IP Library › Granted Patent US 11,755,405
Granted Patent B1
US 11,755,405 · App. 17/713,971 · Granted Sep 12, 2023

Identifying suggested actions for responding to incidents in an it environment

Inventors: Sourabh Satish (Fremont, CA); David Wayman (San Francisco, CA); Glenn Gallien (San Francisco, CA); Akshay Dongaonkar (Oakland, CA)
Assignee: Splunk Inc.
G06F11/0793G06F9/451G06F11/0769G06Q10/06316
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,405
App. No.
17/713,971
Granted
Sep 12, 2023
Kind
B1
Abstract

An information technology (IT) operations platform is described that enables users to execute one or more executable actions from a set of executable actions presented in a prioritized order based on historical data. In response to identifying an occurrence of a type of incident in an IT environment, the IT operations platform generates a workbook based on a customizable workbook template. The customizable workbook template includes a plurality of tasks grouped into a plurality of phases for responding to occurrences of the type of incident, and each task of the plurality of tasks is associated with a respective set of suggested executable actions for completing the corresponding task. The IT operations platform then causes the display of a graphical user interface (GUI) including a representation of the workbook, including interface elements representing the respective set of suggested executable actions displayed in the prioritized order.

Claims (71)

1. A computer-implemented method, comprising:

identifying, by an IT operations platform, an occurrence of a type of incident in an IT environment;

in response to identifying the occurrence of the type of incident, generating a workbook based on a customizable workbook template, wherein the customizable workbook template includes a plurality of tasks for remediating occurrences of the type of incident;

identifying, for a task of the plurality of tasks, one or more suggested executable actions for completing the task, wherein a suggested executable action of the one or more suggested executable actions is identified by correlating a name or description of the suggested executable action to a name or description of the task; and

causing display of a graphical user interface (GUI) including a representation of the workbook, wherein the representation of the workbook includes the one or more suggested executable actions.

2. The computer-implemented method of claim 1 , further comprising:

receiving input selecting the suggested executable action; and

executing, by the IT operations platform, the suggested executable action.

3. The computer-implemented method of claim 1 , further comprising:

receiving input selecting an executable action that is different from the one or more suggested executable actions;

executing, by the IT operations platform, the executable action;

generating log data indicating whether execution of the executable action was successful; and

evaluating the log data to determine whether to include, in the customizable workbook template, the executable action in the one or more suggested executable actions associated with the task.

4. The computer-implemented method of claim 1 , further comprising:

receiving input requesting to remove a suggested executable action from the one or more suggested executable actions for completing the task; and

removing the suggested executable action from the customizable workbook template.

5. The computer-implemented method of claim 1 , wherein identifying the occurrence of the type of incident in the IT environment comprises:

receiving an input from a data intake and query system indicating the occurrence of the type of incident in the IT environment.

6. The computer-implemented method of claim 1 , further comprising:

executing, by the IT operations platform, the suggested executable action;

generating log data indicating whether execution of the suggested executable action was successful; and

modifying an order of the one or more suggested executable actions based on the log data.

7. The computer-implemented method of claim 1 , wherein the type of incident is associated with a severity level, and wherein the method further comprises:

determining a designated amount of time to resolve the occurrence of the type of incident based on the severity level; and

sending a notification to a user account associated with a particular task of the plurality of tasks; and

initiating a timer for the designated amount of time.

8. The computer-implemented method of claim 1 , wherein the type of incident is associated with a severity level, and wherein the method further comprises:

determining a designated amount of time to resolve the occurrence of the type of incident based on the severity level;

sending a notification to a first user account associated with a particular task of the plurality of tasks;

initiating a timer for the designated amount of time; and

in response to an expiration of the timer prior to receiving a selection of an executable action from the first user account, designating a second user account for performance of the particular task.

9. The computer-implemented method of claim 1 , wherein the one or more suggested executable actions are displayed in the GUI in a prioritized order based on historical data, wherein the historical data includes characteristics of previous executions of the one or more suggested executable actions, and wherein the characteristics of the previous executions of the one or more suggested executable actions include one or more of: a result of the previous executions, frequency of use of each of the one or more suggested executable actions, or recency of use of each of the one or more suggested executable actions.

10. The computer-implemented method of claim 1 , wherein the plurality of tasks are grouped in two or more separate phases, wherein the GUI includes a representation of the two or more separate phases.

11. A computing device, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

identifying, by an IT operations platform, an occurrence of a type of incident in an IT environment;

in response to identifying the occurrence of the type of incident, generating a workbook based on a customizable workbook template, wherein the customizable workbook template includes a plurality of tasks for remediating occurrences of the type of incident;

identifying, for a task of the plurality of tasks, one or more suggested executable actions for completing the task, wherein a suggested executable action of the one or more suggested executable actions is identified by correlating a name or description of the suggested executable action to a name or description of the task; and

causing display of a graphical user interface (GUI) including a representation of the workbook, wherein the representation of the workbook includes the one or more suggested executable actions.

12. The computing device of claim 11 , wherein the instructions, when executed by the processor, further cause the processor to perform operations including:

receiving input selecting the suggested executable action; and

executing, by the IT operations platform, the suggested executable action.

13. The computing device of claim 11 , further comprising:

receiving input selecting an executable action that is different from the one or more suggested executable actions;

executing, by the IT operations platform, the executable action;

generating log data indicating whether execution of the executable action was successful; and

evaluating the log data to determine whether to include, in the customizable workbook template, the executable action in the one or more suggested executable actions associated with the task.

14. The computing device of claim 11 , wherein the instructions, when executed by the processor, further cause the processor to perform operations including:

receiving input requesting to remove a suggested executable action from the one or more suggested executable actions for completing the task; and

removing the suggested executable action from the customizable workbook template.

15. The computing device of claim 11 , wherein identifying the occurrence of the type of incident in the IT environment comprises:

receiving an input from a data intake and query system indicating the occurrence of the type of incident in the IT environment.

16. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:

identifying, by an IT operations platform, an occurrence of a type of incident in an IT environment;

in response to identifying the occurrence of the type of incident, generating a workbook based on a customizable workbook template, wherein the customizable workbook template includes a plurality of tasks for remediating occurrences of the type of incident;

identifying, for a task of the plurality of tasks, one or more suggested executable actions for completing the task, wherein a suggested executable action of the one or more suggested executable actions is identified by correlating a name or description of the suggested executable action to a name or description of the task; and

causing display of a graphical user interface (GUI) including a representation of the workbook, wherein the representation of the workbook includes the one or more suggested executable actions.

17. The non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform operations including:

receiving input selecting the suggested executable action; and

executing, by the IT operations platform, the suggested executable action.

18. The non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform operations including:

receiving input selecting an executable action that is different from the one or more suggested executable actions;

executing, by the IT operations platform, the executable action;

generating log data indicating whether execution of the executable action was successful; and

evaluating the log data to determine whether to include, in the customizable workbook template, the executable action in the one or more suggested executable actions associated with the task.

19. The non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to perform operations including:

receiving input requesting to remove a suggested executable action from the one or more suggested executable actions for completing the task; and

removing the suggested executable action from the customizable workbook template.

20. The non-transitory computer-readable medium of claim 16 , wherein identifying the occurrence of the type of incident in the IT environment comprises:

receiving an input from a data intake and query system indicating the occurrence of the type of incident in the IT environment.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2022
From: SATISH, SOURABH; WAYMAN, DAVID; GALLIEN, GLENN; DONGAONKAR, AKSHAY
To: SPLUNK INC.
Reel/Frame 059716/0810 →
Continuity (1)
Continuation 16429043 · Jun 2, 2019
Cited By (3)
US 12,493,615 US 12,608,370 US 12,670,057