×

Managing ephemeral event streams generated from captured network data

  • US 10,523,521 B2
  • Filed: 01/30/2015
  • Issued: 12/31/2019
  • Est. Priority Date: 04/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for facilitating processing of network data, the method comprising:

  • causing display of a graphical user interface (GUI) including interface elements related to generating configuration information for a remote capture agent, the configuration information including information used by the remote capture agent to generate at least one event stream comprising timestamped event data derived from network packets monitored by the remote capture agent;

    receiving, via the GUI, input defining an ephemeral event stream comprising timestamped event data to be generated by the remote capture agent, the input including;

    a search query to be executed against timestamped event data included in the at least one event stream generated by the remote capture agent, wherein timestamped event data satisfying the search query indicates a potential security incident in a computing environment,an identifier of a protocol used by network packets from which timestamped event data of the ephemeral event stream is to be generated, andan indication of an amount of time the remote capture agent is to generate the ephemeral event stream;

    generating configuration information including settings used by the remote capture agent to generate the ephemeral event stream comprising additional timestamped event data automatically generated in response to detection of a trigger condition, wherein the trigger condition is detected when execution of the search query identifies timestamped event data satisfying the search query; and

    transmitting, via a network, the configuration information to the remote capture agent, wherein the configuration information is used to configure the generation of the at least one event stream comprising timestamped event data at the remote capture agent during runtime of the remote capture agent.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×