Identifying events using informational fields
    2.
    发明授权
    Identifying events using informational fields 有权
    使用信息字段识别事件

    公开(公告)号:US09146962B1

    公开(公告)日:2015-09-29

    申请号:US14611213

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: A computer system determines if events in a machine data store satisfy event selection criteria, the event selection criteria including a first field-value pair. To determine if one of the events satisfies the event selection criteria, the computer system compares the first field-value pair of the event selection criteria with a second field-value pair from an entity definition associated with the event by using a third field-value pair from data corresponding to the event in the machine data store.

    Abstract translation: 计算机系统确定机器数据存储器中的事件是否满足事件选择标准,事件选择标准包括第一字段值对。 为了确定事件中的一个是否满足事件选择标准,计算机系统通过使用第三字段值将事件选择标准的第一字段值对与来自与事件相关联的实体定义的第二字段值对进行比较 从与机器数据存储中的事件相对应的数据对。

    CREATING AN ENTITY DEFINITION FROM A SEARCH RESULT SET

    公开(公告)号:US20170322985A1

    公开(公告)日:2017-11-09

    申请号:US15662206

    申请日:2017-07-27

    Applicant: Splunk Inc.

    Abstract: A processing device performs a search query to produce a search result set having entries having data items. A table, having rows and columns, is displayed in a user interface. Each data item of a particular entry appears in a respective column of the same row of the table. Each column may correspond to the ordinal position of its respective data item. User input is received designating, for each respective column, a field name and an entity definition component type to which the respective column pertains, and stores for each data item of the particular entry an element value of an entity definition. The element has the element name designated for the respective column in which the data item appeared, and is associated with an entity definition component having the type designated for the respective column in which the data item appeared.

    IDENTIFYING EVENTS USING INFORMATIONAL FIELDS
    8.
    发明申请
    IDENTIFYING EVENTS USING INFORMATIONAL FIELDS 审中-公开
    使用信息字段识别事件

    公开(公告)号:US20160103862A1

    公开(公告)日:2016-04-14

    申请号:US14866970

    申请日:2015-09-27

    Applicant: Splunk, Inc.

    Abstract: A computer system determines if events in a machine data store satisfy event selection criteria. The events may pertain to a service entity represented by a stored entity definition. The entity definition may include information to identify the events from the machine data. Other informational fields in the entity definition may be effectively attributed to the identified events and take part in satisfying the event selection criteria.

    Abstract translation: 计算机系统确定机器数据存储器中的事件是否满足事件选择标准。 事件可能涉及由存储的实体定义表示的服务实体。 实体定义可以包括用于从机器数据识别事件的信息。 实体定义中的其他信息字段可以有效地归因于所识别的事件并且参与满足事件选择标准。

    Creating entity definition from a search result set
    9.
    发明授权
    Creating entity definition from a search result set 有权
    从搜索结果集创建实体定义

    公开(公告)号:US09146954B1

    公开(公告)日:2015-09-29

    申请号:US14611195

    申请日:2015-01-31

    Applicant: Splunk Inc.

    Abstract: A processing device performs a search query to produce a search result set having entries having data items. Each data item has an ordinal position. A table, having rows and columns, is displayed in a graphical user interface. Each data item of a particular entry appears in a respective column of the same row of the table. Each column corresponds to the ordinal position of its respective data item. User input is received designating, for each respective column, a field name and an entity definition component type to which the respective column pertains, and stores for each data item of the particular entry an element value of an entity definition. The element has the element name designated for the respective column in which the data item appeared, and is associated with an entity definition component having the type designated for the respective column in which the data item appeared.

    Abstract translation: 处理装置执行搜索查询以产生具有具有数据项的条目的搜索结果集。 每个数据项都有一个序数位置。 具有行和列的表格显示在图形用户界面中。 特定条目的每个数据项出现在表的同一行的相应列中。 每列对应于其相应数据项的序数位置。 接收到用户输入,为每个相应列指定相应列所属的字段名称和实体定义组件类型,并且为特定条目的每个数据项存储实体定义的元素值。 元素具有为数据项出现的相应列指定的元素名称,并且与具有指定数据项出现的相应列的类型的实体定义组件相关联。

Patent Agency Ranking