×

GENERATION OF A SEARCH QUERY TO APPROXIMATE REPLICATION OF A CLUSTER OF EVENTS

  • US 20160034525A1
  • Filed: 07/31/2014
  • Published: 02/04/2016
  • Est. Priority Date: 07/31/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • accessing data items in a dataset, each data item containing a portion of raw machine-generated data in textual form generated by a component in an information-technology environment;

    applying a clustering algorithm to the data items to group the data items into two or more clusters, the clustering algorithm generating an ordered list of keywords for each data item that is parsed from that data item and grouping data items into a same cluster when their respective ordered lists of keywords meet a similarity threshold; and

    for each cluster, identifying a set of one or more search terms providing criteria for a search query that substantially reproduces the cluster upon execution of the search query against the dataset, wherein execution of the search query against the dataset comprises evaluating the search terms against the raw machine-generated data in textual form in the data items;

    wherein each of the search terms requires a presence of a particular keyword in the data items, requires an absence of a particular keyword in the data items, or includes a criterion pertaining to a field in the data items;

    wherein the method is performed by one or more processing devices.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×