Identifying events using informational fields
First Claim
Patent Images
1. A method comprising:
- determining if events in a machine data store in a computer memory satisfy event selection criteria of a search query, the machine data store comprising machine data, and the event selection criteria including a first field-value pair;
wherein determining if one of the events satisfies the event selection criteria includes comparing the first field-value pair with a second field-value pair from an entity definition associated with the event via a third field-value pair associated with data corresponding to the event in the machine data store;
reflecting in the computer memory a result for the search query based at least in part on said determining;
wherein the entity definition represents an entity that provides a service, the service being represented by a service definition, the entity definition having an association with the service definition, and the service definition having an associated key performance indicator (KPI) defined by a KPI search query that produces a value from machine data identified in one or more entity definitions associated with the service, the value indicative of how the service is performing at a point in time or during a period of time;
wherein the entity definition and the service definition are stored in the computer memory; and
wherein the method is performed by a computer system comprising one or more processing devices coupled to the computer memory.
1 Assignment
0 Petitions
Accused Products
Abstract
A computer system determines if events in a machine data store satisfy event selection criteria, the event selection criteria including a first field-value pair. To determine if one of the events satisfies the event selection criteria, the computer system compares the first field-value pair of the event selection criteria with a second field-value pair from an entity definition associated with the event by using a third field-value pair from data corresponding to the event in the machine data store.
-
Citations
30 Claims
-
1. A method comprising:
-
determining if events in a machine data store in a computer memory satisfy event selection criteria of a search query, the machine data store comprising machine data, and the event selection criteria including a first field-value pair; wherein determining if one of the events satisfies the event selection criteria includes comparing the first field-value pair with a second field-value pair from an entity definition associated with the event via a third field-value pair associated with data corresponding to the event in the machine data store; reflecting in the computer memory a result for the search query based at least in part on said determining; wherein the entity definition represents an entity that provides a service, the service being represented by a service definition, the entity definition having an association with the service definition, and the service definition having an associated key performance indicator (KPI) defined by a KPI search query that produces a value from machine data identified in one or more entity definitions associated with the service, the value indicative of how the service is performing at a point in time or during a period of time; wherein the entity definition and the service definition are stored in the computer memory; and wherein the method is performed by a computer system comprising one or more processing devices coupled to the computer memory. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
a memory; and a processing device coupled with the memory to; determine if events in a machine data store satisfy event selection criteria of a search query, the machine data store comprising machine data, and the event selection criteria including a first field-value pair, wherein to determine if one of the events satisfies the event selection criteria includes comparing the first field-value pair with a second field-value pair from an entity definition associated with the event via a third field-value pair associated with data corresponding to the event in the machine data store; reflect in the memory a result for the search query based at least in part on said determination; and wherein the entity definition represents an entity that provides a service, the service being represented by a service definition, the entity definition having an association with the service definition, and the service definition having an associated key performance indicator (KPI) defined by a KPI search query that produces a value from machine data identified in one or more entity definitions associated with the service, the value indicative of how the service is performing at a point in time or during a period of time. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23, 24, 25)
-
-
26. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the one or more processing devices to perform operations comprising:
-
determining if events in a machine data store in a computer memory satisfy event selection criteria of a search query, the machine data store comprising machine data, and the event selection criteria including a first field-value pair; wherein determining if one of the events satisfies the event selection criteria includes comparing the first field-value pair with a second field-value pair from an entity definition associated with the event via a third field-value pair associated with data corresponding to the event in the machine data store; reflecting in the computer memory a result for the search query based at least in part on said determining; wherein the entity definition represents an entity that provides a service, the service being represented by a service definition, the entity definition having an association with the service definition, and the service definition having an associated key performance indicator (KPI) defined by a KPI search query that produces a value from machine data identified in one or more entity definitions associated with the service, the value indicative of how the service is performing at a point in time or during a period of time; and wherein the entity definition and the service definition are stored in the computer memory; and wherein the operations are performed by the one or more processing devices. - View Dependent Claims (27, 28, 29, 30)
-
Specification