Wizard for creating a correlation search

US2016019316A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016019316-A1
Application numberUS-201414448081-A
CountryUS
Kind codeA1
Filing dateJul 31, 2014
Priority dateJul 21, 2014
Publication dateJan 21, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One or more processing devices provide a wizard for generating a correlation search, the wizard facilitating user input of (i) one or more search criteria for a search query of the correlation search, (ii) a triggering condition to be applied to a dataset produced by the search query, and (iii) one or more actions to be performed when the dataset produced by the search query satisfies the triggering condition, and causing generation of the correlation search based on the user input.

First claim

Opening claim text (preview).

1 . A method comprising: causing display of a sequence of graphical user interfaces for facilitating user input for generation of a correlation search, wherein the user input comprises (i) one or more search criteria for a search query of the correlation search, (ii) a triggering condition comprising criteria to evaluate a dataset that the search query produces when applied to a non-tabular data store the triggering condition causing execution of one or more actions when the triggering condition is satisfied, and (iii) the one or more actions that execute when the triggering condition is satisfied; causing generation of the correlation search before execution of the search query by storing in memory the search criteria for the search query, the triggering condition, and the one or more actions; wherein the sequence of graphical user interfaces for generating the correlation search comprises (i) a graphical user interface for selecting the non-tabular data store against which to run the search query to produce the dataset, (ii) a graphical user interface for receiving a time range, the time range defining a scope of data of the non-tabular data store to be searched using the search query, and (iii) a graphical user interface for defining the criteria of the triggering condition; and wherein the method is performed by one or more processing devices. 2 . The method of claim 1 , wherein causing generation of the correlation search comprises: receiving the one or more search criteria; causing display of the search query in the sequence of graphical user interfaces; receiving a user request to test an execution of the search query; causing the execution of the search query; and causing display of results from the search query. 3 . The method of claim 1 , further comprising: causing display in the sequence of graphical user interfaces of a plurality of statistics types that can be used for producing an aggregate on data; receiving through the sequence of graphical user interfaces input identifying one of the plurality of statistics types; receiving input identifying an evaluation of the aggregate produced by the statistics type; and wherein causing generation of the correlation search comprises including the evaluation of the aggregate produced by the statistics type in the search query. 4 . The method of claim 1 , further comprising: causing display in the sequence of graphical user interfaces of a plurality of statistics types that can be used for producing an aggregate on data; receiving through the sequence of graphical user interfaces input identifying one of the plurality of statistics types; receiving input identifying an evaluation of the aggregate produced by the statistics type; and wherein causing generation of the correlation search comprises including the evaluation of the aggregate produced by the statistics type in the triggering condition of the correlation search. 5 . The method of claim 1 , wherein causing generation of the correlation search comprises: receiving a user request to test an execution of the search query with the triggering condition; and obtaining, for presentation, the dataset produced based on the execution of the search query with the triggering condition. 6 . The method of claim 1 , wherein causing generation of the correlation search comprises: displaying in the sequence of graphical user interfaces options for the one or more actions to be performed when the dataset produced by search query satisfies the triggering condition; receiving input identifying the one or more actions to be performed; and associating the identified one or more actions with the triggering condition. 7 . The method of claim 1 , wherein causing generation of the correlation search comprises: causing the search query included in the correlation search to be displayed in the sequence of graphical user interfaces. 8 . The method of claim 1 , wherein the one or more actions comprise one or more of updating a display with an entry corresponding to satisfaction of the triggering condition, adjusting a score of an object to which data causing satisfaction of the triggering condition pertains, or sending a notification indicating satisfaction of the triggering condition. 9 . (canceled) 10 . The method of claim 1 , wherein the sequence of graphical user interfaces includes an indication of whether the search query parses successfully. 11 . The method of claim 1 , wherein the search query corresponds to a search language that uses a late binding schema. 12 . The method of claim 1 , further comprising causing execution of the search query against raw machine data. 13 . The method of claim 1 , further comprising causing execution of the search query against time-stamped events that each include a portion of raw machine data. 14 . The method of claim 1 , wherein a calculation of a statistics type is included in the search query. 15 . The method of claim 1 , wherein an evaluation of a calculation of a statistics type is included in the search query. 16 . The method of claim 1 , wherein the dataset satisfies the triggering condition each time the dataset includes an indicator that the search criteria of the search query are satisfied. 17 . The method of claim 1 , wherein the dataset includes a number of times the search criteria of the query are satisfied, and the dataset satisfies the triggering condition when the number of times exceeds a threshold. 18 . The method of claim 1 , wherein the dataset satisfies the triggering condition when an aggregated statistic pertaining to the dataset exceeds a threshold, is under a threshold, or is within a specified range. 19 . A system comprising: a memory; and a processing device coupled with the memory to: cause display of a sequence of graphical user interfaces for facilitating user input for generation of a correlation search, wherein the user input comprises (i) one or more search criteria for a search query of the correlation search, (ii) a triggering condition comprising criteria to evaluate a dataset that the search query produces when applied to a non-tabular data store, the triggering condition causing execution of one or more actions when the triggering condition is satisfied, and (iii) the one or more actions that execute when the triggering condition is satisfied; cause generation of the correlation search before execution of the search query by storing in memory the search criteria for the search query, the triggering condition, and the one or more actions; and wherein the sequence of graphical user interfaces for generating the correlation search comprises (i) a graphical user interface for selecting the non-tabular data store against which to run the search query to produce the dataset, (ii) a graphical user interface for receiving a time range, the time range defining a scope of data of the non-tabular data store to be searched using the search query, and (iii) a graphical user interface for defining the criteria of the triggering condition. 20 . The system of claim 19 , wherein to cause generation of the correlation search comprises: receiving the one or more search criteria; causing display of the search query in the sequence of graphical user interfaces; receiving a user request to test an execution of the search query; causing the execution of the search query; and causing display of results from the search query. 21 . The system of claim 19 , wherein to cause generation of th

Assignees

Inventors

Classifications

  • Query processing · CPC title

  • Retrieval characterised by using metadata, e.g. metadata not derived from the content or metadata generated manually · CPC title

  • Clustering; Classification · CPC title

  • Query formulation · CPC title

  • Physics · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016019316A1 cover?
One or more processing devices provide a wizard for generating a correlation search, the wizard facilitating user input of (i) one or more search criteria for a search query of the correlation search, (ii) a triggering condition to be applied to a dataset produced by the search query, and (iii) one or more actions to be performed when the dataset produced by the search query satisfies the trigg…
Who is the assignee on this patent?
Splunk Inc
What technology area does this patent fall under?
Primary CPC classification G06F16/90335. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 21 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).