IP Library › Granted Patent US 12,596,533
Granted Patent B2
US 12,596,533 · App. 19/094,601 · Granted Apr 7, 2026

Selecting a custom function from available custom functions to be added into a playbook

Inventors: Matthew Hanson (San Jose, CA); Sydney Flak (San Jose, CA); Colin Fagan (San Jose, CA); Jeffery Roberts (San Jose, CA); Govinda Salinas (San Jose, CA); Philip Royer (San Jose, CA)
Assignee: Cisco Technology, Inc.
G06F8/36G06F8/658G06F8/71G06F9/44521
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,533
App. No.
19/094,601
Filed
Mar 28, 2025
Granted
Apr 7, 2026
Kind
B2
Art Unit
2199
USPC
717/122
Abstract

Techniques are described for enabling users of an information technology (IT) and security operations application to create highly reusable custom functions for playbooks. The creation and execution of playbooks using an IT and security operations application generally enables users to automate operations related to an IT environment responsive to the identification of various types of incidents or other triggering conditions. Users can create playbooks to automate operations such as, for example, modifying firewall settings, quarantining devices, restarting servers, etc., to improve users' ability to efficiently respond to various types of incidents operational issues that arise from time to time in IT environments.

Claims (31)

1 . A method comprising:

receiving a first input defining a custom function block;

wherein the first input includes a specification of one or more input parameters to the custom function block, and user-provided executable source code defining functionality of the custom function block;

adding the custom function block to a first playbook in response to user input; and

executing, by a security operations application, the first playbook including the custom function block to perform security operations.

2 . The method of claim 1 further comprising adding the custom function block to a second playbook in response to a new user input, and executing, by the security operations application, the second playbook including the custom function block to perform one or more security operations.

3 . The method of claim 1 wherein the method further comprises saving the custom function block in a repository separate from any playbooks.

4 . The method of claim 1 wherein the one or more input parameters to the custom function block are received from the first playbook during execution of the first playbook.

5 . The method of claim 1 wherein adding the custom function block to the first playbook in response to the user input is performed using a playbook configuration tool.

6 . The method of claim 1 further comprising returning outputs from the custom function block to the first playbook.

7 . A system comprising:

one or more computers each including a processor and a memory, wherein the one or more computers are operable to execute instructions which cause the system to perform operations including:

receiving a first input defining a custom function block;

wherein the first input includes a specification of one or more input parameters to the custom function block, and user-provided executable source code defining functionality of the custom function block;

adding the custom function block to a first playbook in response to user input; and

executing, by a security operations application, the first playbook including the custom function block to perform security operations.

8 . The system of claim 7 wherein the operations further comprise adding the custom function block to a second playbook in response to a new user input, and executing, by the security operations application, the second playbook including the custom function block to perform one or more security operations.

9 . The system of claim 7 wherein the operations further comprise saving the custom function block in a repository separate from any playbooks.

10 . The system of claim 7 wherein the one or more input parameters to the custom function block are received from the first playbook during execution of the first playbook.

11 . The system of claim 7 wherein adding the custom function block to the first playbook in response to the user input is performed using a playbook configuration tool.

12 . The system of claim 7 wherein the operations further comprise returning outputs from the custom function block to the first playbook.

13 . A non-volatile computer-readable media including instructions, which when executed by one or more computers each including a processor and a memory, cause the one or more computers to perform operations including:

receiving a first input defining a custom function block;

wherein the first input includes a specification of one or more input parameters to the custom function block, and user-provided executable source code defining functionality of the custom function block;

adding the custom function block to a first playbook in response to user input; and

executing, by a security operations application, the first playbook including the custom function block to perform security operations.

14 . The non-volatile computer-readable media of claim 13 wherein the operations further comprise adding the custom function block to a second playbook in response to a new user input, and executing, by the security operations application, the second playbook including the custom function block to perform one or more security operations.

15 . The non-volatile computer-readable media of claim 13 wherein the operations further comprise saving the custom function block in a repository separate from any playbooks.

16 . The non-volatile computer-readable media of claim 13 wherein the one or more input parameters to the custom function block are received from the first playbook during execution of the first playbook.

17 . The non-volatile computer-readable media of claim 13 wherein adding the custom function block to the first playbook in response to the user input is performed using a playbook configuration tool.

18 . The non-volatile computer-readable media of claim 13 wherein the operations further comprise returning outputs from the custom function block to the first playbook.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2025
From: HANSON, MATTHEW; FLAK, SYDNEY; FAGAN, COLIN; ROBERTS, JEFFERY; SALINAS, GOVINDA; ROYER, PHILIP
To: SPLUNK INC.
Reel/Frame 070669/0691 →
Continuity (5)
Continuation 18929324 · Oct 28, 2024
Continuation 18539646 · Dec 14, 2023
Continuation 17950848 · Sep 22, 2022
Continuation 16945574 · Jul 31, 2020
Related Publication 20250224934A1 · Jul 10, 2025
References Cited (9)
US 10795649B1 · Drake · 2020 [cited by examiner]
US 11244045B2 · Lunsford et al. · 2022 [cited by applicant]
US 20170063957A1 · Rolih · 2017 [cited by applicant]
US 20170177175A1 · Lai · 2017 [cited by examiner]
US 20170207926A1 · Gil · 2017 [cited by examiner]
US 20180367568A1 · Martinez · 2018 [cited by examiner]
US 20190260769A1 · Sharon · 2019 [cited by examiner]
US 20200175077A1 · Sharan · 2020 [cited by examiner]
US 20200293308A1 · Janssen et al. · 2020 [cited by applicant]