Leading Indicator Identification for Event Forecasting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing and searching massive quantities of machine-generated data from diverse sources in data centers is challenging due to the vast amounts of different types and formats of data, which can be time-consuming and requires efficient methods to identify leading indicators for event forecasting.

Innovation Solution

An event-based data intake and query system, such as the SPLUNKĀ® ENTERPRISE system, is used to collect, index, and search machine-generated data, employing a late-binding schema and flexible data modeling to extract relevant information, allowing for the identification of leading indicators that predict future events, providing users with sufficient time to react.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional data analysis methods are used on massive quantities of machine-generated data, then complete data examination is achieved, but analysis time becomes excessively long and efficiency decreases

Engineering Contradiction:
Improveevent forecasting efficiencyVSAvoiddata analysis time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously collecting and indexing machine-generated data in advance, organizing it into searchable structures before analysis is needed. This pre-processing enables rapid querying and identification of leading indicators when forecasting events, avoiding the need to analyze raw data from scratch each time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts only the relevant leading indicators and specific patterns from the massive quantities of collected data that are most likely to predict target events. Rather than examining all data, the system identifies and focuses on key indicators such as specific log patterns, performance metrics, or error sequences that have historical correlation with future events

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If comprehensive data from diverse sources is collected and analyzed, then prediction accuracy improves, but system complexity and data processing difficulty increase

Engineering Contradiction:
Improveevent prediction accuracyVSAvoiddata processing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements a universal data intake and query architecture that can handle multiple data types and formats from diverse sources through a single platform. The late-binding schema and flexible data modeling capabilities allow the same system to process various data sources (logs, metrics, traces) without requiring separate processing pipelines for each source type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary layer consisting of the data intake platform and query interface that mediates between diverse data sources and the analysis process. This intermediary handles data normalization, indexing, and retrieval, shielding the analysis logic from the complexity of raw data heterogeneity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Duration of action of moving object

If early warning time is extended to allow sufficient user reaction time, then user response capability improves, but the search period must be extended further into the past increasing data processing requirements

Engineering Contradiction:
Improveuser reaction timeVSAvoidhistorical data volume to process
Core Design Contradiction:
Duration of action of moving objectVSQuantity of substance

Solution Approach 1:

The system extracts and monitors only the critical leading indicators that are most predictive of target events, rather than analyzing all historical data. By focusing on specific patterns, metrics, or sequences that have demonstrated correlation with future events, the system can provide early warnings using a manageable subset of historical data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary indexing and organization of historical data structures in advance, creating efficient query capabilities that allow rapid analysis of extended time periods. This pre-structured data organization enables the system to search through large historical volumes without proportional increases in processing time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11915156B1Identifying leading indicators for target event prediction
Publication Date: 2024.02.27 CISCO TECHNOLOGY INC
  • US11915156B1 patent drawing
  • US11915156B1 patent drawing
  • US11915156B1 patent drawing

AI summary

Embodiments of the present invention are directed to facilitating event forecasting. In accordance with aspects of the present disclosure, a set of events determined from raw machine data is obtained. The events are analyzed to identify leading indicators that indicate a future occurrence of a target event, wherein the leading indicators occur during a search period of time the precedes a warning period of time, thereby providing time for an action to be performed prior to an occurrence of a predicted target event. At least one of the leading indicators is used to predict a target event. An event notification is provided indicating the prediction of the target event.