×

Collection query driven generation of summarization information for raw machine data

  • US 10,387,396 B2
  • Filed: 09/15/2017
  • Issued: 08/20/2019
  • Est. Priority Date: 01/31/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • providing a field searchable data store comprising a plurality of partitions of field searchable, time stamped event records, each event record comprising a time-stamped portion of raw machine data;

    receiving a collection query that references a field name, wherein the field name corresponds to at least one field value, and wherein the collection query comprises commands to generate summarization information for one or more field names included therein;

    responsive to the collection query, generating a respective summarization table for each partition of field searchable, time stamped event records by;

    forwarding the collection query to an indexer, wherein the indexer comprises one or more partitions of field searchable, time stamped event records of the plurality of partitions;

    determining partitions of field searchable, time stamped event records responsive to the collection query;

    determining an extraction rule associated with the field name, wherein the extraction rule comprises instructions applied to identify and extract a field value associated with the field name;

    extracting the field value corresponding to the field name from one or more event records in responsive partitions using the extraction rule; and

    populating the respective summarization table responsive to each extracted field value, wherein each entry comprises the field name, the corresponding field value and a posting value that identifies a location in a corresponding partition where an associated event record is storedreceiving a first incoming search query from a search head;

    generating a partial result to the first incoming search query using summarization tables generated corresponding to each partition of field searchable, time stamped event records; and

    generating a result set responsive to the first incoming search query, wherein the result set is generated using the partial result, wherein the search head is operable to combine partial result sets returned from each partition of field searchable, time stamped event records to generate the result set.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×