Incident review interface
First Claim
1. A method comprising:
- automatically performing a correlation search in accordance with a defined frequency, the correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs), each KPI defined by a search query that derives a value from the corresponding machine data to indicate a state of the service at a point in time or during a period of time;
wherein the correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria;
storing a notable event in response to the data identified by the search query satisfying the triggering condition; and
causing display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identification of the correlation search that triggered the storing of the notable event and an identification of the service associated with the correlation search;
wherein each of the entities corresponds to a stored entity definition having an identification of the corresponding machine data, and the service corresponds to a stored service definition referencing the stored entity definitions;
wherein the method is performed by a computer system comprising one or more processing devices coupled to a memory for storing the notable event, the service definition, the entity definitions, and the KPIs.
1 Assignment
0 Petitions
Accused Products
Abstract
A computing machine performs a correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs) that each indicate a state of the service at a point in time or during a period of time and that each derive from the corresponding machine data for the one or more entities. The correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria. The computing machine stores a notable event in response to the data identified by the search query satisfying the triggering condition and causes display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identifier of the correlation search that triggered the storing of the notable event and an identifier of the service associated with the correlation search.
217 Citations
30 Claims
-
1. A method comprising:
-
automatically performing a correlation search in accordance with a defined frequency, the correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs), each KPI defined by a search query that derives a value from the corresponding machine data to indicate a state of the service at a point in time or during a period of time; wherein the correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria; storing a notable event in response to the data identified by the search query satisfying the triggering condition; and causing display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identification of the correlation search that triggered the storing of the notable event and an identification of the service associated with the correlation search; wherein each of the entities corresponds to a stored entity definition having an identification of the corresponding machine data, and the service corresponds to a stored service definition referencing the stored entity definitions; wherein the method is performed by a computer system comprising one or more processing devices coupled to a memory for storing the notable event, the service definition, the entity definitions, and the KPIs. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28)
-
-
29. A system comprising:
-
a memory; and a processing device coupled with the memory to; automatically perform a correlation search in accordance with a defined frequency, the correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs), each KPI defined by a search query that derives a value from the corresponding machine data to indicate a state of the service at a point in time or during a period of time; wherein the correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria; store a notable event in response to the data identified by the search query satisfying the triggering condition; and cause display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identification of the correlation search that triggered the storing of the notable event and an identification of the service associated with the correlation search; wherein each of the entities corresponds to a stored entity definition having an identification of the corresponding machine data, and the service corresponds to a stored service definition referencing the stored entity definitions.
-
-
30. A non-transitory computer readable storage medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the one or more processing devices to perform operations comprising:
-
automatically performing a correlation search in accordance with a defined frequency, the correlation search associated with a service provided by one or more entities that each have corresponding machine data, the service having one or more key performance indicators (KPIs), each KPI defined by a search query that derives a value from the corresponding machine data to indicate a state of the service at a point in time or during a period of time; wherein the correlation search associated with the service comprises search criteria pertaining to the one or more KPIs, and a triggering condition to be applied to data identified by a search query using the search criteria; storing a notable event in response to the data identified by the search query satisfying the triggering condition; and causing display of a graphical user interface presenting information pertaining to the stored notable event, the information comprising an identification of the correlation search that triggered the storing of the notable event and an identification of the service associated with the correlation search; wherein each of the entities corresponds to a stored entity definition having an identification of the corresponding machine data, and the service corresponds to a stored service definition referencing the stored entity definitions.
-
Specification