×

Collection query driven generation of inverted index for raw machine data

  • US 10,061,807 B2
  • Filed: 01/31/2017
  • Issued: 08/28/2018
  • Est. Priority Date: 05/18/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for searching data, the method comprising:

  • providing a field searchable data store comprising a plurality of event records, each event record comprising a time-stamped portion of raw machine data;

    receiving a query that comprises a plurality of parts including a collection query, wherein the collection query references a field name, wherein the field name is associated with a location in an event record containing a field value associated with the field name, wherein the collection query is user initiated, and wherein a first part in the plurality of parts is associated with the collection query and executable to generate an inverted index, and wherein one or more additional parts in the plurality of parts are executable for performing additional processing of the data in the inverted index;

    responsive to the collection query, generating an inverted index by;

    determining an extraction rule associated with the field name;

    extracting a field value corresponding to the field name from one or more event records in the field searchable data store using the extraction rule; and

    populating the inverted index responsive to each extracted field value, wherein each entry comprises the field name, the corresponding field value and a reference value that identifies a location in the field searchable data store where an associated event record is stored; and

    performing the additional processing of the data in the inverted index in accordance with the one or more additional parts in the plurality of parts of the query.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×