IP Library Patent Application 14528932
Patent Application
App. No. 14/528,932

STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/528,932
Abstract

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system provides, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets. The system then includes the one or more event attributes specified through the first set of user-interface elements in the configuration information.

Claims (103)

1 . A method for facilitating the processing of network data, comprising:

providing, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents;

providing, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets; and

including the one or more event attributes specified through the first set of user-interface elements in the configuration information.

2 . The method of claim 1 , further comprising:

providing the configuration information over a network to the one or more remote capture agents, wherein the configuration information is used to configure the generation of the time-series event data at the one or more remote capture agents during runtime of the one or more remote capture agents.

3 . The method of claim 1 , further comprising:

providing, in the GUI, a second set of user-interface elements for managing the event stream; and

obtaining the protocol classification for the event stream from the second set of user-interface elements.

4 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for managing the event stream, and

wherein managing the event stream comprises at least one of:

cloning the event stream from an existing event stream;

deleting the event stream;

enabling the event stream; and

disabling the event stream.

5 . The method of claim 1 , further comprising:

providing, in the GUI, a second set of user-interface elements for filtering the network packets prior to generating the time-series event data from the network packets.

6 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for filtering the network packets, and

wherein filtering the network packets is associated with at least one of:

a Boolean value;

a numeric comparison;

a definition;

a regular expression;

an exact match;

a partial match; and

an ordering.

7 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for filtering the network packets, and

wherein the second set of user-interface elements is used to apply a logical disjunction or a logical conjunction to a set of filters for filtering the network packets.

8 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for filtering the network packets, and

wherein the second set of user-interface elements is used to match a filter to any or all elements of a multi-value event attribute in the event stream.

9 . The method of claim 1 , further comprising:

providing, in the GUI, a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data that is included in the event stream.

10 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data, and

wherein the second set of user-interface elements comprises a user-interface element for identifying an event attribute as:

a key attribute used to generate a key representing the aggregated event data; or

an aggregation attribute to be aggregated prior to inclusion in the aggregated event data.

11 . The method of claim 1 ,

wherein the GUI comprises a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data, and

wherein the second set of user-interface elements comprises:

a first user-interface element for identifying an event attribute as:

a key attribute used to generate a key representing the aggregated event data; or

an aggregation attribute to be aggregated prior to inclusion in the aggregated event data; and

a second user-interface element for obtaining an aggregation interval over which the one or more event attributes are aggregated into the aggregated event data.

12 . The method of claim 1 , wherein the protocol classification comprises at least one of:

a transport layer protocol;

a session layer protocol;

a presentation layer protocol; and

an application layer protocol.

13 . An apparatus, comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the apparatus to:

provide a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents;

provide, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets; and

include the one or more event attributes specified through the first set of user-interface elements in the configuration information.

14 . The apparatus of claim 13 , wherein the memory further stores instructions that, when executed by the one or more processors, cause the apparatus to:

provide the configuration information over a network to the one or more remote capture agents, wherein the configuration information is used to configure the generation of the time-series event data at the one or more remote capture agents during runtime of the one or more remote capture agents.

15 . The apparatus of claim 13 , wherein the memory further stores instructions that, when executed by the one or more processors, cause the apparatus to:

provide, in the GUI, a second set of user-interface elements for managing the event stream; and

obtaining the protocol classification for the event stream from the second set of user-interface elements.

16 . The apparatus of claim 13 , wherein the memory further stores instructions that, when executed by the one or more processors, cause the apparatus to:

provide, in the GUI, a second set of user-interface elements for filtering the network packets prior to generating the time-series event data from the network packets.

17 . The apparatus of claim 13 ,

wherein the GUI comprises a second set of user-interface elements for filtering the network packets, and

wherein filtering the network packets is associated with at least one of:

a Boolean value;

a numeric comparison;

a definition;

a regular expression;

an exact match;

a partial match; and

an ordering.

18 . The apparatus of claim 13 , wherein the memory further stores instructions that, when executed by the one or more processors, cause the apparatus to:

provide, in the GUI, a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data that is included in the event stream.

19 . The apparatus of claim 13 ,

wherein the GUI comprises a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data, and

wherein the second set of user-interface elements comprises:

a first user-interface element for identifying an event attribute as:

a key attribute used to generate a key representing the aggregated event data; or

an aggregation attribute to be aggregated prior to inclusion in the aggregated event data; and

a second user-interface element for obtaining an aggregation interval over which the one or more event attributes are aggregated into the aggregated event data.

20 . A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for facilitating the processing of network data, the method comprising:

providing, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents;

providing, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets; and

including the one or more event attributes specified through the first set of user-interface elements in the configuration information.

21 . The non-transitory computer-readable storage medium of claim 20 , the method further comprising:

providing the configuration information over a network to the one or more remote capture agents, wherein the configuration information is used to configure the generation of the time-series event data at the one or more remote capture agents during runtime of the one or more remote capture agents.

22 . The non-transitory computer-readable storage medium of claim 20 , the method further comprising:

providing, in the GUI, a second set of user-interface elements for managing the event stream; and

obtaining the protocol classification for the event stream from the second set of user-interface elements.

23 . The non-transitory computer-readable storage medium of claim 20 , the method further comprising:

providing, in the GUI, a second set of user-interface elements for filtering the network packets prior to generating the time-series event data from the network packets.

24 . The non-transitory computer-readable storage medium of claim 20 ,

wherein the GUI comprises a second set of user-interface elements for aggregating the one or more event attributes into aggregated event data, and

wherein the second set of user-interface elements comprises:

a first user-interface element for identifying an event attribute as:

a key attribute used to generate a key representing the aggregated event data; or

an aggregation attribute to be aggregated prior to inclusion in the aggregated event data; and

a second user-interface element for obtaining an aggregation interval over which the one or more event attributes are aggregated into the aggregated event data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2014
From: SCHERBAKOV, VLADIMIR A.; DICKEY, MICHAEL R.; NOEL, CARY GLEN; RAMASAYAM, KISHORE R.; BELONGIE, MIGNON L.
To: SPLUNK INC.
Reel/Frame 034219/0707 →