Log Query Interface for Multi-Line Event Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional logging products face difficulties in analyzing large volumes of log data due to their reliance on raw text search and preformatted data structures, making it challenging to parse log files, identify issues, and find errors across multiple data sets and applications in distributed computing systems.

Innovation Solution

A graphical user interface is developed that allows users to define and link parsing rules for unstructured and structured log data, enabling the selection of lines, searching for matching lines, tokenizing attributes, and forming aggregated rules to correlate messages across multiple log lines and files, thereby identifying events that occur across multiple lines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If conventional logging products use raw text search or preformatted data structures to analyze log data, then the analysis process is simple, but the ability to parse log files, identify issues, and find errors across multiple data sets and applications deteriorates

Engineering Contradiction:
Improvesimplicity of analysis processVSAvoidability to parse and identify issues
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments log analysis into multiple hierarchical levels: individual log line parsing, pattern matching across lines, event correlation, and aggregate analysis. This segmentation allows the system to handle complex multi-dataset analysis by breaking it down into manageable processing stages, each contributing to the overall reliability of issue identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal log analysis framework that can handle multiple data sets and applications simultaneously through a single integrated system. The framework provides multi-functional capabilities including parsing, pattern matching, correlation, and aggregation, allowing one system to perform various analysis tasks across diverse log sources, thereby improving reliability without requiring separate specialized tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the volume and variety of log files increase in distributed computing networks, then the coverage of monitoring improves, but the difficulty and tedium of analyzing log data increases

Engineering Contradiction:
Improvecoverage of monitoringVSAvoiddifficulty of analysis
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities through automated pattern recognition and correlation algorithms that independently analyze log data without requiring manual intervention for each log line. The system automatically parses logs, identifies patterns, correlates events, and generates insights, allowing the analysis process to serve itself and reducing the operational burden despite increasing log volume and variety.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent adds dimensional layers to log analysis by introducing temporal correlation, cross-file pattern matching, and hierarchical event aggregation. Instead of analyzing logs in a single linear dimension, the system correlates events across multiple dimensions including time sequences, file relationships, and pattern hierarchies, making the analysis of large volumes of diverse logs more manageable and less tedious.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If conventional products rely on preformatted data structures, then the processing speed is fast, but the flexibility to handle unstructured and varied log formats deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidflexibility to handle various formats
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent employs dynamic parsing capabilities that adapt to different log formats in real-time. The system uses flexible pattern matching rules that can be configured to handle various structured and unstructured log formats, allowing the processing speed to be optimized for each specific format while maintaining the ability to handle diverse log types from different sources and applications.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11126614B2Log query user interface
Publication Date: 2021.09.21 NEW RELIC INC
  • US11126614B2 patent drawing
  • US11126614B2 patent drawing
  • US11126614B2 patent drawing

AI summary

A series of graphical user interfaces allows a user to define rules for parsing unstructured and structured log data and generate an aggregate rule to identify events across multiple lines of one or more log files. A first graphical user interface allows a user to select a line from a log file under analysis, search for matching lines in the log file, define rules for parsing the log file, and tokenize attributes of the selected lines. A second user interface allows the user to aggregate defined rules so that messages may be correlated to identify events that occur across multiple lines.