IP Library Granted Patent US 11,106,691
Granted Patent B2
US 11,106,691 · App. 16/394,754 · Granted Aug 31, 2021

Automated extraction rule generation using a timestamp selector

Inventors: R. David Carasso (San Rafael, CA); Micah James Delfino (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/2477G06F16/9014G06F40/284
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,106,691
App. No.
16/394,754
Granted
Aug 31, 2021
Kind
B2
Abstract

Embodiments are directed towards a graphical user interface identify locations within event records with splittable timestamp information. A display of event records is provided using any of a variety of formats. A splittable timestamp selector allows a user to select one or more locations within event records as having time related information that may be split across the one or more locations, including, information based on date, time of day, day of the week, or other time information. Any of a plurality of mechanisms is used to associate the selected locations with the split timestamp information, including tags, labels, or header information within the event records. In other embodiments, a separate table, list, index, or the like may be generated that associates the selected locations with the split timestamp information. The split timestamp information may be used within extraction rules for selecting subsets or the event records.

Claims (98)

1. A method in a computing system, comprising:

causing display of a set of event records comprising machine data;

receiving a selection of a portion of an event record, wherein the selected portion of the event record comprises time information about time, day, or date that is selected via a timestamp selector being moved from an original location to a point proximate to the selected portion of the event record;

automatically generating an extraction rule that extracts the selected portion of the event record;

using the extraction rule, extracting the selected portion of the event record;

creating a timestamp using the extracted portion of the event record;

associating the timestamp with the event record; and

storing the timestamped event record in a data store.

2. The method of claim 1 , further comprising:

for each event record of the set of event records, using the extraction rule to extract a corresponding timestamp; and

storing the corresponding timestamps in the data store comprising a field-searchable data store.

3. The method of claim 1 , further comprising:

for an additional event record, using the extraction rule to extract a timestamp from the additional event record;

associating the extracted timestamp with the additional event record; and

selecting the additional event record if the associated timestamp satisfies a temporal criterion specified by a filter.

4. The method of claim 1 , further comprising:

causing the timestamp selector to be displayed concurrently with the set of event records.

5. The method of claim 1 , further comprising:

causing the timestamp selector to be displayed concurrently with the set of event records, and

receiving a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record, wherein the generating generates the extraction rule that extracts the selected additional portion of the event record along with the selected portion of the event record.

6. The method of claim 1 , further comprising:

causing to be displayed concurrently with the set of event records, in the original location, the timestamp selector, and

receiving a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record, wherein the generating generates extraction rule that extracts the selected additional portion of the event record along with the selected portion of the event record,

such that, after the selection of the portion of the event record and the selection of the additional portion of the event record are received, the timestamp selector is simultaneously displayed at both the point proximate to the selected portion of the event record and the point proximate to the additional portion of the event record.

7. The method of claim 1 , further comprising:

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds.

8. The method of claim 1 , further comprising:

causing to be displayed concurrently with the set of event records, in the original location, the timestamp selector, and

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds, the input representing manipulating the moved timestamp selector to select one of a plurality of predefined timestamp components available in association with the timestamp selector.

9. The method of claim 1 , further comprising:

causing to be displayed concurrently with the set of event records, in the original location, the timestamp selector, and

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds, the input representing manipulating the moved timestamp selector to select from a drop-down element of the timestamp selector one of a plurality of predefined timestamp components available in the drop-down element of the timestamp selector.

10. The method of claim 1 , further comprising:

storing the generated extraction rule.

11. The method of claim 1 wherein the set of event records is displayed across two or more columns, and wherein the received selection selects one of the columns to select a portion of the event record displayed in that column.

12. The method of claim 1 wherein creating the timestamp using the extracted portion of the event record comprises:

modifying the extracted portion of the event record; and

creating the timestamp to include the modified extracted portion.

13. The method of claim 1 further comprising:

receiving a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record,

receiving input specifying a first timestamp component to which the portion of the event record corresponds; and

receiving input specifying a second timestamp component to which the additional portion of the event record corresponds.

14. The method of claim 1 , wherein the event record comprises structured data or unstructured data.

15. A computing system, comprising:

a processor; and

computer storage memory having computer-executable instructions stored thereon which, when executed by the processor, configure the computing system to:

cause display of a set of event records comprising machine data;

receive a selection of a portion of an event record, wherein the selected portion of the event record comprises time information about time, day, or date that is selected via a timestamp selector being moved from an original location to a point proximate to the selected portion of the event record;

automatically generate an extraction rule that extracts the selected portion of the event record;

use the extraction rule, extracting the selected portion of the event record;

create a timestamp using the extracted portion of the event record;

associate the timestamp with the event record; and

store the timestamped event record in a data store.

16. The system of claim 15 , further comprising:

for each event record of the set of event records, use the extraction rule to extract a corresponding timestamp; and

store the corresponding timestamps in the data store comprising a field-searchable data store.

17. The system of claim 15 , further comprising:

for an additional event record, use the extraction rule to extract a timestamp from the additional event record;

associate the extracted timestamp with the additional event record; and

select the additional event record if the associated timestamp satisfies a temporal criterion specified by a filter.

18. The system of claim 15 , further comprising:

cause the timestamp selector to be displayed concurrently with the set of event records.

19. The system of claim 15 , further comprising:

cause the timestamp selector to be displayed concurrently with the set of event records, and

receive a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record, wherein the generating generates the extraction rule that extracts the selected additional portion of the event record along with the selected portion of the event record.

20. The system of claim 15 , further comprising:

cause to be displayed concurrently with the set of event records, in the original location, the timestamp selector, and

receive a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record, wherein the generating generates extraction rule that extracts the selected additional portion of the event record along with the selected portion of the event record,

such that, after the selection of the portion of the event record and the selection of the additional portion of the event record are received, the timestamp selector is simultaneously displayed at both the point proximate to the selected portion of the event record and the point proximate to the additional portion of the event record.

21. The system of claim 15 , further comprising:

receive from a user input specifying a timestamp component to which the selected portion of the event record corresponds.

22. One or more computer storage media having computer-executable instructions embodied thereon that, when executed by one or more processors, cause the one or more processors to perform a method, the method comprising:

causing display of a set of event records comprising machine data;

receiving a selection of a portion of an event record, wherein the selected portion of the event record comprises time information about time, day, or date that is selected via a timestamp selector being moved from an original location to a point proximate to the selected portion of the event record;

automatically generating an extraction rule that extracts the selected portion of the event record;

using the extraction rule, extracting the selected portion of the event record;

creating a timestamp using the extracted portion of the event record;

associating the timestamp with the event record; and

storing the timestamped event record in a data store.

23. The computer storage media of claim 22 , further comprising:

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds.

24. The computer storage media of claim 22 , further comprising:

causing the timestamp selector to be displayed concurrently with the set of event records, and

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds, the input representing manipulating the moved timestamp selector to select one of a plurality of predefined timestamp components available in association with the timestamp selector.

25. The computer storage media of claim 22 , further comprising:

causing the timestamp selector to be displayed concurrently with the set of event records, and

receiving from a user input specifying a timestamp component to which the selected portion of the event record corresponds, the input representing manipulating the moved timestamp selector to select from a drop-down element of the timestamp selector one of a plurality of predefined timestamp components available in the drop-down element of the timestamp selector.

26. The computer storage media of claim 22 , further comprising:

storing the generated extraction rule.

27. The computer storage media of claim 22 wherein the set of event records is displayed across two or more columns, and wherein the received selection selects one of the columns to select a portion of the event record displayed in that column.

28. The computer storage media of claim 22 wherein creating the timestamp using the extracted portion of the event record comprises:

modifying the extracted portion of the event record; and

creating the timestamp to include the modified extracted portion.

29. The computer storage media of claim 22 further comprising:

receiving a selection of an additional portion of the event record, the selection of the additional portion indicating moving the timestamp selector from the original location to a point proximate to the additional portion of the event record,

receiving input specifying a first timestamp component to which the portion of the event record corresponds; and

receiving input specifying a second timestamp component to which the additional portion of the event record corresponds.

30. The computer storage media of claim 22 , wherein the event record comprises structured data or unstructured data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2019
From: CARASSO, R. DAVID; DELFINO, MICAH JAMES
To: SPLUNK INC.
Reel/Frame 049138/0211 →
Continuity (3)
Continuation 15582599 · Apr 28, 2017
Continuation 13747177 · Jan 22, 2013
Related Publication 20190251086A1 · Aug 15, 2019