Cell-Based Contextual Options for Event Search Query Construction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face challenges in processing and indexing large volumes of heterogeneous performance data due to its unstructured nature, leading to difficulties in semantic meaning application and effective search operations, with traditional database systems often discarding valuable data during pre-processing.
Innovation Solution
The SPLUNK® ENTERPRISE system employs a late-binding schema and event-based processing to store and analyze performance data, allowing flexible schema development at search time, enabling efficient indexing and querying of unstructured data through extraction rules and parallel processing techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If data is maintained in unstructured form to preserve more data, then data completeness is improved, but indexing and searching operations become difficult
Solution Approach 1:
The patent segments unstructured data into structured events with defined attributes and values. Each event is divided into discrete components (time, host, source, attribute, value) that can be independently indexed and searched, transforming the unstructured data into a manageable format while preserving completeness.
Solution Approach 2:
The patent introduces an event-based intermediary layer between raw unstructured data and the indexing/searching system. Events serve as mediators that bridge the gap, allowing unstructured data to be processed through a structured framework without losing original information, enabling efficient indexing while maintaining data completeness.
2Quantity of substance
If traditional database systems pre-process data to reduce size, then storage space is saved, but valuable data is discarded
Solution Approach 1:
Instead of extracting and discarding data during pre-processing, the patent extracts only the essential event structure (attributes and values) while preserving the complete original data payload. The unstructured data is taken out and reorganized into events without removing valuable information, enabling both storage efficiency and data availability.
Solution Approach 2:
The patent changes the parameter representation from storing complete unstructured records to storing structured event parameters (attributes and values). This parameter transformation reduces storage requirements by eliminating redundancy while preserving all valuable data through the event structure, resolving the contradiction between storage efficiency and data availability.
3Loss of information
If search results are provided in large sets, then comprehensive information is delivered, but user interpretation becomes difficult
Solution Approach 1:
The patent applies local quality by providing different levels of data representation: complete event data for thorough analysis and summarized event attributes for quick interpretation. Users can access detailed information when needed while benefiting from structured, easily interpretable summaries for routine operations, resolving the contradiction between information completeness and ease of interpretation.
Data Source
AI summary
A search interface is displayed in a table format that includes one or more columns, each column including data items of an event attribute, the data items being of a set of events, and a plurality of rows forming cells with the one or more columns, each cell including one or more of the data items of the event attribute of a corresponding column. Based on a user selecting one or more of the cells, a list of options if displayed corresponding to the selection, and one or more commands are added to a search query that corresponds to the set of events, the one or more commands being based on at least an option that is selected from the list of options and the event attribute for each of the one or more of the data items of each of the selected one or more cells.


