IP Library Granted Patent US 12,028,208
Granted Patent B1
US 12,028,208 · App. 18/330,299 · Granted Jul 2, 2024

Selective event stream data storage based on network traffic volume

Inventors: Fang I. Hsiao (Berkeley, CA); Wei Jiang (San Francisco, CA); Vladimir A. Shcherbakov (Pleasanton, CA); Ramkumar Chandrasekharan (San Jose, CA); Clayton S. Ching (Sunnyvale, CA)
Assignee: Splunk Inc.
H04L41/0813G06F3/0481G06F3/0482G06F3/04842G06F16/26H04L41/22H04L67/12H04L67/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,028,208
App. No.
18/330,299
Granted
Jul 2, 2024
Kind
B1
Abstract

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements containing a set of statistics associated with one or more event streams that comprise the time-series event data. The system then causes for display, in the GUI, one or more graphs comprising one or more values from the set of statistics. Finally, the system causes for display, in the GUI, a value of a statistic from the set of statistics based on a position of a cursor over the one or more graphs.

Claims (58)

1. A computer-implemented method, comprising:

receiving an event stream from a remote capture agent, wherein the event stream includes timestamped event data generated by the remote capture agent based on network traffic monitored by the remote capture agent;

calculating, based on historical data over one or more periods of time, an unused amount of storage relative to a storage limit associated with the event stream;

determining, based on the unused amount of storage, a suggested percentage of the event stream to store in one or more data stores;

causing display of a graphical user interface (GUI) including text indicating the suggested percentage of the event stream to store in the one or more data stores;

receiving input of a specified percentage of the event stream to store in the one or more data stores; and

causing a portion of the event stream to be stored in the one or more data stores according to the specified percentage.

2. The method of claim 1 , further comprising causing display, in the GUI, of an interface element for adjusting the specified percentage of the event stream to store in the one or more data stores.

3. The method of claim 2 , wherein receiving input of a specified percentage of the event stream to store in the one or more data stores comprises receiving input of movement of the interface element within the GUI.

4. The method of claim 2 , wherein the interface element is a slider.

5. The method of claim 1 , wherein the portion of the event stream is a first portion, and wherein causing the first portion of the event stream to be stored in the one or more data stores includes discarding a second portion of the event stream.

6. The method of claim 1 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the method further comprises:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is greater than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is less than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

7. The method of claim 1 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the method further comprises:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is less than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is greater than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

8. A computing device, comprising:

one or more processors; and

a non-transitory computer-readable medium storing instructions that, when executed by the one or more processors, cause the computing device to perform operations including:

receiving an event stream from a remote capture agent, wherein the event stream includes timestamped event data generated by the remote capture agent based on network traffic monitored by the remote capture agent;

calculating, based on historical data over one or more periods of time, an unused amount of storage relative to a storage limit associated with the event stream;

determining, based on the unused amount of storage, a suggested percentage of the event stream to store in one or more data stores;

causing display of a graphical user interface (GUI) including text indicating the suggested percentage of the event stream to store in the one or more data stores;

receiving input of a specified percentage of the event stream to store in the one or more data stores; and

causing a portion of the event stream to be stored in the one or more data stores according to the specified percentage.

9. The computing device of claim 8 , wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising causing display, in the GUI, of an interface element for adjusting the specified percentage of the event stream to store in the one or more data stores.

10. The computing device of claim 9 , wherein receiving input of a specified percentage of the event stream to store in the one or more data stores comprises receiving input of movement of the interface element within the GUI.

11. The computing device of claim 9 , wherein the interface element is a slider.

12. The computing device of claim 8 , wherein the portion of the event stream is a first portion, and wherein causing the first portion of the event stream to be stored in the one or more data stores includes discarding a second portion of the event stream.

13. The computing device of claim 8 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is greater than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is less than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

14. The computing device of claim 8 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is less than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is greater than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:

receiving an event stream from a remote capture agent, wherein the event stream includes timestamped event data generated by the remote capture agent based on network traffic monitored by the remote capture agent;

calculating, based on historical data over one or more periods of time, an unused amount of storage relative to a storage limit associated with the event stream;

determining, based on the unused amount of storage, a suggested percentage of the event stream to store in one or more data stores;

causing display of a graphical user interface (GUI) including text indicating the suggested percentage of the event stream to store in the one or more data stores;

receiving input of a specified percentage of the event stream to store in the one or more data stores; and

causing a portion of the event stream to be stored in the one or more data stores according to the specified percentage.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising causing display, in the GUI, of an interface element for adjusting the specified percentage of the event stream to store in the one or more data stores.

17. The non-transitory computer-readable medium of claim 16 , wherein receiving input of a specified percentage of the event stream to store in the one or more data stores comprises receiving input of movement of the interface element within the GUI.

18. The non-transitory computer-readable medium of claim 15 , wherein the portion of the event stream is a first portion, and wherein causing the first portion of the event stream to be stored in the one or more data stores includes discarding a second portion of the event stream.

19. The non-transitory computer-readable medium of claim 15 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is greater than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is less than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

20. The non-transitory computer-readable medium of claim 15 , wherein a volume of the network traffic from which the remote capture agent generated the timestamped event data is a first volume of first network traffic as measured at a first point in time, wherein the suggested percentage of the event stream to store in one or more data stores is a first suggested percentage, and wherein the instructions include further instructions that, when executed by the one or more processors, cause the computing device to perform further operations comprising:

determining a second volume of second network traffic from which the remote capture agent generates timestamped event data as measured at a second point in time, wherein the second volume of second network traffic is less than the first volume of first network traffic;

determining a second suggested percentage of the event stream to store in the one or more data stores based on the second volume of the second network traffic, wherein the second suggested percentage is greater than the first suggested percentage; and

causing display of a GUI including text indicating the second suggested percentage of the event stream to store in the one or more data stores.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2023
From: HSIAO, FANG I.; JIANG, WEI; SHCHERBAKOV, VLADIMIR A.; CHANDRASEKHARAN, RAMKUMAR; CHING, CLAYTON S.
To: SPLUNK INC.
Reel/Frame 064973/0870 →
Continuity (6)
Continuation 17578264 · Jan 18, 2022
Continuation 16573937 · Sep 17, 2019
Continuation 14699807 · Apr 29, 2015
Continuation In Part 14610408 · Jan 30, 2015
Continuation In Part 14528898 · Oct 30, 2014
Continuation In Part 14273713 · May 9, 2014
Cited By (46)
US 1,058,589 US 1,058,590 US 1,058,591 US 1,058,592 US 1,058,593 US 1,058,596 US 1,059,398 US 1,059,414 US 1,063,973 US 1,085,145 US 1,089,268 US 1,089,269 US 1,089,270 US 1,089,271 US 1,089,272 US 1,089,273 US 1,091,590 US 1,091,591 US 1,091,592 US 1,091,593 US 1,091,594 US 1,091,595 US 1,091,596 US 1,091,597 US 1,091,598 US 1,092,526 US 1,094,427 US 1,094,428 US 1,094,429 US 1,094,430 US 1,094,431 US 1,094,432 US 1,094,433 US 1,095,578 US 1,095,579 US 1,095,580 US 1,095,581 US 1,095,582 US 1,095,583 US 1,095,584 US 1,095,585 US 1,096,817 US 1,096,835 US 12,474,872 US 12,665,803 US 12,689,549