Remote Capture Agents for Dynamic Network Event Stream Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network data capture technologies are inflexible and challenging to deploy in cloud computing environments, as they require physical hardware and fixed configurations, limiting their ability to adapt to changing business needs and remote data processing.
Innovation Solution
A system that uses remote capture agents to capture and process network data, allowing for protocol-based capture and analysis, and provides a graphical user interface for configuring and managing event streams, enabling dynamic configuration and storage management without the need for physical hardware, facilitating on-the-fly changes and efficient data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hardware-based network capture devices are used, then network data capture can be performed with established reliability, but deployment in cloud computing environments becomes impossible or extremely challenging
Solution Approach 1:
The patent replaces physical hardware-based network capture devices with a software-based virtual capture agent that runs within the cloud computing environment. This substitution eliminates the need for physical hardware deployment while maintaining network data capture functionality, thereby resolving the contradiction between reliability and deployment flexibility.
Solution Approach 2:
The patent creates a virtual copy of the network capture functionality through software agents that replicate the data collection and processing capabilities of physical devices. These virtual agents can be deployed anywhere in the cloud environment without requiring physical hardware, enabling flexible deployment while maintaining capture reliability.
2Ease of manufacture
If fixed configuration network capture technologies are used, then implementation is straightforward, but modification to address different and changing business needs becomes precluded
Solution Approach 1:
The patent implements dynamic configuration capabilities where the virtual capture agent can be remotely configured and reconfigured without requiring physical hardware changes. Users can modify capture parameters, data types, and processing rules through software interfaces, enabling the system to adapt to changing business needs while maintaining implementation simplicity.
Solution Approach 2:
The patent creates a universal network capture platform that can perform multiple functions including security monitoring, performance analysis, and data collection. The single virtual agent can be configured for different business needs and vertical markets, eliminating the need for multiple specialized devices and enabling flexible adaptation to various requirements.
3Adaptability or versatility
If remote capture agents are deployed across the network, then data capture configuration can be changed on-the-fly, but management and processing of large volumes of event data becomes complex
Solution Approach 1:
The patent segments the data processing workload by deploying virtual capture agents at distributed locations across the network, each responsible for capturing and initially processing local data. This segmentation enables on-the-fly configuration changes at each agent while distributing the management complexity across multiple independent units rather than requiring centralized control of all data streams.
Solution Approach 2:
The patent introduces a centralized management system that acts as an intermediary between users and the distributed capture agents. This management system handles the complexity of data processing, aggregation, and analysis, while providing simplified interfaces for configuration changes. The intermediary layer abstracts the complexity from end users while enabling flexible on-the-fly configuration.
4Quantity of substance
If traditional ETL processes are used for data processing, then data can be filtered and transformed, but the processes are cumbersome and time-consuming
Solution Approach 1:
The patent performs data filtering, transformation, and aggregation operations at the virtual capture agent in advance, before data reaches the central processing system. This preliminary action reduces the volume of data that requires subsequent processing, making the overall ETL process more efficient and less time-consuming while maintaining comprehensive data processing capability.
Solution Approach 2:
The patent implements continuous data processing where the virtual capture agents continuously filter, transform, and prepare data streams in real-time as data is captured. This continuous processing eliminates the need for batch ETL operations, reducing processing time and enabling faster data availability while maintaining the ability to handle large volumes of data.
Data Source
AI summary
The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements for managing one or more event streams containing the time-series event data, wherein managing the one or more event streams includes enabling the generation of a set of statistics from an event stream without subsequently storing and processing at least a first portion of the event stream by one or more components on a network. The GUI then updates the configuration information based on input received through the first set of user-interface elements.


