Visualization of Unique Field Values for a Field in a Set of Events
First Claim
1. A method comprising:
- creating a set of time stamped, searchable events from a set of raw data, each event in the set of time stamped, searchable events includes a portion of the set of raw data from which the time stamped, searchable event was derived, the set of raw data related to security or performance aspects of one or more information technology systems;
identifying a set of unique values included in a particular field that is present in one or more time stamped, searchable events in the set of time stamped, searchable events;
causing display of a plurality of rows, each row corresponding to one unique value among the set of unique values, each row having one or more indicators displayed along a timeline, each indicator among the one or more indicators indicating a number of time stamped, searchable events in the set of time stamped, searchable events within a certain time period that includes the unique value in the particular field, each indicator of the one or more indicators is positioned along the timeline according to the certain time period;
wherein the method is performed by one or more computing devices.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems and methods are provided for visualizing the number of events having different values for a field of interest over a selected time range. The events may be derived from machine data obtained from one or more data sources. User input received via a graphical user interface may specify the field of interest, a time range, and a time granularity for displaying counts of the number of events having various values during different time slots within the selected time range. Events including the specified field during the user-selected time range are identified and values for the field are extracted from the identified events. A visualization indicating a relation between a number of the events occurring within each of a plurality of time slots over the selected time range and each of the unique extracted values of the field is provided to the user via the graphical user interface.
-
Citations
20 Claims
-
1. A method comprising:
-
creating a set of time stamped, searchable events from a set of raw data, each event in the set of time stamped, searchable events includes a portion of the set of raw data from which the time stamped, searchable event was derived, the set of raw data related to security or performance aspects of one or more information technology systems; identifying a set of unique values included in a particular field that is present in one or more time stamped, searchable events in the set of time stamped, searchable events; causing display of a plurality of rows, each row corresponding to one unique value among the set of unique values, each row having one or more indicators displayed along a timeline, each indicator among the one or more indicators indicating a number of time stamped, searchable events in the set of time stamped, searchable events within a certain time period that includes the unique value in the particular field, each indicator of the one or more indicators is positioned along the timeline according to the certain time period; wherein the method is performed by one or more computing devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A non-transitory computer readable storage medium, storing instructions that, when executed by one or more processors, cause performance of:
-
creating a set of time stamped, searchable events from a set of raw data, each event in the set of time stamped, searchable events includes a portion of the set of raw data from which the time stamped, searchable event was derived, the set of raw data related to security or performance aspects of one or more information technology systems; identifying a set of unique values included in a particular field that is present in one or more time stamped, searchable events in the set of time stamped, searchable events; causing display of a plurality of rows, each row corresponding to one unique value among the set of unique values, each row having one or more indicators displayed along a timeline, each indicator among the one or more indicators indicating a number of time stamped, searchable events in the set of time stamped, searchable events within a certain time period that includes the unique value in the particular field, each indicator of the one or more indicators is positioned along the timeline according to the certain time period. - View Dependent Claims (17)
-
-
18. A system comprising:
-
a memory having processor-readable instructions stored therein; and a processor configured to access the memory and execute the processor-readable instructions, which when executed by the processor, configures the processor to perform a plurality of functions, including functions to; creating a set of time stamped, searchable events from a set of raw data, each event in the set of time stamped, searchable events includes a portion of the set of raw data from which the time stamped, searchable event was derived, the set of raw data related to security or performance aspects of one or more information technology systems; identifying a set of unique values included in a particular field that is present in one or more time stamped, searchable events in the set of time stamped, searchable events; causing display of a plurality of rows, each row corresponding to one unique value among the set of unique values, each row having one or more indicators displayed along a timeline, each indicator among the one or more indicators indicating a number of time stamped, searchable events in the set of time stamped, searchable events within a certain time period that includes the unique value in the particular field, each indicator of the one or more indicators is positioned along the timeline according to the certain time period. - View Dependent Claims (19, 20)
-
Specification