CLUSTERING OF STRUCTURED LOG DATA BY KEY-VALUES

    公开(公告)号:US20210373990A1

    公开(公告)日:2021-12-02

    申请号:US17009649

    申请日:2020-09-01

    申请人: Sumo Logic, Inc.

    IPC分类号: G06F11/07 G06F16/35

    摘要: Clustering structured log data by key-values includes receiving, via a user interface, a request to apply an operator to cluster a set of raw log messages according to values for a set of keys associated with the request. At least a portion of each raw log message comprises structured machine data including a set of key-value pairs. It further includes receiving a raw log message in the set of raw log messages. It further includes determining whether to include the raw log message in a cluster based at least in part on an evaluation of values in the structured machine data of the raw log message for the set of keys associated with the request. The cluster is included in a plurality of clusters. Each cluster in the plurality is associated with a different combination of values for the set of keys associated with the request. It further includes providing, via the user interface, information associated with the cluster

    CLUSTERING OF STRUCTURED LOG DATA BY KEY SCHEMA

    公开(公告)号:US20210374153A1

    公开(公告)日:2021-12-02

    申请号:US17009643

    申请日:2020-09-01

    申请人: Sumo Logic, Inc.

    IPC分类号: G06F16/25 G06F16/21

    摘要: Clustering structured log data by key schema includes receiving a raw log message. At least a portion of the raw log message comprises structured machine data including a set of key-value pairs. It further includes receiving a map of keys to values. It further includes using the received map of keys to values to determine a key schema of the structured machine data. The key schema is associated with a corresponding cluster. It further includes associating the raw log message with the cluster corresponding to the determined key schema.