×

Time series search with interpolated time stamp

  • US 9,002,854 B2
  • Filed: 01/18/2012
  • Issued: 04/07/2015
  • Est. Priority Date: 10/05/2006
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for searching data, the method comprising:

  • gathering, using a computing device, a stream of data from an information processing environment;

    separating the stream of data into a plurality of events, each event including a respective portion of the stream of data;

    for each event of the plurality of events, determining an associated time stamp representing a time for the event;

    wherein determining the associated time stamp for an event of the plurality of events comprises time information to use in the time stamp from known times corresponding to portions of the stream of data surrounding the portion of the stream of data included in the event;

    assigning each event of the plurality of events to a bucket having an associated time range that includes the time represented by the time stamp for the event;

    receiving a search query that includes a time criterion and a second criterion for selection of events, the second criterion relating to a segment within the events, the segment identified by an extraction rule for extracting a subportion of data from the portion of the stream of data included in an event, the extraction rule using a pattern to identify boundaries of the subportion of data being extracted;

    identifying one or more buckets that each have an associated time range, at least one time in each associated time range satisfying the time criterion;

    based on examining events only in the identified one or more buckets, identifying a set of events that match the time criterion and have a segment that matches the second criterion;

    determining a result based on the set of events; and

    causing the result to be displayed.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×