Event Time Selection for Relative Data Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data analysts face challenges in navigating and analyzing vast amounts of data to identify patterns and correlations, particularly in unstructured performance data from diverse sources, which can be time-consuming and inefficient with conventional methods.

Innovation Solution

The implementation of an event-based system like SPLUNK ENTERPRISE, which uses a late-binding schema to process and store data as events, allowing for flexible data retrieval and analysis at search time, enabling efficient navigation and correlation of events through features like event time selection and relative time specification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data analysts use conventional methods to analyze vast amounts of data, then they can access and retrieve data, but the analysis process becomes time-consuming and inefficient

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoidtime required for data analysis
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically parsing, normalizing, and indexing data from multiple sources before analysis is needed. Events are pre-processed and stored with standardized schemas, enabling rapid retrieval and correlation during actual analysis without requiring time-consuming manual processing at query time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary event processing layer that acts as a mediator between raw data sources and analysis queries. This intermediary component standardizes diverse data formats into unified event objects, enabling efficient retrieval and correlation through standardized interfaces while abstracting the complexity of underlying data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data analysts manually navigate through unstructured performance data, then they can access detailed information, but the process becomes inefficient and patterns are difficult to identify

Engineering Contradiction:
Improveease of data navigationVSAvoidpattern identification efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments unstructured performance data into discrete, standardized event objects with consistent schemas. Each event represents a specific occurrence or measurement, separated from other data. This segmentation enables systematic navigation through individual events while maintaining the ability to identify patterns across the complete data set through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies parameter changes by transforming diverse unstructured data into standardized structured events with consistent fields and formats. By changing the parameter representation of data from varied unstructured formats to uniform structured schemas, the system enables efficient pattern recognition and correlation while simplifying the user interface for data navigation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If the system stores and processes data as events with late-binding schema, then flexible data retrieval is enabled, but device complexity increases

Engineering Contradiction:
Improveflexibility in data retrievalVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamics through late-binding schemas that can adapt to different data formats and structures at query time. The schema is not fixed beforehand but dynamically constructed based on the actual data being processed, enabling flexible retrieval of various data types while managing complexity through on-demand schema generation rather than maintaining multiple rigid schemas.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies universality by creating a single event processing framework that handles multiple data formats and sources through a common standardized schema. This universal approach enables the same processing infrastructure to accommodate diverse data types (logs, metrics, traces, etc.) without requiring separate specialized systems, thereby reducing overall complexity while increasing versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11687515B1Time selection to specify a relative time for event display
Publication Date: 2023.06.27 CISCO TECHNOLOGY INC
  • US11687515B1 patent drawing
  • US11687515B1 patent drawing
  • US11687515B1 patent drawing

AI summary

Event time selection output techniques are described. In one or more implementations, one or more inputs are received, at one or more computing devices, that involve interaction associated with a particular one of a plurality of events via a user interface, in which the plurality of events result from a search of data, each of the plurality of events include the data that is associated with a respective point in time, and the one or more inputs specify a relative time in relation to the respective point in time of the particular event. A determination is made as to which of the plurality of events correspond to the specified relative time by the one or more computing devices and a result of the determination is output by the one or more computing devices for display in the user interface.