Event Search Field-Value Drilldown for Unstructured Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing massive quantities of heterogeneous performance data at search time is challenging due to the unstructured nature of the data and the difficulty of applying semantic meaning, which can lead to missed valuable correlations and inefficient management of IT resources.

Innovation Solution

The SPLUNKĀ® ENTERPRISE system employs an event-based approach with a late-binding schema that allows flexible extraction of field values during search time, using extraction rules and parallel processing to analyze unstructured data effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If unstructured performance data is analyzed at search time, then valuable correlations can be identified, but computational delays increase and analysis efficiency decreases

Engineering Contradiction:
Improvevaluable correlationsVSAvoidcomputational delays
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent applies preliminary action by extracting and storing field values from unstructured performance data during data ingestion rather than waiting until search time. The system pre-processes the data by identifying and storing relevant field values in a structured format, so that when searches are performed, the analysis can quickly access already-processed information without undergoing computationally intensive extraction operations.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If flexible field value extraction is implemented during search time, then adaptability to different data formats is improved, but processing speed decreases

Engineering Contradiction:
Improveflexible extractionVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system performs field value extraction in advance during data ingestion, storing extracted values in a structured format that maintains flexibility for different data formats while enabling rapid retrieval during search operations. This pre-extraction approach preserves adaptability to heterogeneous data sources while eliminating the processing speed penalty that would occur if extraction were performed at search time.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If massive quantities of heterogeneous data are collected, then comprehensive business intelligence is achieved, but data analysis complexity increases

Engineering Contradiction:
Improvedata volumeVSAvoidanalysis complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing heterogeneous performance data into distinct field values during pre-processing. Each field value represents a specific attribute or parameter extracted from the unstructured data. This segmentation organizes the massive quantity of heterogeneous data into manageable, structured components that can be independently analyzed and queried, thereby reducing analysis complexity while preserving the comprehensive nature of the data collection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250258592A1Presenting events based on user-selected fields
Publication Date: 2025.08.14 CISCO TECHNOLOGY INC
  • US20250258592A1 patent drawing
  • US20250258592A1 patent drawing
  • US20250258592A1 patent drawing

AI summary

In embodiments of field value search drill down, a search system exposes a search interface that displays one or more events returned as a search result set. A field-value pair can be emphasized in the field-value pairs of an event displayed in the search interface, and a menu is displayed with search options that are selectable to operate on the emphasized field-value pair of the event. The menu includes the search options to add search criteria of the emphasized field-value pair to a search command in a search bar of the search interface, exclude the search criteria of the emphasized field-value pair from a search, or create a new data search based on the emphasized field-value pair. A selection of one of the search options in the menu can be received, and the search command in the search bar is updated based on the search option that is selected.