Ingestion Buffer Location Marker Updates for Shared Storage Buckets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current tools lack the ability to efficiently search and analyze large sets of raw machine data from diverse sources, particularly in IT environments, due to the complexity and volume of data generated by various devices, which hinders quick identification of data subsets of interest.

Innovation Solution

A data intake and query system that utilizes a flexible schema to process and store machine data as events with timestamps, allowing for field-searchable queries and late-binding schema application during search time, enabling efficient retrieval and analysis of all generated data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored as raw machine data from diverse sources, then data flexibility and completeness are improved, but data search and analysis complexity increases

Engineering Contradiction:
Improvedata flexibilityVSAvoiddata search complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments raw machine data into discrete events with specific schemas, organizing diverse data sources into manageable units that can be independently processed and searched, reducing overall system complexity while maintaining data flexibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary indexing layer that sits between raw data storage and query operations, using location markers and event schemas to mediate between diverse data formats and search requirements, simplifying the search process without losing data flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data is pre-processed to reduce volume, then data analysis efficiency is improved, but data completeness and flexibility are lost

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoiddata flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by assigning event schemas and location markers to raw data during ingestion, organizing data in advance without pre-processing the actual content, enabling efficient future analysis while preserving complete raw data for flexible querying

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial pre-processing by only indexing metadata and location markers rather than processing entire data sets, achieving sufficient efficiency for many queries while leaving full data flexibility intact for complex analysis

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If location markers are updated frequently in the ingestion buffer, then data retrieval accuracy is improved, but system performance and speed are reduced

Engineering Contradiction:
Improvedata retrieval accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent implements periodic updates of location markers in the ingestion buffer, updating markers at intervals rather than continuously, maintaining sufficient retrieval accuracy while reducing the performance overhead of constant updates

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent updates only the necessary portion of location markers (partial action) rather than the entire buffer, achieving required retrieval accuracy for active queries while minimizing the performance impact of update operations

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11250056B1Updating a location marker of an ingestion buffer based on storing buckets in a shared storage system
Publication Date: 2022.02.15 CISCO TECHNOLOGY INC
  • US11250056B1 patent drawing
  • US11250056B1 patent drawing
  • US11250056B1 patent drawing

AI summary

Systems and methods are disclosed for processing and executing queries in a data intake and query system. An indexing system of the data intake and query system receives data from an ingestion buffer that includes a marker that indicates data that is made available to the indexing system. The data intake and query system stores at least a portion of the data in buckets and stores the buckets in a shared storage system. Based on the storage of the buckets in the shared storage system, the indexing system indicates to the ingestion buffer that the marker can be updated.