Sumo Logic, Inc.
Searchable investigation history for event data store

Last updated:

Abstract:

A processing device receives a first query comprising a first field value and a first time period. The processing device performs a first search of a data store to identify a first plurality of events having the first time period and at least one field that comprises the first field value. The processing device generates a first search object comprising the first field value. The first search object may be a data structure, file or data record, and is stored in the data store. The processing device generates a search event comprising the first field value and a reference to the first search object. An event entry for the first search event is then written to the data store. Future searches may return both the first search event and other events, as well as search objects.

Status:
Grant
Type:

Utility

Filling date:

17 Oct 2019

Issue date:

14 Jun 2022