Efficient capture and streaming of data packets
What is disclosed is a method for efficient capture and streaming of data packets in a network device comprises capturing data packets matching predetermined filters, packaging said data packets into samples, and aggregating one or more samples in a high speed bus payload. The method also comprises transferring said high speed bus payload to a CPU, extracting said samples from the high speed bus payload and storing said samples in a shared memory of the CPU, and accessing said samples from the shared memory for streaming to one or more client.
1. A method for analysis of data packets at a network device having an input port configured to receive packets from a network and an output port configured to transmit the data packets to the network, the method comprising:
capturing, by a programmable processor, a data packet received on the input port matching one or more predetermined criteria;
creating one or more metadata related to the captured packet;
sending, at a calculated shaping rate, from the programmable processor, a sample comprising a copy of said captured packet along with the metadata, to a processor via a high speed bus, the calculated shaping rate based on space left in a shared memory of said processor; and
streaming, via said processor, the sample to one or more clients.
2. The method of claim 1 , wherein said metadata is added in a header to the data packet.
3. The method of claim 1 , wherein said matching one or more predetermined criteria is done via a layer-2 filtering protocol.
4. The method of claim 1 , wherein said matching one or more predetermined criteria is done via a layer-3 filtering protocol.
5. The method of claim 1 , wherein said transmitting is done via an Ethernet bus.
6. A network device comprising:
an input port configured to receive packets from a network;
a programmable packet capture processor configured to:
capture a data packet received on the input port matching one or more predetermined criteria;
create one or more metadata related to the captured packet;
send, at a calculated shaping rate, a sample comprising a copy of said captured packet along with the metadata, to a processor of said network device via a high speed bus, the calculated shaping rate based on space left in a shared memory of said processor; and
wherein said processor is configured to stream the sample to one or more clients.
7. The network device of claim 6 wherein the packet capture processor is configured to capture the packets using a layer-2 filtering protocol.
8. The network device of claim 6 wherein the packet capture processor is configured to capture is configured to filter the packets using a layer-3 filtering protocol.