| CPC G06F 21/566 (2013.01) [H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01); G06F 2221/034 (2013.01)] | 30 Claims |

|
1. A computer-implemented method, executed on a computing device, comprising:
defining a first query for a first security-relevant subsystem within a computing platform, including defining a single search in a universal language, and translating the single search in the universal language into a plurality of technology-specific searches, including a first security-relevant subsystem specific search executable by the first security-relevant subsystem, including translating a syntax of the unified query into a syntax of each of the plurality of plurality of technology-specific searches;
processing the first query on the first security-relevant subsystem to generate a first data set concerning security events occurring on the first security-relevant subsystem; and
receiving the first data set concerning the security events occurring on the first security-relevant subsystem.
|