Configurable Real-Time Metric Display for Machine Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data processing systems lack efficient tools to analyze and extract insights from vast amounts of heterogeneous machine data, such as log files, due to their unstructured nature and varying formats, leading to difficulties in distinguishing high-priority events and establishing baselines for system monitoring.
Innovation Solution
A system and method for displaying configurable metrics in real-time, allowing selection from pre-defined or customizable metrics, with continuous updates and graphical representation, including trend analysis and threshold indicators, to identify events of interest and provide actionable insights from machine data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If traditional relational databases are used to store machine data in predefined fields, then data storage is simplified, but the underlying data is discarded and cannot be later analyzed or used as a basis for new search queries
Solution Approach 1:
The patent implements a dynamic data retention architecture where the system can adapt between storing data in predefined database fields for quick access and retaining raw machine data in its original form for flexible analysis. This dynamic approach allows the system to switch between structured storage (for simplicity) and unstructured retention (for adaptability) based on analytical needs.
Solution Approach 2:
The patent recovers the discarded underlying data by implementing a mechanism that preserves raw machine data even after it has been processed and stored in predefined database fields. This allows the system to recover and re-analyze the original data for new search queries and different analytical perspectives without being constrained by the initial predefined schema.
2Reliability
If machine data is stored in unstructured text files, then data integrity is maintained, but it becomes tedious to mine the machine data for analytic insights
Solution Approach 1:
The patent introduces an intermediary processing layer that sits between the unstructured text files and the analysis tools. This intermediary automatically parses, structures, and indexes the raw machine data while preserving its integrity, making it easily mineable for analytic insights without requiring manual intervention or complex querying of unstructured text.
Solution Approach 2:
The patent performs preliminary actions by automatically processing and structuring machine data as it is ingested, rather than requiring manual structuring before analysis. This preliminary processing includes parsing unstructured text, extracting relevant fields, and organizing data in a manner that maintains integrity while enabling efficient analytical querying.
3Stability of the object's composition
If system metrics are made static, then system stability is maintained, but they cannot be customized to address a particular problem
Solution Approach 1:
The patent implements dynamic metrics that can adapt their structure and parameters based on analytical needs. The system allows users to customize metrics by selecting different fields, time periods, and aggregation methods from the retained machine data, while maintaining stable core measurement capabilities. This dynamic customization enables the same metric framework to address different problems without compromising system stability.
4Speed
If machine data is processed using conventional approaches, then processing speed is maintained, but it is difficult to establish what the baseline of the system should be in order to further determine if there is a deviation from that baseline
Solution Approach 1:
The patent performs preliminary analysis actions by automatically establishing baselines from the retained machine data before deviation detection is needed. The system pre-processes the data to identify normal operating ranges, typical patterns, and baseline metrics, enabling faster and more precise deviation detection when anomalies occur without compromising processing speed.
Data Source
AI summary
A system and computer-implemented is provided for displaying a configurable metric relating to an environment in a graphical display along with a value of the metric calculated over a configurable time period. The metric is used to identify events of interest in the environment based on processing real time machine data from one or more sources. The configurable metric is selected and a corresponding value is calculated based on the events of interest over the configurable time period. The value of the metric may be continuously updated in real time based on receiving additional real-time machine data and displayed in a graphical interface as time progresses. Statistical trends in the value of the metric may also be determined over the configurable time period and displayed in the graphical interface as well as an indication if the value of the metric exceeds a configurable threshold value. Further, a selection of one or more thresholds for the value of the metric may be applied and an indication displayed indicating if the threshold(s) have been exceeded.


