IP Library Granted Patent US 12,368,728
Granted Patent B2
US 12,368,728 · App. 18/071,349 · Granted Jul 22, 2025

Security event transformation and logging systems and methods

Inventors: Niyazi Eray Goknel (Broxbourne, GB); Paul Fellner (Marchtrenk, AT); Johannes Mayr (Grieskirchen, AT); Aqil Ahmed (Milton Keynes, GB)
Assignee: Open Text Inc.
H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,728
App. No.
18/071,349
Granted
Jul 22, 2025
Kind
B2
Abstract

Embodiments provide systems and methods for logging events. A computer-implemented method comprises receiving input for selecting one or more event types to receive from an event collector, receiving, based on the one or more event types, a plurality of security events from the event collector, transforming each of the plurality of security events to a standard format to generate a plurality of formatted security events and transmitting the plurality of formatted security events to a security information and event management (SIEM) server.

Claims (71)

1. A system for security event transformation, the system comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for:

at a security event receiver:

receiving a plurality of security events of different formats from an event collector;

selecting, from the plurality of security events based on one or more criteria, security events of interest; and

forwarding the security events of interest to a security event transformer;

at the security event transformer:

receiving the security events of interest from the security event receiver; and

transforming each of the security events of interest to a standard event format so as to generate a plurality of formatted security events processable by a security information and event management (SIEM) server; and

at a security event transmitter coupled to the security event transformer:

receiving the plurality of formatted security events from the security event transformer; and

transmitting the plurality of formatted security events to the SIEM server for processing the plurality of formatted security events agnostic to the different formats.

2. The system of claim 1 , wherein the plurality of security events is pushed from the event collector to the security event receiver.

3. The system of claim 1 , wherein the plurality of security events is fetched from the event collector by the security event receiver.

4. The system of claim 3 , wherein the security event receiver further receives input for a fetch time interval, the security event receiver fetching events at every fetch time interval and forwarding to the security event transformer.

5. The system of claim 1 , wherein the event collector collects a corpus of endpoint events from a plurality of endpoints coupled over a network to the event collector, the security event receiver receiving the endpoint events.

6. The system of claim 1 , wherein the event collector collects a corpus of events, the system further comprising a Security Event Application Programming Interface (Security Event API) coupled between the event collector and the security event receiver, the Security Event API receiving input for one or more event subscriptions, each of the one or more event subscriptions describing attributes of events within the corpus of events to receive, transform, and transfer to the SIEM server.

7. The system of claim 1 , wherein the SIEM server comprises a plurality of SIEM servers, and wherein the standard event format is a universal event format processable by the plurality of SIEM servers.

8. A method for security event transformation, the method comprising:

at a security event receiver:

receiving a plurality of security events of different format from an event collector;

selecting, from the plurality of security events based on one or more criteria, security events of interest; and

forwarding the security events of interest to a security event transformer;

at the security event transformer:

receiving the security events of interest from the security event receiver; and

transforming each of the security events of interest to a standard event format so as to generate a plurality of formatted security events processable by a security information and event management (SIEM) server; and

at a security event transmitter coupled to the security event transformer:

receiving the plurality of formatted security events from the security event transformer; and

transmitting the plurality of formatted security events to the SIEM server for processing the plurality of formatted security events agnostic to the different formats.

9. The method of claim 8 , wherein receiving the plurality of security events from the event collector further comprises:

pushing the plurality of security events from the event collector.

10. The method of claim 8 , wherein receiving the plurality of security events from the event collector further comprises:

fetching the plurality of security events from the event collector.

11. The method of claim 10 , further comprising:

receiving input for a fetch time interval; and

fetching events from the event collector at the fetch time interval.

12. The method of claim 8 , further comprising:

collecting, by the event collector, a corpus of endpoint events from a plurality of endpoints coupled over a network to the event collector; and

receiving, by the security event receiver, the endpoint events.

13. The method of claim 8 , further comprising:

collecting, by the event collector, a corpus of events from a plurality of endpoints coupled over a network to the event collector;

receiving input for one or more event subscriptions, each of the one or more event subscriptions describing attributes of events within the corpus of events; and

receiving, based at least on the one or more event subscriptions, a plurality of security events from the event collector.

14. The method of claim 8 , wherein the SIEM server comprises a plurality of SIEM servers, and wherein the standard event format is a universal event format processable by the plurality of SIEM servers.

15. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

at a security event receiver:

receiving a plurality of security events of different format from an event collector;

selecting, from the plurality of security events based on one or more criteria, security events of interest; and

forwarding the security events of interest to a security event transformer;

at the security event transformer:

receiving the security events of interest from the security event receiver; and

transforming each of the security events of interest to a standard event format so as to generate a plurality of formatted security events processable by a security information and event management (SIEM) server; and

at a security event transmitter coupled to the security event transformer:

receiving the plurality of formatted security events from the security event transformer; and

transmitting the plurality of formatted security events to the SIEM server for processing the plurality of formatted security events agnostic to the different formats.

16. The computer program product of claim 15 , wherein receiving the plurality of security events from the event collector further comprises:

pushing the plurality of security events from the event collector.

17. The computer program product of claim 15 , wherein receiving the plurality of security events from the event collector further comprises:

fetching the plurality of security events from the event collector by the security event receiver.

18. The computer program product of claim 17 , wherein the instructions are further translatable by the processor for:

receiving input for a fetch time interval; and

fetching events from the event collector at the fetch time interval.

19. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

collecting, by the event collector, a corpus of endpoint events from a plurality of endpoints coupled over a network to the event collector; and

receiving, by the security event receiver, the endpoint events.

20. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

collecting, by the event collector, a corpus of events from a plurality of endpoints coupled over a network to the event collector;

receiving input for one or more event subscriptions, each of the one or more event subscriptions describing attributes of events within the corpus of events; and

receiving, based at least on the one or more event subscriptions, a plurality of security events from the event collector.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2023
From: GOKNEL, NIYAZI ERAY; MAYR, JOHANNES; FELLNER, PAUL; AHMED, AQIL
To: OPEN TEXT INC.
Reel/Frame 065369/0790 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
Continuity (1)
Related Publication 20240179154A1 · May 30, 2024
References Cited (15)
US 9960928B1 · Pope · 2018 [cited by applicant]
US 11522812B1 · Thoppai · 2022 [cited by applicant]
US 11818018B1 · Hsiao · 2023 [cited by examiner]
US 20120254313A1 · Fake · 2012 [cited by examiner]
US 20140096181A1 · Rivers · 2014 [cited by examiner]
US 20180048664A1 · Bray · 2018 [cited by examiner]
US 20190130009A1 · McLean · 2019 [cited by examiner]
US 20200106742A1 · Moore · 2020 [cited by examiner]
US 20200162308A1 · Makovsky · 2020 [cited by examiner]
US 20210067423A1 · Newman · 2021 [cited by applicant]
US 20230070608A1 · Sumien · 2023 [cited by examiner]
US 20240176625A1 · Goknel et al. · 2024 [cited by applicant]
Eppy Thatcher, “System Logging: Log Messages Format for your SIEM—RFC 3164 or CEF?”, Townsend Security Data Privacy Blog, Retrieved From https://info.townsendsecurity.com/bid/55495/system-logging-log-messages-format-for… [cited by examiner]
Office Action issued for U.S. Appl. No. 18/071,331 mailed Sep. 26, 2024, 12 pages. [cited by applicant]
Office Action issued for U.S. Appl. No. 18/071,331 mailed Mar. 5, 2025, 14 pages. [cited by applicant]
Cited By (1)
US 12,487,834