×

Sampling events for rule creation with process selection

  • US 9,582,557 B2
  • Filed: 04/29/2015
  • Issued: 02/28/2017
  • Est. Priority Date: 01/22/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • accessing a plurality of events, wherein each event in the plurality of events includes a portion of raw machine data;

    receiving, from a user, a selection of one or more processes for identifying which events to include in a set;

    wherein the one or more processes selected by the user include at least one of the following;

    a diverse event-identification process, an outlier event-identification process, a random event identification process, an earliest event-identification process, and a latest event-identification process;

    for each selected process, identifying events for inclusion in the set using the process;

    causing display of one or more events in the set of events in a graphical user interface that enables development of a field-extraction rule that specifies how to extract, from the raw machine data included in each of the one or more events, a value for a field that is defined for each of the one or more events, wherein each of the one or more events is searchable using the field; and

    wherein identifying events for inclusion in the set includes using a process to identify diverse events, and wherein the process to identify diverse events includes;

    performing a clustering algorithm on a group of events from the plurality of events to form a plurality of clusters, the clustering algorithm placing two events into a same cluster based on similarities in the machine data included in each of the two events; and

    selecting events from one or more most populous clusters in the plurality of clusters.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×