Invention Grant
- Patent Title: Feedback on inferred sourcetypes
-
Application No.: US16175642Application Date: 2018-10-30
-
Publication No.: US11748358B2Publication Date: 2023-09-05
- Inventor: Adam Oliner , Eric Sammer , Kristal Curtis , Nghi Nguyen
- Applicant: Splunk, Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Shook, Hardy & Bacon L.L.P.
- Main IPC: G06F16/245
- IPC: G06F16/245 ; G06F16/2455 ; G06F40/205 ; G06F16/248 ; G06N5/04

Abstract:
As described herein, a portion of machine data of a message may be analyzed to infer, using an inference model, a sourcetype of the message. The portion of machine data may be generated by one or more components in an information technology environment. Based on the inference, a set of extraction rules associated with the sourcetype may be selected. Each extraction rule may define criteria for identifying a sub-portion of text from the portion of machine data of the message to produce a value. The set of extraction rules may be applied to the portion of machine data of the message to produce a result set that indicates a number of values identified using the set of extraction rules. Based on the result set, at least one action may be performed on one or more of inference data associated with the inference model and one or more messages.
Information query