| CPC G06F 16/2372 (2019.01) [G06F 3/0482 (2013.01); G06F 3/0484 (2013.01); G06F 3/04842 (2013.01); G06F 16/00 (2019.01); G06F 16/23 (2019.01); G06F 16/235 (2019.01); G06F 16/2423 (2019.01); G06F 16/24544 (2019.01); G06F 16/24564 (2019.01); G06F 16/2477 (2019.01); G06F 16/26 (2019.01); G06F 16/33 (2019.01); G06F 16/3334 (2019.01); G06F 21/6227 (2013.01); G06F 40/174 (2020.01); G06F 40/177 (2020.01); G06F 40/186 (2020.01); G06Q 10/00 (2013.01); G06T 11/206 (2013.01); G06Q 10/10 (2013.01); G06T 2200/24 (2013.01)] | 20 Claims |

|
1. A computer-implemented method comprising:
causing display of a set of events that are search results of a search query represented as a search string that specifies a plurality of commands, each event corresponding to a portion of raw machine data associated with a timestamp, the display of the set of events being in a table format that enables query generation without query language knowledge and includes:
one or more columns, each column comprising data items of an event attribute, the data items being of the set of events; and
a plurality of rows forming cells with the one or more columns, each cell comprising one or more of the data items of the event attribute of a corresponding column;
causing display of a list of options corresponding to a selected cell or column in the table format; and
causing one or more commands to be added to the search query, wherein the one or more commands are based on an option that is selected from the list of options and a particular event attribute corresponding to the selected cell or column.
|