IP Library Granted Patent US 9,369,368
Granted Patent B2
US 9,369,368 · App. 14/244,315 · Granted Jun 14, 2016

Systems and methods for capturing and consolidating packet tracing in a cluster system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,368
App. No.
14/244,315
Granted
Jun 14, 2016
Kind
B2
Abstract

The present solution relates to systems and methods for capturing and consolidating packet tracing in a cluster system. A multi-nodal cluster processing network traffic contains multiple nodes each handling some of the processing. A node may initially receive a flow and transfer processing of the flow to another node for processing. A flow may therefore pass from one node to another, from two nodes to many nodes. In some instances, it is helpful to generate a trace of a flow. For example, in debugging a network communication flow, a trace of the flow through the cluster can be helpful. Each node has a packet engine (“PE”) which processes data packets and can, when trace is enabled, generate a trace file for the packets processed at the respective node. A trace aggregator merges these distinct trace files into an aggregate trace for the cluster.

Claims (33)

1. A system for consolidating packet trace messages of a cluster of intermediary devices, the system comprising:

a cluster of intermediary devices interconnected by a communication back plane, each of the intermediary devices comprising one or more network interfaces for communications via a network,

a plurality of packet processors each configured to process network packets received at one or more of the network interfaces and write messages to a respective trace buffer, the messages comprising information to trace the network packets and source information identifying the respective packet processor and a sequence number, and

at least one trace aggregator configured to gather the messages into a device log and a first intermediary device of the cluster further configured to collect the respective device logs into an aggregated device log for the cluster.

2. The system of claim 1 , wherein each intermediary device comprises a plurality of cores, and each core of the plurality of cores is configured to execute one or more of the plurality of packet processors.

3. The system of claim 1 , wherein the respective trace buffers are stored in memory shared between the plurality of packet processors.

4. The system of claim 1 , wherein the at least one trace aggregator is further configured to read trace log entries from the trace buffers, apply a filtering constraint to the trace entries, and aggregate the trace entries satisfying the filtering constraint into the device log.

5. The system of claim 1 , wherein each packet processor of the plurality of packet processors is further configured to write packet trace messages to its respective trace buffer responsive to being placed in a trace mode by a control message.

6. The system of claim 5 , wherein each packet processor of the plurality of packet processors is configured to stop writing messages to its respective trace buffer responsive to being removed from the trace mode by a second control message, and wherein the first intermediary device in the cluster of intermediary devices is configured to collect the respective device logs after generating the second control message.

7. The system of claim 1 , wherein the first intermediary device of the cluster is further configured to sort the collected device logs in the aggregated device log for the cluster according to the sequence numbers.

8. The system of claim 1 , wherein the sequence numbers are synchronized time stamps.

9. The system of claim 1 , wherein each packet processor of the plurality of packet processors is configured to operate in between at least one of a logging mode or a non-logging mode, responsive to a control message, and each packet processor is configured to transmit its respective device log to the first intermediary device upon entering the non-logging mode.

10. The system of claim 1 , wherein each respective trace buffer is a ring buffer.

11. A method for consolidating packet trace messages of a cluster of intermediary devices, the method comprising:

writing, by each packet processor of a plurality of packet processors in each intermediary device of a cluster of intermediary devices interconnected by a communication back plane, messages to a trace buffer, the messages comprising information to trace the network packets processed by each respective packet processor and source information identifying the respective packet processor and a sequence number;

gathering, by a trace aggregator for each intermediary device, the messages from the trace buffers into a device log for the respective intermediary device; and

collecting, by a first intermediary device in the cluster of intermediary devices, the device logs from each of the intermediary devices for an aggregated device log for the cluster.

12. The method of claim 11 , wherein each intermediary device comprises a plurality of cores, and each core of the plurality of cores is configured to execute one or more of the plurality of packet processors.

13. The method of claim 11 , further comprising:

reading, by the trace aggregator, trace log entries from the trace buffers;

applying, by the trace aggregator, a filtering constraint to the trace entries; and

aggregating, by the trace aggregator, the trace entries satisfying the filtering constraint into the device log.

14. The method of claim 11 , further comprising writing, by each packet processor, packet trace messages to its respective trace buffer responsive to being placed in a trace mode by a control message.

15. The method of claim 14 , further comprising ceasing, by each packet processor, to write packet trace messages to its respective trace buffer responsive to being removed from the trace mode by a second control message, and collecting, by the first intermediary device, the respective device logs after generating the second control message.

16. The method of claim 11 , further comprising sorting, by the first intermediary device, the collected device logs in the aggregated device log for the cluster according to the sequence numbers.

17. The method of claim 11 , further comprising transmitting, by the first packet processor, its respective device log to the first intermediary device.

18. The method of claim 17 , further comprising receiving, by the first packet processor, a control message; terminating packet trace collection responsive to receiving the control message; and transmitting, by the first packet processor, its respective device log to the first intermediary device after terminating the packet trace collection.

19. A system comprising:

a cluster of intermediary devices interconnected by a communication back plane, each of the intermediary devices comprising one or more network interfaces for communications via a network,

a plurality of packet processors each configured to process network packets received at one or more of the network interfaces and write messages to a respective trace buffer, the messages comprising information to trace the network packets,

at least one trace aggregator configured to gather the messages into a device log and a first intermediary device of the cluster further configured to collect the respective device logs into an aggregated device log for the cluster,

wherein each packet processor of the plurality of packet processors is configured to write packet trace messages to its respective trace buffer responsive to being placed in a trace mode by a control message and to stop writing messages to its respective trace buffer responsive to being removed from the trace mode by a second control message, and

wherein the first intermediary device in the cluster of intermediary devices is configured to collect the respective device logs after generating the second control message.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2014
From: KHANAL, KRISHNA; CHANDRA, SHEKHAR; ANNAMALAISAMI, SARAVANA
To: CITRIX SYSTEMS, INC.
Reel/Frame 032604/0758 →