Suggested field extraction
First Claim
1. A computer-implemented method comprising:
- displaying, in a graphical interface, one or more events in a table format that includes one or more rows and each of the one or more rows includes one or more cells, wherein each of the one or more rows corresponds to one of the one or more events and at least one of the one or more cells of each row displays raw data that is associated with a corresponding event of the one or more events;
based on a first user selection of first one or more values included in a portion of the raw data that is displayed in a particular cell of a particular row corresponding to a particular event of one or more events, automatically determining an extraction rule that includes instructions to extract a field label-value pair from the portion of the raw data, wherein the field label-value pair includes a particular value of the selected first one or more values and a particular field label that indicates a location in the particular event that contains the particular value and the instructions of the extraction rule identifies, within the portion of the raw data, each of the particular value and the particular field label based on one or more demarcating characters included in the portion of the raw data;
causing display of an option corresponding to the determined extraction rule in the graphical interface; and
based on a second user selection of the option in the graphical interface, causing display of second one or more values of one or more additional field label-value pairs, wherein the one or more additional field label-value pairs are extracted from additional portions of the raw data that are associated with additional events of the one or more events using the extraction rule.
1 Assignment
0 Petitions
Accused Products
Abstract
A based on a selection by a user of first one or more values of one or more events displayed in a graphical interface, an extraction rule is automatically determined that is capable of extracting a field label-value pair at least partially within at least the selected one or more values. An option is displayed that correspond to the determined extraction rule in the graphical interface. Based on the user selecting the option in the graphical interface, display is caused of second one or more values of one or more field label-value pairs extracted from the one or more events using the extraction rule. The one or more events may be displayed in a table format, and the first one or more value may be selected by the user selecting one or more cells, columns, or text portions in the table format.
199 Citations
30 Claims
-
1. A computer-implemented method comprising:
-
displaying, in a graphical interface, one or more events in a table format that includes one or more rows and each of the one or more rows includes one or more cells, wherein each of the one or more rows corresponds to one of the one or more events and at least one of the one or more cells of each row displays raw data that is associated with a corresponding event of the one or more events; based on a first user selection of first one or more values included in a portion of the raw data that is displayed in a particular cell of a particular row corresponding to a particular event of one or more events, automatically determining an extraction rule that includes instructions to extract a field label-value pair from the portion of the raw data, wherein the field label-value pair includes a particular value of the selected first one or more values and a particular field label that indicates a location in the particular event that contains the particular value and the instructions of the extraction rule identifies, within the portion of the raw data, each of the particular value and the particular field label based on one or more demarcating characters included in the portion of the raw data; causing display of an option corresponding to the determined extraction rule in the graphical interface; and based on a second user selection of the option in the graphical interface, causing display of second one or more values of one or more additional field label-value pairs, wherein the one or more additional field label-value pairs are extracted from additional portions of the raw data that are associated with additional events of the one or more events using the extraction rule. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
one or more data processors; and one or more computer-readable storage media containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including; displaying, in a graphical interface, one or more events in a table format that includes one or more rows and each of the one or more rows includes one or more cells, wherein each of the one or more rows corresponds to one of the one or more events and at least one of the one or more cells of each row displays raw data that is associated with a corresponding event of the one or more events; based on a first user selection of first one or more values included in a portion of the raw data that is displayed in a particular cell of a particular row corresponding to a particular event of one or more events, automatically determining an extraction rule that includes instructions to extract a field label-value pair from the portion of the raw data, wherein the field label-value pair includes a particular value of the selected first one or more values and a particular field label that indicates a location in the particular event that contains the particular value and the instructions of the extraction rule identifies, within the portion of the raw data, each of the particular value and the particular field label based on one or more demarcating characters included in the portion of the raw data; causing display of an option corresponding to the determined extraction rule in the graphical interface; and based on a second user selection of the option in the graphical interface, causing display of second one or more values of one or more additional field label-value pairs, wherein the one or more additional field label-value pairs are extracted from additional portions of the raw data that are associated with additional events of the one or more events using the extraction rule. - View Dependent Claims (17, 18, 19, 20, 21)
-
-
22. One or more non-transitory computer-storage media storing computer-useable instructions that, when executed by a computing device, perform a method, the method comprising:
-
displaying, in a graphical interface, one or more events in a table format that includes one or more rows and each of the one or more rows includes one or more cells, wherein each of the one or more rows corresponds to one of the one or more events and at least one of the one or more cells of each row displays raw data that is associated with a corresponding event of the one or more events; based on a first user selection of first one or more values included in a portion of the raw data that is displayed in a particular cell of a particular row corresponding to a particular event of one or more events, automatically determining an extraction rule that includes instructions to extract a field label-value pair from the portion of the raw data, wherein the field label-value pair includes a particular value of the selected first one or more values and a particular field label that indicates a location in the particular event that contains the particular value and the instructions of the extraction rule identifies, within the portion of the raw data, each of the particular value and the particular field label based on one or more demarcating characters included in the portion of the raw data; causing display of an option corresponding to the determined extraction rule in the graphical interface; and based on a second user selection of the option in the graphical interface, causing display of second one or more values of one or more additional field label-value pairs, wherein the one or more additional field label-value pairs are extracted from additional portions of the raw data that are associated with additional events of the one or more events using the extraction rule. - View Dependent Claims (23, 24, 25, 26, 27, 28, 29, 30)
-
Specification