Source Type Definition Configuration for Data Intake Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face challenges in analyzing large volumes of machine-generated data due to its unstructured nature and varying types and formats, which complicates the application of semantic meaning and efficient processing.

Innovation Solution

A data intake and query system is configured to enable users to create, modify, and synchronize source type definitions across multiple components, allowing for customized data processing, indexing, and searching through user interfaces that generate and store configuration files, facilitating consistent data handling across different processing stages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If the system processes large volumes of machine-generated data from multiple sources with varying formats, then the data analysis capability is improved, but the system complexity increases due to the need to handle diverse data types and apply semantic meaning

Engineering Contradiction:
Improvevolume of machine dataVSAvoidsystem complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system segments data processing by introducing source type definitions that categorize different data formats and sources. Each source type (e.g., JSON, XML, CSV, log files) has its own processing rules and semantic interpretations, allowing the system to handle diverse data volumes through structured segmentation rather than monolithic processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes processing parameters dynamically based on source type definitions. When new data sources or formats are introduced, the system can modify configuration parameters related to parsing, indexing, and semantic interpretation without changing the core processing architecture, thus managing complexity while handling increasing data volumes

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the system provides customized data processing configurations for different source types, then the adaptability to various data formats is improved, but the configuration management complexity increases

Engineering Contradiction:
Improveadaptability to data formatsVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal configuration framework where source type definitions serve multiple functions: data parsing, semantic interpretation, indexing strategies, and query optimization. This multi-functional approach allows customized processing for different formats without requiring separate management systems for each configuration aspect

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses template-based configuration copying where common processing patterns are defined as reusable templates. When configuring new source types, the system can copy and adapt existing templates rather than creating configurations from scratch, reducing configuration management complexity while maintaining adaptability

Inventive Principle:
Principle #26Copying

3Reliability

If the system synchronizes source type definitions across multiple components, then the data handling consistency is improved, but the synchronization overhead and time required increase

Engineering Contradiction:
Improvedata handling consistencyVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary synchronization of source type definitions before data processing begins. By pre-synchronizing configurations across all components (indexers, search heads, forwarders), the system ensures consistency is established in advance, reducing the need for continuous synchronization during operation and minimizing time loss

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms that monitor configuration synchronization status and automatically adjust synchronization timing. When changes are detected, the system triggers targeted synchronization only to affected components, reducing overall synchronization overhead while maintaining consistency reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11789901B2Source type definition configuration using a graphical user interface
Publication Date: 2023.10.17 CISCO TECHNOLOGY INC
  • US11789901B2 patent drawing
  • US11789901B2 patent drawing
  • US11789901B2 patent drawing

AI summary

A data intake and query system provides interfaces that enable users to configure source type definitions used by the system. A data intake and query system generally refers to a system for collecting and analyzing data including machine-generated data. Such a system may be configured to consume many different types of machine data generated by any number of different data sources including various servers, network devices, applications, etc. At a high level, a source type definition comprises one or more properties that define how various components of a data intake and query system collect, index, store, search and otherwise interact with particular types of data consumed by the system. The interfaces provided by the system generally comprise one or more interface components for configuring various attributes of a source type definition.