IP Library › Granted Patent US 12,732,441
Granted Patent B2
US 12,732,441 · App. 18/600,599 · Granted Sep 8, 2026

Enabling scale out recording capabilities for production network without monitoring fabric

Inventors: Sandip Shah (Santa Clara, CA); Arup Raton Roy (Burnaby, CA); Ryan Izard (Santa Clara, CA)
Assignee: ARISTA NETWORKS, INC.
H04L43/045H04L45/74H04L67/1095
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,441
App. No.
18/600,599
Granted
Sep 8, 2026
Kind
B2
Abstract

To scale out recording capabilities, recorder nodes and service leaf or Top-of-Rack (TOR) switches are added to a production network and provisioned to a network-wide workload orchestration and workflow automation platform operating in a cloud computing environment or on the premises of an enterprise. Additionally, switches in the production network are configured to, at ingress, capture packets of a traffic flow between workload applications, mirror the captured packets, and add metadata to an encapsulation header of each captured packet. The encapsulation header includes a virtual Internet Protocol (VIP) address of a recorder node cluster as the destination IP Address. The mirrored packets are routed to the VIP address. The service leaf or TOR switches symmetrically hash the mirrored packets and store them on a recorder node in the cluster. Through a centralized dashboard, a user can search, select, view, diagnose, analyze, or manage network components of the production network.

Claims (56)

1 . A method for scaling out recording capabilities for a production network, the method comprising:

adding recorder nodes and service leaf or Top-of-Rack (TOR) switches to a production network;

provisioning the recorder nodes and service leaf or TOR switches to a network-wide workload orchestration and workflow automation platform operating in a computing environment;

configuring switches in the production network to, at ingress:

capture packets of a traffic flow between workload applications;

mirror the captured packets in both forward and reverse directions of the traffic flow;

add metadata to an encapsulation header of each of the captured packets, wherein the encapsulated packet uses a virtual Internet Protocol address associated with a recorder node cluster as its destination IP address, and wherein the recorder node cluster comprises the recorder nodes; and

route the mirrored packets to the virtual Internet Protocol address;

configuring the service leaf or TOR switches to:

symmetrically hash the mirrored packets; and

store the mirrored packets to a recorder node in the recorder node cluster; and

providing a centralized dashboard through which a user is able to search, select, view, diagnose, analyze, or manage network components of the production network.

2 . The method according to claim 1 , wherein the network components comprise devices, interfaces, and applications.

3 . The method according to claim 1 , wherein the mirrored packets are routed to the virtual Internet Protocol address through a mirrored forward flow and a mirrored reverse flow, wherein the mirrored forward flow routes copies of the packets of the traffic flow captured in a forward direction of the traffic flow, wherein the mirrored reverse flow routes copies of the packets of the traffic flow captured in a reverse direction of the traffic flow, and wherein the copies of the packets captured in the forward direction and the reverse direction are stored in same recorder node in the recorder node cluster.

4 . The method according to claim 1 , wherein capturing the packets of the traffic flow is performed based on a user configuration or triggered by an event occurring in the production network.

5 . The method according to claim 1 , wherein the recorder node comprises a persistent storage and wherein the recorder node utilizes the metadata to store the mirrored packets in the persistent storage.

6 . The method according to claim 1 , wherein each recorder node in the recorder node cluster comprises a multicore processor.

7 . The method according to claim 1 , wherein the encapsulation header comprises a Generic Routing Encapsulation (GRE) header or a VxLAN header.

8 . A system for scaling out recording capabilities for a production network, the system comprising:

a processor;

a non-transitory computer-readable medium; and

instructions stored on the non-transitory computer-readable medium and translatable by the processor for:

adding recorder nodes and service leaf or Top-of-Rack (TOR) switches to a production network;

provisioning the recorder nodes and service leaf or TOR switches to a network-wide workload orchestration and workflow automation platform operating in a computing environment;

configuring switches in the production network to, at ingress:

capture packets of a traffic flow between workload applications;

mirror the captured packets in both forward and reverse directions of the traffic flow;

add metadata to an encapsulation header of each of the captured packets, wherein the encapsulated packet uses a virtual Internet Protocol address associated with a recorder node cluster as its destination IP address, and wherein the recorder node cluster comprises the recorder nodes; and

route the mirrored packets to the virtual Internet Protocol address;

configuring the service leaf or TOR switches nodes to:

symmetrically hash the mirrored packets; and

store the mirrored packets to a recorder node in the recorder node cluster; and

providing a centralized dashboard through which a user is able to search, select, view, diagnose, analyze, or manage network components of the production network.

9 . The system of claim 8 , wherein the network components comprise devices, interfaces, and applications.

10 . The system of claim 8 , wherein the mirrored packets are routed to the virtual Internet Protocol address through a mirrored forward flow and a mirrored reverse flow, wherein the mirrored forward flow routes copies of the packets of the traffic flow captured in a forward direction of the traffic flow, wherein the mirrored reverse flow routes copies of the packets of the traffic flow captured in a reverse direction of the traffic flow, and wherein the copies of the packets captured in the forward direction and the reverse direction are stored in same recorder node in the recorder node cluster.

11 . The system of claim 8 , wherein capturing the packets of the traffic flow is performed based on a user configuration or triggered by an event occurring in the production network.

12 . The system of claim 8 , wherein the recorder node comprises a persistent storage and wherein the recorder node utilizes the metadata to store the mirrored packets in the persistent storage.

13 . The system of claim 8 , wherein each recorder node in the recorder node cluster comprises a multicore processor.

14 . The system of claim 8 , wherein the encapsulation header comprises a Generic Routing Encapsulation (GRE) header or a VxLAN header.

15 . A computer program product for scaling out recording capabilities for a production network, the computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

adding recorder nodes and service leaf or Top-of-Rack (TOR) switches to a production network;

provisioning the recorder nodes and service leaf or TOR switches to a network-wide workload orchestration and workflow automation platform operating in a computing environment;

configuring switches in the production network to, at ingress:

capture packets of a traffic flow between workload applications;

mirror the captured packets in both forward and reverse directions of the traffic flow;

add metadata to an encapsulation header of each of the captured packets, wherein the encapsulated packet uses a virtual Internet Protocol address associated with a recorder node cluster as its destination IP Address, and wherein the recorder node cluster comprises the recorder nodes; and

route the mirrored packets to the virtual Internet Protocol address;

configuring the service leaf or TOR switches nodes to:

symmetrically hash the mirrored packets; and

store the mirrored packets to a recorder node in the recorder node cluster; and

providing a centralized dashboard through which a user is able to search, select, view, diagnose, analyze, or manage network components of the production network.

16 . The computer program product of claim 15 , wherein the network components comprise devices, interfaces, and applications.

17 . The computer program product of claim 15 , wherein the mirrored packets are routed to the virtual Internet Protocol address through a mirrored forward flow and a mirrored reverse flow, wherein the mirrored forward flow routes copies of the packets of the traffic flow captured in a forward direction of the traffic flow, wherein the mirrored reverse flow routes copies of the packets of the traffic flow captured in a reverse direction of the traffic flow, and wherein the copies of the packets captured in the forward direction and the reverse direction are stored in same recorder node in the recorder node cluster.

18 . The computer program product of claim 15 , wherein capturing the packets of the traffic flow is performed based on a user configuration or triggered by an event occurring in the production network.

19 . The computer program product of claim 15 , wherein the recorder node comprises a persistent storage and wherein the recorder node utilizes the metadata to store the mirrored packets in the persistent storage.

20 . The computer program product of claim 15 , wherein the encapsulation header comprises a Generic Routing Encapsulation (GRE) header or a VxLAN header.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2024
From: SHAH, SANDIP; ROY, ARUP RATON; IZARD, RYAN
To: ARISTA NETWORKS, INC.
Reel/Frame 066754/0547 →
Continuity (2)
Provisional Application 63606972 · Dec 6, 2023
Related Publication 20250193095A1 · Jun 12, 2025
References Cited (7)
US 10419327B2 · Izard et al. · 2019 [cited by applicant]
US 11956126B1 · Jangam · 2024 [cited by examiner]
US 20180367398A1 · Pani · 2018 [cited by examiner]
US 20190116111A1 · Izard · 2019 [cited by examiner]
US 20210182212A1 · Borikar · 2021 [cited by examiner]
US 20230198676A1 · K N · 2023 [cited by examiner]
US 20250184309A1 · Kommula · 2025 [cited by examiner]