发明名称 Identifying events derived from machine data based on an extracted portion from a first event
摘要 Methods and apparatus consistent with the invention provide the ability to organize and build understandings of machine data generated by a variety of information-processing environments. Machine data is a product of information-processing systems (e.g., activity logs, configuration files, messages, database records) and represents the evidence of particular events that have taken place and been recorded in raw data format. In one embodiment, machine data is turned into a machine data web by organizing machine data into events and then linking events together.
申请公布号 US9292590(B2) 申请公布日期 2016.03.22
申请号 US201514691135 申请日期 2015.04.20
申请人 Splunk Inc. 发明人 Baum Michael Joseph;Carasso R. David;Das Robin Kumar;Hall Bradley;Murphy Brian Philip;Sorkin Stephen Phillip;Stechert Andre David;Swan Erik M.;Greene Rory;Mealy Nicholas Christian;Noren Christina Frances Regina
分类号 G06F17/40;G06F17/30;G06K9/62;G06F17/27;G06F11/34 主分类号 G06F17/40
代理机构 Wong & Rees LLP 代理人 Wong & Rees LLP ;Wong Kirk D.
主权项 1. A method, comprising: analyzing machine data stored in at least one storage device in order to segment the machine data into a plurality of events by determining beginning and ending of each event in the plurality of events in the machine data, each event in the plurality of events including some machine data from the stored machine data segmented for that event, the plurality of events including both events produced from a first data resource and events produced from a second data resource that is different from the first data resource and events data in one or more events produced from the fist data resource having a different data format than the machine data in one or more events produced from the second data resource; extracting a particular portion of machine data from an event in the plurality of events; identifying, in the plurality of events, one or more events that include the particular portion of machine data; wherein the method is performed by one or more computing devices.
地址 San Francisco CA US