NetFlow Trigger Policies for Real-Time Network Traffic Reporting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems provide limited data on network traffic, lacking comprehensive real-time reporting and alerting capabilities for detected conditions.

Innovation Solution

Implementing a system that generates triggering policies, starts a netflow process, collects real-time data, generates records, and displays alarms or reports based on network conditions, using components like SD-WAN architecture, vBond appliances, vManage appliances, and vSmart controllers to manage network traffic and generate reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If passive monitoring form is used, then device complexity is reduced, but measurement precision and information completeness deteriorate

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidtraffic data completeness
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces a netflow collector as an intermediary component that passively receives netflow data from network devices. This intermediary aggregates traffic information from multiple sources and makes it available for analysis without requiring active participation from the monitored devices, thus maintaining low complexity while improving data completeness

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Network devices automatically generate and send netflow data records to the collector without requiring manual configuration or active monitoring processes. The devices self-serve by embedding the data collection capability within their normal operation, reducing the complexity of the monitoring system while ensuring comprehensive data capture

Inventive Principle:
Principle #25Self-service

2Measurement precision

If real-time data collection is implemented, then measurement precision improves, but loss of time and processing overhead increase

Engineering Contradiction:
Improvereal-time detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Netflow data is collected and stored in advance in a database before analysis is required. This preliminary data collection and storage allows the system to have real-time detection capability ready without performing heavy processing at the moment of analysis, thus reducing processing time while maintaining real-time precision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses triggering policies that periodically evaluate stored netflow data against defined conditions. Instead of continuous processing, the system periodically checks for policy violations, reducing processing overhead while maintaining the ability to detect conditions in real-time when they occur

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If comprehensive netflow data collection is performed, then measurement precision improves, but device complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork traffic visibilityVSAvoidmonitoring system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary netflow data fields required for specific triggering policies from the complete netflow data stream. Instead of processing all available data, the system selectively extracts relevant information based on policy requirements, reducing complexity while maintaining comprehensive visibility for monitored parameters

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The netflow collector and policy evaluation system are designed to handle multiple different triggering policies and data types through a single unified platform. This multi-functional design allows comprehensive monitoring of various network conditions without requiring separate specialized systems for each monitoring task, thus reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12580831B2Reporting based on collecting and monitoring traffic on network
Publication Date: 2026.03.17 CISCO TECHNOLOGY INC
  • US12580831B2 patent drawing
  • US12580831B2 patent drawing
  • US12580831B2 patent drawing

AI summary

Disclosed are systems, apparatuses, methods, and computer-readable media for generating a report in response to detected conditions in a network environment. A method includes: generating one or more triggering policies; determining if the one or more of the triggering policies has been satisfied; starting a netflow process in response to the determination that the one or more of the trigger policies has been satisfied; collecting in real time data for connected devices that satisfy the one or more triggering policies; generating and saving a record associated with the collected data; generating a report based on analysis of the record; displaying a link to the report.