Wizard for configuring a field extraction rule
First Claim
1. A computer-implemented method comprising:
- providing a wizard configured to guide through configuring a field extraction rule to extract values for fields from events of raw data, wherein the wizard is configured to;
identify a user selection of a source type categorizing a data source of the events;
identify a user selection of a first example event of the events from the data source;
cause display of a field selection interface comprising a first area displaying the first example event with markups indicating (i) user selected tokens from text within the first example event and (ii) correspondence with the fields;
configure the field extraction rule to extract the user selected tokens from the first example event as the values for the fields; and
cause display, on a second area of the field selection interface, of a set of the events from the data source and preview extracted values for the fields, corresponding to the user selected tokens, resulting from applying the field extraction rule to the set of the events.
1 Assignment
0 Petitions
Accused Products
Abstract
The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.
281 Citations
30 Claims
-
1. A computer-implemented method comprising:
providing a wizard configured to guide through configuring a field extraction rule to extract values for fields from events of raw data, wherein the wizard is configured to; identify a user selection of a source type categorizing a data source of the events; identify a user selection of a first example event of the events from the data source; cause display of a field selection interface comprising a first area displaying the first example event with markups indicating (i) user selected tokens from text within the first example event and (ii) correspondence with the fields; configure the field extraction rule to extract the user selected tokens from the first example event as the values for the fields; and cause display, on a second area of the field selection interface, of a set of the events from the data source and preview extracted values for the fields, corresponding to the user selected tokens, resulting from applying the field extraction rule to the set of the events. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
11. A system for configuring a field extraction rule, the system comprising:
-
one or more data processors; and one or more computer-readable storage media containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including; providing a wizard configured to guide through configuring a field extraction rule to extract values for fields from events of raw data, wherein the wizard is configured to; identify a user selection of a source type categorizing a data source of the events; identify a user selection of a first example event of the events from the data source; cause display of a field selection interface comprising a first area displaying the first example event with markups indicating (i) user selected tokens from text within the first example event and (ii) correspondence with the fields; configure the field extraction rule to extract the user selected tokens from the first example event as the values for the fields; and cause display, on a second area of the field selection interface, of a set of the events from the data source and preview extracted values for the fields, corresponding to the user selected tokens, resulting from applying the field extraction rule to the set of the events. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. One or more computer-storage media storing computer-executable instructions that, when executed by a computing device, perform a method for configuring a field extraction rule, the method comprising:
providing a wizard configured to guide through configuring a field extraction rule to extract values for fields from events of raw data, wherein the wizard is configured to; identify a user selection of a source type categorizing a data source of the events; identify a user selection of a first example event of the events from the data source; cause display of a field selection interface comprising a first area displaying the first example event with markups indicating (i) user selected tokens from text within the first example event and (ii) correspondence with the fields; configure the field extraction rule to extract the user selected tokens from the first example event as the values for the fields; and cause display, on a second area of the field selection interface, of a set of the events from the data source and preview extracted values for the fields, corresponding to the user selected tokens, resulting from applying the field extraction rule to the set of the events. - View Dependent Claims (22, 23, 24, 25, 26, 27, 28, 29, 30)
Specification