Statistics time chart interface row mode drill down
First Claim
1. A method, comprising:
- generating a set of events responsive to a search query, each event comprising a timestamp and a portion of raw machine data that reflects activity in an information technology environment of at least one computing system;
causing display of a first interface in a tabular format that includes one or more rows, each row comprising;
a time increment corresponding to a plurality of the events that each have a field-value pair matching a particular event field; and
one or more aggregated metrics, wherein each aggregated metric of a particular row indicates a number of events included in a subset of the plurality of the events that each occurred within the time increment of the particular row and has a particular value in the particular event field; and
in response to a user selection of at least a row of the one or more rows, causing transition to a second interface associated with the row.
1 Assignment
0 Petitions
Accused Products
Abstract
In embodiments of statistics time chart interface row mode drill down, a first interface is displayed in a table format that includes columns each having a column heading comprising a different value, each different value associated with a particular event field, and includes rows each with a time increment and one or more aggregated metrics, each aggregated metric representing a number of events having a field-value pair that matches the different value represented in one of the columns and within the time increment over which the aggregated metric is calculated. A row that includes the time increment and the aggregated metrics can be emphasized in the first interface, and in response, a menu is displayed with selectable options to transition to a second interface based on a selected one of the options.
112 Citations
31 Claims
-
1. A method, comprising:
-
generating a set of events responsive to a search query, each event comprising a timestamp and a portion of raw machine data that reflects activity in an information technology environment of at least one computing system; causing display of a first interface in a tabular format that includes one or more rows, each row comprising; a time increment corresponding to a plurality of the events that each have a field-value pair matching a particular event field; and one or more aggregated metrics, wherein each aggregated metric of a particular row indicates a number of events included in a subset of the plurality of the events that each occurred within the time increment of the particular row and has a particular value in the particular event field; and in response to a user selection of at least a row of the one or more rows, causing transition to a second interface associated with the row. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A computer-implemented system, comprising:
-
one or more processors; and one or more computer-readable media having executable instructions embodied thereon, which, when executed by the one or more processors, cause the one or more processors to perform a method comprising; generating a set of events responsive to a search query, each event comprising a timestamp and a portion of raw machine data that reflects activity in an information technology environment of at least one computing system; causing display of a first interface in a tabular format that includes one or more rows, each row comprising; a time increment corresponding to a plurality of the events that each have a field-value pair matching a particular event field; and one or more aggregated metrics, wherein each aggregated metric of a particular row indicates a number of events included in a subset of the plurality of the events that each occurred within the time increment of the particular row and has a particular value in the particular event field; and in response to a user selection of at least a row of the one or more rows, causing transition to a second interface associated with the row. - View Dependent Claims (20, 21, 22, 23, 24, 25)
-
-
26. One or more computer-readable, non-volatile storage memory comprising stored instructions that are executable to cause one or more processors to perform operations comprising:
-
generating a set of events responsive to a search query, each event comprising a timestamp and a portion of raw machine data that reflects activity in an information technology environment of at least one computing system; causing display of a first interface in a tabular format that includes one or more rows, each row comprising; a time increment corresponding to a plurality of the events that each have a field-value pair matching a particular event field; and one or more aggregated metrics, wherein each aggregated metric of a particular indicates a number of events included in a subset of the plurality of the events that each occurred within the time increment of the particular row and has a particular value in the particular event field; and in response to a user selection of at least a row of the one or more rows, causing transition to a second interface associated with the row. - View Dependent Claims (27, 28, 29, 30, 31)
-
Specification