×

Event limited field picker

  • US 9,922,099 B2
  • Filed: 10/30/2014
  • Issued: 03/20/2018
  • Est. Priority Date: 09/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for machine-data analysis of activity by a component in an information technology environment, comprising:

  • accessing a set of events in a data store in response to a query, each event including a portion of raw machine data that reflects the activity in the information technology environment and is produced by the component of the information technology environment, each event associated with a timestamp extracted from the portion of raw machine data associated with the event;

    causing display of a plurality of events, of the accessed set of events as search results of the query;

    receiving a first user selection of a particular event in the displayed plurality of events;

    based on receiving the first user selection of the particular event, causing display of a field information panel that displays fields having corresponding values for the particular event, each field defined by an extraction rule that when applied extracts a portion of a character string that represents the portion of raw machine data of the particular event by identifying a pattern in the character string to generate the corresponding value for the field from the portion of the character string, the display of the field information panel being in the display of the plurality of events; and

    based on receiving a second user selection of at least one of the fields displayed in the field information panel, executing an updated query that corresponds to the at least one of the fields, and causing an update to the displayed plurality of events to display a new set of the events that are search results of the updated query.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×