IP Library Granted Patent US 12,487,834
Granted Patent B2
US 12,487,834 · App. 18/071,331 · Granted Dec 2, 2025

Event logging protocol connector systems and methods

Inventors: Niyazi Eray Goknel (Broxbourne, GB); Paul Fellner (Marchtrenk, AT); Johannes Mayr (Grieskirchen, AT); Aqil Ahmed (Milton Keynes, GB)
Assignee: Open Text Inc.
G06F9/44505G06F9/5072G06F9/542G06F16/254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,487,834
App. No.
18/071,331
Granted
Dec 2, 2025
Kind
B2
Abstract

Embodiments provide systems and methods for logging events. A computer-implemented method, for example, includes a syslog connector providing a subscription to a cloud source that collects events from a plurality of data sources, the subscription comprising an event selection criterion, receiving event records from the cloud source according to the subscription, the received event records formatted according to a first format, transforming the event records received from the cloud source from the first format to syslog messages and storing, by the syslog connector, the syslog messages to a syslog data sink.

Claims (51)

1 . A computer-implemented method comprising:

providing, by a syslog connector, a subscription to a cloud source that collects events from a plurality of data sources, the subscription comprising an event selection criterion;

receiving, by the syslog connector, event records from the cloud source according to the subscription, the received event records formatted according to a first format;

determining to use an output format from a plurality of supported syslog formats for the received event records;

transforming, by the syslog connector, the event records received from the cloud source from the first format to syslog messages according to output format from the plurality of supported syslog formats; and

storing, by the syslog connector, the syslog messages to a syslog data sink.

2 . The computer-implemented method of claim 1 , wherein the syslog connector is an on-premises syslog connector.

3 . The computer-implemented method of claim 1 , wherein the event records are pushed from the cloud source to the syslog connector.

4 . The computer-implemented method of claim 1 , wherein the event records are pulled by the syslog connector from the cloud source.

5 . The computer-implemented method of claim 1 , further comprising:

receiving, by the syslog connector, an event logging configuration, the event logging configuration comprising the event selection criterion and a data sink configuration for the syslog data sink.

6 . The computer-implemented method of claim 5 , wherein the event logging configuration further comprises a polling interval and wherein the syslog connector polls the cloud source for additional event records according to the polling interval.

7 . The computer-implemented method of claim 1 , further comprising:

establishing an event store for the subscription;

evaluating a new event to determine that the new event is subscribed to according to the subscription;

based on the determination that the new event is subscribed to according to the subscription, add an event record for the new event to the event store for the subscription as an unread event record; and

sending the unread event record to the syslog connector and changing the unread event record to a read event record.

8 . The computer-implemented method of claim 7 , wherein the unread event record is pushed to the syslog connector.

9 . The computer-implemented method of claim 7 , wherein the unread event record is sent to the syslog connector responsive to the syslog connector pulling the unread event record.

10 . The computer-implemented method of claim 1 , wherein storing the syslog messages to the syslog data sink comprises sending a syslog file containing the syslog messages to the syslog data sink.

11 . A computer program product comprising a non-transitory, computer-readable medium storing thereon computer-executable instructions, the computer-executable instructions comprising instructions for:

providing a subscription to a cloud source that collects events from a plurality of data sources, the subscription comprising an event selection criterion;

receiving event records from the cloud source according to the subscription, the received event records formatted according to a first format;

determining to use an output format from a plurality of supported syslog formats for the received event records;

transforming the received event records from the first format to syslog messages according to the output format; and

storing the syslog messages to a syslog data sink.

12 . The computer program product of claim 11 , wherein the event records are received from the cloud source because of being pushed from the cloud source.

13 . The computer program product of claim 11 , further comprising instructions for pulling the event records from the cloud source.

14 . The computer program product of claim 11 , wherein the computer-executable instructions further comprise instructions for receiving an event logging configuration, the event logging configuration comprising the event selection criterion and a data sink configuration for the syslog data sink.

15 . The computer program product of claim 14 , wherein the event logging configuration further comprises a polling interval and wherein the computer-executable instructions further comprise instructions for polling the cloud source for new event records according to the polling interval.

16 . The computer program product of claim 11 , wherein storing the syslog messages to the syslog data sink comprises sending a syslog file containing the syslog messages to the syslog data sink.

17 . An event logging system comprising:

a first processor;

a first non-transitory, computer-readable medium storing thereon first computer-executable instructions that are executable by the first processor, the first computer-executable instructions comprising instructions for:

providing a subscription to a cloud source that collects events from a plurality of data sources, the subscription comprising an event selection criterion;

receiving event records from the cloud source according to the subscription, the received event records formatted according to a first format;

determining to use an output format from a plurality of supported syslog formats for the received event records;

transforming the received event records from the first format to syslog messages according to the output format; and

storing the syslog messages to a syslog data sink;

a second processor; and

a second non-transitory, computer-readable medium storing thereon second computer-executable instructions that are executable by the second processor, the second computer-executable instructions comprising instructions for:

establishing an event store for the subscription;

determining that a new event is subscribed to according to the subscription;

based on the determination that the new event is a subscribed to according to the subscription, adding an unread event record for the new event to the event store for the subscription; and

sending the unread event record to the first processor and changing the unread event record to a read event record in the event store for the subscription.

18 . The event logging system of claim 17 , wherein the second computer-executable instructions comprise instructions executable by the second processor for pushing the unread event record to the first processor.

19 . The event logging system of claim 17 , wherein the first computer-executable instructions comprise instructions executable by the first processor for pulling the unread event record.

20 . The event logging system of claim 19 , wherein the second computer-executable instructions comprise instructions executable by the second processor for sending the unread event record to the first processor responsive to the first processor pulling the unread event record.

21 . The computer-implemented method of claim 1 , further comprising accessing an output format selection associated with the subscription, the output format selection indicating the output format, wherein the syslog connector comprises a plurality of transformations for translating from the first format used by the cloud source to the plurality of supported syslog formats.

22 . The computer program product of claim 11 , wherein the computer-executable instructions further comprise instructions for accessing an output format selection associated with the subscription, the output format selection indicating the output format.

23 . The event logging system of claim 17 , wherein the first computer-executable instructions comprise instructions for accessing an output format selection associated with the subscription, the output format selection indicating the output format.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: GOKNEL, NIYAZI ERAY; MAYR, JOHANNES; FELLNER, PAUL; AHMED, AQIL
To: OPEN TEXT INC.
Reel/Frame 065369/0830 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
Continuity (1)
Related Publication 20240176625A1 · May 30, 2024
References Cited (16)
US 9960928B1 · Pope · 2018 [cited by examiner]
US 11522812B1 · Thoppai · 2022 [cited by examiner]
US 11818018B1 · Hsiao · 2023 [cited by applicant]
US 12368728B2 · Goknel et al. · 2025 [cited by applicant]
US 20120254313A1 · Fake · 2012 [cited by applicant]
US 20140096181A1 · Rivers · 2014 [cited by applicant]
US 20180048664A1 · Bray · 2018 [cited by applicant]
US 20190130009A1 · McLean · 2019 [cited by applicant]
US 20200106742A1 · Moore · 2020 [cited by applicant]
US 20200162308A1 · Makovsky · 2020 [cited by applicant]
US 20210067423A1 · Newman · 2021 [cited by examiner]
US 20230070608A1 · Sumien · 2023 [cited by applicant]
US 20240179154A1 · Goknel et al. · 2024 [cited by applicant]
Office Action issued for U.S. Appl. No. 18/071,349 mailed Dec. 9, 2024, 11 pages. [cited by applicant]
Thatcher, E., “System Logging: Log Messages Format for your SIEM—RFC3164 or CEF?”, Townsend Security Data Privacy Blog, retrieved from <<https://info.townsendsecurity.com/bid/55495/system-logging-log-messages-format-for… [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/071,349, mailed Mar. 26, 2025, 7 pages. [cited by applicant]