Query Execution via Bucket-Node Mapping in Data Intake Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data intake and query systems lack efficient tools for quickly searching and analyzing large sets of raw machine data, particularly in IT environments, where massive volumes of diverse data types are generated, making it challenging to identify data subsets of interest visually and easily.

Innovation Solution

A data intake and query system architecture that includes a flexible schema for event-based data processing, using containerized indexing and search nodes to store and retrieve data in a common storage system, enabling real-time search and analysis through a pipelined search language and late-binding schema.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If massive volumes of diverse raw machine data are stored for later retrieval and analysis, then data flexibility and analysis capability are improved, but data retrieval efficiency and analysis speed deteriorate

Engineering Contradiction:
Improvedata flexibilityVSAvoiddata retrieval efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the large volume of raw machine data into discrete events with specific schemas. Each event is structured with defined fields and data types, transforming the unstructured mass into organized, queryable units. This segmentation enables efficient retrieval while maintaining flexibility through the event-based architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an event schema as an intermediary layer between raw machine data and analysis tools. The schema defines the structure and properties of events, acting as a mediator that enables efficient querying and analysis while preserving the flexibility to handle diverse data types through standardized event formats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If tools search data systems separately and collect results over a network, then comprehensive data coverage is improved, but search speed and user ease of operation deteriorate

Engineering Contradiction:
Improvedata coverageVSAvoidsearch ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate data system searches into a unified event-based search interface. By consolidating diverse data sources into a common event schema framework, the system provides comprehensive data coverage through a single search operation, eliminating the need for users to separately query multiple data systems and manually aggregate results.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If pre-processing extracts specified data items based on anticipated analysis needs, then retrieval efficiency for those items is improved, but data flexibility and ability to analyze all generated data deteriorate

Engineering Contradiction:
Improveretrieval efficiencyVSAvoiddata flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic event schema that can adapt to different analysis needs without requiring pre-processing decisions. The schema allows the system to efficiently retrieve and analyze any subset of the generated data based on actual query requirements, providing both retrieval efficiency and flexibility through its dynamic, query-driven architecture.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11874691B1Managing efficient query execution including mapping of buckets to search nodes
Publication Date: 2024.01.16 CISCO TECHNOLOGY INC
  • US11874691B1 patent drawing
  • US11874691B1 patent drawing
  • US11874691B1 patent drawing

AI summary

Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system receives a query identifying a set of data to be processed and a manner of processing the set of data. The data intake and query system identifies buckets that are to be searched and search nodes to execute the query. The data intake and query system maps the identified buckets to the search nodes and executes the query using the identified bucket and search nodes.