IP Library Granted Patent US 10,212,063
Granted Patent B2
US 10,212,063 · App. 15/390,416 · Granted Feb 19, 2019

Network aware distributed business transaction anomaly detection

Inventors: Harish Nataraj (Berkeley, CA); Ajay Chandel (Fremont, CA); Prakash Kaligotla (San Francisco, CA); Naveen Kondapalli (San Ramon, CA)
Assignee: Cisco Technology, Inc.
H04L43/0876H04L29/08072H04L41/0631H04L43/062H04L43/08H04L63/1408H04L41/046H04L41/22H04L43/087H04L43/0888
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,212,063
App. No.
15/390,416
Granted
Feb 19, 2019
Kind
B2
Abstract

A system monitors applications and network flows used during the business transaction to determine distributed business transaction anomalies caused at least in part by network performance issues. A network flow associated with a business transaction is monitored by a network agent. The network agent may capture packets, analyze the packets and other network data to determine one or more baselines, and dynamically compare subsequent network flow performance to those baselines to determine an anomaly. When an anomaly in a network flow is detected, this information may be provided to a user along with other data regarding a business transaction that is utilizing the network flow. Concurrently with the network agent monitoring, application agents may monitor one or more applications performing the business transaction. The present system reports performance data for a business transaction in terms of application performance and network performance, all in the context of a distributed business transaction.

Claims (39)

1. A method for monitoring a distributed business transaction over a plurality of machines and at least one network, comprising:

monitoring, by an application agent running on a host device in the at least one network, one or more applications running on the plurality of machines that process requests and perform one or more functions that make up the distributed business transaction to generate application data;

monitoring, by a network agent running on the host device in the at least one network, one or more sockets that are used to process one or more communications among the plurality of machines as part of the distributed business transaction by intercepting and performing packet capture on one or more packets from the one or more sockets to generate network flow data;

detecting, by the application agent, an application anomaly within at least one of the one or more monitored applications based on a performance baseline of the one or more application established by the application agent;

based on the detecting of the application anomaly, transmitting, by the application agent, a query to a plurality of network agents including the network agent to determine whether at least one of the plurality of network agents has detected a network flow anomaly, wherein the query includes one or more parameters that specify to the plurality of network agents which of the one or more communications to analyze to identify the network flow anomaly, and wherein the network flow anomaly is determined by the plurality of network agents based on a performance baseline of network flow established by the plurality of network agents;

based on the query, receiving, by the application agent, a detected network flow anomaly that is associated with the one or more communications specified by the one or more parameters;

transmitting, by the application agent, the detected application anomaly and the detected network flow anomaly to a controller device;

receiving, by the application agent and from the controller device, business transaction data associated with the distributed business transaction, wherein the business transaction data is indicative of a correlation between the detected application anomaly and the detected network flow anomaly, and wherein the correlation is based on stitching portions of data received from different agents into a plurality of groups of data associated with the distributed business transaction that identify the detected application anomaly as being affected by the detected network flow anomaly; and

receiving, by the application agent and from the controller device, a snapshot that displays the business transaction data on a web-based interface, the snapshot illustrating the plurality of machines associated with the detected application anomaly and performance of a network flow among the plurality of machines for the distributed business transaction, wherein the detected application anomaly is shown as being dependent on the performance of the network flow.

2. The method of claim 1 , wherein the query includes business transaction context Information, and wherein the network flow anomaly is determined by the plurality of network agents based on the business transaction context information.

3. The method of claim 1 , wherein the monitoring, by the application agent, the one or more applications includes collecting metrics associated with performance of the one or more applications on the plurality of machines that process the distributed business transaction.

4. The method of claim 1 , wherein the monitoring, by the network agent, the one or more sockets that are used to process the communications among the plurality of machines as part of the distributed business transaction includes collecting metrics associated with performance of a given network flow between the plurality of machines that process the distributed business transaction.

5. The method of claim 1 , wherein the correlation is further based on a grouping of the application data and the network flow data by matching address locations in the data received from the different agents.

6. The method of claim 1 , including providing a call graph that displays the correlated detected application anomaly and the detected network flow anomaly associated with the distributed business transaction.

7. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to cause operations for monitoring a distributed business transaction, including:

monitoring, by an application agent running on a host device in at least one network, one or more applications running on a plurality of machines that process requests and perform one or more functions that make up the distributed business transaction to generate application data;

monitoring, by a network agent running on the host device in the at least one network, one or more sockets that are used to process one or more communications among the plurality of machines as part of the distributed business transaction by intercepting and performing packet capture on one or more packets from the one or more sockets to generate network flow data;

detecting, by the application agent, an application anomaly within at least one of the one or more monitored applications based on a performance baseline of the one or more applications established by the application agent;

based on the detecting of the application anomaly, transmitting, by the application agent, a query to a plurality of network agents including the network agent to determine whether at least one of the plurality of network agents has detected a network flow anomaly, wherein the query includes one or more parameters that specify to the plurality of network agents which of the one or more communications to analyze to identify the network flow anomaly, and wherein the network flow anomaly is determined by the plurality of network agents based on a performance baseline of network flow established by the plurality of network agents;

based on the query, receiving, by the application agent, a detected network flow anomaly that is associated with the one or more communications specified by the one or more parameters;

transmitting, by the application agent, the detected application anomaly and the detected network flow anomaly to a controller device;

receiving, by the application agent and from the controller device, business transaction data associated with the distributed business transaction, wherein the business transaction data is indicative of a correlation between the detected application anomaly and the detected network flow anomaly, and wherein the correlation is based on stitching portions of data received from different agents into a plurality of groups of data associated with the distributed business transaction that identify the detected application anomaly as being affected by the detected network flow anomaly; and

receiving, by the application agent and from the controller device, a snapshot that displays the business transaction data on a web-based interface, the snapshot illustrating the plurality of machines associated with the detected application anomaly and performance of a network flow among the plurality of machines for the distributed business transaction, wherein the detected application anomaly is shown as being dependent on the performance of the network flow.

8. The non-transitory computer readable storage medium of claim 7 , wherein the query includes business transaction context information, and wherein the network flow anomaly is determined by the of plurality of network agents based on the business transaction context information.

9. The non-transitory computer readable storage medium of claim 7 , wherein the monitoring, by the application agent, the one or more applications include collecting metrics associated with performance of the one or more applications on the plurality of machines that process the distributed business transaction.

10. The non-transitory computer readable storage medium of claim 7 , the snapshot further Illustrating a call graph that displays the correlated detected application anomaly and the detected network flow anomaly associated with the distributed business transaction.

11. A system for monitoring a distributed business transaction performed by multiple computers, comprising:

a server including a memory and a processor; and

one or more modules stored in the memory and executable by the processor to perform operations including:

monitoring, by an application agent running on a host device in at least one network, one or more applications running on a plurality of machines that process requests and perform one or more functions that make up the distributed business transaction to generate application data;

monitoring, by a network agent running on the host device in the at least one network, one or more sockets that are used to process one or more communications among the plurality of machines as part of the distributed business transaction by intercepting and performing packet capture on one or more packets from the one or more sockets to generate network flow data;

detecting, by the application agent, an application anomaly within at least one of the one or more monitored applications based on a performance baseline of the one or more applications established by the application agent;

based on the detecting of the application anomaly, transmitting, by the application agent, a query to a plurality of network agents including the network agent to determine whether at least one of the plurality of network agents has detected a network flow anomaly, wherein the query includes one or more parameters that specify to the plurality of network agents which of the one or more communications to analyze to identify the network flow anomaly, and wherein the network flow anomaly is determined by the plurality of network agents based on a performance baseline of network flow established by the plurality of agents;

based on the query, receiving, by the application agent, a detected network flow anomaly that is associated with the one or more communications specified by the one or more parameters;

transmitting, by the application agent, the detected application anomaly and the detected network flow anomaly to a controller device;

receiving, by the application agent and from the controller device, business transaction data associated with the distributed business transaction, wherein the business transaction data is indicative of a correlation between the detected application anomaly and the detected network flow anomaly, and wherein the correlation is based on stitching portions of data received from different agents into a plurality of groups of data associated with the distributed business transaction that identify the detected application anomaly as being affected by the detected network flow anomaly; and

receiving, by the application agent and from the controller device, a snapshot that displays the business transaction data on a web-based interface, the snapshot Illustrating the plurality of machines associated with the detected application anomaly and performance of a network flow among the plurality of machines for the distributed business transaction, wherein the detected application anomaly is shown as being dependent on the performance of the network flow.

12. The system of claim 11 , wherein the query includes business transaction context Information, and wherein the network flow anomaly is determined by the plurality of network agents based on the business transaction context information.

13. The system of claim 12 , wherein the business transaction context Information includes a business transaction identifier, tier identification for tiers involved in a given network flow, node identification information for nodes involved in a given network flow, or an identification of a portion of the distributed business transaction being executed over a given network flow.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2017
From: APPDYNAMICS LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 044173/0050 →
CHANGE OF NAME Recorded Jun 23, 2017
From: APPDYNAMICS, INC.
To: APPDYNAMICS LLC
Reel/Frame 042964/0229 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2017
From: NATARAJ, HARISH; KALIGOTLA, PRAKASH; CHANDEL, AJAY; KONDAPALLI, NAVEEN
To: APPDYNAMICS, INC.
Reel/Frame 041640/0173 →
Continuity (2)
Continuation 14928982 · Oct 30, 2015
Related Publication 20170126531A1 · May 4, 2017