Composite IT Incident Display via Late-Binding Schema
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face challenges in analyzing and searching massive quantities of machine-generated data due to its unstructured nature and diverse formats, which complicates indexing and retrieval operations.
Innovation Solution
A data intake and query system utilizing a flexible schema, known as a late-binding schema, processes and stores machine data as events with timestamps, allowing for field-searchable and semantically-related data extraction, enabling efficient querying and analysis across disparate data sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional indexing methods are used on unstructured machine data, then data storage is simple, but data retrieval and analysis become inefficient
Solution Approach 1:
The patent segments unstructured machine data into structured events with defined fields (timestamp, host, source, etc.). Each event is broken down into discrete searchable components, allowing efficient indexing while maintaining simplicity. The segmentation transforms raw data into organized units that can be independently processed and retrieved.
Solution Approach 2:
The patent introduces an intermediary processing layer (the event structure) between raw machine data and the indexing system. This intermediary format serves as a mediator that translates unstructured data into a standardized structure, enabling efficient retrieval without directly complicating the indexing mechanism.
2Adaptability or versatility
If data is stored in diverse formats from multiple sources, then data coverage is comprehensive, but data integration and searching become difficult
Solution Approach 1:
The patent creates a universal event structure that can accommodate data from multiple diverse sources (systems, applications, hosts). This single standardized format serves multiple functions: it preserves source-specific details while enabling unified searching across all data sources. The event structure acts as a multi-functional container that handles various data types consistently.
Solution Approach 2:
The patent changes the parameter representation of data by transforming diverse source-specific formats into a standardized set of parameters (timestamp, host, source, event type). This parameter transformation maintains the adaptability to receive different data types while simplifying the searching operation through consistent parameter access.
3Loss of information
If extensive data processing is performed to add semantic meaning, then data analysis capability improves, but processing time increases
Solution Approach 1:
The patent performs preliminary action by extracting and structuring key semantic information (timestamp, host, source, event type) during data ingestion. This advance processing captures essential meaning without exhaustive analysis, allowing faster subsequent retrieval and analysis while retaining critical semantic content.
Solution Approach 2:
The patent extracts only the most essential semantic elements from raw machine data (temporal information, source identification, event classification) rather than processing entire data sets. This selective extraction maintains semantic information necessary for analysis while significantly reducing processing time by ignoring non-critical data.
Data Source
AI summary
An application executing on a mobile computing platform provides independent data channels over a mobile network to multiple separate computing systems that each maintain some data pertinent to problem determination and resolution when an incident arises in a monitored information technology (IT) environment. The application maintains and separately exercises the channels to provide timely information in a user interface that composites data to present a single interface with a multi-sourced contextual rendering. Some systems may include an IT monitoring system and a separate incident management system among its sources. Channels may include extended functionality to improve security or other aspects of communication with mobile platforms.


