Graphical user interface for parsing events using a designated field delimiter

    公开(公告)号:US11604763B2

    公开(公告)日:2023-03-14

    申请号:US17589799

    申请日:2022-01-31

    Applicant: Splunk Inc.

    Inventor: Jesse Miller

    Abstract: A graphical user interface allows a customer to specify delimiters and/or patterns that occur in event data and indicate the presence of a particular field. The graphical user interface applies a customer's delimiter specifications directly to event data and displays the resulting event data in real time. Delimiter specifications may be saved as configuration settings and systems in a distributed setting may use the delimiter specifications to extract field values as the systems process raw data into event data. Extracted field values may be used to accelerate search queries that a system receives.

    Providing extraction results for a particular field

    公开(公告)号:US11423216B2

    公开(公告)日:2022-08-23

    申请号:US17169254

    申请日:2021-02-05

    Applicant: SPLUNK Inc.

    Abstract: The technology disclosed relates to formulating and refining field extraction rules that are used at query time on raw data with a late-binding schema. The field extraction rules identify portions of the raw data, as well as their data types and hierarchical relationships. These extraction rules are executed against very large data sets not organized into relational structures that have not been processed by standard extraction or transformation methods. By using sample events, a focus on primary and secondary example events help formulate either a single extraction rule spanning multiple data formats, or multiple rules directed to distinct formats. Selection tools mark up the example events to indicate positive examples for the extraction rules, and to identify negative examples to avoid mistaken value selection. The extraction rules can be saved for query-time use, and can be incorporated into a data model for sets and subsets of event data.

    Data summary view with filtering
    46.
    发明授权

    公开(公告)号:US10204093B2

    公开(公告)日:2019-02-12

    申请号:US14815932

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: In some embodiments, a method may include display of a data summary view of a set of events that correspond to query results of a query. Each event of the set of events may include data items of a plurality of event attributes. In embodiments, the data summary view can include various summary reports. Each summary report can include summary entries and a summary graph that each present a summary of data items of a selected event attribute, of the plurality of event attributes. At least one summary report can include summary entries that are selectable by a user. The method may further include filtering the set of event, in response to, and based on, selection of one or more of the selectable summary entries by the user and updating of at least the first and second summary graphs to correspond to the filtered set of events.

    Data summary view
    47.
    发明授权

    公开(公告)号:US10185708B2

    公开(公告)日:2019-01-22

    申请号:US14815928

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present invention provide methods, computer-readable media, and systems directed at providing a data summary view. In some embodiments, a method may include receiving a request to display a data summary view of search results of a search query. The request may be received while the search results are displayed in a table format. The method may further include causing display of the data summary view. The data summary view can include a summary report for a selected event attribute of a plurality of event attributes that are represented in the table format. The summary report can include summary entries that present a summary of data items of the selected event attribute and a summary graph of the data items. The summary graph may depict a distribution of at least a subset of the data items of the selected event attribute over a period of time.

    Source type management
    48.
    发明授权

    公开(公告)号:US10037331B2

    公开(公告)日:2018-07-31

    申请号:US14611010

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: A data intake and query system provides interfaces that enable users to configure source type definitions used by the system. A data intake and query system generally refers to a system for collecting and analyzing data including machine-generated data. Such a system may be configured to consume many different types of machine data generated by any number of different data sources including various servers, network devices, applications, etc. At a high level, a source type definition comprises one or more properties that define how various components of a data intake and query system collect, index, store, search and otherwise interact with particular types of data consumed by the system. The interfaces provided by the system generally comprise one or more interface components for configuring various attributes of a source type definition.

    RUNTIME PERMISSIONS OF QUERIES
    50.
    发明申请
    RUNTIME PERMISSIONS OF QUERIES 审中-公开
    QUY的允许时间

    公开(公告)号:US20160224631A1

    公开(公告)日:2016-08-04

    申请号:US14815929

    申请日:2015-07-31

    Applicant: SPLUNK INC.

    Abstract: A method includes assigning an access permission of a first user to a query object that represents a first query, the access permission granting are first user access rights to one or more data sources of the first query, the access permission being assigned as a runtime permission of the first query, granting a request from a second user to execute a second query, the first query being a subquery of the second query, and allowing the second user to execute the first query on the one or more data sources of the first query using the runtime permission assigned to the first query in executing the second query using the first query as the subquery.

    Abstract translation: 一种方法包括将第一用户的访问许可分配给表示第一查询的查询对象,访问许可授予是对第一查询的一个或多个数据源的第一用户访问权限,访问许可被分配为运行时权限 所述第一查询授予来自第二用户的请求以执行第二查询,所述第一查询是所述第二查询的子查询,并且允许所述第二用户对所述第一查询的所述一个或多个数据源执行所述第一查询 使用第一个查询作为子查询执行第二个查询时分配给第一个查询的运行时权限。

Patent Agency Ranking