Configurable playbooks in an IT and security operations application
Techniques are described for providing a new “capability block” for information technology (IT) and security operations application playbooks. A capability block broadly enables playbook creators to create automations including generic actions that are not tied to computing environment-specific assumptions about a computing environment in which the playbook is to be executed. Once a playbook containing one or more capability blocks is distributed to a user's computing environment, a user can use a visual playbook editor or other interface to configure the capability blocks for their environment. The configuration of a capability block can include selecting an input playbook that accepts input parameters and provides output parameters required by the capability block, where the input playbook includes implementation steps for a particular type of computing environment.
1 . A computer-implemented method comprising:
causing, by an information technology (IT) and security operations application, display of an automation playbook including a capability block, wherein the automation playbook defines a collection of actions to be performed based on an event provided as input to the automation playbook, and wherein the capability block defines a generic action to be performed and is not associated with any specific application, computing asset, or environment-dependent configuration prior to distribution of the automation playbook, when the automation playbook is configured or executed in a user's environment;
receiving input selecting an input playbook associated with a first app to assign to the capability block, wherein the input playbook accepts as input one or more input parameters and, upon execution, generates one or more output parameters; and
executing the automation playbook, wherein executing the automation playbook includes, upon reaching the capability block, invoking execution of the input playbook;
wherein the automation playbook includes a second capability block that is assigned a second input playbook associated with a second app.
2 . The computer-implemented method of claim 1 , further comprising:
obtaining, from the input playbook, one or more output values corresponding to the one or more output parameters; and
providing the one or more output values to a downstream component of the automation playbook.
3 . The computer-implemented method of claim 1 , wherein execution of the input playbook includes execution of an action provided by an app of the IT and security operations application, and wherein the app is configured to interface with a third-party application or service.
4 . The computer-implemented method of claim 1 , wherein the automation playbook is displayed in a visual playbook editor of the IT and security operations application, wherein the automation playbook includes a plurality of capability blocks including the capability block, and wherein the visual playbook editor indicates which capability blocks are not associated with an implementing input playbook.
5 . The computer-implemented method of claim 1 , wherein the first app is associated with a first type of third-party application or service, wherein the second app is associated with a second type of third-party application or service.
6 . The computer-implemented method of claim 1 , wherein the input playbook is a first input playbook, wherein the first input playbook is assigned to the capability block at a first point in time, and wherein the method further comprises:
receiving, at a second point in time, additional input selecting a second input playbook to assign to the capability block, wherein the first input playbook is associated with a first action implementation, and wherein the second input playbook is associated with a second action implementation that is different from the first action implementation; and
executing the automation playbook, wherein executing the automation playbook includes, upon reaching the capability block, invoking execution of the second input playbook.
7 . The computer-implemented method of claim 1 , further comprising receiving, via a visual playbook editor, input selecting a repository storing a plurality of input playbooks including the input playbook.
8 . The computer-implemented method of claim 1 , wherein the input selecting the input playbook is first input, and wherein the method further comprises:
receiving second input identifying a label associated with events triggering execution of the automation playbook,
wherein executing the automation playbook includes identifying an event including the label.
9 . The computer-implemented method of claim 1 , further comprising:
identifying, by the IT and security operations application, the input playbook from a plurality of candidate input playbooks for implementing the capability block, wherein the IT and security operations application identifies the input playbook based on matching the input playbook to a parameter specification; and
causing, in a visual playbook editor, display of the input playbook as a recommended playbook for implementing the capability block.
10 . A computing device comprising:
a processor; and
a non-transitory computer-readable medium having stored thereon instructions configured for execution by the processor, which cause the processor to perform operations including:
causing, by an information technology (IT) and security operations application, display of an automation playbook including a capability block, wherein the automation playbook defines a collection of actions to be performed based on an event provided as input to the automation playbook, and wherein the capability block defines a generic action to be performed and is not associated with any specific application, computing asset, or environment-dependent configuration prior to distribution of the automation playbook, when the automation playbook is configured or executed in a user's environment;
receiving input selecting an input playbook associated with a first app to assign to the capability block, wherein the input playbook accepts as input one or more input parameters and, upon execution, generates one or more output parameters; and
executing the automation playbook, wherein executing the automation playbook includes, upon reaching the capability block, invoking execution of the input playbook;
wherein the automation playbook includes a second capability block that is assigned a second input playbook associated with a second app.
11 . The computing device of claim 10 , where the operations further include:
obtaining, from the input playbook, one or more output values corresponding to the one or more output parameters; and
providing the one or more output values to a downstream component of the automation playbook.
12 . The computing device of claim 10 , wherein execution of the input playbook includes execution of an action provided by an app of the IT and security operations application, and wherein the app is configured to interface with a third-party application or service.
13 . The computing device of claim 10 , wherein the automation playbook is displayed in a visual playbook editor of the IT and security operations application, wherein the automation playbook includes a plurality of capability blocks including the capability block, and wherein the visual playbook editor indicates which capability blocks are not associated with an implementing input playbook.
14 . A non-transitory, computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:
causing, by an information technology (IT) and security operations application, display of an automation playbook including a capability block, wherein the automation playbook defines a collection of actions to be performed based on an event provided as input to the automation playbook, and wherein the capability block defines a generic action to be performed and is not associated with any specific application, computing asset, or environment-dependent configuration prior to distribution of the automation playbook, when the automation playbook is configured or executed in a user's environment;
receiving input selecting an input playbook associated with a first app to assign to the capability block, wherein the input playbook accepts as input one or more input parameters and, upon execution, generates one or more output parameters; and
executing the automation playbook, wherein executing the automation playbook includes, upon reaching the capability block, invoking execution of the input playbook;
wherein the automation playbook includes a second capability block that is assigned a second input playbook associated with a second app.
15 . The non-transitory, computer-readable medium of claim 14 , wherein the operations further include:
obtaining, from the input playbook, one or more output values corresponding to the one or more output parameters; and
providing the one or more output values to a downstream component of the automation playbook.
16 . The non-transitory, computer-readable medium of claim 14 , wherein execution of the input playbook includes execution of an action provided by an app of the IT and security operations application, and wherein the app is configured to interface with a third-party application or service.
17 . The non-transitory, computer-readable medium of claim 14 , wherein the automation playbook is displayed in a visual playbook editor of the IT and security operations application, wherein the automation playbook includes a plurality of capability blocks including the capability block, and wherein the visual playbook editor indicates which capability blocks are not associated with an implementing input playbook.