CPC G06F 16/2425 (2019.01) [G06F 3/0482 (2013.01); G06F 16/245 (2019.01); G06F 16/248 (2019.01); G06F 16/24575 (2019.01); G06F 16/27 (2019.01); G06F 16/9535 (2019.01); G06F 40/186 (2020.01)] | 19 Claims |
1. A computer-implemented method, comprising:
identifying a first data set to be retrieved and analyzed, a report template that is associated with one or more selected data models, wherein:
the first data set comprises a plurality of time-stamped, searchable events stored in a first data store,
each event in the plurality of time-stamped, searchable events includes a portion of unstructured raw machine data reflecting activity in an information technology environment, and
the one or more selected data models represent a view of the first data set and include a first object,
selecting, based on the first data set, a report template that is associated with the first object, wherein the first object is associated with (i) an object query that, when executed, retrieves a first set of time stamped, searchable events included in the first data set and (ii) an object schema;
executing the object query to retrieve, from the first data store, a first set of time-stamped, searchable events, wherein the first set of time-stamped, searchable events includes portions of unstructured raw machine data;
applying the object schema to the first set of time-stamped, searchable events to generate one or more fields of structured data from the portions of unstructured raw machine data; and
generating a report corresponding to the report template based on the one or more fields of structured data.
|