×

Aggregation and display of search results from multi-criteria search queries on event data

  • US 9,922,066 B2
  • Filed: 01/27/2016
  • Issued: 03/20/2018
  • Est. Priority Date: 10/05/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • creating, in real-time, a plurality of searchable events from machine data as the machine data is collected in real-time from one or more data sources, each event in the plurality of searchable events is segmented from the machine data and includes an associated portion of the machine data and an associated timestamp derived from the machine data;

    dividing the plurality of events into sets of events that are organized by time;

    indexing the timestamped events;

    hashing each event in the sets of events, wherein each event is tested for duplication using its associated hash value, wherein an event having a hash value that is a duplicate of an existing hash value is removed;

    as the plurality of events are being created in real-time, receiving a search query that includes at least a time criterion, a second criterion for selection of events, and a page value;

    generating a result set for an event search query by executing the event search query across the plurality of events, the event search query includes the time criterion and the second criterion for selection of events, the result set includes events that match the time criterion and have an associated portion of the machine data that fulfills the second criterion for selection of events;

    sorting the result set according to time;

    causing display of a plurality of aggregated display lines, wherein each aggregated display line among the plurality of aggregated display lines is a summary of one or more search results among the set of search results that have features that satisfy a particular interval among a plurality of intervals and the page value, each interval among the plurality of intervals fitting within a display page.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×