Sumo Logic, Inc.
Searchable investigation history for event data store

Last updated:

Abstract:

A processing device receives a first query comprising a first field value and a first time period. The processing device performs a first search of a data store to identify a first plurality of events having the first time period and at least one field that comprises the first field value. The processing device generates a first search object comprising the first field value. The processing device generates a search event comprising the first field value and a reference to the first search object. An event entry for the first search event is then written to the data store. Future searches may return both the first search event and other events.

Status:
Grant
Type:

Utility

Filling date:

9 May 2016

Issue date:

24 Dec 2019