×

Query handling using summarization tables

  • US 10,685,001 B2
  • Filed: 04/30/2018
  • Issued: 06/16/2020
  • Est. Priority Date: 01/31/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • creating a set of field searchable, time stamped event records from raw data stored in at least one datastore, wherein each field searchable, time stamped event record in the set of field searchable, time stamped event records comprises a portion of the raw data and is associated with a time stamp derived from the raw data;

    generating a summarization table for a set of field names in the set of field searchable, time stamped event records that identifies one or more field values associated with the set of field names and further generating, for each field value, one or more posting values to field searchable, time stamped event records in the at least one data store having the field value, wherein a field value comprises a value that appears in connection with an associated field name in one or more field searchable, time stamped event records in the set of field searchable, time stamped event records, and wherein each posting value of the one or more posting values references a location of a corresponding field searchable, time stamped event record in the at least one data store;

    storing the summarization table;

    receiving a search query that includes search criteria for evaluating field values for one or more field names;

    using the search criteria to evaluate the field values for the one or more field names in the summarization table to generate a query result;

    causing display of information based on the query result.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×