a relation between information included in a first event and information included in a second event, and wherein relating the set of events based on a particular stitching scheme comprises; identifying that a same entity is associated with a first particular event of the set of events and a second particular event of the set of events, the first particular event being associated with a first data source and the second particular event being associated with a second data source; and causing display of results of the relating. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21)
-
-
22. A computing system, comprising:
one or more processing devices configured to; obtain information describing a user journey, the user journey comprising a plurality of steps, wherein each step of the plurality of steps corresponds to a query to be applied to one or more field-searchable data stores storing a plurality of events, wherein each event of the plurality of events includes a portion of machine data that reflects activity in an information technology environment and that is produced by a component of that information technology environment; relate, based on the obtained information, a set of events returned as a result of the plurality of queries, wherein relating the set of events is based on one or more stitching schemes, wherein a stitching scheme indicates a relation between information included in a first event and information included in a second event, and wherein relating the set of events based on a particular stitching scheme comprises; identifying that a same entity is associated with a first particular event of the set of events and a second particular event of the set of events, the first particular event being associated with a first data source and the second particular event being associated with a second data source; and cause display of results of the relating. - View Dependent Claims (23, 24, 25, 26)
-
27. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system, cause the computing system to:
-
obtain information describing a user journey, the user journey comprising a plurality of steps, wherein each step of the plurality of steps corresponds to a query to be applied to one or more field-searchable data stores storing a plurality of events, wherein each event of the plurality of events includes a portion of machine data that reflects activity in an information technology environment and that is produced by a component of that information technology environment, wherein each event is associated with a timestamp extracted from the portion of machine data of that event; relate, based on the obtained information, a set of events returned as a result of the plurality of queries, wherein relating the set of events is based on one or more stitching schemes, wherein a stitching scheme indicates a relation between information included in a first event and information included in a second event, and wherein relating the set of events based on a particular stitching scheme comprises; identifying that a same entity is associated with a first particular event of the set of events and a second particular event of the set of events, the first particular event being associated with a first data source and the second particular event being associated with a second data source; and cause display of results of the relating. - View Dependent Claims (28, 29)
-
Specification