Splunk Inc.
FACILITATING CUSTOM CONTENT EXTRACTION RULE CONFIGURATION FOR REMOTE CAPTURE AGENTS

Last updated:

Abstract:

The disclosed embodiments provide a system for extracting custom content from network packets. During operation, the system receives a stream of packets. The system then parses packets in the stream to determine a protocol for each packet. Next, the system applies a custom-content-extraction rule to each packet associated with a target protocol to obtain the extracted content. Then, the system stores the extracted content in events in a data store to facilitate subsequent queries involving the extracted content.

Status:
Application
Type:

Utility

Filling date:

3 Sep 2021

Issue date:

21 Apr 2022