Remote Bucket Catalog for Unified Data Query Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data intake and query systems lack efficient tools for quickly searching and analyzing large sets of raw machine data, particularly in IT environments, where massive volumes of diverse data types pose challenges for visualization and insight derivation.

Innovation Solution

A data intake and query system architecture that includes containerized indexing and search nodes, enabling flexible schema application at search time, bucket management, and query execution across a scalable environment, facilitating efficient data ingestion, indexing, and querying of machine data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If tools allow analysts to search data systems separately and collect results over a network, then data can be retrieved from diverse sources, but the analysis process becomes piecemeal and inefficient

Engineering Contradiction:
Improveability to search diverse data systemsVSAvoidefficiency of data analysis
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent combines multiple separate data system searches into a single unified search operation. The system integrates connections to diverse data systems (databases, cloud services, file systems) and allows analysts to search all these systems simultaneously through one interface, consolidating what would otherwise require multiple separate search operations into a single coordinated action that returns unified results.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system provides a universal search interface that works across multiple different data system types and formats. A single search tool can query relational databases, cloud storage services, local file systems, and other data sources using a consistent methodology, eliminating the need for separate specialized tools for each data system type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If massive quantities of raw data are stored for later retrieval and analysis, then greater flexibility in data analysis is enabled, but storage management and data retrieval complexity increase

Engineering Contradiction:
Improveflexibility in data analysisVSAvoidcomplexity of storage and retrieval system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically manages the complexity of storing and retrieving massive quantities of raw data from multiple sources. It performs self-service functions including automatic data ingestion from various systems, centralized storage management, and intelligent retrieval operations. The analyst simply initiates a search without needing to manually manage the underlying storage infrastructure or coordinate complex retrieval operations across multiple systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system acts as an intermediary layer between the analyst and the complex distributed storage infrastructure. It provides a simplified interface that abstracts away the complexity of data location, format differences, and retrieval coordination across multiple data systems. The intermediary handles all the complex operations of searching across diverse stored data sources and presenting unified results to the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If pre-processing is applied to reduce data volume before storage, then storage costs are reduced, but flexibility to analyze all generated data is lost

Engineering Contradiction:
Improvevolume of stored dataVSAvoidability to analyze all generated data
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary data ingestion and centralized storage of complete raw data from all sources before any analysis occurs. Rather than pre-processing data to reduce volume (which would lose information), the system captures and stores all generated data in its original form, preserving complete flexibility for future analysis. The preliminary action is data collection and centralized storage, not data reduction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10984044B1Identifying buckets for query execution using a catalog of buckets stored in a remote shared storage system
Publication Date: 2021.04.20 CISCO TECHNOLOGY INC
  • US10984044B1 patent drawing
  • US10984044B1 patent drawing
  • US10984044B1 patent drawing

AI summary

Systems and methods are disclosed for processing and executing queries in a data intake and query system. The data intake and query system maintains a catalog of buckets stored in a remote shared storage system. The buckets store raw machine data associated with a timestamp. The data intake and query receives a query identifying a set of data to be processed and a manner of processing the set of data, and executes the query based on the catalog of buckets.