×

Determining timestamps to be associated with events in machine data

  • US 9,922,065 B2
  • Filed: 10/30/2015
  • Issued: 03/20/2018
  • Est. Priority Date: 10/05/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • segmenting machine data stored on at least one storage device into a set of events that are searchable, each event in the set of events includes a portion of the machine data, wherein the portions of the machine data associated with at least a subset of events in the set of events includes time information;

    creating a timestamp for each event in the subset of events that includes time information by;

    iterating over known time stamp format patterns from a list of known time stamp format patterns to find a matching pattern in the time information, wherein each time stamp format pattern in the list represents a pattern that may occur in the time information which indicates where a time stamp may be extracted from, wherein the list is dynamically ordered and the matching pattern is moved to the front of the list;

    extracting a time value from the time information using the matching pattern; and

    associating the timestamp with that event using the time value;

    for each event that does not contain time information in the included portion of machine data;

    determining a time stamp corresponding to that event from at least one other event in the set of events; and

    associating the determined time stamp with the corresponding event;

    servicing time-based search queries across the set of events;

    wherein the method is performed by one or more computing devices.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×