IP Library Patent Application 14253767
Patent Application
App. No. 14/253,767

GRAPHICAL CONFIGURATION OF EVENT STREAMS FOR NETWORK DATA CAPTURE AND PROCESSING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/253,767
Abstract

The disclosed embodiments provide a method and system for facilitating processing of network data. During operation, the system provides a graphical user interface (GUI) for obtaining configuration information for configuring the generation of event data from network data obtained from network packets at one or more remote capture agents. Next, the system enables use of the GUI in configuring the connection of one or more event streams containing the event data to one or more reactors for subsequent processing of the event data by the one or more reactors.

Claims (47)

1 . A computer-implemented method for facilitating processing of network data, comprising:

providing a graphical user interface (GUI) for obtaining configuration information for configuring the generation of event data from network data obtained from network packets at one or more remote capture agents; and

enabling use of the GUI in configuring the connection of one or more event streams comprising the event data to one or more reactors for subsequent processing of the event data by the one or more reactors by:

displaying one or more graphical representations of the one or more event streams in the GUI,

displaying one or more additional graphical representations of the one or more reactors in the GUI, wherein the one or more reactors include: collection reactors that collect event data, processing reactors that process event data, and storage reactors that store event data, and

enabling a user of the GUI to use a graphical linkage that implies a data flow direction to connect the one or more graphical representations of the one or more event streams and the one or more additional graphical representations of the one or more reactors;

wherein connecting a graphical representation of an event stream to a graphical representation of a reactor causes events from the event stream to pass into the reactor, which performs processing operations on the events to facilitate processing of the network data.

2 . The computer-implemented method of claim 1 , further comprising:

providing the configuration information over a network to the one or more remote capture agents, wherein the configuration information is used to configure the generation of the event data at the one or more remote capture agents during runtime of the one or more remote capture agents.

3 . The computer-implemented method of claim 1 , further comprising:

enabling use of the GUI in configuring the subsequent processing of the event data by the one or more reactors.

4 . The computer-implemented method of claim 1 , wherein the one or more reactors comprise at least one of a collection reactor, a processing reactor, and a storage reactor.

5 . The computer-implemented method of claim 1 , wherein the one or more reactors are provided by one or more transformation servers that transform the event data.

6 . The computer-implemented method of claim 1 , wherein the configuration information comprises at least one of a description, an event stream type, a custom field, and an additional parameter.

7 . The computer-implemented method of claim 1 , wherein the configuration information is obtained using a configuration dialog of the GUI.

8 . (canceled)

9 . The computer-implemented method of claim 1 , wherein the configuration information is further used to configure the transformation of the network data or the event data into transformed event data at the one or more remote capture agents.

10 . A system for facilitating processing of network data, comprising:

a graphical user interface (GUI) configured to:

obtain configuration information for configuring the generation of event data from network data obtained from network packets at one or more remote capture agents; and

enable the configuration of the connection of one or more event streams comprising the event data to one or more reactors for subsequent processing of the event data by the one or more reactors by:

displaying one or more graphical representations of the one or more event streams in the GUI,

displaying one or more additional graphical representations of the one or more reactors in the GUI, wherein the one or more reactors include: collection reactors that collect event data, processing reactors that process event data, and storage reactors that store event data, and

enabling a user of the GUI to use a graphical linkage that implies a data flow direction to connect the one or more graphical representations of the one or more event streams and the one or more additional graphical representations of the one or more reactors;

wherein connecting a graphical representation of an event stream to a graphical representation of a reactor causes events from the event stream to pass into the reactor, which performs processing operations on the events to facilitate processing of the network data; and

a configuration server configured to:

provide the GUI; and

provide the configuration information over a network to the one or more remote capture agents, wherein the configuration information is used to configure the generation of the event data at the one or more remote capture agents during runtime of the one or more remote capture agents.

11 . The system of claim 10 , wherein the GUI is further configured to:

enable the configuration of the subsequent processing of the event data by the one or more reactors.

12 . The system of claim 10 , wherein the one or more reactors comprise at least one of a collection reactor, a processing reactor, and a storage reactor.

13 . The system of claim 10 , wherein the configuration information comprises at least one of a description, an event stream type, a custom field, and an additional parameter.

14 . The system of claim 10 , wherein the configuration information is obtained using a configuration dialog of the GUI.

15 . (canceled)

16 . The system of claim 10 , wherein the configuration information is further used to configure the transformation of the network data or the event data into transformed event data at the one or more remote capture agents.

17 . A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for facilitating processing of network data, the method comprising:

providing a graphical user interface (GUI) for obtaining configuration information for configuring the generation of event data from network data obtained from network packets at one or more remote capture agents; and

enabling use of the GUI in configuring the connection of one or more event streams comprising the event data to one or more reactors for subsequent processing of the event data by the one or more reactors by:

displaying one or more graphical representations of the one or more event streams in the GUI,

displaying one or more additional graphical representations of the one or more reactors in the GUI, wherein the one or more reactors include: collection reactors that collect event data, processing reactors that process event data, and storage reactors that store event data, and

enabling a user of the GUI to use a graphical linkage that implies a data flow direction to connect the one or more graphical representations of the one or more event streams and the one or more additional graphical representations of the one or more reactors;

wherein connecting a graphical representation of an event stream to a graphical representation of a reactor causes events from the event stream to pass into the reactor, which performs processing operations on the events to facilitate processing of the network data.

18 . The non-transitory computer-readable storage medium of claim 17 , the method further comprising:

enabling use of the GUI in configuring the subsequent processing of the event data by the one or more reactors.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the one or more reactors comprise at least one of a collection reactor, a processing reactor, and a storage reactor.

20 . The non-transitory computer-readable storage medium of claim 17 , wherein the configuration information comprises at least one of a description, an event stream type, a custom field, and an additional parameter.

21 . (canceled)

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2014
From: DICKEY, MICHAEL
To: SPLUNK INC.
Reel/Frame 032929/0751 →