Timestamp Selector for Event Record Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid increase in machine-generated data creates large, complex datasets that are difficult to analyze, especially when unstructured, making it challenging to determine effective extraction rules for field values, leading to improper or omitted values.

Innovation Solution

A graphical user interface is provided to identify and split timestamp information across locations within event records, allowing users to select and associate locations with timestamp information, which can then be used to generate extraction rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If users manually analyze large datasets to determine extraction rules, then extraction accuracy can be improved, but the time and complexity of analysis increases significantly

Engineering Contradiction:
Improveextraction rule accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically generating extraction rules through machine learning algorithms that analyze event data and timestamps without requiring manual user intervention. The extractor automatically identifies patterns and creates extraction rules, eliminating the time-consuming manual analysis process while maintaining high accuracy through algorithmic pattern recognition.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual analysis process with an automated computational system. Machine learning models and algorithms substitute human analysts, using computational power to rapidly process large datasets and generate extraction rules, thereby reducing analysis time while preserving or improving accuracy through systematic pattern recognition.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual extraction rules are created for unstructured machine data, then data extraction accuracy can be improved, but the complexity of determining correct rules increases

Engineering Contradiction:
Improvefield value extraction accuracyVSAvoidextraction rule determination complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces complex manual rule creation with automated machine learning systems that process unstructured machine data. The system uses algorithms to automatically identify patterns in event timestamps and data structures, generating extraction rules without requiring users to manually analyze and determine complex rules, thereby reducing determination complexity while maintaining extraction accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The extraction system performs self-service by automatically analyzing unstructured machine data and generating appropriate extraction rules. The machine learning model independently determines how to extract field values from various data formats, eliminating the need for users to manually create and manage complex extraction rules for different data types.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive extraction rules are applied to terabyte-scale datasets, then data analysis completeness can be improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvedata analysis completenessVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary action by pre-processing and indexing event data before comprehensive analysis. Machine learning models pre-identify patterns and structures in the data, creating optimized extraction rules in advance. This preliminary processing enables subsequent comprehensive analysis of terabyte-scale datasets to be completed more efficiently, maintaining completeness while improving processing speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual comprehensive data analysis with automated machine learning systems that can efficiently process terabyte-scale datasets. The computational system uses optimized algorithms and parallel processing to apply extraction rules across large volumes of data, maintaining comprehensive analysis coverage while significantly improving processing speed compared to manual methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11709850B1Using a timestamp selector to select a time information and a type of time information
Publication Date: 2023.07.25 CISCO TECHNOLOGY INC
  • US11709850B1 patent drawing
  • US11709850B1 patent drawing
  • US11709850B1 patent drawing

AI summary

Embodiments are directed towards a graphical user interface identify locations within event records with splittable timestamp information. A display of event records is provided using any of a variety of formats. A splittable timestamp selector allows a user to select one or more locations within event records as having time related information that may be split across the one or more locations, including, information based on date, time of day, day of the week, or other time information. Any of a plurality of mechanisms is used to associate the selected locations with the split timestamp information, including tags, labels, or header information within the event records. In other embodiments, a separate table, list, index, or the like may be generated that associates the selected locations with the split timestamp information. The split timestamp information may be used within extraction rules for selecting subsets or the event records.