×

Time stamp creation for event data

DC
  • US 10,255,312 B2
  • Filed: 10/31/2016
  • Issued: 04/09/2019
  • Est. Priority Date: 10/05/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for improving machine data analysis, comprising:

  • creating a set of searchable events by segmenting raw time series machine data received from at least one data source in an information technology environment into searchable events, the raw time series machine data reflecting activity in the information technology environment, each searchable event including at least a portion of the segmented raw time series machine data thereby allowing application of time-based search phrases across at least a portion of events in the set of searchable events to search the segmented raw time series machine data in the at least a portion of the events;

    detecting whether time information is present in the raw time series machine data of an event in the set of searchable events;

    in response to detecting that the time information is present in the event;

    extracting the time information from the raw time series machine data of the event;

    determining a time zone in the extracted time information;

    generating an offset by normalizing the extracted time information using the determined time zone;

    generating a time stamp based on the offset; and

    associating the generated time stamp with the event, thereby enabling the event to be searched using the generated time stamp;

    in response to detecting that the time information is not present in the event;

    calculating a time stamp for the event using one or more stored time stamps, wherein the one or more stored time stamps are time stamps stored from one or more earlier processed events selected on a periodic basis in order to facilitate time stamp creation; and

    associating the calculated time stamp with the event, thereby enabling the event to be searched using the created time stamp;

    wherein the method is performed by one or more computing devices.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×