Systems and methods of network monitoring
First Claim
1. A method for network monitoring comprising the steps of:
- receiving a first packet;
creating a first filter instance if the first received packet matches a filter template, the first filter instance based at least partially on the filter template;
receiving a second packet;
storing the second received packet if the second received packet matches the created first filter instance; and
creating a second filter instance based at least in part on information contained in a third received packet and at least in part on one of a plurality of predefined filter templates.
11 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods of network monitoring are disclosed. One exemplary method includes receiving a first packet, creating a filter instance if the first received packet matches a filter template, receiving a second packet, and storing the second received packet if the second received packet matches the created filter instance. The filter instance is based at least partially on the filter template. An exemplary system includes a network interface, a memory, and a processor. The memory stores program code which programs the network monitor device to receive a first packet, create a filter instance if the first received packet matches a filter template, receive a second packet, and store the second received packet if the second received packet matches the created filter instance. The filter instance is based at least partially on the filter template.
13 Citations
16 Claims
-
1. A method for network monitoring comprising the steps of:
-
receiving a first packet; creating a first filter instance if the first received packet matches a filter template, the first filter instance based at least partially on the filter template; receiving a second packet; storing the second received packet if the second received packet matches the created first filter instance; and creating a second filter instance based at least in part on information contained in a third received packet and at least in part on one of a plurality of predefined filter templates. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A network monitor device comprising:
-
a network interface; memory having program code stored thereon; and a processor programmed by at least the program code to enable the network monitor device to; receive a first packet from the network interface; create a filter instance if the first received packet matches a filter template, the filter instance based at least partially on the filter template; receive a description of the filter template including at least one protocol header field and at least one value associated with the at least one protocol header field; receive a second packet from the network interface; and store the second received packet if the second received packet matches the created filter instance. - View Dependent Claims (10, 11, 12, 13)
-
-
14. A system for network monitoring comprising:
-
means for receiving a first packet; means for creating a filter instance if the first received packet matches a filter template, the filter instance based at least partially on the filter template; means for receiving a second packet; means for storing the second received packet if the second received packet matches the created filter instance; means for receiving a monitor request from a remote device, the request including a filter instance and an address; means for capturing packets in accordance with the filter instance; and means for sending a report associated with the captured packets to the address in the request. - View Dependent Claims (15, 16)
-
Specification