Collection query driven generation of inverted index for raw machine data

    公开(公告)号:US10061807B2

    公开(公告)日:2018-08-28

    申请号:US15421236

    申请日:2017-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide a method for generating an inverted index in accordance with a user generated collection query. The method comprises providing a field searchable data store that comprises a plurality of event records, each event record comprising a time-stamped portion of raw machine data. The method further comprises receiving a collection query that references a field name. Further, responsive to the collection query, an inverted index is generated by: a) determining an extraction rule associated with the field name; b) extracting a field value corresponding to the field name from one or more event records in the field searchable data store using the extraction rule; and c) populating the inverted index responsive to each extracted field value, wherein each entry comprises the field name, the corresponding field value and a reference value that identifies a location in the field searchable data store where an associated event record is stored.

    COLLECTION QUERY DRIVEN GENERATION OF INVERTED INDEX FOR RAW MACHINE DATA

    公开(公告)号:US20170139996A1

    公开(公告)日:2017-05-18

    申请号:US15421236

    申请日:2017-01-31

    Applicant: SPLUNK INC.

    Abstract: Embodiments of the present disclosure provide a method for generating an inverted index in accordance with a user generated collection query. The method comprises providing a field searchable data store that comprises a plurality of event records, each event record comprising a time-stamped portion of raw machine data. The method further comprises receiving a collection query that references a field name. Further, responsive to the collection query, an inverted index is generated by: a) determining an extraction rule associated with the field name; b) extracting a field value corresponding to the field name from one or more event records in the field searchable data store using the extraction rule; and c) populating the inverted index responsive to each extracted field value, wherein each entry comprises the field name, the corresponding field value and a reference value that identifies a location in the field searchable data store where an associated event record is stored

Patent Agency Ranking