Event-Based Data Intake System for Flexible Machine Data Querying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing and searching massive quantities of machine data presents challenges due to its vastness and diversity, requiring efficient methods to manage, understand, and utilize this data effectively.

Innovation Solution

An event-based data intake and query system processes, indexes, and stores machine data as events, allowing for flexible schema application at search time, enabling field-searchable capabilities and efficient querying across diverse data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If massive quantities of raw machine data are stored for later retrieval and analysis, then data analysis flexibility and completeness are improved, but data storage requirements and retrieval complexity increase

Engineering Contradiction:
Improvedata analysis flexibilityVSAvoiddata storage requirements
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments machine data into discrete events with structured fields, organizing massive data volumes into manageable, queryable units. Each event contains specific fields (timestamp, host, source, sourcetype, etc.) that can be independently indexed and searched, transforming unwieldy raw data into organized, analysis-ready information while maintaining storage efficiency through selective field extraction and indexing.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If diverse data from numerous devices is collected and stored, then data diversity and insight potential are improved, but data management and search complexity increase

Engineering Contradiction:
Improvedata diversityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal event schema that can accommodate diverse machine data from numerous devices through a common structure. The event format with standardized fields (timestamp, host, source, sourcetype, etc.) provides a multi-functional framework that handles various data types uniformly, enabling consistent management and search across heterogeneous data sources while preserving data diversity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies local quality by allowing specific field structures and data types to vary according to the data source and context while maintaining an overall uniform event framework. Different devices can contribute events with source-specific field variations, enabling tailored data capture for each device type while maintaining global consistency through the common event schema and standardized indexing approach.

Inventive Principle:
Principle #3Local quality

3Productivity

If pre-processing is applied to reduce data volume, then data retrieval efficiency is improved, but data analysis flexibility and completeness deteriorate

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoiddata analysis completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent performs preliminary action by structuring and indexing key fields during data ingestion without discarding raw data. The system pre-processes data to extract and index essential fields (timestamp, host, source, sourcetype) for efficient retrieval, while maintaining the complete event structure for later comprehensive analysis. This preliminary organization enables fast search while preserving all original data for complete analysis when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250036645A1Execution of a second query on a set of data identified for execution of a first query
Publication Date: 2025.01.30 CISCO TECHNOLOGY INC
  • US20250036645A1 patent drawing
  • US20250036645A1 patent drawing
  • US20250036645A1 patent drawing

AI summary

Systems and methods are described for generation and execution of modified queries. An input can be received via a visualization of a user interface. The input may identify a first field value and a first field for execution of a query. A set of data for execution of the query can be identified based on the input. Alias data may identify a second field that is associated with the first field. Using the alias data, a modified query can be generated based on the query and the second field. The modified query can be executed to generate query results. The query results can be displayed via a visualization of the user interface based on the first field.