CLUSTERING EVENTS WHILE EXCLUDING EXTRACTED VALUES

    公开(公告)号:US20210149912A1

    公开(公告)日:2021-05-20

    申请号:US17158880

    申请日:2021-01-26

    Applicant: SPLUNK INC.

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    Syntax templates for coding
    12.
    发明授权

    公开(公告)号:US10528607B2

    公开(公告)日:2020-01-07

    申请号:US15223598

    申请日:2016-07-29

    Applicant: SPLUNK INC.

    Abstract: Various approaches for automating code completion are described herein. More particularly, approaches are provided that automatically generate coded commands of a coding language (i.e., code) that function and operate as intended by the user. As the user codes the commands, such approaches assist a user in various ways. For example, such automated assistance provides the user an understanding of various coding options available in the coding language. The assistance also enforces the proper employment of the available coding options, as well as provides an understanding of the functionality of the generated code. Automating code completion provides various benefits to the user, such as decreasing the time the user spends generating code, increasing the likelihood that the generated code functions and operates on a system as intended, and reducing the number of code versions required to be executed or compiled by the system.

    Event Segment Search Drill Down
    13.
    发明申请
    Event Segment Search Drill Down 审中-公开
    事件段搜索向下钻取

    公开(公告)号:US20160098463A1

    公开(公告)日:2016-04-07

    申请号:US14526380

    申请日:2014-10-28

    Applicant: Splunk Inc.

    Abstract: In embodiments of event segment search drill down, a search system exposes a search interface that displays multiple events returned as a search result set. A segment can be emphasized in event raw data of an event that is one of multiple events displayed in the search interface, and a menu is displayed with search options that are selectable to operate on the emphasized segment. The menu includes the search options to add the emphasized segment as a keyword to a search command in a search bar of the search interface, exclude the keyword that represents the emphasized segment from a search, or create a new data search based on the highlighted segment. A selection of one of the search options in the menu can be received, and the search command in the search bar is updated based on the search option that is selected.

    Abstract translation: 在事件段搜索向下钻取的实施例中,搜索系统公开了显示作为搜索结果集返回的多个事件的搜索界面。 可以在事件的原始数据中突出显示分段,该事件是在搜索界面中显示的多个事件中的一个,并且显示具有可选择以在被强调的段上操作的搜索选项的菜单。 该菜单包括搜索选项,将强调段作为关键字添加到搜索接口的搜索栏中的搜索命令,从搜索中排除表示强调段的关键字,或者基于突出显示的段创建新的数据搜索 。 可以接收菜单中的一个搜索选项的选择,并且基于所选择的搜索选项来更新搜索栏中的搜索命令。

    Custom Communication Alerts
    14.
    发明申请
    Custom Communication Alerts 审中-公开
    自定义通信警报

    公开(公告)号:US20160098402A1

    公开(公告)日:2016-04-07

    申请号:US14528905

    申请日:2014-10-30

    Applicant: Splunk Inc.

    Abstract: Custom communication alert techniques are described. In one or more implementations, a triggering condition is detected by one or more computing devices that is found by searching data using one or more extraction rules of a late-binding schema. Responsive to the detection of the triggering condition of the alert, a communication is formed by the one or more computing devices that corresponds to the alert and that includes one or more tokens based on one or more values of the data taken from fields defined by the one or more extraction rules. The communication is caused to be transmitted by the one or more computing device via a network for receipt by at least one computing device of an intended recipient of the communication.

    Abstract translation: 描述自定义通信警报技术。 在一个或多个实现中,通过使用后期绑定模式的一个或多个提取规则通过搜索数据而发现的一个或多个计算设备来检测触发条件。 响应于警报的触发条件的检测,由与警报对应的一个或多个计算设备形成通信,并且基于从由所述警报定义的字段取得的数据的一个或多个值来包括一个或多个令牌 一个或多个提取规则。 该通信被一个或多个计算设备经由网络发送,以由通信的预期接收者的至少一个计算设备接收。

    Statistics Value Chart Interface Cell Mode Drill Down
    15.
    发明申请
    Statistics Value Chart Interface Cell Mode Drill Down 审中-公开
    统计值图表界面单元格模式向下钻取

    公开(公告)号:US20160098385A1

    公开(公告)日:2016-04-07

    申请号:US14526468

    申请日:2014-10-28

    Applicant: Splunk Inc.

    Abstract: In embodiments of statistics value chart interface cell mode drill down, a first interface displays in a table format that includes columns each with field values of an event field, and each column having a column heading of a different one of the event fields, and includes rows each with one or more of the field values, each field value in a row associated with a different one of the event fields, and having an aggregated metric that represents a number of events with field-value pairs that match all of the field values listed in a respective row and the corresponding event fields listed in the respective columns. A cell can be emphasized that includes one of the field values in a row that corresponds to one of the different event fields in a column, and in response, a menu displays options to transition to a second interface.

    Abstract translation: 在统计值图表接口单元模式下拉的实施例中,第一界面以表格格式显示,其格式包括各自具有事件字段的字段值的列,并且每列具有不同的事件字段的列标题,并且包括 每个具有一个或多个字段值的行,与行事件字段中的不同一个相关联的行中的每个字段值,并且具有表示具有与所有字段值匹配的字段值对的事件的数量的聚合度量 列在相应的行中以及相应列中列出的相应事件字段。 可以强调一个单元格,其中包括与列中的不同事件字段之一相对应的行中的一个字段值,并且作为响应,菜单显示用于转换到第二接口的选项。

    Supplementing extraction rules based on event clustering

    公开(公告)号:US12099517B1

    公开(公告)日:2024-09-24

    申请号:US18300936

    申请日:2023-04-14

    Applicant: Splunk Inc.

    CPC classification number: G06F16/26

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    Search interface with search query history based functionality

    公开(公告)号:US10387408B2

    公开(公告)日:2019-08-20

    申请号:US14929150

    申请日:2015-10-30

    Applicant: SPLUNK INC.

    Abstract: In various embodiments, methods and systems for presenting a search interface with search query history based functionality is provided. A search query history store comprising search queries is accessed. The search query history store includes search queries executed in a search computing system. A search query comprises one or more commands. A plurality of search queries retrieved from the search query history store is displayed on the search interface using a placement style. A placement style, such as an indent style, provides a structure for separating and arranging commands of a plurality of search queries displayed. The search interface further provides for receiving a selection of at least a portion of a search query from the plurality of search queries to initiate actions or execute actions based on the selection. The search interface includes a search input interface, such as a search bar, where the selection of the portion of the search query is displayed based on a selected action.

Patent Agency Ranking