×

Index time, delimiter based extractions and previewing for use in indexing

  • US 9,922,037 B2
  • Filed: 01/30/2015
  • Issued: 03/20/2018
  • Est. Priority Date: 01/30/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • retrieving one or more events;

    causing display of a graphical user interface that displays one or more field delimiter options specifying one or more delimiters that indicate a boundary of a field value;

    in response to a selection of a field delimiter option of the one or more field delimiter options, parsing at least one of the one or more events to identify field values using the selected field delimiter option;

    causing display of the field values identified in the at least one of the one or more events as the parsing occurs;

    storing the selected field delimiter option and one or more associated field names in a configuration file, wherein the configuration file specifies configuration parameters for field extraction during raw data indexing;

    receiving raw data from a data source;

    parsing the raw data into a plurality of timestamped events, each timestamped event in the plurality of timestamped events comprising at least a portion of the parsed raw data;

    concurrent with parsing the raw data into a plurality of timestamped events, identifying a particular field in the timestamped events using the selected field delimiter obtained from the configuration file that is associated with the particular field; and

    storing a field value pair for each unique value extracted from the particular field in the timestamped events along with an associated field name obtained from the configuration file on at least one storage device.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×