IP Library Granted Patent US 11,614,856
Granted Patent B2
US 11,614,856 · App. 17/029,773 · Granted Mar 28, 2023

Row-based event subset display based on field metrics

Inventors: Cory Eugene Burke (San Bruno, CA); Katherine Kyle Feeney (Oakland, CA); Divanny I. Lamas (San Francisco, CA); Marc Vincent Robichaud (San Francisco, CA); Matthew G. Ness (Oakland, CA); Clara E. Lee (Pacifica, CA)
Assignee: Splunk Inc.
G06F3/04842G06F3/0482G06F3/04847G06F16/221G06F16/242G06F16/248G06F16/2455G06F16/252G06F16/951G06F40/18G06V10/22G06F9/451G06F16/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,614,856
App. No.
17/029,773
Granted
Mar 28, 2023
Kind
B2
Abstract

In embodiments of statistics value chart interface row mode drill down, a first interface is displayed in a table format that includes columns each with field values of an event field, and each column having a column heading of a different one of the event fields, and includes rows each with one or more of the field values, where each field value in a row is associated with a different one of the event fields, and each row includes an aggregated metric that represents a number of events having field-value pairs that match all of the one or more field values listed in a respective row and the corresponding event fields listed in the respective columns. A row can be emphasized in the first interface, and in response, a menu is displayed with selectable options to transition to a second interface that displays a listing of the events based on a selected one of the options.

Claims (35)

1. A method implemented by a computing device, comprising:

executing a search query to identify a set of events, wherein the search query indicates a computation to perform to produce metrics for the set of events, and wherein the metrics aggregate a set of fields included in the set of events;

causing display of a first interface including a table, wherein column headings of the table include a first field name for a first field included in the set of events, a second field name for a second field included in the set of events, and an indication of a type of metric, wherein a row of the table includes a first value associated with the first field, a second value associated with the second field and a metric from the metrics, and wherein the metric comprises a statistic computed, using the computation, from a quantity of events from the set of events that have the first value in the row associated with the first field and the second value in the row associated with the second field;

causing, in response to first input selecting the row, display of an option selectable to display a subset of events of the set of events, wherein the subset of events correspond to the first value associated with the first field in the row and the second value associated with the second field in the row; and

causing, in response to second input selecting the option, display of a second interface, wherein the second interface includes a listing of the subset of events.

2. The method of claim 1 , wherein the column headings of the table include the first field name and the second field name based on the first field name and the second field name being specified in the search query.

3. The method of claim 1 , wherein the set of fields is a subset of the set of fields included in the set of events.

4. The method of claim 1 , wherein the computation is performed based on being specified in the search query.

5. The method of claim 1 , wherein the subset of events include the first value and the second value in the row based on the first value and the second value being associated with the row.

6. The method of claim 1 , wherein the subset of events do not include the first value and the second value in the row based on the first value and the second value being associated with the row.

7. The method of claim 1 , wherein the display of the option is in a menu that includes a designation of a field from the first field and the second field and a corresponding value associated with the row.

8. The method of claim 1 , wherein the listing of the subset of events in the second interface includes a portion of raw machine data of an event in the subset of events.

9. The method of claim 1 , wherein the option is displayed in a menu that includes a plurality of options,

a first of the plurality of options being selectable to transition to the second interface that includes the listing of the subset of events based on the subset of events including field-value pairs that match the first field and the second field and the first value and the second value in the row.

10. The method of claim 1 , further comprising causing, in response to third input indicating a third selection of the row, an emphasis indicator of the row in the first interface, wherein the first input is to the emphasis indicator of the row, and wherein the row represents the events from the set of events that have the first value and the second value in the row.

11. A computer-implemented system, comprising:

one or more processors; and

one or more computer-readable media comprising instructions that are executable to cause the one or more processors to perform operations comprising:

executing a search query to identify a set of events, wherein the search query indicates a computation to perform to produce metrics for the set of events, and wherein the metrics aggregate a set of fields included in the set of events;

causing display of a first interface including a table, wherein column headings of the table include a first field name for a first field included in the set of events, a second field name for a second field included in the set of events, and an indication of a type of metric, wherein a row of the table includes a first value associated with the first field, a second value associated with the second field and a metric from the metrics, and wherein the metric comprises a statistic computed, using the computation, from a quantity of events from the set of events that have the first value in the row associated with the first field and the second value in the row associated with the second field;

causing, in response to first input selecting the row, display of an option selectable to display a subset of events of the set of events, wherein the subset of events correspond to the first value associated with the first field in the row and the second value associated with the second field in the row; and

causing, in response to second input selecting the option, display of a second interface, wherein the second interface includes a listing of the subset of events.

12. The system of claim 11 , wherein the computation and the first field and the second field are user specified using the first interface.

13. The system of claim 11 , wherein the table only includes column headings for the first field name, the second field name, and the indication of the type of metric.

14. The system of claim 11 , wherein the causing of the display of the first interface is in response to a command in the search query that indicates the computation and the first field and the second field.

15. The system of claim 11 , wherein the computation is an average.

16. One or more computer-readable non-transitory storage memory comprising stored instructions that are executable and, responsive to execution by a computing device, the computing device performs operations comprising:

executing a search query to identify a set of events, wherein the search query indicates a computation to perform to produce metrics for the set of events, and wherein the metrics aggregate a set of fields included in the set of events;

causing display of a first interface including a table, wherein column headings of the table include a first field name for a first field included in the set of events, a second field name for a second field included in the set of events, and an indication of a type of metric, wherein a row of the table includes a first value associated with the first field, a second value associated with the second field and a metric from the metrics, and wherein the metric comprises a statistic computed, using the computation, from a quantity of events from the set of events that have the first value in the row associated with the first field and the second value in the row associated with the second field;

causing, in response to first input selecting the row, display of an option selectable to display a subset of events of the set of events, wherein the subset of events correspond to the first value associated with the first field in the row and the second value associated with the second field in the row; and

causing, in response to second input selecting the option, display of a second interface, wherein the second interface includes a listing of the subset of events.

17. The one or more computer-readable non-volatile storage memory of claim 16 , wherein the column headings of the table include the first field name and the second field name based on the first field name and the second field name being specified in the search query.

18. The one or more computer-readable non-volatile storage memory of claim 16 , wherein the set of fields is a subset of fields included in the set of events.

19. The one or more computer-readable non-volatile storage memory of claim 16 , wherein the computation is performed based on being specified in the search query.

20. The one or more computer-readable non-volatile storage memory of claim 16 , wherein the subset of events include the first value and the second value in the row based on the first value and the second value being associated with the row.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2020
From: BURKE, CORY EUGENE; FEENEY, KATHERINE KYLE; LAMAS, DIVANNY I.; ROBICHAUD, MARC VINCENT; NESS, MATTHEW G.; LEE, CLARA E.
To: SPLUNK INC.
Reel/Frame 053861/0718 →
Continuity (12)
Continuation 14526430 · Oct 28, 2014
Provisional Application 62060560 · Oct 6, 2014
Provisional Application 62060567 · Oct 6, 2014
Provisional Application 62060545 · Oct 6, 2014
Provisional Application 62060551 · Oct 6, 2014
Provisional Application 62059988 · Oct 5, 2014
Provisional Application 62059994 · Oct 5, 2014
Provisional Application 62059989 · Oct 5, 2014
Provisional Application 62059993 · Oct 5, 2014
Provisional Application 62060001 · Oct 5, 2014
Provisional Application 62059998 · Oct 5, 2014
Related Publication 20210004144A1 · Jan 7, 2021