GROUPING AND MANAGING EVENT STREAMS GENERATED FROM CAPTURED NETWORK DATA
First Claim
1. A method for facilitating the processing of network data, comprising:
- causing for display, on a computer system, a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents;
causing for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams; and
causing for display, in the GUI, a second set of user-interface elements comprising event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute.
1 Assignment
0 Petitions
Accused Products
Abstract
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams. The system then causes for display, in the GUI, a second set of user-interface elements containing event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute.
-
Citations
30 Claims
-
1. A method for facilitating the processing of network data, comprising:
-
causing for display, on a computer system, a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents; causing for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams; and causing for display, in the GUI, a second set of user-interface elements comprising event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19)
-
-
20. An apparatus, comprising:
-
one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the apparatus to; cause for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents; cause for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams; and cause for display, in the GUI, a second set of user-interface elements comprising event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute. - View Dependent Claims (21, 22, 23, 24, 25, 26, 27)
-
-
28. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for facilitating the processing of network data, the method comprising:
-
causing for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents; causing for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams; and causing for display, in the GUI, a second set of user-interface elements comprising event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute. - View Dependent Claims (29, 30)
-
Specification