Column-based table manipulation of event data
First Claim
1. A computer-implemented method comprising:
- causing display of a set of events that are search results of a search query represented as a search string that specifies a plurality of commands, each event corresponding to a portion of raw machine data associated with a timestamp, the display of the set of events being in a table format that includes;
a plurality of columns, each column comprising data items of an event attribute, the data items being of the set of events, wherein each column is selectable by a user; and
a plurality of rows forming cells with the plurality of columns, each cell comprising one or more of the data items of the event attribute of a corresponding column;
based on a user selection of one or more of the columns of the plurality of columns in the table format;
causing display of a list of options corresponding to the selected one or more columns; and
causing one or more commands to be added to the search query sequentially after the search string, wherein the one or more commands are based on an option that is selected from the list of options and the event attribute corresponding to the selected one or more columns.
1 Assignment
0 Petitions
Accused Products
Abstract
A search interface is displayed in a table format that includes a plurality of columns, each column including data items of an event attribute, the data items being of a set of events, each column being selectable by a user, and a plurality of rows forming cells with the one or more columns, each cell comprising one or more of the data items of the event attribute of a corresponding column. Based on the user selecting one or more of the columns, a list of options is displayed corresponding to the selected one or more columns, and one or more commands are added to a search query that corresponds to the set of events. The one or more commands are based on at least an option that is selected from the list of options and the event attribute of each of the selected one or more columns.
172 Citations
40 Claims
-
1. A computer-implemented method comprising:
-
causing display of a set of events that are search results of a search query represented as a search string that specifies a plurality of commands, each event corresponding to a portion of raw machine data associated with a timestamp, the display of the set of events being in a table format that includes; a plurality of columns, each column comprising data items of an event attribute, the data items being of the set of events, wherein each column is selectable by a user; and a plurality of rows forming cells with the plurality of columns, each cell comprising one or more of the data items of the event attribute of a corresponding column; based on a user selection of one or more of the columns of the plurality of columns in the table format; causing display of a list of options corresponding to the selected one or more columns; and causing one or more commands to be added to the search query sequentially after the search string, wherein the one or more commands are based on an option that is selected from the list of options and the event attribute corresponding to the selected one or more columns. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29)
-
-
30. A computer-implemented system for searching data, the system comprising:
-
one or more data processors; and one or more computer-readable storage media containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including; causing display of a set of events that are search results of a search query represented as a search string that specifies a plurality of commands, each event corresponding to a portion of raw machine data associated with a timestamp, the display of the set of events being in a table format that includes; a plurality of columns, each column comprising data items of an event attribute, the data items being of the set of events, wherein each column is selectable by a user; and a plurality of rows forming cells with the plurality of columns, each cell comprising one or more of the data items of the event attribute of a corresponding column; based on a user selection of one or more of the columns of the plurality of columns in the table format; causing display of a list of options corresponding to the selected one or more columns; and causing one or more commands to be added to the search query sequentially after the search string, wherein the one or more commands are based on an option that is selected from the list of options and the event attribute corresponding to the selected one or more columns. - View Dependent Claims (31, 32, 33)
-
-
34. One or more non-transitory computer-storage media storing computer-useable instructions that, when executed by at least one computing device, cause the at least one computing device to perform a method, the method comprising:
-
causing display of a set of events that are search results of a search query represented as a search string that specifies a plurality of commands, each event corresponding to a portion of raw machine data associated with a timestamp, the display of the set of events being in a table format that includes; a plurality of columns, each column comprising data items of an event attribute, the data items being of the set of events, wherein each column is selectable by a user; and a plurality of rows forming cells with the plurality of columns, each cell comprising one or more of the data items of the event attribute of a corresponding column; based on a user selection of one or more of the columns of the plurality of columns in the table format; causing display of a list of options corresponding to the selected one or more columns; and causing one or more commands to be added to the search query sequentially after the search string, wherein the one or more commands are based on an option that is selected from the list of options and the event attribute corresponding to the selected one or more columns. - View Dependent Claims (35, 36, 37, 38, 39, 40)
-
Specification