Content Pack Management for Data Intake Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing and searching massive quantities of diverse machine data generated from various sources, such as system logs, network data, and sensor data, is challenging due to the vast amount of data types and formats, leading to inefficiencies in data retrieval and analysis.

Innovation Solution

An event-based data intake and query system with a flexible schema that allows for late-binding schema application, enabling the storage and search of raw machine data with field-searchability, using extraction rules and configuration files to process and index data on the fly, facilitating the use of a common information model across disparate data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If massive quantities of raw machine data are stored for later retrieval and analysis, then data flexibility and analytical opportunities are improved, but data retrieval and search efficiency deteriorate

Engineering Contradiction:
Improvedata flexibilityVSAvoiddata retrieval efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments raw machine data into structured fields and values during ingestion, creating a hierarchical data model where data is divided into manageable components (fields, values, events) that can be efficiently indexed and retrieved while preserving the complete raw data for flexibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary schema-based field extraction and indexing when data is ingested, organizing raw data into searchable fields and values before retrieval operations. This preliminary structuring enables efficient search without sacrificing the ability to analyze all raw data later

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If diverse data types and formats from numerous sources are retained, then analytical insights are improved, but system complexity increases

Engineering Contradiction:
Improveinformation completenessVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a universal schema-based data model that can accommodate diverse data types and formats from multiple sources through a common structure of fields, values, and events. This universal model handles varied data sources (logs, metrics, traces) uniformly, reducing system complexity while preserving information completeness

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses configurable schema parameters to adapt the data model to different data sources and types. By changing schema parameters and field definitions, the system can handle diverse data formats without requiring fundamentally different processing paths, thereby managing complexity while retaining complete data

Inventive Principle:
Principle #35Parameter changes

3Productivity

If pre-processing extracts specified data items for efficient retrieval, then data retrieval speed is improved, but data quantity and flexibility are reduced

Engineering Contradiction:
Improvedata retrieval speedVSAvoiddata quantity
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts specified data items (fields and values) from raw machine data during ingestion and stores them in an indexed structure for efficient retrieval. Simultaneously, it preserves the complete raw data in its original form, enabling both fast retrieval of specific items and access to the full data quantity for comprehensive analysis

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a nested data structure where indexed fields and values are embedded within the broader context of complete raw data events. This nesting allows the system to provide fast access to extracted fields while maintaining the ability to retrieve and analyze the complete nested event structure when needed

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11892988B1Content pack management
Publication Date: 2024.02.06 CISCO TECHNOLOGY INC
  • US11892988B1 patent drawing
  • US11892988B1 patent drawing
  • US11892988B1 patent drawing

AI summary

A method includes selecting, from content packs in a centralized content management system, a content pack to update in a data intake and query system. The content pack includes utility objects. For each utility object of at least a subset of the utility objects determining whether the utility object already exists in the data intake and query system, and loading the utility object to the data intake and query system when the utility object does not exist to obtain an updated utility object. The method further includes monitoring, by the data intake and query system, an endpoint of an endpoint type using the updated utility object.