- 专利标题: Protocol-based capture of network data using remote capture agents
-
申请号: US14528898申请日: 2014-10-30
-
公开(公告)号: US09838512B2公开(公告)日: 2017-12-05
- 发明人: Vladimir A. Shcherbakov , Michael R. Dickey
- 申请人: Splunk Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Splunk Inc.
- 当前专利权人: Splunk Inc.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Nicholson De Vos Webster & Elliott LLP
- 主分类号: H04L29/08
- IPC分类号: H04L29/08 ; H04L29/06
摘要:
The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.
公开/授权文献
信息查询