×

Dynamic configuration of remote capture agents for network data capture

  • US 9,923,767 B2
  • Filed: 04/15/2014
  • Issued: 03/20/2018
  • Est. Priority Date: 04/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method performed by a remote capture agent coupled to a network, the method comprising:

  • obtaining configuration information from a configuration server over the network, the configuration information specifying a plurality of event streams to be generated by the remote capture agent and further specifying a respective event type associated with each event stream of the plurality of event streams;

    monitoring network traffic comprising a plurality of network packets;

    generating, based on the configuration information, a plurality of events from the network traffic, wherein generating an event of the plurality of events comprises;

    extracting network packet data from at least one network packet of the plurality of network packets and associating the extracted network packet data with the event;

    applying a filtering rule to the extracted network packet data to determine an event type associated with the event;

    adding, based on the determined event type, the event to at least one event stream of the plurality of event streams;

    for each event stream of the plurality of event streams;

    selecting, based on the event type for the event stream specified in the configuration information, a component of a plurality of components on the network to which to send the event stream; and

    sending the event stream to the selected component on the network for subsequent processing.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×