×

Determining events associated with a value

  • US 10,579,648 B2
  • Filed: 04/29/2017
  • Issued: 03/03/2020
  • Est. Priority Date: 01/23/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • accessing a set of events in a field-searchable data store that acts as a persistent repository for the events that each include a portion of raw machine data in textual form being produced by a component within an information technology environment and reflecting activity within the information technology environment, wherein the field-searchable data store of events is field-searchable such that a plurality of search queries each containing at least one criterion for a field is executable against the events in the field-searchable data store to cause comparison between the at least one criterion and values extracted from the events by an extraction rule defining the field;

    applying an extraction rule, which specifies how to extract a subportion of text from a larger portion of text, to the portion of raw machine data in textual form in each event in the accessed set of events to extract a set of values;

    for a first unique extracted value and a second unique extracted value in the extracted set of values, determining a first count of a first unique extracted value in a field defined by the extraction rule and a second count of a second unique extracted value in the field defined by the extraction rule;

    causing display of a first display area that presents the first unique extracted value and the second unique extracted value concurrently with the corresponding first count of the first unique extracted value in the field defined by the extraction rule and the second count of the second unique extracted value in the field defined by the extraction rule; and

    causing display of a second display area that presents at least a portion of the events, wherein the first unique extracted value and the second unique extracted value are visually emphasized in the displayed events, wherein the method is performed by one or more computing devices.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×