Composite IT Incident Display via Late-Binding Schema

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face challenges in analyzing and searching massive quantities of machine-generated data due to its unstructured nature and diverse formats, which complicates indexing and retrieval operations.

Innovation Solution

A data intake and query system utilizing a flexible schema, known as a late-binding schema, processes and stores machine data as events with timestamps, allowing for field-searchable and semantically-related data extraction, enabling efficient querying and analysis across disparate data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional indexing methods are used on unstructured machine data, then data storage is simple, but data retrieval and analysis become inefficient

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoidindexing system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments unstructured machine data into structured events with defined fields (timestamp, host, source, etc.). Each event is broken down into discrete searchable components, allowing efficient indexing while maintaining simplicity. The segmentation transforms raw data into organized units that can be independently processed and retrieved.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer (the event structure) between raw machine data and the indexing system. This intermediary format serves as a mediator that translates unstructured data into a standardized structure, enabling efficient retrieval without directly complicating the indexing mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is stored in diverse formats from multiple sources, then data coverage is comprehensive, but data integration and searching become difficult

Engineering Contradiction:
Improvedata source compatibilityVSAvoiddata searching ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal event structure that can accommodate data from multiple diverse sources (systems, applications, hosts). This single standardized format serves multiple functions: it preserves source-specific details while enabling unified searching across all data sources. The event structure acts as a multi-functional container that handles various data types consistently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter representation of data by transforming diverse source-specific formats into a standardized set of parameters (timestamp, host, source, event type). This parameter transformation maintains the adaptability to receive different data types while simplifying the searching operation through consistent parameter access.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If extensive data processing is performed to add semantic meaning, then data analysis capability improves, but processing time increases

Engineering Contradiction:
Improvesemantic information retentionVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary action by extracting and structuring key semantic information (timestamp, host, source, event type) during data ingestion. This advance processing captures essential meaning without exhaustive analysis, allowing faster subsequent retrieval and analysis while retaining critical semantic content.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the most essential semantic elements from raw machine data (temporal information, source identification, event classification) rather than processing entire data sets. This selective extraction maintains semantic information necessary for analysis while significantly reducing processing time by ignoring non-critical data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11601324B1Composite display of multi-sourced IT incident related information
Publication Date: 2023.03.07 CISCO TECHNOLOGY INC
  • US11601324B1 patent drawing
  • US11601324B1 patent drawing
  • US11601324B1 patent drawing

AI summary

An application executing on a mobile computing platform provides independent data channels over a mobile network to multiple separate computing systems that each maintain some data pertinent to problem determination and resolution when an incident arises in a monitored information technology (IT) environment. The application maintains and separately exercises the channels to provide timely information in a user interface that composites data to present a single interface with a multi-sourced contextual rendering. Some systems may include an IT monitoring system and a separate incident management system among its sources. Channels may include extended functionality to improve security or other aspects of communication with mobile platforms.