Automatic generation of a field-extraction rule based on selections in a sample event
    41.
    发明授权
    Automatic generation of a field-extraction rule based on selections in a sample event 有权
    基于样本事件中的选择自动生成场提取规则

    公开(公告)号:US08909642B2

    公开(公告)日:2014-12-09

    申请号:US13748306

    申请日:2013-01-23

    申请人: Splunk Inc.

    IPC分类号: G06F17/30

    CPC分类号: G06F17/271

    摘要: Embodiments are directed towards automatically generating extraction rules for extracting fields from event records. An extraction rule application receives field data describing the fields to be extracted (including one or more examples) and a collection of event records that may be a representative sample set from a larger set of events records. The extraction rule application generates extraction rules based on the event records and the field data. These extraction rules may be ranked using a determined quality score. Quality scores for extraction rules may be determined based on various metrics related to the operation of the extraction rules and the resultant extracted values. Preferred extraction rules may be determined by ranking the extraction rules based on their quality scores. Also, natural language expressions may be used to create, edit, or modify extraction rules.

    摘要翻译: 实施例针对自动生成从事件记录中提取字段的提取规则。 提取规则应用程序接收描述要提取的字段(包括一个或多个示例)的字段数据以及可以是来自较大事件记录集合的代表性样本集合的事件记录的集合。 提取规则应用程序根据事件记录和字段数据生成提取规则。 这些提取规则可以使用确定的质量得分进行排名。 可以基于与提取规则的操作和所得到的提取值相关的各种度量来确定提取规则的质量分数。 可以通过基于它们的质量得分对提取规则进行排名来确定优选的提取规则。 此外,自然语言表达式可用于创建,编辑或修改提取规则。

    Indexing Preview
    42.
    发明申请
    Indexing Preview 有权
    索引预览

    公开(公告)号:US20140337354A1

    公开(公告)日:2014-11-13

    申请号:US14445001

    申请日:2014-07-28

    申请人: Splunk Inc.

    IPC分类号: G06F17/30 G06F3/0484

    摘要: Embodiments are directed towards previewing results generated from indexing data raw data before the corresponding index data is added to an index store. Raw data may be received from a preview data source. After an initial set of configuration information may be established, the preview data may be submitted to an index processing pipeline. A previewing application may generate preview results based on the preview index data and the configuration information. The preview results may enable previewing how the data is being processed by the indexing application. If the preview results are not acceptable, the configuration information may be modified. The preview application enables modification of the configuration information until the generated preview results may be acceptable. If the configuration information is acceptable, the preview data may be processed and indexed in one or more index stores.

    摘要翻译: 实施例针对在将对应的索引数据添加到索引存储之前预览从索引数据原始数据生成的结果。 可以从预览数据源接收原始数据。 在可以建立一组初始配置信息之后,可以将预览数据提交给索引处理流水线。 预览应用可以基于预览索引数据和配置信息生成预览结果。 预览结果可能可以预览索引应用程序如何处理数据。 如果预览结果不可接受,则可以修改配置信息。 预览应用程序可以修改配置信息,直到生成的预览结果可以接受。 如果配置信息是可接受的,则预览数据可以在一个或多个索引存储中被处理和索引。

    AUTOMATICALLY GENERATING REGULAR EXPRESSIONS FOR DATA FIELD EXTRACTIONS WITH NATURAL LANGUAGE EDITING
    43.
    发明申请
    AUTOMATICALLY GENERATING REGULAR EXPRESSIONS FOR DATA FIELD EXTRACTIONS WITH NATURAL LANGUAGE EDITING 有权
    用自然语言编辑自动生成数据字段提取的常规表达

    公开(公告)号:US20140207792A1

    公开(公告)日:2014-07-24

    申请号:US13748306

    申请日:2013-01-23

    申请人: SPLUNK INC.

    IPC分类号: G06F17/30

    CPC分类号: G06F17/271

    摘要: Embodiments are directed towards automatically generating extraction rules for extracting fields from event records. An extraction rule application receives field data describing the fields to be extracted (including one or more examples) and a collection of event records that may be a representative sample set from a larger set of events records. The extraction rule application generates extraction rules based on the event records and the field data. These extraction rules may be ranked using a determined quality score. Quality scores for extraction rules may be determined based on various metrics related to the operation of the extraction rules and the resultant extracted values. Preferred extraction rules may be determined by ranking the extraction rules based on their quality scores. Also, natural language expressions may be used to create, edit, or modify extraction rules.

    摘要翻译: 实施例针对自动生成从事件记录中提取字段的提取规则。 提取规则应用程序接收描述要提取的字段(包括一个或多个示例)的字段数据以及可以是来自较大事件记录集合的代表性样本集合的事件记录的集合。 提取规则应用程序根据事件记录和字段数据生成提取规则。 这些提取规则可以使用确定的质量得分进行排名。 可以基于与提取规则的操作和所得到的提取值相关的各种度量来确定提取规则的质量分数。 可以通过基于它们的质量得分对提取规则进行排名来确定优选的提取规则。 此外,自然语言表达式可用于创建,编辑或修改提取规则。