Network Event Stream Aggregation via Remote Capture Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, requiring physical hardware and fixed configurations, which limits their adaptability to changing business needs and hinders efficient data processing and analysis.
Innovation Solution
A system that uses remote capture agents to capture network data, generating time-series event streams that can be configured and managed through a GUI, allowing for protocol-based capture and analysis, and enabling dynamic configuration and processing of network data without the need for physical hardware, facilitating on-the-fly changes and efficient data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware appliances are used for network data capture, then reliable network monitoring can be achieved, but deployment complexity increases and adaptability to cloud environments is lost
Solution Approach 1:
The patent replaces physical hardware appliances with software-based capture agents that replicate network monitoring functionality through software copies deployed on cloud servers. These agents capture network traffic data and transmit it to a centralized processing system, eliminating the need for complex physical hardware deployment while maintaining reliable network monitoring capabilities in cloud environments.
2Ease of manufacture
If fixed configuration network capture devices are used, then implementation simplicity is maintained, but adaptability to changing business needs deteriorates
Solution Approach 1:
The patent implements dynamic configuration capabilities allowing the network data capture system to adapt to changing business needs. The centralized processing system enables users to define custom capture criteria, filter data based on specific protocols or patterns, and modify monitoring parameters without reconfiguring hardware. This dynamic software-based approach maintains implementation simplicity while providing high adaptability through programmable capture agents and flexible data processing rules.
3Productivity
If ETL processes are used to process network data, then data extraction and transformation can be achieved, but processing time and complexity increase
Solution Approach 1:
The patent applies preliminary action by performing data extraction, transformation, and aggregation operations at the capture agent level before data is transmitted to the centralized processing system. The capture agents pre-process network traffic according to configured criteria, filtering and transforming data locally to reduce the volume of data requiring centralized processing. This preliminary processing action significantly reduces processing time and complexity while maintaining high data processing capability.
Data Source
AI summary
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams. The system then causes for display, in the GUI, a second set of user-interface elements containing event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute.


