USER INTERFACE FOR EVENT DATA STORE
First Claim
1. A method comprising:
- receiving, by a processing device, a query comprising a first field value and a time period;
performing, by the processing device, a first search of a data store using the first field value to identify a plurality of events having the time period and at least one field that comprises the first field value;
determining a first subset of the plurality of events associated with a first context definition;
determining a plurality of fields specified in the first context definition;
determining, for events in the first subset, field values of one or more fields specified in the first context definition;
generating a report based on the field values of the one or more fields specified in the first context definition from the events in the first subset; and
generating a response to the query that comprises at least a portion of the report.
3 Assignments
0 Petitions
Accused Products
Abstract
A processing device receives a query comprising a first field value and a time period and performs a first search of a data store using the first field value to identify a plurality of events having the time period and a field that comprises the first field value. The processing device determines a first subset of the plurality of events associated with a first context definition and determines a plurality of fields specified in the first context definition. The processing device determines, for events in the first subset, field values of one or more fields specified in the first context definition. The processing device generates a report based on the field values of the one or more fields specified in the first context definition from the events in the first subset. The processing device generates a response to the query that comprises at least a portion of the report.
21 Citations
21 Claims
-
1. A method comprising:
-
receiving, by a processing device, a query comprising a first field value and a time period; performing, by the processing device, a first search of a data store using the first field value to identify a plurality of events having the time period and at least one field that comprises the first field value; determining a first subset of the plurality of events associated with a first context definition; determining a plurality of fields specified in the first context definition; determining, for events in the first subset, field values of one or more fields specified in the first context definition; generating a report based on the field values of the one or more fields specified in the first context definition from the events in the first subset; and generating a response to the query that comprises at least a portion of the report. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A computing device comprising:
-
a memory; and a processing device operatively coupled to the memory, the processing device to; receive a query comprising a first field value and a time period; perform a first search of a data store using the first field value to identify a plurality of events having the time period and at least one field that comprises the first field value; determine a first subset of the plurality of events associated with a first context definition; determine a plurality of fields specified in the first context definition; determine, for events in the first subset, field values of one or more fields specified in the first context definition; generate a report based on the field values of the one or more fields specified in the first context definition from the events in the first subset; and generate a response to the query that comprises at least a portion of the report. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. A computer readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:
-
receiving, by the processing device, a query comprising a first field value and a time period; performing, by the processing device, a first search of a data store using the first field value to identify a plurality of events having the time period and at least one field that comprises the first field value; determining a first subset of the plurality of events associated with a first context definition; determining a plurality of fields specified in the first context definition; determining, for events in the first subset, field values of one or more fields specified in the first context definition; generating a report based on the field values of the one or more fields specified in the first context definition from the events in the first subset; and generating a response to the query that comprises at least a portion of the report.
-
Specification