CPC G06F 16/93 (2019.01) [G06F 3/0482 (2013.01); G06F 16/248 (2019.01); G06F 16/2428 (2019.01); G06F 16/2477 (2019.01); G06F 16/9038 (2019.01)] | 20 Claims |
1. A computer-implemented method comprising:
causing display, in a table format in a graphical interface, of a textual representation of first raw machine data associated with a first event of a set of events;
receiving a user selection of a text portion of the displayed textual representation of the first raw machine data by clicking on the text portion in a cell in a row of the table format, the row corresponding to the first event in the table format, the text portion, in the row corresponding to the first event in the table format, including at least a field label of a first field label-value pair; and
determining an extraction rule that when applied extracts, from second raw machine data associated with a second event of the set of events, a second field label-value pair, wherein based on the field label being included in the user-selected text portion in the row corresponding to the first event in the table format, the extraction rule uses a location in the second raw machine data of the field label to identify, within the second raw machine data, a value of the second field label-value pair.
|