SEARCH-TIME FIELD EXTRACTION IN A DATA INTAKE AND QUERY SYSTEM

    公开(公告)号:US20230134578A1

    公开(公告)日:2023-05-04

    申请号:US18078876

    申请日:2022-12-09

    Applicant: Splunk Inc.

    Abstract: An improved data intake and query system that can perform and display ingest-time and search-time field extraction, redaction, copy, and/or categorization is described herein. As described herein, ingest-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by a log observer system of the data intake and query system on raw machine data as the raw machine data is ingested or received from a publisher. As described herein, search-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by the log observer system and/or other components of the improved data intake and query system on historical raw machine data that has already been ingested and indexed by the improved data intake and query system.

    EXECUTING ONE QUERY BASED ON RESULTS OF ANOTHER QUERY

    公开(公告)号:US20220188306A1

    公开(公告)日:2022-06-16

    申请号:US17686239

    申请日:2022-03-03

    Applicant: Splunk Inc.

    Abstract: Systems and methods are disclosed for performing multiple queries in a single graphical user interface (GUI) displayed in a client browser. The client browser causes the display of a first user interface field in a first area of the GUI, where the first user interface field can be used to enter or edit a first query. The client browser also causes first query results generated by a data intake and query system executing the first query to be displayed in the first area. The client browser further causes the display of a second user interface field in a second area of the GUI, where the second user interface field can be used to enter or edit a second query. The client browser also causes second query results generated by the data intake and query system executing the second query to be displayed in the second area.

    Generation of queries using non-textual input

    公开(公告)号:US12298981B1

    公开(公告)日:2025-05-13

    申请号:US18441788

    申请日:2024-02-14

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described for generation of a query using a non-textual input. For example, the query can be generated using a point and click input. A selection of a data source can be identified and an initial query can be automatically generated based on the selection of the data source. A graphical user interface can be displayed and populated with one or more selectable parameters based on the initial query. A selection of the one or more selectable parameters can be received as a non-textual input and a query can be automatically generated based on the selection. For example, a query for execution by a data intake and query system can be generated based on the selection. The query can be provided to the data intake and query system. The data intake and query system may then execute the query on a set of data.

    Generating metric data from log data using metricization rules

    公开(公告)号:US11714823B1

    公开(公告)日:2023-08-01

    申请号:US17246229

    申请日:2021-04-30

    Applicant: Splunk Inc.

    CPC classification number: G06F16/254 G06F16/24556

    Abstract: Systems and methods are described for generating metrics from real-time streaming log data. In order to generate the metrics, a metricization rule associated with the log data can be obtained. For example, the metricization rule may be obtained from a user. The metricization rule may include one or more field-value pairs that define how the metrics are generated from the log data. Preview metric data can be generated by applying the metricization rule to the log data. For example, the preview metric data may be displayed via a user interface. Further, the metricization rule can be accepted or approved by the user. Further, the additional log data can be ingested and based on determining that the metricization rule has been accepted, metric data may be generated by applying the metricization rule to the additional log data.

Patent Agency Ranking