Event Subtype Definition Using User Examples
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face challenges in analyzing and searching massive quantities of heterogeneous machine-generated data due to its unstructured nature and the complexity of indexing and querying across diverse data sources, requiring tools that can simplify the selection of data subtypes for effective organization and retrieval.
Innovation Solution
A software and hardware facility is developed to define event subtypes using examples, allowing users to create and refine subtypes by selecting positive and negative examples, which uses machine-learning techniques to generate queries and apply visual indications for event classification, enabling easier organization and searching of machine-generated data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If machine-generated data is organized into events for analysis, then data retrieval capability is improved, but device complexity increases due to the need for indexing and querying infrastructure
Solution Approach 1:
The patent segments the large set of events into smaller subsets based on user-selected criteria. Instead of requiring users to search through all events, the system divides events into manageable subsets that can be independently analyzed and retrieved, reducing the complexity of the indexing infrastructure while maintaining retrieval capability.
Solution Approach 2:
The system performs preliminary filtering and organization of events into subsets before the user needs to search. By pre-organizing events based on user-selected criteria, the system reduces the workload of the indexing and querying infrastructure, as users only need to search within predefined subsets rather than the entire event set.
2Stability of the object's composition
If users manually organize and search through voluminous unstructured data, then data organization is achieved, but loss of time increases due to the manual effort required
Solution Approach 1:
The system enables users to define their own event subsets by selecting criteria that matter to their specific analysis needs. This self-service approach allows users to automatically organize data according to their requirements without manual intervention, reducing the time spent on data organization while maintaining stable and meaningful data composition.
Solution Approach 2:
The system allows users to dynamically change the parameters and criteria for event subset definition. By enabling flexible parameter adjustment, the system adapts to different analysis requirements without requiring manual reorganization, thus maintaining data organization stability while minimizing time loss.
3Measurement precision
If computing resources are allocated for searching and analyzing massive data sets, then search effectiveness is improved, but use of energy increases due to the computational load
Solution Approach 1:
The patent extracts and isolates specific subsets of events that are relevant to user-defined criteria, separating them from the larger dataset. This extraction reduces the amount of data that needs to be processed and searched, thereby improving search effectiveness for relevant events while reducing the computational energy required compared to searching the entire dataset.
Solution Approach 2:
Instead of processing and searching the entire massive dataset, the system applies partial action by focusing computational resources only on user-selected event subsets. This approach achieves sufficient search effectiveness for the relevant data while avoiding the excessive energy consumption that would result from processing all available data.
Data Source
AI summary
A facility for defining an event subtype using examples is described. The facility displays events identified among machine-generated data. The facility receives user input selecting a first subset of the events as examples of an event subtype. In response to receiving the user input, the facility displays a second subset of the events predicted to belong to the event subtype on the basis of the examples of the event subtype.


