IP Library › Granted Patent US 12,615,236
Granted Patent B2
US 12,615,236 · App. 18/659,759 · Granted Apr 28, 2026

High-fidelity event data for multi-cloud services

Inventors: Praveen Kumar Patnala (Santa Clara, CA); Ganesh Narayanaswamy (Sunnyvale, CA); Mark Landgrebe (Marina Del Rey, CA)
Assignee: Cisco Technology, Inc.
H04L63/0263G06F12/0802H04B10/25H04L9/0861H04L9/3242H04L9/3247H04L41/16H04L63/0227H04L63/0236H04L63/083H04L63/10H04L63/1416H04L63/1425H04L63/145H04L63/20H04L67/1008H04Q11/0066G06F16/2365G06F16/27H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,236
App. No.
18/659,759
Granted
Apr 28, 2026
Kind
B2
Abstract

Disclosed are systems, apparatuses, methods, and computer-readable media for high-fidelity event data for multi-cloud services. A method includes: storing first event information of a multi-cloud service in a cache, wherein the first event information is received from a first gateway controlled by the controller; storing second event information of the multi-cloud service in the cache, wherein the second event information is received from a first external service; mapping the second event information to the first event information to at least one identifier associated with the controller; and generating a first synthesized event information based on mapping the second event information to the first event information, the first synthesized event information including the at least one identifier, at least one event from the first event information, and at least one event from the second event information.

Claims (57)

1 . A method of synthesizing logs from different clouds and services of a multi-cloud service, comprising:

storing first event information of the multi-cloud service in a cache, wherein the first event information is received from a first gateway controlled by a controller;

storing second event information of the multi-cloud service in the cache, wherein the second event information is received from a first external service;

mapping the second event information to the first event information by identifying a dynamic address in the first event information and associating the dynamic address with configuration information provided by the controller, wherein the configuration information includes at least one identifier associated with the first gateway; and

generating a first synthesized event information based on mapping the second event information to the first event information, the first synthesized event information including the at least one identifier, at least one event from the first event information, and at least one event from the second event information.

2 . The method of claim 1 , further comprising:

after the first synthesized event information is generated, receiving third event information from a second external service; and

updating the first synthesized event information based on information in the third event information.

3 . The method of claim 1 , further comprising:

after a period of time, storing the first synthesized event information in a storage system; and

when the first synthesized event information is stored, removing the first event information, the second event information, and the first synthesized event information from the cache.

4 . The method of claim 1 , further comprising:

retrieving supplemental information based on the first event information and the second event information, wherein the supplemental information is associated with a security assessment of a source or a destination of the first event information and the second event information; and

updating the first synthesized event information based on the supplemental information.

5 . The method of claim 4 , wherein the second event information is applied to a second synthesized event information that has a timestamp that is before a timestamp of the first synthesized event information and a third synthesized event information that has a timestamp that is after the timestamp of the first synthesized event information.

6 . The method of claim 1 , further comprising:

generating a security recommendation based on synthesized event information.

7 . The method of claim 1 , wherein the first synthesized event information identifies at least one security policy applied to the first gateway.

8 . A computing device for performing a function, comprising:

at least one memory; and

at least one processor coupled to the at least one memory and configured to:

store first event information of a multi-cloud service in a cache, wherein the first event information is received from a first gateway controlled by a controller;

store second event information of the multi-cloud service in the cache, wherein the second event information is received from a first external service;

map the second event information to the first event information by identifying a dynamic address in the first event information and associating the dynamic address with configuration information provided by the controller, wherein the configuration information includes at least one identifier associated with the first gateway; and

generate a first synthesized event information based on mapping the second event information to the first event information, the first synthesized event information including the at least one identifier, at least one event from the first event information, and at least one event from the second event information.

9 . The computing device of claim 8 , wherein the at least one processor is configured to:

after the first synthesized event information is generated, receive third event information from a second external service; and

update the first synthesized event information based on information in the third event information.

10 . The computing device of claim 8 , wherein the at least one processor is configured to:

after a period of time, store the first synthesized event information in a storage system; and

when the first synthesized event information is stored, remove the first event information, the second event information, and the first synthesized event information from the cache.

11 . The computing device of claim 8 , wherein the at least one processor is configured to:

retrieve supplemental information based on the first event information and the second event information, wherein the supplemental information is associated with a security assessment of a source or a destination of the first event information and the second event information; and

update the first synthesized event information based on the supplemental information.

12 . The computing device of claim 11 , wherein the second event information is applied to a second synthesized event information that has a timestamp that is before a timestamp of the first synthesized event information and a third synthesized event information that has a timestamp that is after the timestamp of the first synthesized event information.

13 . The computing device of claim 8 , wherein the at least one processor is configured to:

generate a security recommendation based on synthesized event information.

14 . The computing device of claim 8 , wherein the first synthesized event information identifies at least one security policy applied to the first gateway.

15 . A computing device for performing a function, comprising:

a storage configured to store instructions; and

a processor configured to execute the instructions and cause the processor to:

store first event information of a multi-cloud service in a cache, wherein the first event information is received from a first gateway controlled by a controller;

store second event information of the multi-cloud service in the cache, wherein the second event information is received from a first external service;

map the second event information to the first event information by identifying a dynamic address in the first event information and associating the dynamic address with configuration information provided by the controller, wherein the configuration information includes at least one identifier associated with the first gateway; and

generate a first synthesized event information based on mapping the second event information to the first event information, the first synthesized event information including the at least one identifier, at least one event from the first event information, and at least one event from the second event information.

16 . The computing device of claim 15 , wherein the processor is configured to execute the instructions and cause the processor to:

after the first synthesized event information is generated, receive third event information from a second external service; and

update the first synthesized event information based on information in the third event information.

17 . The computing device of claim 15 , wherein the processor is configured to execute the instructions and cause the processor to:

after a period of time, store the first synthesized event information in a storage system; and

when the first synthesized event information is stored, remove the first event information, the second event information, and the first synthesized event information from the cache.

18 . The computing device of claim 15 , wherein the processor is configured to execute the instructions and cause the processor to:

retrieve supplemental information based on the first event information and the second event information, wherein the supplemental information is associated with a security assessment of a source or a destination of the first event information and the second event information; and

update the first synthesized event information based on the supplemental information.

19 . The computing device of claim 15 , wherein the processor is configured to:

generate a security recommendation based on synthesized event information.

20 . The computing device of claim 15 , wherein the first synthesized event information identifies at least one security policy applied to the first gateway.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2024
From: NARAYANASWAMY, GANESH; PATNALA, PRAVEEN KUMAR; LANDGREBE, MARK
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067407/0215 →
Continuity (2)
Provisional Application 63609196 · Dec 12, 2023
Related Publication 20250193250A1 · Jun 12, 2025
References Cited (20)
US 8918371B1 · Prikhodko et al. · 2014 [cited by applicant]
US 11374982B1 · Keren · 2022 [cited by examiner]
US 11516069B1 · Satish et al. · 2022 [cited by applicant]
US 11922222B1 · Chawla · 2024 [cited by examiner]
US 12309185B1 · Skarphedinsson · 2025 [cited by examiner]
US 20170085447A1 · Chen · 2017 [cited by examiner]
US 20180006913A1 · Asenjo · 2018 [cited by examiner]
US 20180302853A1 · Chandra · 2018 [cited by examiner]
US 20200092391A1 · Poydence et al. · 2020 [cited by applicant]
US 20200167323A1 · Swamy · 2020 [cited by examiner]
US 20210136170A1 · Katre · 2021 [cited by examiner]
US 20210192867A1 · Fang · 2021 [cited by examiner]
US 20210209228A1 · Maor et al. · 2021 [cited by applicant]
US 20210281650A1 · George et al. · 2021 [cited by applicant]
US 20220353975A1 · Ma · 2022 [cited by examiner]
US 20230388352A1 · Gilad · 2023 [cited by examiner]
US 20250184358A1 · Ghosh · 2025 [cited by examiner]
WO WO2024102856A1 · 2024 [cited by examiner]
WO WO2024227182A1 · 2024 [cited by examiner]
Huo et al, AutoLog: A log sequence Synthesis Framework for Anomaly Detection, 2023 IEEE/ACM International Conference on Automated Software Engineering (ASE), p. 497-509 (Year: 2023). [cited by examiner]