Progressive charting of network traffic flow data
View Patent ↗Embodiments of the invention include an apparatus, method, and computer program for progressive charting of network traffic flow data. The method includes, in one example, receiving, at a network traffic analyzer, a query of network traffic flow data over a certain time period. The method further includes modifying the query to produce sub-queries each based on different segments of time within the certain time period, executing at least one of the sub-queries, and incrementally outputting results of each of said executed sub-queries as each of the sub-queries are completed.
1. A method, comprising:
scanning a plurality of network entities to report traffic flow data that encapsulates network traffic data;
selecting for reporting at least one network entity that transfers a largest amount of data among the plurality of network entities;
receiving, at a NetFlow network traffic analyzer, a query of network traffic flow data over a certain time period for the selected at least one network entity;
modifying the query to produce a plurality of sub-queries, wherein each of the sub-queries are based on different segments of time within the certain time period;
executing at least one of the sub-queries;
incrementally outputting results of each of said executed sub-queries as each of the sub-queries are completed; and
iteratively performing the incremental outputting until all of the sub-queries are completed,
wherein said incrementally outputting the results comprises immediately outputting the results of a sub-query when the sub-query is completed, wherein said immediately outputting the results of the sub-query further comprises generating a graphical chart illustrating the incremental results of the sub-query as the sub-query is completed, and wherein the query relates to traffic flow data from at least one network entity.
2. An apparatus, comprising:
a processor configured to control the apparatus to
scan a plurality of network entities to report traffic flow data that encapsulates network traffic data;
select for reporting at least one network entity that transfers a largest amount of data among the plurality of network entities;
a receiver comprised in a NetFlow network traffic analyzer, the receiver configured to receive a query of network traffic flow data over a certain time period for the selected at least one network entity; and
the processor further configured to control the apparatus to
modify the query to produce sub-queries each based on different segments of time within the certain time period;
execute at least one of the sub-queries; and
incrementally output results of said sub-queries as the sub-queries are completed; and
iteratively perform the incremental outputting until all of the sub-queries are completed,
wherein the processor is further configured to control the apparatus to immediately output the results of a sub-query when the sub-query is completed, and to generate a graphical chart illustrating the incremental results of the sub-query as the sub-query is completed, and
wherein the query relates to traffic flow data from at least one network entity.
3. A computer program, embodied on a non-transitory computer readable medium, the computer program configured to control a processor to perform operations comprising:
scanning a plurality of network entities to report traffic flow data that encapsulates network traffic data;
selecting for reporting at least one network entity that transfers a largest amount of data among the plurality of network entities;
receiving, at a NetFlow network traffic analyzer, a query of network traffic flow data over a certain time period for the selected at least one network entity;
modifying the query to produce sub-queries each based on different segments of time within the certain time period;
executing at least one of the sub-queries; and
incrementally outputting results of each of said executed sub-queries as each of the sub-queries are completed; and
iteratively performing the incremental outputting until all of the sub-queries are completed,
wherein said incrementally outputting the results comprises immediately outputting the results of a sub-query when the sub-query is completed, wherein said immediately outputting the results of the sub-query further comprises generating a graphical chart illustrating the incremental results of the sub-query as the sub-query is completed, and wherein the query relates to traffic flow data from at least one network entity.
4. An apparatus, comprising:
scanning means for scanning a plurality of network entities to report traffic flow data that encapsulates network traffic data;
selecting means for selecting for reporting at least one network entity that transfers a largest amount of data among the plurality of network entities;
receiving means for receiving, at a NetFlow network traffic analyzer, a query of network traffic flow data over a certain time period for the selected at least one network entity;
modifying means for modifying the query to produce sub-queries each based on different segments of time within the certain time period;
executing means for executing at least one of the sub-queries; and
outputting means for incrementally outputting results of each of said executed sub-queries as each of the sub-queries are completed,
wherein the outputting means comprises means for iteratively performing the incremental outputting until all of the sub-queries are completed,
wherein said outputting means comprises means for immediately outputting the results of a sub-query when the sub-query is completed, wherein said means for immediately outputting the results of the sub-query further comprises means for generating a graphical chart illustrating the incremental results of the sub-query as the sub-query is completed, and wherein the query relates to traffic flow data from at least one network entity.