IP Library Granted Patent US 10,127,273
Granted Patent B2
US 10,127,273 · App. 14/253,713 · Granted Nov 13, 2018

Distributed processing of network data using remote capture agents

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,127,273
App. No.
14/253,713
Granted
Nov 13, 2018
Kind
B2
Abstract

The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains one or more event streams from one or more remote capture agents over one or more networks, wherein the one or more event streams include event data generated from network packets captured by the one or more remote capture agents. Next, the system applies one or more transformations to the one or more event streams to obtain transformed event data from the event data. The system then enables querying of the transformed event data.

Claims (59)

1. A computer-implemented method performed by a transformation server coupled via a network to a plurality of remote capture agents and used to improve processing of network data collected by the plurality of remote capture agents distributed across the network, the method comprising:

receiving configuration information from a configuration server over the network, wherein the configuration information is usable by the transformation server to generate event streams containing transformed timestamped events;

receiving timestamped events from one or more of the plurality of remote capture agents over the network, the timestamped events generated from network packets captured by the one or more of the plurality of remote capture agents;

identifying, in the configuration information received from the configuration server, information describing an event stream to be generated by transforming the timestamped events received from the one or more of the plurality of remote capture agents into transformed timestamped events, the information indicating one or more fields to be included in the transformed timestamped events and further indicating, for at least one field of the one or more fields, an identifier of data in the timestamped events to be transformed to obtain a value for the at least one field, and a type of transformation to apply to the data in the timestamped events to obtain the value for the at least one field; and

generating, based on the configuration information received from the configuration server, the event stream containing the transformed timestamped events by transforming the timestamped events received from the one or more of the plurality of remote capture agents into the transformed timestamped events.

2. The computer-implemented method of claim 1 , further comprising storing in a data store at least one of the timestamped events and the transformed timestamped events.

3. The computer-implemented method of claim 1 , further comprising enabling querying of the transformed timestamped events, wherein enabling querying of the transformed timestamped events comprises:

indexing the transformed timestamped events; and

executing queries on the indexed transformed timestamped events.

4. The computer-implemented method of claim 1 , further comprising:

indexing the transformed timestamped events; and

executing queries on the indexed transformed timestamped events, wherein execution of a query is performed on different subsets of the transformed timestamped events by one or more indexers in parallel.

5. The computer-implemented method of claim 1 , further comprising:

receiving a query requesting information from the transformed timestamped events; and

executing the query using at least one of a database and a log file.

6. The computer-implemented method of claim 1 , wherein the type of transformation comprises at least one of: an aggregation, a calculation, a filter, a normalization, and a formatting.

7. The computer-implemented method of claim 1 , wherein at least one of the timestamped events includes an identifier of a type of transaction associated with the at least one of the timestamped events.

8. The computer-implemented method of claim 1 , further comprising transmitting the transformed timestamped events over the network to a set of indexers, wherein the set of indexers are used to process queries using a late-binding schema of the transformed timestamped events.

9. The computer-implemented method of claim 1 , wherein the type of transformation is an aggregation operation that aggregates the timestamped events across multiple events to produce aggregated information, and generates transformed timestamped events including the aggregated information.

10. The computer-implemented method of claim 1 , wherein the information describing the event stream further indicates, for at least one field of the one or more fields, a name used to identify the at least one field.

11. A system used to improve processing of network data collected by a plurality of remote capture agents distributed across a network, comprising:

the plurality of remote capture agents implemented by a first one or more computing devices; and

a transformation server implemented by a second one or more computing devices, the transformation server including instructions that upon execution cause the transformation server to:

receive configuration information from a configuration server over the network, wherein the configuration information is usable by the transformation server to generate event streams containing transformed timestamped events;

receive timestamped events from one or more of the plurality of remote capture agents over the network, the timestamped events generated from network packets captured by the one or more of the plurality of remote capture agents;

identify, in the configuration information received from the configuration server, information describing an event stream to be generated by transforming the timestamped events received from the one or more of the plurality of remote capture agents into transformed timestamped events, the information indicating one or more fields to be included in the transformed timestamped events and further indicating, for at least one field of the one or more fields, an identifier of data in the timestamped events to be transformed to obtain a value for the at least one field, and a type of transformation to apply to the data in the timestamped events to obtain the value for the at least one field; and

generating, based on the configuration information received from the configuration server, the event stream containing the transformed timestamped events by transforming the timestamped events received from the one or more of the plurality of remote capture agents into the transformed timestamped events.

12. The system of claim 11 , wherein each of the plurality of remote capture agents includes instructions that upon execution cause the remote capture agent to:

generate timestamped events by applying one or more other transformations to the timestamped events; and

transmit the timestamped events to the one or more transformation servers.

13. The system of claim 11 , wherein the instructions, upon execution, further cause the transformation server to store in a data store at least one of: the timestamped events and the transformed timestamped events.

14. The system of claim 11 , wherein enabling the instructions, upon execution, further cause the transformation server to:

index the transformed timestamped events; and

execute queries on the indexed transformed timestamped events.

15. The system of claim 11 , wherein the instructions, upon execution, further cause the transformation server to:

index the transformed timestamped events; and

execute queries on the indexed transformed timestamped events, wherein execution of a query is performed on different subsets of the transformed timestamped events by one or more indexers in parallel.

16. The system of claim 11 , wherein the type of transformation comprises at least one of: an aggregation, a calculation, a filter, a normalization, and a formatting.

17. The system of claim 11 , further comprising an indexer implemented by a third one or more computing devices, the indexer including instructions that upon execution cause the indexer to:

receive the transformed timestamped events over the network from the transformation server; and

processing a query using a late-binding schema of the transformed timestamped events.

18. The system of claim 11 , wherein the type of transformation is an aggregation operation that aggregates the timestamped events across multiple events to produce aggregated information, and generates transformed timestamped events including the aggregated information.

19. The system of claim 11 , wherein the information describing the event stream further indicates, for at least one field of the one or more fields, a name used to identify the at least one field.

20. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause performance of operations comprising:

receiving configuration information from a configuration server over a network, wherein the configuration information is usable by a transformation server to generate event streams containing transformed timestamped events;

receiving timestamped events from one or more of the plurality of remote capture agents over the network, the timestamped events generated from network packets captured by the one or more of the plurality of remote capture agents;

identifying, in the configuration information received from the configuration server, information describing an event stream to be generated by transforming the timestamped events received from the one or more of the plurality of remote capture agents into transformed timestamped events, the information indicating one or more fields to be included in the transformed timestamped events and further indicating, for at least one field of the one or more fields, an identifier of data in the timestamped events to be transformed to obtain a value for the at least one field, and a type of transformation to apply to the data in the timestamped events to obtain the value for the at least one field; and

generating, based on the configuration information received from the configuration server, the event stream containing the transformed timestamped events by transforming the timestamped events received from the one or more of the plurality of remote capture agents into the transformed timestamped events.

21. The non-transitory computer-readable storage medium of claim 20 , wherein the instructions, when executed by the one or more processors, further cause performance of operations comprising storing in a data store at least one of: the timestamped events and the transformed events.

22. The non-transitory computer-readable storage medium of claim 20 , wherein the instructions, when executed by the one or more processors, further cause performance of operations comprising enabling querying of the transformed timestamped events, wherein enabling querying of the transformed timestamped events comprises:

indexing the transformed timestamped events; and

executing queries on the indexed transformed timestamped events.

23. The non-transitory computer-readable storage medium of claim 20 , wherein the instructions, when executed by the one or more processors, further cause performance of operations comprising:

indexing the transformed timestamped events; and

executing queries on the indexed transformed timestamped events, wherein execution of a query is performed on different subsets of the transformed timestamped events by one or more indexers in parallel.

24. The non-transitory computer-readable storage medium of claim 20 , wherein the type of transformation comprises at least one of: an aggregation, a calculation, a filter, a normalization, and a formatting.

25. The non-transitory computer-readable storage medium of claim 20 , wherein at least one of the timestamped events includes an identifier of a type of transaction associated with the at least one of the timestamped events.

26. A non-transitory computer-readable storage medium of claim 20 , wherein the type of transformation is an aggregation operation that aggregates the timestamped events across multiple events to produce aggregated information, and generates transformed timestamped events including the aggregated information.

27. A non-transitory computer-readable storage medium of claim 20 , wherein the information describing the event stream further indicates, for at least one field of the one or more fields, a name used to identify the at least one field.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2014
From: DICKEY, MICHAEL
To: SPLUNK INC.
Reel/Frame 032929/0739 →
Cited By (60)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,284,207 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,348 US 12,348,545 US 12,355,626 US 12,355,793 US 12,368,745 US 12,381,901 US 12,401,669 US 12,407,701 US 12,407,702 US 12,418,555 US 12,452,272 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,489,771 US 12,495,052 US 12,506,762 US 12,511,110 US 12,526,297 US 12,537,836 US 12,549,575 US 12,549,577 US 12,556,559 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,935 US 12,580,937 US 12,592,950 US 12,598,205 US 12,613,930 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,333 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896