Splunk Inc.
Leveraging references values in inverted indexes to retrieve associated event records comprising raw machine data

Last updated:

Abstract:

Embodiments of the present disclosure provide techniques for performing searches of event records by leveraging reference values in an inverted index. A method of searching comprises accessing a query associated with a first set of event records in a field searchable data store, each event record comprising a time-stamped portion of raw machine data. The method further comprises evaluating the query and generating results for the query by accessing an inverted index, wherein each entry in the inverted index comprises at least one field, a corresponding at least one field value and a reference value that identifies a location in the field searchable data store where an associated event record is stored. The method further comprises performing a search to filter out a second set of event records and retrieving the second set of event records from the field searchable data store using reference values in the inverted index.

Status:
Grant
Type:

Utility

Filling date:

31 Jul 2019

Issue date:

5 Jul 2022