Splunk Inc.
FACILITATING CUSTOM CONTENT EXTRACTION RULE CONFIGURATION FOR REMOTE CAPTURE AGENTS
Last updated:
Abstract:
The disclosed embodiments provide a system for extracting custom content from network packets. During operation, the system receives a stream of packets. The system then parses packets in the stream to determine a protocol for each packet. Next, the system applies a custom-content-extraction rule to each packet associated with a target protocol to obtain the extracted content. Then, the system stores the extracted content in events in a data store to facilitate subsequent queries involving the extracted content.
Status:
Application
Type:
Utility
Filling date:
3 Sep 2021
Issue date:
21 Apr 2022