Flexible Schema Data Intake System for Machine Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing and searching massive quantities of machine-generated data from diverse sources in data centers is challenging due to the unstructured nature of the data and the difficulty in applying semantic meaning, leading to inefficiencies in processing and retrieval.

Innovation Solution

A data intake and query system utilizing a flexible schema and late-binding schema that processes and stores machine data as events with timestamps, allowing for field-searchable and semantically-related data retrieval, even from disparate sources, using extraction rules and configuration files to refine searches dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If machine data from diverse sources is processed and stored with minimal processing to maintain flexibility, then adaptability and retrieval efficiency are improved, but data volume and storage requirements increase significantly

Engineering Contradiction:
Improvedata retrieval flexibilityVSAvoiddata volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts and stores only essential metadata and structural information from machine data while maintaining the ability to retrieve and analyze specific fields on demand. Configuration files define extraction rules that identify and store key parameters without duplicating entire data sets, reducing storage requirements while preserving adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements a universal data model that can handle multiple data sources and formats through a common schema framework. This multi-functional approach allows the same storage structure to accommodate diverse machine data types without requiring separate processing pipelines for each source, improving efficiency while managing data volume.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If data is processed and structured immediately upon ingestion, then search and analysis efficiency are improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesearch efficiencyVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary structuring by defining schemas and extraction rules in advance through configuration files. These pre-defined structures enable rapid data parsing and field extraction during ingestion without requiring complex real-time processing, thus improving search efficiency while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic processing approach where the level of data structuring adapts based on query requirements. Configuration files allow the system to dynamically select which fields to process and structure, enabling efficient searches for common parameters while avoiding unnecessary processing of less frequently accessed data.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If extensive processing and structuring is applied to machine data, then semantic meaning and searchability are improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata semantic meaningVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system changes parameters by applying different levels of processing intensity based on data type and query requirements. Configuration files define parameter extraction rules that transform raw machine data into structured formats with semantic meaning only when necessary, reducing processing complexity while maintaining data precision for searches that require it.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces configuration files as an intermediary layer between raw machine data and the search system. These files contain extraction rules and schema definitions that automatically translate diverse data formats into a common structured format, improving semantic meaning without requiring complex processing logic in the main system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Speed

If real-time data processing is implemented for immediate insights, then response time is improved, but computational resource consumption increases

Engineering Contradiction:
Improveresponse timeVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system applies partial processing by focusing computational resources on extracting and structuring only the specific fields required for real-time monitoring and analysis. Configuration files enable the system to perform selective field extraction rather than processing entire data sets, achieving fast response times with reduced computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11023511B1Mobile device composite interface for dual-sourced incident management and monitoring system
Publication Date: 2021.06.01 CISCO TECHNOLOGY INC
  • US11023511B1 patent drawing
  • US11023511B1 patent drawing
  • US11023511B1 patent drawing

AI summary

An application executing on a mobile computing platform provides independent data channels over a mobile network to multiple separate computing systems that each maintain some data pertinent to problem determination and resolution when an incident arises in a monitored information technology (IT) environment. The application maintains and separately exercises the channels to provide timely information in a user interface that composites data to present a single interface with a multi-sourced contextual rendering. Some systems may include an IT monitoring system and a separate incident management system among its sources. Channels may include extended functionality to improve security or other aspects of communication with mobile platforms.