Remote Capture Agents for Dynamic Cloud Event Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network capture technologies are inflexible and difficult to deploy in cloud environments, requiring physical hardware and fixed configurations that cannot adapt to changing business needs.

Innovation Solution

A system of dynamically configurable remote capture agents and a configuration server that allows for real-time modification of event stream destinations and transformations, enabling network data capture and processing in distributed networks, including cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If physical hardware appliances are used for network data capture, then capture capability is provided, but deployment in cloud environments becomes impossible or extremely challenging

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidphysical hardware requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware network capture devices with software-based remote capture agents that run on cloud computing instances. These agents capture network data through virtualized mechanisms rather than physical hardware connections, enabling deployment in cloud environments where physical hardware cannot be installed. The configuration server manages these software agents remotely, providing the same network capture functionality without requiring physical appliances.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If fixed configuration network capture devices are used, then specific purpose is addressed, but modification to address different business needs becomes precluded

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidbusiness need responsiveness
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements dynamic configuration capabilities where the configuration server can modify event stream destinations and transformations in real-time without requiring physical device reconfiguration. The system allows changing capture parameters, event routing destinations, and data transformation rules dynamically based on evolving business requirements. This dynamic approach enables the same capture infrastructure to adapt to different business needs without hardware changes or complex redeployment processes.

Inventive Principle:
Principle #15Dynamics

3Productivity

If ETL processes are performed to filter and transform data, then business value extraction is enabled, but process complexity and resource consumption increase

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidETL process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent performs data filtering and transformation actions at the remote capture agents during the initial capture process, rather than performing complete ETL processes later. By pre-processing and filtering data locally at the capture agents, the system reduces the volume of data that needs to be transmitted and processed centrally, thereby reducing overall processing complexity and resource consumption while still enabling business value extraction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250238420A1Dynamically modifying remote capture agent event stream destinations
Publication Date: 2025.07.24 CISCO TECHNOLOGY INC
  • US20250238420A1 patent drawing
  • US20250238420A1 patent drawing
  • US20250238420A1 patent drawing

AI summary

The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains one or more event streams from one or more remote capture agents over one or more networks, wherein the one or more event streams include event data generated from network packets captured by the one or more remote capture agents. Next, the system applies one or more transformations to the one or more event streams to obtain transformed event data from the event data. The system then enables querying of the transformed event data.