Event limited field picker
First Claim
1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, comprising:
- accessing a set of events in a data store in response to a query, each event including a portion of raw machine data that reflects the activity in the information technology environment and is produced by the component of the information technology environment, each event associated with a timestamp extracted from the portion of raw machine data associated with the event;
causing display of a plurality of events, of the accessed set of events as search results of the query;
receiving a first user selection of a particular event in the displayed plurality of events;
based on receiving the first user selection of the particular event, causing display of a field information panel that displays fields having corresponding values for the particular event, each field defined by an extraction rule that when applied extracts a portion of a character string that represents the portion of raw machine data of the particular event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string, the display of the field information panel being in the display of the plurality of events; and
based on receiving a second user selection of at least one of the fields displayed in the field information panel, executing an updated query that corresponds to the at least one of the fields, and causing an update to the displayed plurality of events to display a new set of the events that are search results of the updated query.
1 Assignment
0 Petitions
Accused Products
Abstract
An event limited field picker for a search user interface is described. In one or more implementations, a service may operate to collect and store data as events each of which includes a portion of the data correlated with a point in time. Clients may use a search user interface perform searches by input of search criteria. Responsive to receiving search criteria, the service may operate to apply a late binding schema to extract events that match the search criteria and provide search results for display via the search user interface. The search user interface exposes an event limited field picker operable to make selections of fields with respect to individual events in a view of the search results. In response to receiving an indication of a fields selected via the picker, visibility of selected fields may be updated to control which field and values are included in different views.
87 Citations
30 Claims
-
1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, comprising:
-
accessing a set of events in a data store in response to a query, each event including a portion of raw machine data that reflects the activity in the information technology environment and is produced by the component of the information technology environment, each event associated with a timestamp extracted from the portion of raw machine data associated with the event; causing display of a plurality of events, of the accessed set of events as search results of the query; receiving a first user selection of a particular event in the displayed plurality of events; based on receiving the first user selection of the particular event, causing display of a field information panel that displays fields having corresponding values for the particular event, each field defined by an extraction rule that when applied extracts a portion of a character string that represents the portion of raw machine data of the particular event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string, the display of the field information panel being in the display of the plurality of events; and based on receiving a second user selection of at least one of the fields displayed in the field information panel, executing an updated query that corresponds to the at least one of the fields, and causing an update to the displayed plurality of events to display a new set of the events that are search results of the updated query. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. One or more non-transitory computer-readable storage media comprising instructions that are stored thereon that, responsive to execution by a computing device, cause the computing device to perform operations for machine-data analysis of activity by a component in an information technology environment, the operations comprising:
-
accessing a set of events in a data store in response to a query, each event including a portion of raw machine data that reflects the activity in the information technology environment and is produced by the component of the information technology environment, each event associated with a timestamp extracted from the portion of raw machine data associated with the event; causing display of a plurality of events, of the accessed set of events as search results of the query; receiving a first user selection of a particular event in the displayed plurality of events; based on receiving the first user selection of the particular event, causing display of a field information panel that displays fields having corresponding values for the particular event, each field defined by an extraction rule that when applied extracts a portion of a character string that represents the portion of raw machine data of the particular event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string, the display of the field information panel being in the display of the plurality of events; and based on receiving a second user selection of at least one of the fields displayed in the field information panel, executing an updated query that corresponds to the at least one of the fields, and causing an update to the displayed plurality of events to display a new set of the events that are search results of the updated query. - View Dependent Claims (20, 21, 22, 23, 24)
-
-
25. A computer-implemented system comprising:
-
at least one processor; one or more non-transitory computer-readable media storing instructions that when executed via the at least one processor, causes the at least one processor to perform operations for machine-data analysis of activity by a component in an information technology environment, the operations including; accessing a set of events in a data store in response to a query, each event including a portion of raw machine data that reflects the activity in the information technology environment and is produced by the component of the information technology environment, each event associated with a timestamp extracted from the portion of raw machine data associated with the event; causing display of a plurality of events, of the accessed set of events as search results of the query; receiving a first user selection of a particular event in the displayed plurality of events; based on receiving the first user selection of the particular event, causing display of a field information panel that displays fields having corresponding values for the particular event, each field defined by an extraction rule that when applied extracts a portion of a character string that represents the portion of raw machine data of the particular event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string, the display of the field information panel being in the display of the plurality of events; and based on receiving a second user selection of at least one of the fields displayed in the field information panel, executing an updated query that corresponds to the at least one of the fields, and causing an update to the displayed plurality of events to display a new set of the events that are search results of the updated query. - View Dependent Claims (26, 27, 28, 29, 30)
-
Specification