Distinguishing Field Labels From Multiple Extractions
First Claim
1. A computer-implemented method, comprising:
- extracting first one or more values from a plurality of events using a first extraction rule;
assigning the extracted first one or more values to a first field of the plurality of events as a first set of field-data item pairs;
assigning a field label to the first field;
extracting second one or more values and a field label corresponding to the second one or more values from the plurality of the events using a second extraction rule, the extracted field label corresponding to the assigned field label of the first field; and
assigning the extracted second one or more values to a second field of the plurality of events as a second set of field-data item pairs, thereby distinguishing the extracted second one or more values from the extracted first one or more values.
1 Assignment
0 Petitions
Accused Products
Abstract
First one or more values are extracted from a plurality of events using a first extraction rule. The extracted first one or more values are assigned to a first field of the plurality of events as a first set of field-data item pairs and a field label is assigned to the first field. Second one or more values and a field label corresponding to the second one or more values are extracted from the plurality of the events using a second extraction rule, where the extracted field label corresponds to the assigned field label of the first field. The extracted second one or more values are assigned to a second field of the plurality of events as a second set of field-data item pairs, thereby distinguishing the extracted second one or more values from the extracted first one or more values.
51 Citations
30 Claims
-
1. A computer-implemented method, comprising:
-
extracting first one or more values from a plurality of events using a first extraction rule; assigning the extracted first one or more values to a first field of the plurality of events as a first set of field-data item pairs; assigning a field label to the first field; extracting second one or more values and a field label corresponding to the second one or more values from the plurality of the events using a second extraction rule, the extracted field label corresponding to the assigned field label of the first field; and assigning the extracted second one or more values to a second field of the plurality of events as a second set of field-data item pairs, thereby distinguishing the extracted second one or more values from the extracted first one or more values. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
one or more data processors; and one or more computer-readable storage media containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including; extracting first one or more values from a plurality of events using a first extraction rule; assigning the extracted first one or more values to a first field as a first set of field-data item pairs; assigning a field label to the first field of the plurality of events; extracting second one or more values and a field label corresponding to the second one or more values from the plurality of the events using a second extraction rule, the extracted field label corresponding to the assigned field label of the first field; and assigning the extracted second one or more values to a second field of the plurality of events as a second set of field-data item pairs, thereby distinguishing the extracted second one or more values from the extracted first one or more values. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23)
-
-
24. One or more computer-storage media storing computer-useable instructions that, when executed by a computing device, perform a method, the method comprising:
-
extracting first one or more values from a plurality of events using a first extraction rule; assigning the extracted first one or more values to a first field as a first set of field-data item pairs; assigning a field label to the first field of the plurality of events; extracting second one or more values and a field label corresponding to the second one or more values from the plurality of the events using a second extraction rule, the extracted field label corresponding to the assigned field label of the first field; and assigning the extracted second one or more values to a second field of the plurality of events as a second set of field-data item pairs, thereby distinguishing the extracted second one or more values from the extracted first one or more values. - View Dependent Claims (25, 26, 27, 28, 29, 30)
-
Specification