DISCOVERING FIELDS TO FILTER DATA RETURNED IN RESPONSE TO A SEARCH
First Claim
1. A method comprising:
- discovering fields in events returned in response to an initial search query, wherein the events comprise portions of raw data, and the fields are defined by extraction rules for extracting values from corresponding portions of raw data;
causing display of a graphical user interface (GUI) that enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar;
receiving through a portion of the GUI that does not include a search bar for entering a search query at least one criterion for at least one field from the subset of the discovered fields; and
causing, by a processing device, the events returned in response to the initial search query to be filtered based on the received at least one criterion for the at least one field.
1 Assignment
0 Petitions
Accused Products
Abstract
Fields may be discovered in events that are returned in response to an initial search. The events may comprise portions of raw data. Furthermore, the fields may be defined by extraction rules for extracting values from corresponding portions of raw data. The displaying of a graphical user interface (GUI) may be caused where the GUI enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar. At least one criterion for at least one field from the subset of the discovered fields may be received through a portion of the GUI that does not include a search bar for entering a search query. The events returned in response to the initial search query may be caused to be filtered based on the received criterion.
-
Citations
30 Claims
-
1. A method comprising:
-
discovering fields in events returned in response to an initial search query, wherein the events comprise portions of raw data, and the fields are defined by extraction rules for extracting values from corresponding portions of raw data; causing display of a graphical user interface (GUI) that enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar; receiving through a portion of the GUI that does not include a search bar for entering a search query at least one criterion for at least one field from the subset of the discovered fields; and causing, by a processing device, the events returned in response to the initial search query to be filtered based on the received at least one criterion for the at least one field. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
a memory; and a processing device coupled to the memory and to; discover fields in events returned in response to an initial search query, wherein the events comprise portions of raw data, and the fields are defined by extraction rules for extracting values from corresponding portions of raw data; cause display of a graphical user interface (GUI) that enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar field; receive through a portion of the GUI that does not include a search bar for entering a search query at least one criterion for at least one field from the subset of the discovered fields; and cause the events returned in response to the initial search query to be filtered based on the received at least one criterion for the at least one field. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23)
-
-
24. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by a processing device, cause the processing device to perform operations comprising:
-
discovering fields in events returned in response to an initial search query, wherein the events comprise portions of raw data, and the fields are defined by extraction rules for extracting values from corresponding portions of raw data; causing display of a graphical user interface (GUI) that enables a user to select or enter criteria for a subset of the discovered fields without entering a search query in a search bar field; receiving through a portion of the GUI that does not include a search bar for entering a search query at least one criterion for at least one field from the subset of the discovered fields; and causing the events returned in response to the initial search query to be filtered based on the received at least one criterion for the at least one field. - View Dependent Claims (25, 26, 27, 28, 29, 30)
-
Specification