CPC H04L 63/1433 (2013.01) [G06F 16/285 (2019.01); G06F 21/554 (2013.01); H04L 63/14 (2013.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); G06F 2221/034 (2013.01); G06F 2221/2151 (2013.01); H04L 63/20 (2013.01)] | 20 Claims |
1. A method comprising:
creating, by a computer system, an event group, the event group including a plurality of events, each event in the event group having a respective portion of machine data, wherein each event in the event group is included in the event group based on an event matching criterion relating to one or more field values of a respective one or more fields present in a respective portion of machine data;
creating, by the computer system, an event group summary that summarizes one or more fields present in the portion of machine data included in the plurality of events included in the event group;
causing, by the computer system, display of a graphical user interface that includes a plurality of event group summaries including the event group summary;
receiving, by the computer system, one or more new events, each having a respective portion of machine data; and
in response to receiving the one or more new events,
identifying, by the computer system, the one or more new events as belonging to the event group, and
modifying, by the computer system, the event group summary based upon one or more fields present in the machine data contained in the one or more new events.
|