Real time display of statistics and values for selected regular expressions
First Claim
1. A computer-implemented method, comprising:
- accessing a set of events for a computing system, wherein each event in the set includes a portion of raw machine data, and wherein at least two events have their respective portions of raw machine data in different data formats;
extracting a plurality of values from the events using an extraction rule, wherein the extraction rule defines where to find a field within the portion of raw machine data in an event and how to extract the value of the field without modifying the portion of the raw machine data;
causing display of a plurality of the events in a first portion of a graphical interface, wherein values extracted from the displayed events are emphasized in the displayed events;
causing display of a subset of the plurality of extracted values in a second portion of the graphical interface;
determining a statistic that is a proportion of events that include the extracted values for the displayed subset of the extracted values; and
causing display of the statistic in the second portion of the graphical interface;
wherein the second portion and the first portion are concurrently displayed in a same graphical interface.
1 Assignment
0 Petitions
Accused Products
Abstract
Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.
-
Citations
27 Claims
-
1. A computer-implemented method, comprising:
-
accessing a set of events for a computing system, wherein each event in the set includes a portion of raw machine data, and wherein at least two events have their respective portions of raw machine data in different data formats; extracting a plurality of values from the events using an extraction rule, wherein the extraction rule defines where to find a field within the portion of raw machine data in an event and how to extract the value of the field without modifying the portion of the raw machine data; causing display of a plurality of the events in a first portion of a graphical interface, wherein values extracted from the displayed events are emphasized in the displayed events; causing display of a subset of the plurality of extracted values in a second portion of the graphical interface; determining a statistic that is a proportion of events that include the extracted values for the displayed subset of the extracted values; and causing display of the statistic in the second portion of the graphical interface; wherein the second portion and the first portion are concurrently displayed in a same graphical interface. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A system, comprising:
-
one or more processor; and one or more non-transitory computer-readable storage media storing instructions programmed to cause the one or more processors to perform operations including; accessing a set of events for a computing system, wherein each event in the set includes a portion of raw machine data, and wherein at least two events have their respective portions of raw machine data in different data formats; extracting a plurality of values from the events using an extraction rule, wherein the extraction rule defines where to find a field within the portion of the raw machine data in an event and how to extract the value of the field without modifying the portion of the raw machine data; causing display of a plurality of the events in a first portion of a graphical interface, wherein values extracted from the displayed events are emphasized in the displayed events; causing display of a subset of the plurality of extracted values in a second portion of the graphical interface; determining a statistic that is a proportion of events that include the extracted values for the displayed subset of the extracted values; and causing display of the statistic in the second portion of the graphical interface;
wherein the second portion and the first portion are concurrently displayed in a same graphical interface. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A computer-program product, tangibly embodied in a non-transitory machine-readable medium, including instructions programmed to cause a data processing apparatus to perform a process including:
-
accessing a set of events for a computing system, wherein each event in the set includes a portion of raw machine data, and wherein at least two events have their respective portions of raw machine data in different data formats; extracting a plurality of values from the events using an extraction rule, wherein the extraction rule defines where to find a field within the portion of raw machine data in an event and how to extract the value of the field without modifying the portion of the raw machine data; causing display of a plurality of the events in a first portion of a graphical interface, wherein values extracted from the displayed events are emphasized in the displayed events; causing display of a subset of the plurality of extracted values in a second portion of the graphical interface; determining a statistic that is a proportion of events that include the extracted values for the displayed subset of the extracted values; and causing display of the statistic in the second portion of the graphical interface; wherein the second portion and the first portion are concurrently displayed in a same graphical interface. - View Dependent Claims (20, 21, 22, 23, 24, 25, 26, 27)
-
Specification