Linking event streams across applications of a data intake and query system

    公开(公告)号:US11086897B2

    公开(公告)日:2021-08-10

    申请号:US16442338

    申请日:2019-06-14

    申请人: Splunk Inc.

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.

    INTERVAL-BASED GENERATION OF EVENT STREAMS BY REMOTE CAPTURE AGENTS

    公开(公告)号:US20200336390A1

    公开(公告)日:2020-10-22

    申请号:US16908564

    申请日:2020-06-22

    申请人: Splunk Inc.

    IPC分类号: H04L12/24 H04L12/26

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system obtains a set of event streams from one or more remote capture agents over one or more networks, wherein the set of event streams comprises time-series event data generated from network packets captured by the one or more remote capture agents. Next, the system causes for display, within a graphical user interface (GUI), a first set of user interface elements, wherein the first set of user interface elements includes event stream information for an event stream in the set of event streams and a first graph of a metric associated with the time-series event data in the event stream. The system then updates the first graph in real-time with the time-series event data from the one or more remote capture agents.

    Managing ephemeral event streams generated from captured network data

    公开(公告)号:US10523521B2

    公开(公告)日:2019-12-31

    申请号:US14610457

    申请日:2015-01-30

    申请人: Splunk Inc.

    IPC分类号: H04L12/24 H04L12/26

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display, on a computer system, a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more ephemeral event streams that contain temporarily generated time-series event data from the network packets, wherein managing the one or more ephemeral event streams comprises modifying an end time for terminating the capture of time-series event data in an ephemeral event stream. The system then updates the configuration information based on input received through the first set of user-interface elements.

    INLINE VISUALIZATIONS OF METRICS RELATED TO CAPTURED NETWORK DATA
    4.
    发明申请
    INLINE VISUALIZATIONS OF METRICS RELATED TO CAPTURED NETWORK DATA 审中-公开
    与捕获的网络数据相关的度量的在线可视化

    公开(公告)号:US20150295778A1

    公开(公告)日:2015-10-15

    申请号:US14609223

    申请日:2015-01-29

    申请人: Splunk Inc.

    IPC分类号: H04L12/24 G06F3/0484

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system obtains a set of event streams from one or more remote capture agents over one or more networks, wherein the set of event streams comprises time-series event data generated from network packets captured by the one or more remote capture agents. Next, the system causes for display, within a graphical user interface (GUI), a first set of user interface elements, wherein the first set of user interface elements includes event stream information for an event stream in the set of event streams and a first graph of a metric associated with the time-series event data in the event stream. The system then updates the first graph in real-time with the time-series event data from the one or more remote capture agents.

    摘要翻译: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统通过一个或多个网络从一个或多个远程捕获代理获得一组事件流,其中该组事件流包括由一个或多个远程捕获代理捕获的网络分组生成的时间序列事件数据。 接下来,系统导致在图形用户界面(GUI)内显示第一组用户界面元素,其中第一组用户界面元素包括事件流集合中的事件流的事件流信息,以及第一组 与事件流中的时间序列事件数据相关联的度量图。 系统随后使用来自一个或多个远程捕获代理程序的时间序列事件数据实时更新第一个图形。

    Generating event streams based on application-layer events captured by remote capture agents

    公开(公告)号:US11936764B1

    公开(公告)日:2024-03-19

    申请号:US17865041

    申请日:2022-07-14

    申请人: Splunk Inc.

    IPC分类号: H04L69/22 H04L67/10

    CPC分类号: H04L69/22 H04L67/10

    摘要: The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.

    BIDIRECTIONAL LINKING OF EPHEMERAL EVENT STREAMS TO CREATORS OF THE EPHEMERAL EVENT STREAMS

    公开(公告)号:US20190303385A1

    公开(公告)日:2019-10-03

    申请号:US16442338

    申请日:2019-06-14

    申请人: Splunk Inc.

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.

    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS
    8.
    发明申请
    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS 审中-公开
    基于协议的网络数据捕获的构建由远程捕获代理

    公开(公告)号:US20160127180A1

    公开(公告)日:2016-05-05

    申请号:US14528932

    申请日:2014-10-30

    申请人: Splunk Inc.

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system provides, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets. The system then includes the one or more event attributes specified through the first set of user-interface elements in the configuration information.

    摘要翻译: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统提供图形用户界面(GUI),用于获得用于配置由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息。 接下来,系统在GUI中提供用于在与网络分组的协议分类相关联的事件流的时间序列事件数据中包括一个或多个事件属性的第一组用户界面元素。 然后,该系统包括通过配置信息中的第一组用户界面元素指定的一个或多个事件属性。

    BIDIRECTIONAL LINKING OF EPHEMERAL EVENT STREAMS TO CREATORS OF THE EPHEMERAL EVENT STREAMS
    9.
    发明申请
    BIDIRECTIONAL LINKING OF EPHEMERAL EVENT STREAMS TO CREATORS OF THE EPHEMERAL EVENT STREAMS 审中-公开
    环境事件流的双向链接到环境事件流的创造者

    公开(公告)号:US20150295779A1

    公开(公告)日:2015-10-15

    申请号:US14610438

    申请日:2015-01-30

    申请人: Splunk Inc.

    IPC分类号: H04L12/24 H04L29/06

    摘要: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.

    摘要翻译: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统使得显示图形用户界面(GUI),用于获得用于配置从一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息。 接下来,系统导致在GUI中显示第一组用户界面元素,其包括用于从网络分组临时生成时间序列事件数据的一个或多个临时事件流的事件流信息。 然后,系统在GUI中显示用于在事件流信息和用于一个或多个临时事件流的一个或多个创建者的创建信息之间导航的机制。