×

Facilitating custom content extraction from network packets

  • US 10,334,085 B2
  • Filed: 01/29/2015
  • Issued: 06/25/2019
  • Est. Priority Date: 01/29/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by a remote capture agent coupled to a computer network, the method comprising:

  • monitoring a stream of network packets;

    for each network packet of a plurality of network packets in the stream of network packets;

    parsing the network packet to identify a structure of the network packet, the structure of the network packet used to determine a protocol associated with the network packet;

    applying an extraction rule associated with the protocol to the network packet to obtain extracted content, wherein applying the extraction rule includes;

    identifying at least one user-specified field in the network packet containing structured data from which the extracted content is to be obtained, andextracting data from the structured data contained in the user-specified field of the network packet;

    generating a timestamped event including a field storing the extracted content; and

    sending the timestamped event including the extracted content to another component on the computer network for storage in a data store, the data store facilitating the querying of timestamped event data stored in the data store using late-binding schemas generated from received queries.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×