GRAPHICAL DISPLAY OF FIELD VALUES EXTRACTED FROM MACHINE DATA
First Claim
1. A method comprising:
- receiving a search query entered by a user in textual form into a query box;
creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment;
determining a set of fields that have each been defined for one or more events in the set of events, each field associated with an extraction rule for extracting a value from the raw data in each of the one or more events for which the field has been defined;
causing display of one or more graphical controls, each graphical control corresponding to a field in the determined set of fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields.
1 Assignment
0 Petitions
Accused Products
Abstract
The disclosure relates to certain system and method embodiments for generating reports from unstructured data. In one embodiment, a method can include identifying events matching criteria of an initial search query (each of the events including a portion of raw machine data that is associated with a time), identifying a set of fields, each field defined for one or more of the identified events, causing display of an interactive graphical user interface (GUI) that includes one or more interactive elements enabling a user to define a report for providing information relating to the matching events (each interactive element enabling processing or presentation of information in the matching events using one or more fields in the identified set of fields), receiving, via the GUI, a report definition indicating how to report information relating to the matching events, and generating, based on the report definition, a report including information relating to the matching events.
71 Citations
20 Claims
-
1. A method comprising:
-
receiving a search query entered by a user in textual form into a query box; creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment; determining a set of fields that have each been defined for one or more events in the set of events, each field associated with an extraction rule for extracting a value from the raw data in each of the one or more events for which the field has been defined; causing display of one or more graphical controls, each graphical control corresponding to a field in the determined set of fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19)
-
-
20. One or more non-transitory computer readable storage media storing instructions which, when executed by one or more computing devices, cause:
-
receiving a search query entered by a user in textual form into a query box; creating a set of events by applying the search query across a data store of field-searchable events to find matching events, including raw data produced by one or more components in an information technology environment and reflecting activity within the information technology environment; determining a set of fields that have each been defined for one or more events in the set of events, each field associated with an extraction rule for extracting a value from the raw data in each of the one or more events for which the field has been defined; causing display of one or more graphical controls, each graphical control corresponding to a field in the determined set of fields, the graphical controls enabling the user to process the set of events using the corresponding one or more fields.
-
Specification