Data collection with user identification
Abstract
Methods, systems and computer program products for collecting data processing system status information monitoring network communications with the data processing system to observe transaction(s) associated with the data processing system. The transaction(s) is analyzed to determine if the transaction(s) complies with a quality standard and a trigger is generated based on the analysis of the transaction(s). System status information is collected responsive to the generation of the trigger. The collection of system status information may be provided by collecting system status information so that collection of the system status information automatically time correlates the collected system status information with the trigger.
Claims
exact text as granted — not AI-modified1 . A method for accessing communication information, comprising:
gathering network communications using an intermediate entity, said network communications include a plurality of data units; grouping said data units into multiple groups based on one or more identifiers, a particular group of said multiple groups having a particular data unit that includes a particular user identification and another data unit that does not have said particular user identification; binding said particular user identification to said particular group; and providing different treatment of data units based on said particular user identification.
2 . A method according to claim 1 , wherein:
said grouping said data units into multiple groups comprises grouping said data units into transactions and grouping said transactions into sessions; one transaction of a particular session is a login transaction; said particular data unit is part of said login transaction; said another data unit is part of a transaction subsequent to said login transaction, but in the same session as said login transaction; and said binding said particular user identification to said particular group associates said particular user identification with said another data unit.
3 . A method according to claim 1 , wherein:
said intermediate entity is a data center switch.
4 . A method according to claim 1 , wherein:
said gathering network communications using an intermediate entity includes receiving packets from a mirrored port on a data center switch.
5 . A method according to claim 1 , wherein:
said groups are flows.
6 . A method according to claim 1 , wherein:
said groups are connections.
7 . A method according to claim 1 , wherein:
said groups are sessions.
8 . A method according to claim 1 , wherein:
said groups are transactions.
9 . A method according to claim 1 , wherein:
said providing different treatment includes weighting information associated with said particular group based on said particular user identification; and acting on said information based on said weighting.
10 . A method according to claim 1 , wherein:
said particular user identification includes user identity information from a login transaction.
11 . A method according to claim 1 , wherein:
said particular user identification includes an address that is associated with a user identity.
12 . A method according to claim 1 , further comprising:
retrieving user attributes from a storage system based on said particular user identification; and binding said user attributes to said particular group.
13 . A method according to claim 1 , wherein:
said grouping said data units into multiple groups comprises:
assembling said data units into flows,
identifying transactions based on said flows,
identifying sessions and binding transactions to sessions, and
examining a particular transaction to find said particular user identification, said particular transaction includes a session identification for one of said sessions; and
said binding said particular user identification to said particular group comprises associating said particular user identification with said session identification.
14 . A method according to claim 13 , further comprising:
using said session identification to relate said user identification to another transaction.
15 . A method according to claim 1 , wherein:
said data units are packets.
16 . A method according to claim 1 , wherein:
said data units are transactions.
17 . A method for accessing communication information, comprising:
gathering packets from network communications monitored at an intermediate entity; identifying flows between two entities; demarcating transactions for said flows; grouping transactions into sessions; identifying that a particular transaction includes a user identification; associating said user identification with one or more other transactions of a same session as said particular transaction based on said step of identifying; and providing differentiated treatment of transactions based on said user identification.
18 . A method according to claim 17 , wherein:
said step of gathering packets includes receiving packets from a mirrored port on a data center switch.
19 . A method according to claim 17 , wherein:
said associating includes binding said user identification to a session identification for said same session as said particular transaction; and said one or more other transactions are associated with said session identification for said same session as said particular transaction.
20 . A method according to claim 17 , wherein:
said packets are part of an HTTP stream.
21 . A method according to claim 17 , wherein:
said particular transaction includes a cookie in an HTTP header for a web application; and said cookie includes said user identification.
22 . A processor readable storage device having processor readable code embodied on said processor readable storage device, said processor readable code for programming a processor to perform a method comprising:
receiving network communications monitored at an intermediate entity, said network communication includes a plurality of data units; grouping said data units into multiple groups; determining that a particular data unit of a particular group of said multiple groups includes a particular user identification; associating said particular user identification with one or more other data units of said particular group based on said step of determining that said particular data unit of said particular group of said multiple groups includes said particular user identification; and providing different treatment of data units based on said particular user identification.
23 . A processor readable storage device according to claim 22 , wherein:
said receiving network communications includes communicating with a mirrored port on a data center switch.
24 . A processor readable storage device according to claim 22 , wherein:
said receiving network communications includes receiving packets; said grouping includes grouping packets into transactions and grouping transaction into sessions; said particular group is a particular session; said particular data unit is a particular transaction of said particular session; and said one or more other data units are one or more other transactions of said particular session.
25 . A processor readable storage device according to claim 22 , wherein:
said associating includes binding said particular user identification with a particular session identification associated with said particular session.
26 . A processor readable storage device according to claim 22 , wherein:
said data units are packets in an HTTP stream.
27 . A processor readable storage device having processor readable code embodied on said processor readable storage device, said processor readable code for programming a processor to perform a method comprising:
receiving packets from an intermediate entity on a network transporting said packets; assembling said packets into flows; identifying transactions based on said flows; identifying sessions and binding transactions to said sessions; examining a particular transaction to find a user identification, said particular transaction includes a session identification for one of said sessions; using said session identification to relate said user identification to another transaction; and acting on said another transaction based on said user identification.
28 . A processor readable storage device according to claim 27 , wherein:
said receiving packets includes receiving said packets from a mirrored port on a data center switch.
29 . A processor readable storage device according to claim 27 , wherein:
using said session identification to relate said user identification to another transaction includes binding said user identification to said session identification after said examining said particular transaction, said session identification becomes associated with said particular transaction after finding said user identification with respect to said particular transaction.
30 . A processor readable storage device according to claim 27 , wherein:
said particular transaction is a login transaction.
31 . An apparatus for accessing communication information, comprising:
a communication interface; a storage device; and a processor in communication with said communication interface and said storage device, said processor performs a method comprising:
accessing network communications from an intermediate entity on a network,
grouping a subset of data units of said network communications into a particular group based on one or more identifiers, said particular group having a particular data unit that includes a particular user identification and another data unit that does not have said particular user identification,
identifying said particular user identification with said particular group, and
providing said particular group with treatment that is different from a different group of said data units based on said particular user identification.
32 . An apparatus according to claim 31 , wherein said grouping comprises:
assembling said subset of data units into flows; identifying transactions based on said flows; identifying sessions and binding transactions to sessions; and examining a particular transaction to find said particular user identification, said particular transaction includes a session identification for one of said sessions.Join the waitlist — get patent alerts
Track US2006095570A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.