IP Library Granted Patent US 11,500,866
Granted Patent B2
US 11,500,866 · App. 17/128,913 · Granted Nov 15, 2022

Interactive table-based query construction using contextual forms

Inventors: Marc V. Robichaud (San Francisco, CA); Jesse Miller (San Francisco, CA); Cory Burke (San Francisco, CA); Alexander James (San Francisco, CA); Jeffrey Thomas Lloyd (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/24524G06F3/0482G06F3/0484G06F3/04842G06F16/00G06F16/22G06F16/23G06F16/235G06F16/2372G06F16/2423G06F16/2455G06F16/2477G06F16/24544G06F16/24564G06F16/26G06F16/33G06F16/3334G06F21/6227G06F40/177G06Q10/00G06T11/206G06Q10/10G06T2200/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,500,866
App. No.
17/128,913
Granted
Nov 15, 2022
Kind
B2
Abstract

A method includes causing display of events that correspond to search results of a search query in a table. The table includes rows representing events comprising data items of event attributes, columns forming cells with the row, the columns representing respective event attributes, and interactive regions corresponding to one or more data items of the displayed data items. The method also includes in response to the user selecting a designated interactive region, causing display of a list of options, each displayed option corresponding to an interface template for composing query commands, and based on the user selecting an option in the displayed list of options, causing one or more commands to be added to the search query, the one or more commands composed based on the one or more data items that corresponds to the designated interactive region according to instructions of the interface template of the selected option.

Claims (50)

1. A computer-implemented method comprising:

causing display of a set of events in a table, an event corresponding to a portion of raw machine data associated with a timestamp, the table comprising data items of event attributes associated with the set of events and an interactive region corresponding to one or more of the data items;

in response to a selection corresponding to the interactive region, causing display of one or more form elements that correspond to parameters of one or more commands, at least a form element of the one or more form elements being based on an event attribute associated with the interactive region; and

causing the one or more commands to be added to a query, the parameters of the one or more commands composed at least from one or more values of the form element.

2. The computer-implemented method of claim 1 , wherein the one or more commands are composed based on user input into the form element, the form element mapping to one or more portions of the one or more commands.

3. The computer-implemented method of claim 1 , further comprising based on the selection, causing display of a graphical user interface comprising the one or more form elements, wherein the one or more commands are composed from user input to the graphical user interface.

4. The computer-implemented method of claim 1 , further comprising:

after adding the one or more commands to the query, receiving a request to modify the one or more commands added to the query;

in response to the request, causing the one or more form elements to be presented; and

modifying the one or more commands in the query based on user input that modifies the one or more values of the form element.

5. The computer-implemented method of claim 1 , comprising, based on the selection of the interactive region:

extracting at least one value of the one or more data items; and

determining a number of the one or more form elements to display based on the at least one value.

6. The computer-implemented method of claim 1 , wherein the causing one or more commands to be added to the query automatically causes the set of events displayed in the table to be updated to correspond to results of the query comprising the one or more commands.

7. The computer-implemented method of claim 1 , further comprising:

receiving user input corresponding to a command entry representing one or more previously added commands of the query; and

based on the user input, causing a currently displayed form that includes the one or more form elements to be replaced with a form for modifying the one or more previously added commands.

8. The computer-implemented method of claim 1 , wherein a set of form elements selectable to compose a set of commands of the query are displayed in an interface panel, and the method further comprises:

in response to a user request to hide the interface panel, hiding the interface panel including the set of form elements; and

based on the selection, causing the interface panel to be automatically unhidden in the display of the one or more form elements.

9. The computer-implemented method of claim 1 , wherein the display of the one or more form elements includes the one or more values in the form element based on the one or more of the data items.

10. The computer-implemented method of claim 1 , wherein the query is represented in a pipelined query language and the one or more commands are written in the pipelined query language in which a command of the query produces an output from an input of the command, and the input is an output of a prior command of the query.

11. One or more non-transitory computer-readable media having instructions stored thereon, the instructions, when executed by a processor of a computing device, to cause the computing device to perform a method comprising:

causing display of a set of events in a table, an event corresponding to a portion of raw machine data associated with a timestamp, the table comprising data items of event attributes associated with the set of events and an interactive region corresponding to one or more of the data items;

in response to a selection corresponding to the interactive region, causing display of one or more form elements that correspond to parameters of one or more commands, at least a form element of the one or more form elements being based on an event attribute associated with the interactive region; and

causing the one or more commands to be added to a query, the parameters of the one or more commands composed at least from one or more values of the form element.

12. The one or more non-transitory computer-readable media of claim 11 , wherein the one or more commands are composed based on user input into the form element, the form element mapping to one or more portions of the one or more commands.

13. The one or more non-transitory computer-readable media of claim 11 , wherein the method further comprises based on the selection, causing display of a graphical user interface comprising the one or more form elements, wherein the one or more commands are composed from user input to the graphical user interface.

14. The one or more non-transitory computer-readable media of claim 11 , wherein the method further comprises:

after adding the one or more commands to the query, receiving a request to modify the one or more commands added to the query;

in response to the request, causing the one or more form elements to be presented; and

modifying the one or more commands in the query based on user input that modifies the one or more values of the form element.

15. The one or more non-transitory computer-readable media of claim 11 , wherein the method further comprises, based on the selection of the interactive region:

extracting at least one value of the one or more data items; and

determining a number of the one or more form elements to display based on the at least one value.

16. A computer-implemented system comprising:

one or more processors; and

memory having instructions stored thereon, the instructions, when executed by the one or more processors, to cause the one or more processors to perform a method comprising:

causing display of a set of events in a table, an event corresponding to a portion of raw machine data associated with a timestamp, the table comprising data items of event attributes associated with the set of events and an interactive region corresponding to one or more of the data items;

in response to a selection corresponding to the interactive region, causing display of one or more form elements that correspond to parameters of one or more commands, at least a form element of the one or more form elements being based on an event attribute associated with the interactive region; and

causing the one or more commands to be added to a query, the parameters of the one or more commands composed at least from one or more values of the form element.

17. The computer-implemented system of claim 16 , wherein the one or more commands are composed based on user input into the form element, the form element mapping to one or more portions of the one or more commands.

18. The computer-implemented system of claim 16 , wherein the method further comprises based on the selection, causing display of a graphical user interface comprising the one or more form elements, wherein the one or more commands are composed from user input to the graphical user interface.

19. The computer-implemented system of claim 16 , wherein the method further comprises:

after adding the one or more commands to the query, receiving a request to modify the one or more commands added to the query;

in response to the request, causing the one or more form elements to be presented; and

modifying the one or more commands in the query based on user input that modifies the one or more values of the form element.

20. The computer-implemented system of claim 16 , wherein the method further comprises, based on the selection of the interactive region:

extracting at least one value of the one or more data items; and

determining a number of the one or more form elements to display based on the at least one value.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2020
From: ROBICHAUD, MARC V.; MILLER, JESSE; BURKE, CORY; LLOYD, JEFFREY THOMAS
To: SPLUNK INC.
Reel/Frame 054710/0844 →
Continuity (4)
Continuation 15799917 · Oct 31, 2017
Continuation 14815923 · Jul 31, 2015
Continuation In Part 14611002 · Jan 30, 2015
Related Publication 20210109928A1 · Apr 15, 2021