| CPC H04L 63/1416 (2013.01) [H04L 63/20 (2013.01)] | 20 Claims |

|
1. A system for security event transformation, the system comprising:
a processor;
a non-transitory computer-readable medium; and
stored instructions translatable by the processor for:
at a security event receiver:
receiving a plurality of security events of different formats from an event collector;
selecting, from the plurality of security events based on one or more criteria, security events of interest; and
forwarding the security events of interest to a security event transformer;
at the security event transformer:
receiving the security events of interest from the security event receiver; and
transforming each of the security events of interest to a standard event format so as to generate a plurality of formatted security events processable by a security information and event management (SIEM) server; and
at a security event transmitter coupled to the security event transformer:
receiving the plurality of formatted security events from the security event transformer; and
transmitting the plurality of formatted security events to the SIEM server for processing the plurality of formatted security events agnostic to the different formats.
|