IP Library Granted Patent US 10,885,049
Granted Patent B2
US 10,885,049 · App. 15/936,351 · Granted Jan 5, 2021

User interface to identify one or more pivot identifiers and one or more step identifiers to process events

Inventors: Joerg Beringer (Redwood City, CA); Isabelle Park (San Mateo, CA); Joshua Walters (Santa Clara, CA); Eric Tschetter (Redwood City, CA); Simon Fishel (San Francisco, CA)
Assignee: Splunk Inc.
G06F16/248G06F3/0482G06F16/2455G06F16/252
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,885,049
App. No.
15/936,351
Granted
Jan 5, 2021
Kind
B2
Abstract

Systems and methods are disclosed for generating a user interface to enable identification of one or more pivot identifiers and one or more step identifiers. The system executes a query on events having raw machine data associated with a timestamp and obtains fields associated with the events. The system further populates a graphical user interface with field identifiers associated with the obtained fields and enables identification of one or more fields as one or more pivot identifiers and one or more step identifiers.

Claims (56)

1. A method comprising:

executing a query to search events in a computer system, each event including raw machine data associated with a time stamp;

obtaining fields from a plurality of events that are identified by the query;

populating a graphical user interface with field identifiers for a subset of the fields obtained from the plurality of events;

enabling, via the graphical user interface, concurrent:

identification of a first field of the subset of the fields as a step identifier field, wherein event field values for the step identifier field are used to categorize the plurality of events into a plurality of step instances, wherein each of the plurality of step instances is associated with a step of a plurality of steps, and

identification of a second field of the subset of the fields as a pivot identifier field, wherein event field values for the pivot identifier field are used to group the plurality of step instances into a plurality of journey instances; and

responsive to identification of the first field as the step identifier field and identification of the second field as the pivot identifier field:

categorizing the plurality of events into the plurality of step instances, wherein at least two step instances of the plurality of step instances include a same event field value for the step identifier field and are associated with a same step of the plurality of steps,

generating the plurality of journey instances, wherein a journey instance includes a set of step instances, and

causing display of a particular journey instance of the plurality of journey instances, wherein a step instance display object is displayed for each step instance of the particular journey instance, wherein the particular journey instance includes at least two time-ordered step instances that include a same event field value for the pivot identifier field, wherein the at least two time-ordered step instances are time ordered based on a time field associated with each of the at least two time-ordered step instances, and wherein each of the at least two time-ordered step instances correspond to an event of the plurality of events, respectively.

2. The method of claim 1 , further comprising indicating via the graphical user interface a quantity of the subset of the fields identified as pivot identifier fields.

3. The method of claim 1 , further comprising indicating via the graphical user interface a quantity of the subset of the fields identified as step identifier fields.

4. The method of claim 1 , further comprising providing, via the graphical user interface, an indication of a suggested field of the subset of the fields for use as the pivot identifier field.

5. The method of claim 1 , further comprising providing, via the graphical user interface, a dropdown menu proximate each of the field identifiers that enables the identification of the first field as the step identifier field and the identification of the second field as the pivot identifier field.

6. The method of claim 1 , wherein the subset of the fields correspond to one or more fields associated with one data source of a plurality of data sources related to the plurality of events.

7. The method of claim 1 , wherein the subset of the fields correspond to one or more fields associated with any one of a plurality of data sources related to the plurality of events.

8. The method of claim 1 , further comprising populating the graphical user interface with data source identifiers corresponding to one or more data sources related to the plurality of events.

9. The method of claim 1 , wherein the obtaining fields is based on one or more configuration files associated with the plurality of events.

10. The method of claim 1 , wherein the obtaining fields, comprises:

identifying one or more configuration files associated with the plurality of events; and

obtaining the fields based on an identification of field definitions in the one or more configuration files.

11. The method of claim 1 , further comprising populating the graphical user interface with event field values associated with at least one of the subset of the fields.

12. The method of claim 1 , further comprising populating the graphical user interface with event field values associated with at least one of the subset of the fields based on one or more inverted indexes associated with the plurality of events.

13. The method of claim 1 , further comprising populating the graphical user interface with event field values associated with at least one of the subset of the fields, and for each event field value, a count corresponding to a quantity of events of the plurality of events that include the each event field value.

14. The method of claim 1 , further comprising populating the graphical user interface with event field values associated with a selected field identifier of the field identifiers.

15. The method of claim 1 , further comprising populating the graphical user interface with event field values associated with at least one of the subset of the fields based on a review of the raw machine data of the plurality of events.

16. The method of claim 1 , further comprising causing display of a visualization of a set of events of the plurality of events based on the identification of the first field as the step identifier field and the identification of the second field as the pivot identifier field.

17. The method of claim 1 , further comprising causing display of a visualization of a plurality of sets of events of the plurality of events based on the identification of the first field as the step identifier field and the identification of the second field as the pivot identifier field.

18. The method of claim 1 , further comprising causing display of a visualization of a combination of a plurality of sets of events of the plurality of events based on the identification of the first field as the step identifier field and the identification of the second field as the pivot identifier field.

19. The method of claim 1 , wherein the events are stored in a field-searchable time series data store and the raw machine data reflects activity in an information processing environment and is produced by a component of the information processing environment.

20. The method of claim 1 , wherein said executing the query comprises applying a late binding schema.

21. A computing system, comprising:

one or more processing devices configured to:

execute a query to search events in a computer system, each event including raw machine data associated with a time stamp;

obtain fields from a plurality of events that are identified by the query;

populate a graphical user interface with field identifiers for a subset of the fields obtained from the plurality of events;

enable, via the graphical user interface, concurrent:

identification of a first field of the subset of the fields as a step identifier field, wherein event field values for the step identifier field are used to categorize the plurality of events into a plurality of step instances, wherein each of the plurality of step instances is associated with a step of a plurality of steps, and

identification of a second filed of the subset of the fields as a pivot identifiers field, wherein event field values for the pivot identifier field are used to group the plurality of step instances into a plurality of journey instances; and

responsive to identification of the first field as the step identifier field and identification of the second field as the pivot identifier field:

categorize the plurality of events into the plurality of step instances, wherein at least two step instances of the plurality of step instances include a same event field value for the step identifier field and are associated with a same step of the plurality of steps,

generate the plurality of journey instances, wherein a journey instance includes a set of step instances, and

cause display of a particular journey instance of the plurality of journey instances, wherein a step instance display object is displayed for each step instance of the particular journey instance, wherein the particular journey instance includes at least two time-ordered step instances that include a same event field value for the pivot identifier field, wherein the at least two time-ordered step instances are time ordered based on a time field associated with each of the at least two time-ordered step instances, and wherein each of the at least two time-ordered step instances correspond to an event of the plurality of events, respectively.

22. The computing system of claim 21 , further comprising indicating via the graphical user interface a quantity of the subset of the fields identified as pivot identifier fields.

23. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system, cause the computing system to:

execute a query to search events in a computer system, each event including raw machine data associated with a time stamp;

obtain fields from a plurality of events that are identified by the query;

populate a graphical user interface with field identifiers for a subset of the fields obtained from the plurality of events;

enable, via the graphical user interface, concurrent:

identification of a first field of the subset of the fields as a step identifier field, wherein event field values for the step identifier field are used to categorize the plurality of events into a plurality of step instances, wherein each of the plurality of step instances is associated with a step of a plurality of steps, and

identification of a second field of the subset of the fields as a pivot identifiers field, wherein event field values for the pivot identifier field are used to group the plurality of step instances into a plurality of journey instances; and

responsive to identification of the first field as the step identifier field and identification of the second field as the pivot identifier field:

categorizing the plurality of events into the plurality of step instances, wherein at least two step instances of the plurality of step instances include a same event field value for the step identifier field and are associated with a same step of the plurality of steps,

generating the plurality of journey instances, wherein a journey instance includes a set of step instances, and

causing display of a particular journey instance of the plurality of journey instances, wherein a step instance display object is displayed for each step instance of the particular journey instance, wherein the particular journey instance includes at least two time-ordered step instances that include a same event field value for the pivot identifier field, wherein the at least two time-ordered step instances are time ordered based on a time field associated with each of the at least two time-ordered step instances, and wherein each of the at least two time-ordered step instances correspond to an event of the plurality of events, respectively.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2018
From: BERINGER, JOERG; PARK, ISABELLE; WALTERS, JOSHUA; TSCHETTER, ERIC; FISHEL, SIMON
To: SPLUNK INC.
Reel/Frame 045612/0193 →
Continuity (1)
Related Publication 20190294719A1 · Sep 26, 2019
Cited By (2)
US 12,197,908 US 12,217,106