Clustering events while excluding extracted values

    公开(公告)号:US11657065B2

    公开(公告)日:2023-05-23

    申请号:US17158880

    申请日:2021-01-26

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/26

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    TRIGGERING ALERTS FROM SEARCHES ON EVENTS
    3.
    发明申请

    公开(公告)号:US20190179824A1

    公开(公告)日:2019-06-13

    申请号:US16260998

    申请日:2019-01-29

    Applicant: Splunk Inc.

    Abstract: Custom communication alert techniques are described. In one or more implementations, a triggering condition is detected by one or more computing devices that is found by searching data using one or more extraction rules of a late-binding schema. Responsive to the detection of the triggering condition of the alert, a communication is formed by the one or more computing devices that corresponds to the alert and that includes one or more tokens based on one or more values of the data taken from fields defined by the one or more extraction rules. The communication is caused to be transmitted by the one or more computing device via a network for receipt by at least one computing device of an intended recipient of the communication.

    CLUSTERING EVENTS BASED ON EXTRACTION RULES
    4.
    发明申请

    公开(公告)号:US20180089303A1

    公开(公告)日:2018-03-29

    申请号:US15276693

    申请日:2016-09-26

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/26

    Abstract: Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

    SEARCH INTERFACE WITH SEARCH QUERY HISTORY BASED FUNCTIONALITY

    公开(公告)号:US20170124220A1

    公开(公告)日:2017-05-04

    申请号:US14929150

    申请日:2015-10-30

    Applicant: SPLUNK INC.

    CPC classification number: G06F16/2425

    Abstract: In various embodiments, methods and systems for presenting a search interface with search query history based functionality is provided. A search query history store comprising search queries is accessed. The search query history store includes search queries executed in a search computing system. A search query comprises one or more commands. A plurality of search queries retrieved from the search query history store is displayed on the search interface using a placement style. A placement style, such as an indent style, provides a structure for separating and arranging commands of a plurality of search queries displayed. The search interface further provides for receiving a selection of at least a portion of a search query from the plurality of search queries to initiate actions or execute actions based on the selection. The search interface includes a search input interface, such as a search bar, where the selection of the portion of the search query is displayed based on a selected action.

    Field Value Search Drill Down
    6.
    发明申请
    Field Value Search Drill Down 审中-公开
    字段值搜索向下钻取

    公开(公告)号:US20160098485A1

    公开(公告)日:2016-04-07

    申请号:US14526406

    申请日:2014-10-28

    Applicant: Splunk Inc.

    Abstract: In embodiments of field value search drill down, a search system exposes a search interface that displays one or more events returned as a search result set. A field-value pair can be emphasized in the field-value pairs of an event displayed in the search interface, and a menu is displayed with search options that are selectable to operate on the emphasized field-value pair of the event. The menu includes the search options to add search criteria of the emphasized field-value pair to a search command in a search bar of the search interface, exclude the search criteria of the emphasized field-value pair from a search, or create a new data search based on the emphasized field-value pair. A selection of one of the search options in the menu can be received, and the search command in the search bar is updated based on the search option that is selected.

    Abstract translation: 在字段值搜索向下钻取的实施例中,搜索系统公开了显示作为搜索结果集返回的一个或多个事件的搜索界面。 可以在搜索界面中显示的事件的字段值对中强调字段值对,并且显示具有可选择以在事件的强调字段值对上操作的搜索选项的菜单。 该菜单包括搜索选项,以将搜索条件增加到搜索接口的搜索栏中的搜索命令,从搜索中排除强调字段值对的搜索条件,或创建新数据 基于强调的字段值对进行搜索。 可以接收菜单中的一个搜索选项的选择,并且基于所选择的搜索选项来更新搜索栏中的搜索命令。

    Statistics Value Chart Interface Row Mode Drill Down
    7.
    发明申请
    Statistics Value Chart Interface Row Mode Drill Down 审中-公开
    统计值图表接口行模式向下钻取

    公开(公告)号:US20160098409A1

    公开(公告)日:2016-04-07

    申请号:US14526430

    申请日:2014-10-28

    Applicant: Splunk Inc.

    Abstract: In embodiments of statistics value chart interface row mode drill down, a first interface is displayed in a table format that includes columns each with field values of an event field, and each column having a column heading of a different one of the event fields, and includes rows each with one or more of the field values, where each field value in a row is associated with a different one of the event fields, and each row includes an aggregated metric that represents a number of events having field-value pairs that match all of the one or more field values listed in a respective row and the corresponding event fields listed in the respective columns. A row can be emphasized in the first interface, and in response, a menu is displayed with selectable options to transition to a second interface that displays a listing of the events based on a selected one of the options.

    Abstract translation: 在统计值图表接口行方式向下钻取的实施例中,以表格格式显示第一接口,该格式包括各自具有事件字段的字段值的列,并且每列具有不同的事件字段的列标题,以及 包括每个具有一个或多个字段值的行,其中,行中的每个字段值与事件字段中的不同的一个相关联,并且每行包括表示具有匹配的字段值对的事件的数量的聚合度量 在相应行中列出的所有一个或多个字段值以及相应列中列出的相应事件字段。 在第一个界面中可以强调一行,作为响应,显示一个带有可选择选项的菜单,以转换到第二个界面,该界面基于选定的一个选项显示事件列表。

Patent Agency Ranking