Invention Grant
- Patent Title: Search-time field extraction in a data intake and query system
-
Application No.: US17246154Application Date: 2021-04-30
-
Publication No.: US11526504B1Publication Date: 2022-12-13
- Inventor: Amin Moshgabadi , Baibhav Gautam , Hema Krishnamurthy Mohan , Joshua Vertes
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Knobbe Martens Olson & Bear LLP
- Main IPC: G06F16/00
- IPC: G06F16/00 ; G06F16/242 ; G06F3/0482 ; G06F16/25 ; G06F16/245

Abstract:
An improved data intake and query system that can perform and display ingest-time and search-time field extraction, redaction, copy, and/or categorization is described herein. As described herein, ingest-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by a log observer system of the data intake and query system on raw machine data as the raw machine data is ingested or received from a publisher. As described herein, search-time field extraction, redaction, copy, and/or categorization may refer to field or field value extraction, redaction, copy, and/or categorization that is performed by the log observer system and/or other components of the improved data intake and query system on historical raw machine data that has already been ingested and indexed by the improved data intake and query system.
Information query