IP Library Granted Patent US 12,099,517
Granted Patent B1
US 12,099,517 · App. 18/300,936 · Granted Sep 24, 2024

Supplementing extraction rules based on event clustering

Inventors: Jesse Brandau Miller (San Francisco, CA); Katherine Kyle Feeney (San Francisco, CA); Yuan Xie (San Francisco, CA); Steve Zhang (San Francisco, CA); Adam Jamison Oliner (San Francisco, CA); Jindrich Dinga (San Francisco, CA); Jacob Leverich (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,099,517
App. No.
18/300,936
Granted
Sep 24, 2024
Kind
B1
Abstract

Systems and methods include causing presentation of a first cluster in association with an event of the first cluster, the first cluster from a first set of clusters of events. Each event includes a time stamp and event data. Based on the presentation of the first cluster, an extraction rule corresponding to the event of the first cluster is received from a user. Similarities in the event data between the events are determined based on the received extraction rule. The events are grouped into a second set of clusters based on the determined similarities. Presentation is caused of a second cluster in association with an event of the second cluster, where the second cluster is from the second set of clusters.

Claims (46)

1. A computer-implemented method, comprising:

clustering events into clusters based on a set of extraction rules associated with a set of fields of the events, each event comprising a portion of raw machine data;

causing presentation of at least one cluster in association with corresponding events of the at least one cluster; and

supplementing the set of extraction rules with a new extraction rule associated with an event field.

2. The computer-implemented method of claim 1 , wherein the events are clustered in accordance with a source type.

3. The computer-implemented method of claim 1 , wherein each cluster is presented in association with the corresponding events.

4. The computer-implemented method of claim 1 , where the new extraction rule is user selected for the event field.

5. The computer-implemented method of claim 1 further comprising clustering the events into clusters based on the set of extraction rules and the new extraction rule.

6. The computer-implemented method of claim 1 further comprising:

clustering the events into clusters based on the set of extraction rules and the new extraction rule;

causing presentation of a set of clusters in association with corresponding events of the set of clusters; and

supplementing the set of extraction rules with another new extraction rule associated with another event field.

7. The computer-implemented method of claim 1 , wherein clustering events into clusters comprises:

identifying values from the events using at least a portion of the set of extraction rules; and

clustering the events based on comparisons between the portions of raw machine data of the events, wherein portions of raw machine data that correspond to the values identified are excluded from the comparisons.

8. The computer-implemented method of claim 1 , wherein clustering events into clusters comprises:

identifying values from the events; and

clustering the events based on comparisons between the portions of raw machine data of the events, wherein portions of raw machine data that correspond to the values identified are excluded from the comparisons, wherein the values identified are excluded from the comparisons based on masking text or tokenizing text portions.

9. The computer-implemented method of claim 1 , wherein the events are clustered based on a similarity between data associated with the events.

10. The computer-implemented method of claim 1 further comprising applying the new extraction rule to at least one event.

11. The computer-implemented method of claim 1 further comprising:

causing display of the new extraction rule;

obtaining an extraction rule adjustment of the new extraction rule; and

supplementing the set of extraction rules with the adjusted new extraction rule.

12. A system comprising:

one or more processors; and

computer memory having instructions stored thereon, the instructions, when executed by the one or more processors causing the system to perform a method comprising:

clustering events into clusters based on a set of extraction rules associated with a set of fields of the events, each event comprising a portion of raw machine data;

causing presentation of at least one cluster in association with corresponding events of the at least one cluster; and

supplementing the set of extraction rules with a new extraction rule associated with an event field.

13. The system of claim 12 , wherein the events are clustered in accordance with a source type.

14. The system of claim 12 , wherein each cluster is presented in association with the corresponding events.

15. The system of claim 12 , where the new extraction rule is user selected for the event field.

16. One or more computer-readable media having instructions stored thereon, the instructions, when executed by a processor of a computing device, to cause the computing device to perform a method comprising:

clustering events into clusters based on a set of extraction rules associated with a set of fields of the events, each event comprising a portion of raw machine data;

causing presentation of at least one cluster in association with corresponding events of the at least one cluster; and

supplementing the set of extraction rules with a new extraction rule associated with an event field.

17. The one or more computer-readable media of claim 16 further comprising clustering the events into clusters based on the set of extraction rules and the new extraction rule.

18. The one or more computer-readable media of claim 16 further comprising:

clustering the events into clusters based on the set of extraction rules and the new extraction rule;

causing presentation of a set of clusters in association with corresponding events of the set of clusters; and

supplementing the set of extraction rules with another new extraction rule associated with another event field.

19. The one or more computer-readable media of claim 16 , wherein clustering events into clusters comprises:

identifying values from the events; and

clustering the events based on comparisons between the portions of raw machine data of the events, wherein portions of raw machine data that correspond to the values identified are excluded from the comparisons, wherein the values identified are excluded from the comparisons based on masking text or tokenizing text portions.

20. The one or more computer-readable media of claim 16 further comprising applying the new extraction rule to at least one event.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2023
From: MILLER, JESSE BRANDAU; FEENEY, KATHERINE KYLE; XIE, YUAN; ZHANG, STEVE; OLINER, ADAM JAMISON; DINGA, JUNDRICH; LEVERICH, JACOB
To: SPLUNK INC.
Reel/Frame 063329/0318 →
Continuity (2)
Continuation 17158880 · Jan 26, 2021
Continuation 15276693 · Sep 26, 2016