Cloud Machine Data Forwarder Firewall Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Analyzing and searching massive quantities of machine data pose challenges due to the need for efficient data processing and storage, as existing tools often discard non-pre-specified data during preprocessing, limiting flexibility and insights.

Innovation Solution

A distributed machine data acquisition and search system (MDASS) that operates partially in the cloud, utilizing on-premises security features and supporting the SOCKS5 protocol to authenticate data forwarders, allowing them to pass machine data through firewalls and forward event data to cloud-based indexers, enabling flexible schema application at search time and efficient data retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If pre-processing extracts and stores only pre-specified data items, then retrieval efficiency is improved, but flexibility and analytical insights are reduced

Engineering Contradiction:
Improveretrieval efficiencyVSAvoidflexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary extraction of only essential metadata and structured fields during pre-processing, while retaining the complete raw machine data in its original format. This allows efficient retrieval of structured information while preserving full analytical flexibility through the retained raw data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a dual-layer data architecture where structured extracted data and raw machine data coexist in different dimensional spaces. The structured data provides immediate retrieval efficiency, while the raw data maintains full analytical dimensionality for flexible exploration and discovery.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If all machine data is stored for later analysis, then flexibility and insights are improved, but system complexity and processing challenges increase

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments machine data into distinct components: structured extracted data for efficient retrieval and raw machine data for comprehensive analysis. This segmentation allows each component to be processed and managed according to its specific requirements, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The raw machine data serves multiple functions simultaneously: it acts as the source for structured extraction, maintains as an archive for future analysis, and provides complete data for flexible querying. This multi-functionality reduces the need for separate systems and simplifies the overall architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud-based processing is used, then scalability is improved, but security requirements become more stringent

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security intermediaries including firewalls and authentication mechanisms that mediate between on-premises data sources and cloud-based processing components. These intermediaries enable secure data transmission while maintaining the scalability benefits of cloud processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security functions into distinct components: authentication mechanisms for access control, firewalls for network security, and encryption for data protection. This segmentation allows each security function to be optimized and managed independently while working together to protect data in the cloud environment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9853946B2Security compliance for cloud-based machine data acquisition and search system
Publication Date: 2017.12.26 CISCO TECHNOLOGY INC
  • US9853946B2 patent drawing
  • US9853946B2 patent drawing
  • US9853946B2 patent drawing

AI summary

Disclosed herein are a method, apparatus and system that authenticate a first data forwarder, of a distributed machine data acquisition and search system (MDASS), to a node that regulates traversal of a firewall that protects a protected environment within which the data forwarder operates. The authentication may be performed by using a SOCKS5 authentication process. The method further includes, only after successful completion of the SOCKS5 authentication process, establishing a first connection, through a network, between the first data forwarder and a first indexer of the distributed MDASS, where the first indexer operates outside the protected environment, and sending machine data acquired by the first data forwarder from a machine data source, to the first indexer via the first connection.