Storing events associated with a time stamp extracted from log data and performing a search on the events and data that is not log data
First Claim
Patent Images
1. A computer-implemented method for time searching data, comprising:
- obtaining log data generated by at least one component in an information processing environment;
obtaining data that is not log data from a real-time monitoring environment;
storing in a data store, a plurality of events, wherein each event is based on at least a portion of the log data and is associated with a time stamp extracted from the log data;
storing the data that is not log data in the data store; and
executing a search on the plurality of events and the data that is not log data in the data store.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is stored as discrete events time stamps. A search is received and relevant event information is retrieved based in whole or in part on the time stamp, a keyword indexing mechanism, or statistical indices calculated at the time of the search.
366 Citations
30 Claims
-
1. A computer-implemented method for time searching data, comprising:
-
obtaining log data generated by at least one component in an information processing environment; obtaining data that is not log data from a real-time monitoring environment; storing in a data store, a plurality of events, wherein each event is based on at least a portion of the log data and is associated with a time stamp extracted from the log data; storing the data that is not log data in the data store; and executing a search on the plurality of events and the data that is not log data in the data store. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28)
-
-
29. A computing system, comprising:
-
memory; and one or more processing devices coupled to the memory and configured to; obtain log data generated by at least one component in an information processing environment; obtain data that is not log data from a real-time monitoring environment; store in a data store, a plurality of events, wherein each event is based on at least a portion of the log data and is associated with a time stamp extracted from the log data; store the data that is not log data in the data store; and execute a search on the plurality of events and the data that is not log data in the data store.
-
-
30. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system of a data intake and query system, cause the computing system to:
-
obtain log data generated by at least one component in an information processing environment; obtain data that is not log data from a real-time monitoring environment; store in a data store, a plurality of events, wherein each event is based on at least a portion of the log data and is associated with a time stamp extracted from the log data; store the data that is not log data in the data store; and execute a search on the plurality of events and the data that is not log data in the data store.
-
Specification