Generating event streams based on application-layer events captured by remote capture agents

    公开(公告)号:US11936764B1

    公开(公告)日:2024-03-19

    申请号:US17865041

    申请日:2022-07-14

    Applicant: Splunk Inc.

    CPC classification number: H04L69/22 H04L67/10

    Abstract: The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.

    Configuring generation of event streams by remote capture agents

    公开(公告)号:US10382599B2

    公开(公告)日:2019-08-13

    申请号:US15665268

    申请日:2017-07-31

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that processes network data. During operation, the system obtains, at a remote capture agent, a first protocol classification for a first packet flow captured by the remote capture agent. Next, the system uses configuration information associated with the first protocol classification to build a first event stream from the first packet flow at the remote capture agent, wherein the first event stream comprises time-series event data generated from network packets in the first packet flow based on the first protocol classification. The system then transmits the first event stream over a network for subsequent storage and processing of the first event stream by one or more components on the network.

    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS
    6.
    发明申请
    STREAMLINING CONFIGURATION OF PROTOCOL-BASED NETWORK DATA CAPTURE BY REMOTE CAPTURE AGENTS 审中-公开
    基于协议的网络数据捕获的构建由远程捕获代理

    公开(公告)号:US20160127180A1

    公开(公告)日:2016-05-05

    申请号:US14528932

    申请日:2014-10-30

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system provides a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system provides, in the GUI, a first set of user-interface elements for including one or more event attributes in the time-series event data of an event stream associated with a protocol classification of the network packets. The system then includes the one or more event attributes specified through the first set of user-interface elements in the configuration information.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统提供图形用户界面(GUI),用于获得用于配置由一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息。 接下来,系统在GUI中提供用于在与网络分组的协议分类相关联的事件流的时间序列事件数据中包括一个或多个事件属性的第一组用户界面元素。 然后,该系统包括通过配置信息中的第一组用户界面元素指定的一个或多个事件属性。

    BIDIRECTIONAL LINKING OF EPHEMERAL EVENT STREAMS TO CREATORS OF THE EPHEMERAL EVENT STREAMS
    7.
    发明申请
    BIDIRECTIONAL LINKING OF EPHEMERAL EVENT STREAMS TO CREATORS OF THE EPHEMERAL EVENT STREAMS 审中-公开
    环境事件流的双向链接到环境事件流的创造者

    公开(公告)号:US20150295779A1

    公开(公告)日:2015-10-15

    申请号:US14610438

    申请日:2015-01-30

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for obtaining configuration information for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements comprising event stream information for one or more ephemeral event streams used to temporarily generate the time-series event data from the network packets. The system then causes for display, in the GUI, a mechanism for navigating between the event stream information and creation information for one or more creators of the one or more ephemeral event streams.

    Abstract translation: 所公开的实施例提供了有助于网络数据的处理的系统。 在操作期间,系统使得显示图形用户界面(GUI),用于获得用于配置从一个或多个远程捕获代理捕获的网络分组生成时间序列事件数据的配置信息。 接下来,系统导致在GUI中显示第一组用户界面元素,其包括用于从网络分组临时生成时间序列事件数据的一个或多个临时事件流的事件流信息。 然后,系统在GUI中显示用于在事件流信息和用于一个或多个临时事件流的一个或多个创建者的创建信息之间导航的机制。

    Isolated execution environment system monitoring

    公开(公告)号:US11567960B2

    公开(公告)日:2023-01-31

    申请号:US17143063

    申请日:2021-01-06

    Applicant: Splunk Inc.

    Abstract: Systems and methods are described to determine relationships between one or more components of an isolated execution environment system based on data obtained from a data intake and query system. Based on the determined relationships, an interactive visualization is generated that indicates the hierarchical relationship of the components. In some cases, to illustrate the relationship between components of the isolated execution environment system, the visualization can include one or more display objects displayed in a subordinate or superior relationship to other display objects. In certain cases, based on an interaction with a display object, the system can generate a query and/or display additional information and/or visualizations based on the results of the query.

    Interval-based generation of event streams by remote capture agents

    公开(公告)号:US11296951B2

    公开(公告)日:2022-04-05

    申请号:US16908564

    申请日:2020-06-22

    Applicant: Splunk Inc.

    Abstract: The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system obtains a set of event streams from one or more remote capture agents over one or more networks, wherein the set of event streams comprises time-series event data generated from network packets captured by the one or more remote capture agents. Next, the system causes for display, within a graphical user interface (GUI), a first set of user interface elements, wherein the first set of user interface elements includes event stream information for an event stream in the set of event streams and a first graph of a metric associated with the time-series event data in the event stream. The system then updates the first graph in real-time with the time-series event data from the one or more remote capture agents.

Patent Agency Ranking