Event limited field picker
First Claim
1. A computer-implemented method comprising:
- receiving a search query on events, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system;
causing display of a set of the events that are responsive to the search query, the set of the events comprising fields, each field of the fields being defined by an extraction rule that is applied to the portion of machine data; and
based on receiving a user selection of a graphical interface control associated with a particular event of the set of the events, causing display of an event limited field picker including a list of field identifiers of the fields corresponding to the particular event with corresponding field values, wherein at least one field identifier in the list of field identifiers is user selectable to toggle between causing field values of a corresponding field to be displayed for events of the set of events and causing the field values of the corresponding field to be removed from display for the events.
1 Assignment
0 Petitions
Accused Products
Abstract
An event limited field picker for a search user interface is described. In one or more implementations, a service may operate to collect and store data as events each of which includes a portion of the data correlated with a point in time. Clients may use a search user interface perform searches by input of search criteria. Responsive to receiving search criteria, the service may operate to apply a late binding schema to extract events that match the search criteria and provide search results for display via the search user interface. The search user interface exposes an event limited field picker operable to make selections of fields with respect to individual events in a view of the search results. In response to receiving an indication of a fields selected via the picker, visibility of selected fields may be updated to control which field and values are included in different views.
102 Citations
30 Claims
-
1. A computer-implemented method comprising:
-
receiving a search query on events, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system; causing display of a set of the events that are responsive to the search query, the set of the events comprising fields, each field of the fields being defined by an extraction rule that is applied to the portion of machine data; and based on receiving a user selection of a graphical interface control associated with a particular event of the set of the events, causing display of an event limited field picker including a list of field identifiers of the fields corresponding to the particular event with corresponding field values, wherein at least one field identifier in the list of field identifiers is user selectable to toggle between causing field values of a corresponding field to be displayed for events of the set of events and causing the field values of the corresponding field to be removed from display for the events. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. One or more computer-readable storage media comprising instructions that are stored thereon that, responsive to execution by one or more processors, cause the one or more processors to perform operations comprising:
-
receiving a search query on events, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system; causing display of a set of the events that are responsive to the search query, the set of the events comprising fields, each field of the fields being defined by an extraction rule that is applied to the portion of machine data; and based on receiving a user selection of a graphical interface control associated with a particular event of the set of the events, causing display of an event limited field picker including a list of field identifiers of the fields corresponding to the particular event with corresponding field values, wherein at least one field identifier in the list of field identifiers is user selectable to toggle between causing field values of a corresponding field to be displayed for events of the set of events and causing the field values of the corresponding field to be removed from display for the events. - View Dependent Claims (19, 20, 21, 22, 23, 24)
-
-
25. A computer-implemented system comprising:
-
one or more processors; and one or more computer-readable storage media comprising instructions that are stored thereon that, responsive to execution by the one or more processors, cause the one or more processors to perform operations comprising; receiving a search query on events, each event comprising a time stamp and a portion of machine data that reflects activity in an information technology environment of at least one computing system; causing display of a set of the events that are responsive to the search query, the set of the events comprising fields, each field of the fields being defined by an extraction rule that is applied to the portion of machine data; and based on receiving a user selection of a graphical interface control associated with a particular event of the set of the events, causing display of an event limited field picker including a list of field identifiers of the fields corresponding to the particular event with corresponding field values, wherein at least one field identifier in the list of field identifiers is user selectable to toggle between causing field values of a corresponding field to be displayed for events of the set of events and causing the field values of the corresponding field to be removed from display for the events. - View Dependent Claims (26, 27, 28, 29, 30)
-
Specification