IP Library Granted Patent US 12695681
Granted Patent B1
US 12695681 · App. 17/732,064 · Granted Jul 28, 2026

Systems and methods for analytics of edge device ingested data

Inventor: Alexander William Cruise (Vancouver, CA)
Assignee: Cisco Technology, Inc.
H04L43/028H04W4/70H04W24/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695681
App. No.
17/732,064
Granted
Jul 28, 2026
Kind
B1
Abstract

A computerized method is disclosed that includes operations of obtaining ingested data from a plurality of edge devices, performing analyses of the ingested data from each of the plurality of edge devices, wherein the analyses include performing machine learning modeling on the ingested data from each of the plurality of edges to determine predicted values for data expected to be ingested by each of the plurality of edge devices, and based on results generated from performing the machine learning modeling, determining whether predicted values for data expected to be ingested by each of the plurality of edge devices satisfies a predetermined condition for each of the plurality of edge devices. The machine learning modeling may utilize contextual data corresponding to one or more of the plurality of edge devices, wherein contextual data corresponding to a first edge device is data obtained by a device other than the first edge device.

Claims (47)

1 . A computerized method comprising:

obtaining, at a server computer system, correlated data from a plurality of edge devices,

wherein the correlated data includes ingested data that has undergone processing by at least a first edge device of the plurality of edge devices prior to transmission of the correlated data to the server computer system by the first edge device, and

wherein the processing comprises a correlation operation that includes an evaluation of relatedness between (i) data ingested by the first edge device and (ii) data ingested by a second edge device of the plurality of edge devices;

performing, by the server computer system, analyses of the correlated data from the plurality of edge devices, wherein the analyses include performing, by one or more processors of the server computer system, machine learning modeling on the correlated data from the plurality of edges, wherein the machine learning modeling results in a determination of predicted values for data expected to be ingested by the plurality of edge devices;

determining, by the server computer system, whether the predicted values for data expected to be ingested by the plurality of edge devices satisfies a threshold comparison for the plurality of edge devices; and

transmitting, by the server computer system, global instructions to the plurality of edge devices upon the predicted values satisfying the threshold comparison, wherein the global instructions are (i) generated based on the correlated data from the plurality of edge devices for use in determining local instructions to be updated through replacement or modification and (ii) configured to cause updating of the local instructions that are stored by and directed to controlling operations for indexing, storing, searching, or extracting raw data or data items from the raw data by each of the plurality of edge devices in response to the predicted values for data satisfying the threshold comparison,

wherein the local instructions are executable by one or more processors for each of the plurality of edge devices to perform the operations as part of data intake and query processes performed by each of the plurality of edge devices.

2 . The computerized method of claim 1 , wherein the machine learning modeling utilizes contextual data corresponding to one or more of the plurality of edge devices, wherein contextual data corresponding to a first edge device is data obtained by a device other than the first edge device.

3 . The computerized method of claim 1 , wherein performing the analyses of the correlated data is initiated by user input requesting performance of a simulation of future ingested data by at least a subset of the plurality of edge devices.

4 . The computerized method of claim 1 , wherein determining whether the predicted values satisfy the threshold comparison for the plurality of edge devices includes performing a comparison of the predicted values for the plurality of edge devices to one or more thresholds.

5 . The computerized method of claim 4 , further comprising:

based on results of comparing the predicted values to the one or more thresholds, transmitting a communication to one or more of the plurality of edge devices, wherein the communication includes instructions for performing analyses on subsequently ingested data or for transmitting the subsequently ingested data to a server computer system communicatively coupled to the plurality of edge devices.

6 . The computerized method of claim 1 , wherein performing machine learning modeling includes deployment of an individual trained machine learning model for each type of edge device include in the plurality of edge devices.

7 . The computerized method of claim 6 , wherein each individual trained machine learning model is trained using data obtained by a corresponding edge device.

8 . A non-transitory computer readable storage medium having stored thereon instructions, the instructions being executable by one or more processors to perform operations comprising:

obtaining, at a server computer system, correlated data from a plurality of edge devices,

wherein the correlated data includes ingested data that has undergone processing by a first edge device of the plurality of edge devices prior to transmission of the correlated data to the server computer system by the first edge device, and

wherein the processing includes a correlation operation that includes an evaluation of relatedness between at least (i) data ingested by the first edge device and (ii) data ingested by a second edge device of the plurality of edge devices;

performing, by the server computer system, analyses of the correlated data from the plurality of edge devices, wherein the analyses include performing, by one or more processors of the server computer system, machine learning modeling on the correlated data from the plurality of edges, wherein the machine learning modeling results in a determination of predicted values for data expected to be ingested by the plurality of edge devices;

determining, by the server computer system, whether the predicted values for data expected to be ingested by the plurality of edge devices satisfies a threshold comparison for the plurality of edge devices; and

transmitting, by the server computer system, global instructions to the plurality of edge devices upon the predicted values satisfying the threshold comparison, wherein the global instructions are (i) generated based on the correlated data from the plurality of edge devices for use in determining local instructions to be updated through replacement or modification and (ii) configured to cause updating of the local instructions that are stored by and directed to controlling operations for indexing, storing, searching, or extracting raw data or data items from the raw data by each of the plurality of edge devices,

wherein the local instructions are executable by one or more processors deployed within each of the plurality of edge devices to perform the operations as part of data intake and query processes performed by each of the plurality of edge devices.

9 . The non-transitory computer readable storage medium of claim 8 , wherein the machine learning modeling utilizes contextual data corresponding to one or more of the plurality of edge devices, wherein contextual data corresponding to a first edge device is data obtained by a device other than the first edge device.

10 . The non-transitory computer readable storage medium of claim 8 , wherein performing the analyses of the correlated data is initiated by user input requesting performance of a simulation of future ingested data by at least a subset of the plurality of edge devices.

11 . The non-transitory computer readable storage medium of claim 8 , wherein determining whether the predicted values satisfy the threshold comparison for the plurality of edge devices includes performing a comparison of the predicted values for the plurality of edge devices to one or more thresholds.

12 . The non-transitory computer readable storage medium of claim 11 , the instructions being executable by the one or more processors to perform further operations comprising:

based on results of comparing the predicted values to the one or more thresholds, transmitting a communication to one or more of the plurality of edge devices, wherein the communication includes instructions for performing analyses on subsequently ingested data or for transmitting the subsequently ingested data to a server computer system communicatively coupled to the plurality of edge devices.

13 . The non-transitory computer readable storage medium of claim 8 , wherein performing machine learning modeling includes deployment of an individual trained machine learning model for each type of edge device include in the plurality of edge devices.

14 . The non-transitory computer readable storage medium of claim 13 ,

wherein each individual trained machine learning model is trained using data obtained by a corresponding edge device.

15 . A system comprising:

a memory to store executable instructions; and

a processing device coupled with the memory, wherein the instructions, when executed by the processing device, cause operations including:

obtaining, at a server computer system, correlated data from a plurality of edge devices,

wherein the correlated data includes ingested data that has undergone processing by a first edge device of the plurality of edge devices prior to transmission of the correlated data to the server computer system by the first edge device,

wherein the processing includes a correlation operation that includes an evaluation of relatedness between at least (i) data ingested by the first edge device and (ii) data ingested by a second edge device of the plurality of edge devices, and

wherein the processing by the first edge device occurs prior to transmission of the correlated data to the server computer system by the first edge device;

performing, by the server computer system, analyses of the correlated data from the plurality of edge devices, wherein the analyses include performing, by one or more processors of the server computer system, machine learning modeling on the correlated data from the plurality of edges, wherein the machine learning modeling results in a determination of predicted values for data expected to be ingested by the plurality of edge devices;

determining, by the server computer system, whether the predicted values for data expected to be ingested by the plurality of edge devices satisfies a threshold comparison for the plurality of edge devices; and

transmitting, by the server computer system, global instructions to the plurality of edge devices upon the predicted values satisfying the threshold comparison, wherein the global instructions are (i) generated based on the correlated data from the plurality of edge devices for use in determining local instructions to be updated through replacement or modification and (ii) configured to cause updating of the local instructions that are stored by and directed to controlling operations for indexing, storing, searching, or extracting raw data or data items from the raw data by each of the plurality of edge devices in response to the predicted values for data satisfying the threshold comparison, wherein the local instructions are executable by one or more processors for each of the plurality of edge devices to perform the operations as part of data intake and query processes performed by each of the plurality of edge devices.

16 . The system of claim 15 , wherein the machine learning modeling utilizes contextual data corresponding to one or more of the plurality of edge devices, wherein contextual data corresponding to a first edge device is data obtained by a device other than the first edge device.

17 . The system of claim 15 , wherein performing the analyses of the correlated data is initiated by user input requesting performance of a simulation of future ingested data by at least a subset of the plurality of edge devices.

18 . The system of claim 15 , wherein determining whether the predicted values satisfy the threshold comparison for the plurality of edge devices includes performing a comparison of the predicted values for the plurality of edge devices to one or more thresholds.

19 . The system of claim 18 , wherein the operations further comprising:

based on results of comparing the predicted values to the one or more thresholds, transmitting a communication to one or more of the plurality of edge devices, wherein the communication includes instructions for performing analyses on subsequently ingested data or for transmitting the subsequently ingested data to a server computer system communicatively coupled to the plurality of edge devices.

20 . The system of claim 15 , wherein performing machine learning modeling includes deployment of an individual trained machine learning model for each type of edge device include in the plurality of edge devices.