Isolated Execution Log Extraction from Mixed Data Chunks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data analysis tools lack the ability to quickly and efficiently search and analyze large sets of raw machine data to visually identify data subsets of interest, particularly in IT environments with diverse and massive data systems, leading to challenges in managing and understanding the data for deriving insights.

Innovation Solution

A data intake and query system that utilizes a flexible schema and late-binding schema to process and search machine data, enabling field-searchability and allowing extraction rules to be applied at search time, facilitating the use of a common information model across disparate data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If tools are used to search data systems separately and collect results over a network, then data can be retrieved from multiple sources, but the analysis process becomes piecemeal and inefficient

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoiddata search complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent combines multiple separate data system searches into a single unified search operation. The system executes one search query across multiple data systems simultaneously, consolidating what would otherwise require multiple separate tool invocations and manual result aggregation. This merging eliminates the piecemeal analysis process while maintaining the ability to retrieve data from diverse sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system provides a universal search interface that can query across multiple different data systems with diverse schemas. Instead of requiring separate specialized tools for each data system, a single search mechanism handles multiple data sources uniformly, making the system adaptable to various data types and structures while simplifying the user operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If pre-processing is applied to extract specified data items for efficient retrieval, then analysis speed improves, but flexibility to analyze all generated data is reduced

Engineering Contradiction:
Improvedata retrieval speedVSAvoiddata analysis flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its processing approach based on the search query and data schema. Rather than applying fixed pre-processing extraction rules, the system can adjust its retrieval strategy in real-time, selecting which data items to extract and how to process them based on the specific analysis needs. This dynamic behavior maintains both speed and flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes processing parameters based on the search requirements. When a search query is executed, the system adjusts extraction and processing parameters to optimize for that specific query type, allowing efficient retrieval for common patterns while maintaining the capability to handle novel or complex queries that require different processing approaches.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If massive quantities of raw data are stored for later retrieval, then analysis flexibility increases, but search and analysis efficiency decreases

Engineering Contradiction:
Improveanalysis flexibilityVSAvoidsearch efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system performs preliminary indexing and schema registration actions when data is first ingested, even before any search queries are executed. This preliminary organization of data metadata and structure enables efficient retrieval later without requiring full data processing. The preliminary action prepares the data for fast searching while maintaining the ability to analyze all raw data when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12417210B2Log data extraction from data chunks of an isolated execution environment
Publication Date: 2025.09.16 CISCO TECHNOLOGY INC
  • US12417210B2 patent drawing
  • US12417210B2 patent drawing
  • US12417210B2 patent drawing

AI summary

Systems and methods are disclosed for processing data associated with isolated execution environments. A chunk of data associated with an isolated execution environment can include log data and non-log data. At least a portion of the log data can include log data generated by the isolated execution environment. The system can parse the chunk of data to identify the log data and the non-log data and extract at least a portion of the log data from the chunk of data. The extracted data can be further processed to generate one or more events.