Applying updated configuration dynamically to remote capture agents

US2025233811A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2025233811-A1
Application numberUS-202418983051-A
CountryUS
Kind codeA1
Filing dateDec 16, 2024
Priority dateApr 15, 2014
Publication dateJul 17, 2025
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains, at a remote capture agent, configuration information for the remote capture agent from a configuration server over a network. Next, the system uses the configuration information to configure the generation of event data from network data obtained from network packets at the remote capture agent. The system then uses the configuration information to configure transformation of the event data or the network data into transformed event data at the remote capture agent.

First claim

Opening claim text (preview).

1 - 20 . (canceled) 21 . A computer-implemented method, comprising: obtaining, at a configuration server, configuration information for a remote capture agent on a network in an information technology (IT) environment; providing, by the configuration server, configuration information to the remote capture agent; obtaining, at the configuration server, an update to the configuration information; and providing, by the configuration server, the updated configuration information to the remote capture agent. 22 . The method of claim 21 , wherein the remote capture agent executes in a cloud computing system 23 . The method of claim 21 , wherein the remote capture agent monitors network packets traversing a plurality of network interfaces including the network interface. 24 . The method of claim 21 , wherein the configuration information is obtained at the configuration server from a user or an application used to access event data generated by the remote capture agent. 25 . The method of claim 21 , wherein the configuration information is used by the remote capture agent to configure generation or transformation of event data. 26 . The method of claim 21 , wherein the update to the configuration information enables generation of new event streams at the remote capture agent for use with one or more new use cases associated with network data captured by the remote capture agent. 27 . The method of claim 21 , wherein the updated configuration information is used by the remote capture agent to reconfigure generation or transformation of event data at the remote capture agent during runtime of the remote capture agent. 28 . The method of claim 21 , wherein the updated configuration information is provided by the configuration server based on the configuration server being configured to dynamically configure the remote capture agent. 29 . The method of claim 21 , wherein the configuration information identifies a first network component to which the remote capture agent is to send timestamped events, and the updated configuration information identifies a second network component to which the remote capture agent is to send timestamped events. 30 . The method of claim 21 , wherein the configuration information indicates a first manner in which to generate or send a first plurality of timestamped events, and the updated configuration information identifies a second manner in which to generate or send a second plurality of timestamped events. 31 . The method of claim 21 , wherein the configuration information indicates a first field to include in a first plurality of timestamped events generated by the remote capture agent, and the updated configuration information identifies a second field to include in a second plurality of timestamped events generated by the remote capture agent. 32 . A computing device, comprising: a processor; and a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including: obtaining, at a configuration server, configuration information for a remote capture agent on a network in an information technology (IT) environment; providing, by the configuration server, configuration information to the remote capture agent; obtaining, at the configuration server, an update to the configuration information; and providing, by the configuration server, the updated configuration information to the remote capture agent. 33 . The computing device of claim 32 , wherein the configuration information identifies a first network component to which the remote capture agent is to send timestamped events, and the updated configuration information identifies a second network component to which the remote capture agent is to send timestamped events. 34 . The computing device of claim 32 , wherein the configuration information indicates a first manner in which to generate or send a first plurality of timestamped events, and the updated configuration information identifies a second manner in which to generate or send a second plurality of timestamped events. 35 . The computing device of claim 32 , wherein the configuration information indicates a first field to include in a first plurality of timestamped events generated by the remote capture agent, and the updated configuration information identifies a second field to include in a second plurality of timestamped events generated by the remote capture agent. 36 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including: obtaining, at a configuration server, configuration information for a remote capture agent on a network in an information technology (IT) environment; providing, by the configuration server, configuration information to the remote capture agent; obtaining, at the configuration server, an update to the configuration information; and providing, by the configuration server, the updated configuration information to the remote capture agent. 37 . The non-transitory computer-readable medium of claim 36 , wherein the remote capture agent monitors network packets traversing a plurality of network interfaces including the network interface. 38 . The non-transitory computer-readable medium of claim 36 , wherein the configuration information is used by the remote capture agent to configure generation or transformation of event data. 39 . The non-transitory computer-readable medium of claim 36 , wherein the update to the configuration information enables generation of new event streams at the remote capture agent for use with one or more new use cases associated with network data captured by the remote capture agent. 40 . The non-transitory computer-readable medium of claim 36 , wherein the updated configuration information is provided by the configuration server based on the configuration server being configured to dynamically configure the remote capture agent.

Assignees

Inventors

Classifications

  • using time related information in packets, e.g. by adding timestamps · CPC title

  • the condition being an adaptation, e.g. in response to network events · CPC title

  • comprising network management agents or mobile agents therefor · CPC title

  • by backing up or archiving configuration information · CPC title

  • H04L43/04Primary

    Processing captured monitoring data, e.g. for logfile generation · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2025233811A1 cover?
The disclosed embodiments provide a method and system for processing network data. During operation, the system obtains, at a remote capture agent, configuration information for the remote capture agent from a configuration server over a network. Next, the system uses the configuration information to configure the generation of event data from network data obtained from network packets at the r…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/0856. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 17 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).