Event-Based Data Drill Down via Keyword Indexing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data analysts face challenges in identifying valuable correlations and patterns within large volumes of heterogeneous performance data from various sources, particularly due to the unstructured nature of the data and the difficulty in applying semantic meaning, which hampers efficient analysis and strategic insights.
Innovation Solution
The implementation of an event-based system like SPLUNKĀ® ENTERPRISE, which uses a late-binding schema to process and store data as events, allowing for flexible extraction of information and enabling users to refine extraction rules at search time, facilitates the analysis of unstructured performance data by converting raw data into timestamped events and utilizing a keyword index for fast querying.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If data is stored in unstructured format at ingestion time, then data processing speed is improved, but data analysis capability deteriorates
Solution Approach 1:
The patent applies preliminary action by extracting and indexing key information from unstructured data at ingestion time without full processing. The system performs preliminary text extraction, keyword identification, and indexing during data ingestion, creating a structured framework that enables both fast processing and effective analysis later. This preliminary structuring allows the system to maintain processing speed while enabling subsequent analytical capabilities.
Solution Approach 2:
The patent segments data processing into multiple stages: initial unstructured ingestion, text extraction, keyword identification, indexing, and subsequent analysis. By dividing the data processing pipeline into discrete segments, the system can process data quickly in the ingestion phase while maintaining the capability for detailed analysis in later phases without requiring full processing at each stage.
2Difficulty of detecting and measuring
If all data is processed and structured at ingestion time, then data analysis capability is improved, but processing time and resource consumption increase
Solution Approach 1:
The patent applies partial action by performing only essential text extraction and keyword indexing at ingestion time, rather than complete data processing and structuring. This partial processing provides sufficient structure for effective analysis while avoiding the time and resource costs of comprehensive preprocessing. The system does exactly what is needed for subsequent analysis without over-processing the data.
3Measurement precision
If detailed extraction rules are applied at ingestion time, then data extraction precision is improved, but system complexity increases
Solution Approach 1:
The patent applies dynamics by making extraction rules configurable and adaptable rather than fixed. The system allows extraction rules to be modified, adjusted, and optimized based on specific data types and analysis requirements. This dynamic approach enables precise extraction when needed while keeping the system flexible enough to simplify rules for different scenarios, balancing precision with manageable complexity.
Data Source
AI summary
In embodiments of statistics chart row mode drill down, a first interface is displayed in a table format that includes columns and rows, where each row is associated with an event and each column includes field for a respective event. The rows can further include one or more aggregated metrics representing a number of events associated with a respective row. A row can be emphasized in the first interface and, in response a menu can be displayed with selectable options to transition to a second interface, where the data displayed by the second interface is based on an option selected from the menu.


