CPC G06F 16/285 (2019.01) [G06F 9/54 (2013.01); G06F 9/541 (2013.01); G06F 9/542 (2013.01); G06F 18/21 (2023.01)] | 20 Claims |
1. A method comprising:
identifying a first source signature for a first source of machine data and a second source signature for a second source of machine data;
receiving machine data;
comparing a first portion of the machine data with the first source signature and a second portion of the machine data with the second source signature;
based on comparing the first portion of the machine data with the first source signature and the second portion of the machine data with the second source signature, determining the first portion of the machine data is associated with the first source of machine data and the second portion of the machine data is associated with the second source of machine data;
based on determining the first portion of the machine data is associated with the first source of machine data, segmenting the first portion of the machine data into at least one first event, wherein segmenting the first portion of the machine data into the at least one first event comprises determining a particular starting point in the first portion of the machine data and a particular ending point in the first portion of the machine data for the at least one first event;
based on determining the second portion of the machine data is associated with the second source of machine data, segmenting the second portion of the machine data into at least one second event, wherein segmenting the second portion of the machine data into at least one second event comprises determining a particular starting point in the second portion of the machine data and a particular ending point in the second portion of the machine data for the at least one second event;
identifying, in real time, a pattern that associates the at least one first event with the at least one second event; and
providing, to a computing system, information associated with the pattern that associates the at least one first event with the at least one second event.
|