IP Library Granted Patent US 12706932
Granted Patent B1
US 12706932 · App. 17/957,137 · Granted Aug 11, 2026

Dynamic updating of agent operation by way of a data platform

Inventors: Anil K. Nanduri (Fremont, CA); Xiaofei Guo (Sunnyvale, CA); Ross T. Bunker (Seattle, WA); Alex Ramachandran Nirmala (Cupertino, CA); Matti A. Vanninen (Cary, NC); Chirag P. Pandya (Sammamish, WA); Yijou Chen (Cupertino, CA)
Assignee: FORTINET, INC.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706932
App. No.
17/957,137
Granted
Aug 11, 2026
Kind
B1
Abstract

An illustrative method for operating software agent deployed within a compute environment may include directing the software agent to collect and transmit, to a data platform, a first type of workload data associated with one or more workloads deployed within the compute environment, detecting, while the software agent is operating to collect and transmit the first type of workload data, a request for the software agent to collect a second type of workload data associated with the one or more workloads, and directing, based on the request and without modifying executable code of the software agent, the software agent to collect and transmit, to the data platform, the second type of workload data.

Claims (30)

1 . A method comprising:

directing a software agent deployed within a compute environment to collect and transmit, to a data platform, a first type of workload data associated with a first activity for one or more workloads deployed within the compute environment;

detecting, while the software agent is operating to collect and transmit the first type of workload data, a request for the software agent to collect a second type of workload data associated with a second activity for the one or more workloads, wherein the second activity type of workload data is different than the first activity type of workload data; and

directing, based on the request and without modifying executable code of the software agent, the software agent to collect and transmit, to the data platform, the second type of workload data.

2 . The method of claim 1 , wherein the request for the software agent to collect the second type of workload data is performed by a select one or more of the data platform, the software agent, or a computing device associated with an entity associated with the compute environment.

3 . The method of claim 1 , wherein the request for the software agent to collect the second type of workload data is based on a detection of an anomaly associated with the first type of workload data.

4 . The method of claim 1 , wherein the request for the software agent to collect the second type of workload data is based on an analysis of workload data associated with one or more workloads included in a compute environment separate from the compute environment.

5 . The method of claim 1 , wherein the request for the software agent to collect the second type of workload data is based on a graph comprising a plurality of nodes connected by a plurality of edges, wherein each node of the plurality of nodes represents a logical entity from the first type of workload data and each edge of the plurality of edges represents a behavioral relationship between nodes connected by the edge.

6 . The method of claim 1 , wherein the directing the software agent to collect and transmit the second type of workload data comprises updating configuration data that is accessed by the software agent.

7 . The method of claim 6 , wherein the updating the configuration data includes transmitting, by the data platform, the configuration data to the software agent.

8 . The method of claim 6 , wherein the software agent is configured to phone home to the data platform to access the updated configuration data.

9 . The method of claim 1 , wherein the collection of the second type of workload data is in place of the collection of the first type of workload data.

10 . The method of claim 1 , wherein the collection of the second type of workload data is in addition to the collection of the first type of workload data.

11 . The method of claim 1 , wherein the software agent is configured to transmit both the first and second types of workload data by exporting the first and second types of workload data into a dataset that uses a same schema specified by the data platform.

12 . The method of claim 11 , wherein the schema allows the dataset to be queried using a query language associated with the data platform.

13 . The method of claim 1 , wherein the first type of workload data is associated with a first workload and wherein the second type of workload data is associated with a second workload that is different than the first workload.

14 . The method of claim 1 , wherein the first type of workload data is associated with a first event associated with the one or more workloads and the second type of workload data is associated with a second event associated with the one or more workloads.

15 . The method of claim 1 , further comprising directing the software agent to filter a select one or both of the first type of workload data or the second type of workload data prior to transmitting the first type of workload data or the second type of workload data to the data platform.

16 . The method of claim 15 , wherein the directing the software agent to filter the select one or both of the first type of workload data or the second type of workload data comprises updating configuration data that is accessed by the software agent.

17 . The method of claim 15 , wherein the software agent is configured to filter the select one or both of the first type of workload data or the second type of workload data by using an eBPF module included in a kernel of an operating system associated with the one or more workloads.

18 . The method of claim 1 , wherein the software agent is configured to collect a select one or both of the first type of workload data or the second type of workload data by using one or more eBPF modules included in a kernel of an operating system associated with the one or more workloads.

19 . A method comprising:

collecting and transmitting, to a data platform, by a software agent deployed within a compute environment, a first type of workload data associated with a first activity for one or more workloads deployed within the compute environment;

detecting, by the software agent while the software agent is operating to collect and transmit the first type of workload data, a change in configuration data maintained by the data platform; and

collecting and transmitting, to the data platform, by the software agent based on the change in the configuration data, a second type of workload data associated with a second activity for the one or more workloads, wherein the second activity type of workload data is different than the first activity type of workload data.

20 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

directing a software agent deployed within a compute environment to collect and

transmit, to a data platform, a first type of workload data associated with a first activity for one or more workloads deployed within the compute environment;

detecting, while the software agent is operating to collect and transmit the first type of workload data, a request for the software agent to collect a second type of workload data associated with a second activity for the one or more workloads, wherein the second activity type of workload data is different than the first activity type of workload data; and

directing, based on the request and without modifying executable code of the software agent, the software agent to collect and transmit, to the data platform, the second type of workload data.