Split Templates for Network Telemetry Export

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic telemetry technologies, such as NetFlow and IPFIX, face challenges in rapid periodic exports due to the bulky nature of monolithic templates, which cause pressure on network devices and lead to packet drops, especially when exporting static and almost static information elements frequently.

Innovation Solution

The solution involves splitting a conventional monolithic template into a static template and a dynamic template, where static templates generate records for static characteristics and dynamic templates generate records for dynamic characteristics, allowing for rapid periodic exports without redundant data, thereby reducing bandwidth overhead and enabling more frequent exports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monolithic templates are used for network traffic telemetry exports, then complete flow information is captured, but the template size becomes bulky causing pressure on network devices and packet drops

Engineering Contradiction:
Improvepacket export reliabilityVSAvoidtemplate size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides a monolithic template into multiple smaller sub-templates, each handling specific flow information elements. This segmentation reduces the size of individual templates exported to the flow collector, lowering processing pressure on network devices while maintaining complete flow information through coordinated use of multiple sub-templates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts only the necessary flow information elements required for specific telemetry purposes from the complete monolithic template. By selecting and exporting only relevant elements through sub-templates, the system reduces unnecessary data transmission and processing overhead while maintaining the ability to capture complete flow information when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If frequent exports are performed to achieve real-time network visibility, then rapid periodic exports are enabled, but packet drops increase due to processing pressure from bulky templates

Engineering Contradiction:
Improveexport frequencyVSAvoidpacket export reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

By segmenting the monolithic template into smaller sub-templates, the patent enables more frequent exports without overwhelming network device processing capacity. The reduced size of each sub-template allows rapid periodic exports to occur reliably, achieving real-time network visibility while maintaining packet export reliability.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If all flow information elements are included in exports, then complete flow information is captured, but bandwidth overhead increases due to redundant static data

Engineering Contradiction:
Improveflow information completenessVSAvoidbandwidth overhead
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts only the specific flow information elements needed for particular telemetry purposes from the complete set of available elements. By exporting only relevant data through selectively designed sub-templates, the system reduces bandwidth overhead from redundant static information while maintaining completeness of essential flow information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11265257B2Rapid network traffic telemetry exports with split templates and flow records
Publication Date: 2022.03.01 CISCO TECHNOLOGY INC
  • US11265257B2 patent drawing
  • US11265257B2 patent drawing
  • US11265257B2 patent drawing

AI summary

A solution that provides for increased high-frequency, record exports giving real-time insight of traffic patterns, by splitting a conventional monolithic template into a static template and a dynamic template. Static flow records are sent only at the beginning of a flow, or when ‘almost static’ information elements change. Dynamic records are sent very frequently, and only when there is a dynamic information element change.