Network Event Stream Aggregation via Remote Capture Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network data capture technologies are inflexible and difficult to deploy in cloud computing environments, requiring physical hardware and fixed configurations, which limits their adaptability to changing business needs and hinders efficient data processing and analysis.

Innovation Solution

A system that uses remote capture agents to capture network data, generating time-series event streams that can be configured and managed through a GUI, allowing for protocol-based capture and analysis, and enabling dynamic configuration and processing of network data without the need for physical hardware, facilitating on-the-fly changes and efficient data management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hardware appliances are used for network data capture, then reliable network monitoring can be achieved, but deployment complexity increases and adaptability to cloud environments is lost

Engineering Contradiction:
Improvenetwork monitoring reliabilityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware appliances with software-based capture agents that replicate network monitoring functionality through software copies deployed on cloud servers. These agents capture network traffic data and transmit it to a centralized processing system, eliminating the need for complex physical hardware deployment while maintaining reliable network monitoring capabilities in cloud environments.

Inventive Principle:
Principle #26Copying

2Ease of manufacture

If fixed configuration network capture devices are used, then implementation simplicity is maintained, but adaptability to changing business needs deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to changing needs
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration capabilities allowing the network data capture system to adapt to changing business needs. The centralized processing system enables users to define custom capture criteria, filter data based on specific protocols or patterns, and modify monitoring parameters without reconfiguring hardware. This dynamic software-based approach maintains implementation simplicity while providing high adaptability through programmable capture agents and flexible data processing rules.

Inventive Principle:
Principle #15Dynamics

3Productivity

If ETL processes are used to process network data, then data extraction and transformation can be achieved, but processing time and complexity increase

Engineering Contradiction:
Improvedata processing capabilityVSAvoidprocessing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing data extraction, transformation, and aggregation operations at the capture agent level before data is transmitted to the centralized processing system. The capture agents pre-process network traffic according to configured criteria, filtering and transforming data locally to reduce the volume of data requiring centralized processing. This preliminary processing action significantly reduces processing time and complexity while maintaining high data processing capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11281643B2Generating event streams including aggregated values from monitored network data
Publication Date: 2022.03.22 CISCO TECHNOLOGY INC
  • US11281643B2 patent drawing
  • US11281643B2 patent drawing
  • US11281643B2 patent drawing

AI summary

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for specifying a grouping of a set of event streams containing the time-series event data by an event stream attribute associated with the event streams. The system then causes for display, in the GUI, a second set of user-interface elements containing event stream information for one or more subsets of the event streams represented by the grouping of the event streams by the event stream attribute.