Configuring the generation of additional time-series event data by remote capture agents

    公开(公告)号:US10812514B2

    公开(公告)日:2020-10-20

    申请号:US16228509

    申请日:2018-12-20

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    Configuring the generation of event data based on a triggering search query

    公开(公告)号:US10193916B2

    公开(公告)日:2019-01-29

    申请号:US15799167

    申请日:2017-10-31

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    Capture triggers for capturing network data
    4.
    发明授权
    Capture triggers for capturing network data 有权
    捕获捕获网络数据的触发器

    公开(公告)号:US09596253B2

    公开(公告)日:2017-03-14

    申请号:US14528918

    申请日:2014-10-30

    Applicant: Splunk Inc.

    CPC classification number: H04L63/1425 H04L63/0218 H04L63/0236

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在运行期间,系统提供一种风险识别机制,用于从由分布在网络上的一个或多个远程捕获代理捕获的网络分组产生的时间序列事件数据中识别安全风险。 接下来,系统提供捕获触发器,用于基于安全风险从一个或多个远程捕获代理上的网络分组生成附加的时间序列事件数据,其中附加的时间序列事件数据包括一个或多个事件属性。

    CAPTURE TRIGGERS FOR CAPTURING NETWORK DATA

    公开(公告)号:US20170142146A1

    公开(公告)日:2017-05-18

    申请号:US15421269

    申请日:2017-01-31

    Applicant: Splunk Inc.

    CPC classification number: H04L63/1425 H04L63/0218 H04L63/0236

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    Capture triggers for capturing network data

    公开(公告)号:US09843598B2

    公开(公告)日:2017-12-12

    申请号:US15421269

    申请日:2017-01-31

    Applicant: Splunk Inc.

    CPC classification number: H04L63/1425 H04L63/0218 H04L63/0236

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    CAPTURE TRIGGERS FOR CAPTURING NETWORK DATA
    8.
    发明申请
    CAPTURE TRIGGERS FOR CAPTURING NETWORK DATA 有权
    捕获网络数据的捕获触发器

    公开(公告)号:US20160127401A1

    公开(公告)日:2016-05-05

    申请号:US14528918

    申请日:2014-10-30

    Applicant: Splunk Inc.

    CPC classification number: H04L63/1425 H04L63/0218 H04L63/0236

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a risk-identification mechanism for identifying a security risk from time-series event data generated from network packets captured by one or more remote capture agents distributed across a network. Next, the system provides a capture trigger for generating additional time-series event data from the network packets on the one or more remote capture agents based on the security risk, wherein the additional time-series event data includes one or more event attributes.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在运行期间,系统提供一种风险识别机制,用于从由分布在网络上的一个或多个远程捕获代理捕获的网络分组产生的时间序列事件数据中识别安全风险。 接下来,系统提供捕获触发器,用于基于安全风险从一个或多个远程捕获代理上的网络分组生成附加的时间序列事件数据,其中附加的时间序列事件数据包括一个或多个事件属性。

Patent Agency Ranking