Aggregation and Display of Search Results from Multi-Criteria Search Queries on Event Data
First Claim
Patent Images
1. A method, comprising:
- receiving a search query that includes a time criterion and a second criterion for selection of events;
generating result sets in response to the search query, the sets including events that match the time criterion and the second criterion;
merging the result sets into a set of search results;
sorting the set of search results according to time;
causing display of aggregated display lines summarizing the set of search results according to time windows.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is organized into discrete events with normalized time stamps and the events are indexed by time and keyword. A search is received and relevant event information is retrieved based in whole or in part on the time indexing mechanism, keyword indexing mechanism, or statistical indices calculated at the time of the search.
42 Citations
20 Claims
-
1. A method, comprising:
-
receiving a search query that includes a time criterion and a second criterion for selection of events; generating result sets in response to the search query, the sets including events that match the time criterion and the second criterion; merging the result sets into a set of search results; sorting the set of search results according to time; causing display of aggregated display lines summarizing the set of search results according to time windows. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. An apparatus, comprising:
-
a search query receiver, implemented at least partially in hardware, that receives a search query that includes a time criterion and a second criterion for selection of events; a search result generator, implemented at least partially in hardware, that generates result sets in response to the search query, the sets including events that match the time criterion and the second criterion; a search result merger, implemented at least partially in hardware, that merges the result sets into a set of search results; a search result sorter, implemented at least partially in hardware, that sorts the set of search results according to time; a display formatter, implemented at least partially in hardware, that causes display of aggregated display lines summarizing the set of search results according to time windows. - View Dependent Claims (13, 14, 15, 16)
-
-
17. One or more non-transitory computer-readable storage media, storing one or more sequences of instructions, which when executed by one or more processors cause performance of:
-
receiving a search query that includes a time criterion and a second criterion for selection of events; generating result sets in response to the search query, the sets including events that match the time criterion and the second criterion; merging the result sets into a set of search results; sorting the set of search results according to time; causing display of aggregated display lines summarizing the set of search results according to time windows. - View Dependent Claims (18, 19, 20)
-
Specification