发明名称 Network aware distributed business transaction anomaly detection
摘要 A system monitors applications and network flows used during the business transaction to determine distributed business transaction anomalies caused at least in part by network performance issues. A network flow associated with a business transaction is monitored by a network agent. The network agent may capture packets, analyze the packets and other network data to determine one or more baselines, and dynamically compare subsequent network flow performance to those baselines to determine an anomaly. When an anomaly in a network flow is detected, this information may be provided to a user along with other data regarding a business transaction that is utilizing the network flow. Concurrently with the network agent monitoring, application agents may monitor one or more applications performing the business transaction. The present system reports performance data for a business transaction in terms of application performance and network performance, all in the context of a distributed business transaction.
申请公布号 US9531614(B1) 申请公布日期 2016.12.27
申请号 US201514928982 申请日期 2015.10.30
申请人 AppDynamics, Inc. 发明人 Nataraj Harish;Chandel Ajay;Kaligotla Prakash;Kondapalli Naveen
分类号 G06F15/16;H04L12/26;H04L29/08;G06F12/00 主分类号 G06F15/16
代理机构 Bachmann Law Group 代理人 Bachmann Law Group
主权项 1. A method for monitoring a distributed business transaction over a plurality of machines and at least one network, comprising: monitoring, by a plurality of application agents, one or more applications that process requests and perform functions that make up the distributed business transaction to generate application data; monitoring, by a plurality of network agents, network sockets that are used to process communications between the plurality of machines as part of the distributed business transaction to generate network flow data; detecting, by one of the application agents, an application anomaly with the one or more monitored applications; based on the detecting of the application anomaly, querying the plurality of network agents to determine whether one of the network agents has detected a network flow anomaly associated with the monitored network sockets, wherein the querying the plurality of network agents include providing to the network agents, parameters that specify which of the monitored network sockets to analyze to identify the network flow anomaly; associating the detected network flow anomaly with the distributed business transaction; correlating the detected application anomaly and the detected network flow anomaly to identify the application anomaly as being affected by the network flow anomaly; and providing a snapshot displaying the correlated application anomaly and network flow anomaly associated with the distributed business transaction to indicate a relationship between the application anomaly and the network flow anomaly in the distributed business transaction.
地址 San Francisco CA US