US 11,816,082 B2
Searchable investigation history for event data store
Kenny Tidwell, Los Altos, CA (US); David Frampton, Portola Valley, CA (US); and Brendan O'Connell, Sandown, NH (US)
Assigned to Sumo Logic, Inc., Redwood City, CA (US)
Filed by Sumo Logic, Inc., Redwood City, CA (US)
Filed on May 10, 2022, as Appl. No. 17/662,721.
Application 17/662,721 is a continuation of application No. 16/656,448, filed on Oct. 17, 2019, granted, now 11,360,957.
Application 16/656,448 is a continuation of application No. 15/150,131, filed on May 9, 2016, granted, now 10,515,062.
Prior Publication US 2022/0300473 A1, Sep. 22, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 16/22 (2019.01); G06F 16/245 (2019.01); G06F 16/28 (2019.01); G06F 11/30 (2006.01); G06F 21/55 (2013.01); H04L 9/40 (2022.01); G06F 21/00 (2013.01); G06Q 10/10 (2023.01)
CPC G06F 16/2228 (2019.01) [G06F 11/30 (2013.01); G06F 16/245 (2019.01); G06F 16/282 (2019.01); G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); G06Q 10/10 (2013.01); H04L 63/1416 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method comprising:
storing, in an event data store, store events associated with logs generated by one or more computing devices;
storing, in the event data store, search events associated with search queries submitted for querying the event store, the search queries having associated search time periods, wherein the search events are stored with corresponding stored time periods that are configurable to be equal to the search time periods and configurable to be greater than the search time periods;
receiving a query having a value for a first field and a query time period;
searching the event data store based on the value of the first field and the query time period to produce results, the results comprising:
a set of store events associated with the value of the first field and the query time period; and
a set of search events associated with the value of the first field and the query time period, wherein at least one stored time period of the set of search events is greater than the query time period, wherein the set of search events cover a range of time that is greater than the query time period to provide information beyond the requested query time period; and
causing presentation on a display of the results, the presentation providing information about the set of store events and the set of search events.