IP Library Granted Patent US 12,182,111
Granted Patent B1
US 12,182,111 · App. 18/241,487 · Granted Dec 31, 2024

Dynamic query recommender

Inventors: Bashyam Tca (Walnut Creek, CA); David M. Andrzejewski (San Francisco, CA); Tejaswi Redkar (San Ramon, CA); Aaishwarya Bansal (Waterloo, CA); Rohith Kumar Poshala (Milpitas, CA); Michael J. Haskell (San Jose, CA); Ayan Ghatak (Kolkata, IN)
Assignee: Sumo Logic, Inc.
G06F16/243G06F11/0787G06F16/2445
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,182,111
App. No.
18/241,487
Granted
Dec 31, 2024
Kind
B1
Abstract

Techniques are presented for recommending queries to search log information. The system provides useful insights and recommendations based on user needs and queries by utilizing the user context, with information about the user activities (e.g., recent alerts) and the user configuration in the system (e.g., applications configured by the user), to provide recommendations. There may not be enough context for a new user to provide good recommendations, so the system determines the context based on the activities of other users, such as more experienced users or users investigating the same type of problem. Based on the context, the user recommends natural language queries (NLQ) or system queries to accelerate the search process and assist the user during an investigation. Further, NLQs may be converted to complex search queries that use the search query language, and the NLQs may also be used as part of the context for the subsequent recommendations.

Claims (67)

1. A computer-implemented method comprising:

causing presentation of a user interface (UI) on a device of a user, the UI providing options for searching log data stored by an online service;

identifying a plurality of search queries based on the user and one or more alerts generated by the online service based on the log data received by the online service, wherein identifying the plurality of search queries comprises:

identifying an alert triggered by the online service within a predetermined time period;

determining a source category associated with the alert triggered by the online service, the source category being a user-customizable metadata tag to identify a source of data;

identifying previously-entered queries to search for logs with the determined source category as metadata; and

identifying the plurality of search queries based on the previously-entered queries for the source category; and

presenting the plurality of search queries on the UI as selectable options for searching the log data.

2. The method as recited in claim 1 , wherein identifying the plurality of search queries based on the source category further comprises:

determining additional source categories used by other users of the online service; and

identifying previously-entered search queries on the online service that search for logs having any of the additional source categories as metadata.

3. The method as recited in claim 1 , wherein identifying the plurality of search queries based on the source category further comprises:

determining most searched source categories across users of a same organization; and

identifying search queries associated with the most searched source categories.

4. The method as recited in claim 1 , further comprising:

detecting search text input entered via the UI;

identifying a new plurality of search queries based on the search text input, the user, and the one or more alerts generated by the online service; and

presenting the new plurality of search queries on the UI as selectable options for searching the log data.

5. The method as recited in claim 4 , wherein identifying a new plurality of search queries further comprises:

identifying query suggestions based on queries associated with customizable panels of dashboards created by users of the online service.

6. The method as recited in claim 4 , wherein identifying a new plurality of search queries further comprises:

identifying search queries received by the online service that contain a search for the source category.

7. The method as recited in claim 1 , further comprising:

detecting a selection in the UI of a search query from the plurality of search queries; and

executing the selected search query.

8. A system comprising:

a memory comprising instructions; and

one or more computer processors, wherein the instructions, when executed by the one or more computer processors, cause the system to perform operations comprising:

causing presentation of a user interface (UI) on a device of a user, the UI providing options for searching log data stored by an online service;

identifying a plurality of search queries based on the user and one or more alerts generated by the online service based on the log data received by the online service, wherein identifying the plurality of search queries comprises:

identifying an alert triggered by the online service within a predetermined time period:

determining a source category associated with the alert triggered by the online service, the source category being a user-customizable metadata tag to identify a source of data;

identifying previously-entered queries to search for logs with the determined source category as metadata; and

identifying the plurality of search queries based on the previously-entered queries for the source category; and

presenting the plurality of search queries on the UI as selectable options for searching the log data.

9. The system as recited in claim 8 , wherein identifying the plurality of search queries based on the source category further comprises:

determining additional source categories used by other users of the online service; and

identifying previously-entered search queries on the online service that search for logs having any of the additional source categories as metadata.

10. The system as recited in claim 8 , wherein identifying the plurality of search queries based on the source category further comprises:

determining most searched source categories across users of a same organization; and

identifying search queries associated with the most searched source categories.

11. The system as recited in claim 8 , wherein the instructions further cause the one or more computer processors to perform operations comprising:

detecting search text input entered via the UI;

identifying a new plurality of search queries based on the search text input, the user, and the one or more alerts generated by the online service; and

presenting the new plurality of search queries on the UI as selectable options for searching the log data.

12. The system as recited in claim 11 , wherein identifying a new plurality of search queries further comprises:

identifying query suggestions based on queries associated with customizable panels of dashboards created by users of the online service.

13. The system as recited in claim 11 , wherein identifying a new plurality of search queries further comprises:

identifying search queries received by the online service that contain a search for the source category.

14. A non-transitory machine-readable storage medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:

causing presentation of a user interface (UI) on a device of a user, the UI providing options for searching log data stored by an online service;

identifying a plurality of search queries based on the user and one or more alerts generated by the online service based on the log data received by the online service, wherein identifying the plurality of search queries comprises:

identifying an alert triggered by the online service within a predetermined time period;

determining a source category associated with the alert triggered by the online service, the source category being a user-customizable metadata tag to identify a source of data;

identifying previously-entered queries to search for logs with the determined source category as metadata; and

identifying the plurality of search queries based on the previously-entered queries for the source category; and

presenting the plurality of search queries on the UI as selectable options for searching the log data.

15. The non-transitory machine-readable storage medium as recited in claim 14 , wherein identifying the plurality of search queries based on the source category further comprises:

determining additional source categories used by other users of the online service; and

identifying previously-entered search queries on the online service that search for logs having any of the additional source categories as metadata.

16. The non-transitory machine-readable storage medium as recited in claim 14 , wherein identifying the plurality of search queries based on the source category further comprises:

determining most searched source categories across users of a same organization; and

identifying search queries associated with the most searched source categories.

17. The non-transitory machine-readable storage medium as recited in claim 14 , wherein the machine further performs operations comprising:

detecting search text input entered via the UI;

identifying a new plurality of search queries based on the search text input, the user, and the one or more alerts generated by the online service; and

presenting the new plurality of search queries on the UI as selectable options for searching the log data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: TCA, BASHYAM; ANDRZEJEWSKI, DAVID M.; REDKAR, TEJASWI; BANSAL, AAISHWARYA; POSHALA, ROHITH KUMAR; HASKELL, MICHAEL J.; GHATAK, AYAN
To: SUMO LOGIC, INC.
Reel/Frame 066841/0950 →
Cited By (3)
US 12,332,878 US 12,664,155 US 12,681,991