主权项 |
1. A method, comprising:
selecting a portion of raw data from at least one data source; causing display of one or more selectable parsing rules; receiving a first user input selecting a parsing rule among the one or more selectable parsing rules, the parsing rule to be applied to the selected portion of raw data; parsing the selected portion of raw data into a set of searchable, time-stamped events using the parsing rule, each searchable, time-stamped event in the set of searchable, time-stamped events including raw data from the selected portion of raw data; causing display of at least a portion of the set of searchable, time-stamped events; receiving a second user input indicating a user preference to use a different parsing rule; selecting a second parsing rule; processing raw data from the at least one data source using the second parsing rule, to create searchable, time-stamped events, the processed raw data including the selected portion of raw data and additional raw data different from the selected portion of raw data; storing the searchable, time-stamped events in an index store among a plurality of index stores, wherein the searchable, time-stamped events in the index store are used to service search queries received from a search engine; wherein the method is performed by one or more computing devices. |