IP Library Granted Patent US 12,164,889
Granted Patent B1
US 12,164,889 · App. 18/539,646 · Granted Dec 10, 2024

Selecting a custom function from available custom functions to be added into a playbook

Inventors: Matthew Hanson (San Jose, CA); Sydney Flak (San Jose, CA); Colin Fagan (Santa Clara, CA); Jeffery Roberts (Orleans, CA); Govinda Salinas (San Jose, CA); Philip Royer (Boston, MA)
Assignee: Splunk Inc.
G06F8/36G06F8/658G06F8/71G06F9/44521
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,164,889
App. No.
18/539,646
Granted
Dec 10, 2024
Kind
B1
Abstract

Techniques are described for enabling users of an information technology (IT) and security operations application to create highly reusable custom functions for playbooks. The creation and execution of playbooks using an IT and security operations application generally enables users to automate operations related to an IT environment responsive to the identification of various types of incidents or other triggering conditions. Users can create playbooks to automate operations such as, for example, modifying firewall settings, quarantining devices, restarting servers, etc., to improve users' ability to efficiently respond to various types of incidents operational issues that arise from time to time in IT environments.

Claims (58)

1. A method, comprising:

storing a user-provided code in a repository, wherein the user-provided code defines a custom function available for use in user-configurable playbooks;

causing, by an information technology (IT) and security operations application, a visual playbook editor interface to be presented, the visual playbook editor interface allowing for user-configuration of a playbook for use in responding to a security or operational issue in an IT environment, wherein the visual playbook editor interface displays identifiers of multiple custom functions from the repository, including the custom function, that are available for inclusion in the playbook;

receiving, by the IT and security operations application via the visual playbook editor interface, an input from a first user indicating a request to insert a custom function block associated with the custom function into the playbook;

detecting the security or operational issue in the IT environment; and

executing the playbook, comprising obtaining and executing the user-provided code from the repository.

2. The method of claim 1 , wherein the user-provided code defining the custom function is generated by a second user, the second user being a different user from the first user indicating the request to insert the custom function block associated with the custom function into the playbook.

3. The method of claim 1 , further comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more input parameters associated with the custom function.

4. The method of claim 3 , wherein the one or more input parameters associated with the custom function include:

one or more data elements associated with one or more upstream function blocks of the playbook;

one or more data elements associated with an incident container;

one or more globally accessible data elements.

5. The method of claim 1 , further comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more output values associated with the custom function, wherein the one or more output values are used as inputs into a downstream function block of the playbook.

6. The method of claim 1 , further comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user modifying the user-provided code defining the custom function; and

storing the modified user-provided code as a separate copy of the custom function in the repository.

7. The method of claim 6 , further comprising:

causing, by the IT and security operations application via the visual playbook editor interface, an option to be presented to store the modified user-provided code as the separate copy of the custom function in the repository.

8. A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors of a computing device, cause the computing device to implement an information technology (IT) and security operations application to perform operations comprising:

storing a user-provided code in a repository, wherein the user-provided code defines a custom function available for use in user-configurable playbooks;

causing a visual playbook editor interface to be presented, the visual playbook editor interface allowing for user-configuration of a playbook for use in responding to a security or operational issue in an IT environment, wherein the visual playbook editor interface displays identifiers of multiple custom functions from the repository, including the custom function, that are available for inclusion in the playbook;

receiving, via the visual playbook editor interface, an input from a first user indicating a request to insert a custom function block associated with the custom function into the playbook;

detecting the security or operational issue in the IT environment; and

executing the playbook, comprising obtaining and executing the user-provided code from the repository.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the user-provided code defining the custom function is generated by a second user, the second user being a different user from the first user indicating the request to insert the custom function block associated with the custom function into the playbook.

10. The non-transitory computer-readable storage medium of claim 8 , wherein the instructions, when executed by the one or more processors of the computing device, further cause operations comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more input parameters associated with the custom function.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the one or more input parameters associated with the custom function include:

one or more data elements associated with one or more upstream function blocks of the playbook;

one or more data elements associated with an incident container;

one or more globally accessible data elements.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the instructions, when executed by the one or more processors of the computing device, further cause operations comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more output values associated with the custom function, wherein the one or more output values are used as inputs into a downstream function block of the playbook.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the instructions, when executed by the one or more processors of the computing device, further cause operations comprising:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user modifying the user-provided code defining the custom function; and

storing the modified user-provided code as a separate copy of the custom function in the repository.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions, when executed by the one or more processors of the computing device, further cause operations comprising:

causing, by the IT and security operations application via the visual playbook editor interface, an option to be presented to store the modified user-provided code as the separate copy of the custom function in the repository.

15. A computing device, comprising:

a processor;

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the computing device to perform operations including:

storing a user-provided code in a repository, wherein the user-provided code defines a custom function available for use in user-configurable playbooks;

causing, by an information technology (IT) and security operations application, a visual playbook editor interface to be presented, the visual playbook editor interface allowing for user-configuration of a playbook for use in responding to a security or operational issue in an IT environment, wherein the visual playbook editor interface displays identifiers of multiple custom functions from the repository, including the custom function, that are available for inclusion in the playbook;

receiving, by the IT and security operations application via the visual playbook editor interface, an input from a first user_indicating a request to insert a custom function block associated with the custom function into the playbook;

detecting the security or operational issue in the IT environment; and

executing the playbook, comprising obtaining and executing the user-provided code from the repository.

16. The computing device of claim 15 , wherein the user-provided code defining the custom function is generated by a second user, the second user being a different user from the first user indicating the request to insert the custom function block associated with the custom function into the playbook.

17. The computing device of claim 15 , wherein the instructions, when executed by the computing device, further cause the computing device to perform operations including:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more input parameters associated with the custom function.

18. The computing device of claim 15 , wherein the instructions, when executed by the computing device, further cause the computing device to perform operations including:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user indicating one or more output values associated with the custom function, wherein the one or more output values are used as inputs into a downstream function block of the playbook.

19. The computing device of claim 15 , wherein the instructions, when executed by the computing device, further cause the computing device to perform operations including:

receiving, by the IT and security operations application via the visual playbook editor interface, another input from the first user modifying the user-provided code defining the custom function; and

storing the modified user-provided code as a separate copy of the custom function in the repository.

20. The computing device of claim 19 , wherein the instructions, when executed by the processor, further cause the processor to perform operations including:

causing, by the IT and security operations application via the visual playbook editor interface, an option to be presented to store the modified user-provided code as the separate copy of the custom function in the repository.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2023
From: HANSON, MATTHEW; FLAK, SYDNEY; FAGAN, COLIN; ROBERTS, JEFFERY; SALINAS, GOVINDA; ROYER, PHILIP
To: SPLUNK INC.
Reel/Frame 065869/0800 →
Continuity (2)
Continuation 17950848 · Sep 22, 2022
Continuation 16945574 · Jul 31, 2020
Cited By (1)
US 12,298,981