ADVANCED FIELD EXTRACTOR WITH MODIFICATION OF AN EXTRACTED FIELD
First Claim
1. A method, comprising:
- receiving a first selection associated with an event of a plurality of events, wherein each event in the plurality of events includes a portion of raw data, and wherein the first selection is of a portion of text within the raw data of the event to be extracted as a value of a field;
automatically determining an extraction rule that extracts the selected portion of text as the value of the field; and
causing display of an interface to allow user modification of a representation of the value.
2 Assignments
0 Petitions
Accused Products
Abstract
The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.
237 Citations
30 Claims
-
1. A method, comprising:
-
receiving a first selection associated with an event of a plurality of events, wherein each event in the plurality of events includes a portion of raw data, and wherein the first selection is of a portion of text within the raw data of the event to be extracted as a value of a field; automatically determining an extraction rule that extracts the selected portion of text as the value of the field; and causing display of an interface to allow user modification of a representation of the value. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A computer-implemented system comprising:
-
receiving a first selection associated with an event of a plurality of events, wherein each event in the plurality of events includes a portion of raw data, and wherein the first selection is of a portion of text within the raw data of the event to be extracted as a value of a field; automatically determining an extraction rule that extracts the selected portion of text as the value of the field; and causing display of an interface to allow user modification of a representation of the value. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23)
-
-
24. A tangible computer-readable memory having instructions stored in the memory that implement the actions including:
-
receiving a first selection associated with an event of a plurality of events, wherein each event in the plurality of events includes a portion of raw data, and wherein the first selection is of a portion of text within the raw data of the event to be extracted as a value of a field; automatically determining an extraction rule that extracts the selected portion of text as the value of the field; and causing display of an interface to allow user modification of a representation of the value. - View Dependent Claims (25, 26, 27, 28, 29, 30)
-
Specification