Log data time stamp extraction and search on log data real-time monitoring environment
First Claim
Patent Images
1. A computer-implemented method, comprising:
- obtaining log data generated by at least one component in an information processing environment;
obtaining data that is not log data from a real-time monitoring environment;
identifying boundaries within the log data that separate the log data into sections, each section of log data reflecting activity in the information processing environment that occurred at a particular time;
for each section of log data,extracting a time stamp from the section, andstoring in a searchable time series data store at least a portion of log data in the section in association with the extracted time stamp for that section;
storing the data that is not log data in the searchable time series data store; and
executing a search on the log data and the data that is not log data in the searchable time series data store.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus consistent with the invention provide the ability to organize, index, search, and present time series data based on searches. Time series data are sequences of time stamped records occurring in one or more usually continuous streams, representing some type of activity. In one embodiment, time series data is stored as discrete events time stamps. A search is received and relevant event information is retrieved based in whole or in part on the time stamp, a keyword indexing mechanism, or statistical indices calculated at the time of the search.
278 Citations
30 Claims
-
1. A computer-implemented method, comprising:
-
obtaining log data generated by at least one component in an information processing environment; obtaining data that is not log data from a real-time monitoring environment; identifying boundaries within the log data that separate the log data into sections, each section of log data reflecting activity in the information processing environment that occurred at a particular time; for each section of log data, extracting a time stamp from the section, and storing in a searchable time series data store at least a portion of log data in the section in association with the extracted time stamp for that section; storing the data that is not log data in the searchable time series data store; and executing a search on the log data and the data that is not log data in the searchable time series data store. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24)
-
-
25. A system comprising:
-
a memory; and a processing device coupled with the memory to; obtain log data generated by at least one component in an information processing environment; obtain data that is not log data from a real-time monitoring environment; identify boundaries within the log data that separate the log data into sections, each section of log data reflecting activity in the information processing environment that occurred at a particular time; for each section of log data, extract a time stamp from the section, and store in a searchable time series data store at least a portion of log data in the section in association with the extracted time stamp for that section; store the data that is not log data in the searchable time series data store; and execute a search on the log data and the data that is not log data in the searchable time series data store. - View Dependent Claims (26, 27)
-
-
28. A non-transitory computer-readable medium encoding instructions thereon that, in response to execution by one or more processing devices, cause the one or more processing devices to:
-
obtain log data generated by at least one component in an information processing environment; obtain data that is not log data from a real-time monitoring environment; identify boundaries within the log data that separate the log data into sections, each section of log data reflecting activity in the information processing environment that occurred at a particular time; for each section of log data, extract a time stamp from the section, and store in a searchable time series data store at least a portion of log data in the section in association with the extracted time stamp for that section; store the data that is not log data in the searchable time series data store; and execute a search on the log data and the data that is not log data in the searchable time series data store. - View Dependent Claims (29, 30)
-
Specification