Determining Timestamps To Be Associated With Events In Machine Data
First Claim
Patent Images
1. A method, comprising:
- aggregating a collection of machine data stored on at least one storage device into a set of events, wherein the machine data associated with at least a subset of the events includes time information;
extracting a timestamp for each event in the subset of events that includes time information;
for each event that does not contain time information in the associated machine data, determining a time stamp from at least one other event in the collection of machine data; and
associating the determined time stamp with the corresponding event,wherein the method is performed by one or more computing devices.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is organized into discrete events with normalized time stamps and the events are indexed by time and keyword. A search is received and relevant event information is retrieved based in whole or in part on the time indexing mechanism, keyword indexing mechanism, or statistical indices calculated at the time of the search.
-
Citations
30 Claims
-
1. A method, comprising:
-
aggregating a collection of machine data stored on at least one storage device into a set of events, wherein the machine data associated with at least a subset of the events includes time information; extracting a timestamp for each event in the subset of events that includes time information; for each event that does not contain time information in the associated machine data, determining a time stamp from at least one other event in the collection of machine data; and associating the determined time stamp with the corresponding event, wherein the method is performed by one or more computing devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19)
-
-
20. A non-transitory, computer-readable storage medium storing instructions, an execution of which in a computer system causes the computer system to perform operations comprising:
-
aggregating a collection of machine data stored on at least one storage device into a set of events, wherein the machine data associated with at least a subset of the events includes time information; extracting a timestamp for each event in the subset of events that includes time information; for each event that does not contain time information in the associated machine data, determining a time stamp from at least one other event in the collection of machine data; and associating the determined time stamp with the corresponding event. - View Dependent Claims (21, 22, 23, 24)
-
-
25. A computer system comprising:
-
computer memory for storing machine data; and a processor for; aggregating a collection of machine data stored on at least one storage device into a set of events, wherein the machine data associated with at least a subset of the events includes time information; extracting a timestamp for each event in the subset of events that includes time information; for each event that does not contain time information in the associated machine data, determining a time stamp from at least one other event in the collection of machine data; and associating the determined time stamp with the corresponding event. - View Dependent Claims (26, 27, 28, 29, 30)
-
Specification