Splunk Inc.
Facilitating custom content extraction rule configuration for remote capture agents
Last updated:
Abstract:
The disclosed embodiments provide a system for extracting custom content from network packets. During operation, the system receives a stream of packets. The system then parses packets in the stream to determine a protocol for each packet. Next, the system applies a custom-content-extraction rule to each packet associated with a target protocol to obtain the extracted content. Then, the system stores the extracted content in events in a data store to facilitate subsequent queries involving the extracted content.
Status:
Grant
Type:
Utility
Filling date:
6 May 2019
Issue date:
7 Sep 2021