Event Search Field-Value Drilldown for Unstructured Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing massive quantities of heterogeneous performance data at search time is challenging due to the unstructured nature of the data and the difficulty of applying semantic meaning, which can lead to missed valuable correlations and inefficient management of IT resources.
Innovation Solution
The SPLUNKĀ® ENTERPRISE system employs an event-based approach with a late-binding schema that allows flexible extraction of field values during search time, using extraction rules and parallel processing to analyze unstructured data effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If unstructured performance data is analyzed at search time, then valuable correlations can be identified, but computational delays increase and analysis efficiency decreases
Solution Approach 1:
The patent applies preliminary action by extracting and storing field values from unstructured performance data during data ingestion rather than waiting until search time. The system pre-processes the data by identifying and storing relevant field values in a structured format, so that when searches are performed, the analysis can quickly access already-processed information without undergoing computationally intensive extraction operations.
2Adaptability or versatility
If flexible field value extraction is implemented during search time, then adaptability to different data formats is improved, but processing speed decreases
Solution Approach 1:
The system performs field value extraction in advance during data ingestion, storing extracted values in a structured format that maintains flexibility for different data formats while enabling rapid retrieval during search operations. This pre-extraction approach preserves adaptability to heterogeneous data sources while eliminating the processing speed penalty that would occur if extraction were performed at search time.
3Quantity of substance
If massive quantities of heterogeneous data are collected, then comprehensive business intelligence is achieved, but data analysis complexity increases
Solution Approach 1:
The patent applies segmentation by dividing heterogeneous performance data into distinct field values during pre-processing. Each field value represents a specific attribute or parameter extracted from the unstructured data. This segmentation organizes the massive quantity of heterogeneous data into manageable, structured components that can be independently analyzed and queried, thereby reducing analysis complexity while preserving the comprehensive nature of the data collection.
Data Source
AI summary
In embodiments of field value search drill down, a search system exposes a search interface that displays one or more events returned as a search result set. A field-value pair can be emphasized in the field-value pairs of an event displayed in the search interface, and a menu is displayed with search options that are selectable to operate on the emphasized field-value pair of the event. The menu includes the search options to add search criteria of the emphasized field-value pair to a search command in a search bar of the search interface, exclude the search criteria of the emphasized field-value pair from a search, or create a new data search based on the emphasized field-value pair. A selection of one of the search options in the menu can be received, and the search command in the search bar is updated based on the search option that is selected.


