IP Library › Granted Patent US 12,271,287
Granted Patent B2
US 12,271,287 · App. 17/725,116 · Granted Apr 8, 2025

Method and system for recommending runbooks for detected events

Inventors: Raghu Hanumanth Reddy Patti (San Bruno, CA); Christopher A. Roy (Amherst, NH); Ana Maria Hernandez McCollum (Belmont, CA); Manas Goswami (San Ramon, CA); Janet Kay Kolko (Golden, CO); Sreenivas Reddy (San Ramon, CA)
Assignee: Oracle International Corporation
G06F11/3636G06F11/079G06F11/0793G06F11/3051G06F11/3065G06F11/3438G06F11/3466G06F11/3495G06F11/366G06Q10/06316G06Q10/0633G06Q10/0637G06Q10/103G06Q10/20H04L43/02G06F2201/86H04L67/00H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,271,287
App. No.
17/725,116
Granted
Apr 8, 2025
Kind
B2
Abstract

Techniques for selecting a runbook to recommend for remediating a detected event are disclosed. When a system detects an event, the system obtains metadata associated with the event. The metadata provides information about the event and a system topology of the system in which the event occurred. The system generates a recommendation for a runbook to remediate the event based on one or both of characteristics of the event and characteristics of the topology in which the event occurred. The system compares a system topology to system topologies associated with previously-executed runbooks. The system recommends one of the previously-executed runbooks to remediate a detected event based on determining that the topology associated with the previously-executed runbook is similar to the topology of the system in which the event occurred.

Claims (74)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors cause performance of operations comprising:

detecting an occurrence of an event to be remediated, the event corresponding to a target component;

obtaining first topology data indicating a first set of one or more topological relationships between the target component and a first set of one or more other components;

obtaining second topology data indicating a second set of one or more topological relationships between a second component and a second set of one or more other components;

identifying a runbook previously executed in relation to the second component, the runbook defining a list of independently executable operations; and

based on determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion, presenting the runbook as a recommendation for remediating the event,

wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

determining at least one of (a) a percentage of components that is the same in the first topology data and the second topology data, or (b) a percentage of communication channels that is the same in the first topology data and the second topology data, meets a threshold percentage.

2. The non-transitory computer readable medium of claim 1 , wherein the first topology data and the second topology data are obtained responsive to:

presenting a runbook selection interface including functionality for selecting at least one of a plurality of runbooks for execution; and

selecting the event to be remediated.

3. The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

collecting metadata associated with the event,

wherein the first topology data is obtained based on the metadata associated with the event.

4. The non-transitory computer readable medium of claim 1 , wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

identifying a first set of components in the first topology data that have a particular topological relationship with the target component; and

determining that a second set of components in the second topology data has the same particular topological relationship with a particular component in the second topology data.

5. The non-transitory computer readable medium of claim 1 , wherein the first set of one or more topological relationships includes being communicatively connected to the target component within a predefined degree of separation, the predefined degree of separation defined by a number of intervening components along a communications path between a particular component and the target component.

6. The non-transitory computer readable medium of claim 1 , wherein the second topology data is obtained from a repository of a plurality of topologies, each topology comprising a plurality of components and connections among the plurality of components,

wherein each of the plurality of topologies is associated in the repository with at least one runbook previously executed in relation at least one component in a respective topology.

7. The non-transitory computer readable medium of claim 1 , wherein presenting the runbook as the recommendation for remediating the event is further based on:

identifying a particular event to which the runbook was previously applied to remediate the particular event; and

determining that the event associated with the first topology data and the particular event meet a threshold level of similarity to each other.

8. The non-transitory computer readable medium of claim 1 , wherein the runbook includes at least one user-generated data label specifying at least one topological relationship in the second set of one or more topological relationships.

9. A method comprising:

detecting an occurrence of an event to be remediated, the event corresponding to a target component;

obtaining first topology data indicating a first set of one or more topological relationships between the target component and a first set of one or more other components;

obtaining second topology data indicating a second set of one or more topological relationships between a second component and a second set of one or more other components;

identifying a runbook previously executed in relation to the second component, the runbook defining a list of independently executable operations; and

based on determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion, presenting the runbook as a recommendation for remediating the event,

wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

determining at least one of (a) a percentage of components that is the same in the first topology data and the second topology data, or (b) a percentage of communication channels that is the same in the first topology data and the second topology data, meets a threshold percentage.

10. The method of claim 9 , wherein the first topology data and the second topology data are obtained responsive to:

presenting a runbook selection interface including functionality for selecting at least one of a plurality of runbooks for execution; and

selecting the event to be remediated.

11. The method of claim 9 , wherein the operations further comprise:

collecting metadata associated with the event,

wherein the first topology data is obtained based on the metadata associated with the event.

12. The method of claim 9 , wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

identifying a first set of components in the first topology data that have a particular topological relationship with the target component; and

determining that a second set of components in the second topology data has the same particular topological relationship with a particular component in the second topology data.

13. The method of claim 9 , wherein the first set of one or more topological relationships includes being communicatively connected to the target component within a predefined degree of separation, the predefined degree of separation defined by a number of intervening components along a communications path between a particular component and the target component.

14. The method of claim 9 , wherein the second topology data is obtained from a repository of a plurality of topologies, each topology comprising a plurality of components and connections among the plurality of components,

wherein each of the plurality of topologies is associated in the repository with at least one runbook previously executed in relation at least one component in a respective topology.

15. The method of claim 9 , wherein presenting the runbook as the recommendation for remediating the event is further based on:

identifying a particular event to which the runbook was previously applied to remediate the particular event; and

determining that the event associated with the first topology data and the particular event meet a threshold level of similarity to each other.

16. The method of claim 9 , wherein the runbook includes at least one user-generated data label specifying at least one topological relationship in the second set of one or more topological relationships.

17. A system, comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the system to perform operations comprising:

detecting an occurrence of an event to be remediated, the event corresponding to a target component;

obtaining first topology data indicating a first set of one or more topological relationships between the target component and a first set of one or more other components;

obtaining second topology data indicating a second set of one or more topological relationships between a second component and a second set of one or more other components;

identifying a runbook previously executed in relation to the second component, the runbook defining a list of independently executable operations; and

based on determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion, presenting the runbook as a recommendation for remediating the event,

wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

determining at least one of (a) a percentage of components that is the same in the first topology data and the second topology data, or (b) a percentage of communication channels that is the same in the first topology data and the second topology data, meets a threshold percentage.

18. The system of claim 17 , wherein the first topology data and the second topology data are obtained responsive to:

presenting a runbook selection interface including functionality for selecting at least one of a plurality of runbooks for execution; and

selecting the event to be remediated.

19. The system of claim 17 , wherein the operations further comprise:

collecting metadata associated with the event,

wherein the first topology data is obtained based on the metadata associated with the event.

20. The system of claim 17 , wherein determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion comprises:

identifying a first set of components in the first topology data that have a particular topological relationship with the target component; and

determining that a second set of components in the second topology data has the same particular topological relationship with a particular component in the second topology data.

21. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors cause performance of operations comprising:

detecting an occurrence of an event to be remediated, the event corresponding to a target component;

obtaining first topology data indicating a first set of one or more topological relationships between the target component and a first set of one or more other components;

obtaining second topology data indicating a second set of one or more topological relationships between a second component and a second set of one or more other components;

identifying a runbook previously executed in relation to the second component, the runbook defining a list of independently executable operations; and

based on determining the first set of one or more topological relationships and the second set of one or more topological relationships meet a similarity criterion, presenting the runbook as a recommendation for remediating the event,

wherein the first set of one or more topological relationships includes being communicatively connected to the target component within a predefined degree of separation, the predefined degree of separation defined by a number of intervening components along a communications path between a particular component and the target component.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2022
From: PATTI, RAGHU HANUMANTH REDDY; ROY, CHRISTOPHER A.; MCCOLLUM, ANA MARIA HERNANDEZ; GOSWAMI, MANAS; KOLKO, JANET KAY; REDDY, SREENIVAS
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059655/0815 →
Continuity (6)
Provisional Application 63261832 · Sep 29, 2021
Provisional Application 63236563 · Aug 24, 2021
Provisional Application 63236561 · Aug 24, 2021
Provisional Application 63236557 · Aug 24, 2021
Provisional Application 63236565 · Aug 24, 2021
Related Publication 20230064625A1 · Mar 2, 2023
References Cited (76)
US 1167760A · Shahbaz · 1916 [cited by examiner]
US 8533608B1 · Tantiprasut · 2013 [cited by applicant]
US 8713436B2 · Cheng et al. · 2014 [cited by applicant]
US 8767593B1 · Allen et al. · 2014 [cited by applicant]
US 9164965B2 · Molesky et al. · 2015 [cited by applicant]
US 9819547B2 · Maini · 2017 [cited by examiner]
US 9891971B1 · Kuhhirte · 2018 [cited by examiner]
US 10120552B2 · King et al. · 2018 [cited by applicant]
US 10284437B2 · Scallan · 2019 [cited by examiner]
US 10379990B2 · Krishnamoorthy et al. · 2019 [cited by applicant]
US 10671263B2 · King et al. · 2020 [cited by applicant]
US 10678610B2 · Ebrahimi et al. · 2020 [cited by applicant]
US 10769043B2 · Sabharwal et al. · 2020 [cited by applicant]
US 10866872B1 · Gudka et al. · 2020 [cited by applicant]
US 10878042B2 · Busch · 2020 [cited by examiner]
US 10922493B1 · Das · 2021 [cited by examiner]
US 10970632B2 · Sabharwal et al. · 2021 [cited by applicant]
US 10999164B1 · Sridhar et al. · 2021 [cited by applicant]
US 11074512B1 · Forte et al. · 2021 [cited by applicant]
US 11080121B2 · Thornhill et al. · 2021 [cited by applicant]
US 11550652B1 · Arora et al. · 2023 [cited by applicant]
US 11704474B2 · Huang et al. · 2023 [cited by applicant]
US 20050223285A1 · Faihe et al. · 2005 [cited by applicant]
US 20120303772A1 · Ennis · 2012 [cited by applicant]
US 20130090996A1 · Stark · 2013 [cited by applicant]
US 20130103973A1 · Werth et al. · 2013 [cited by applicant]
US 20150142825A1 · Deshmukh et al. · 2015 [cited by applicant]
US 20150188768A1 · Maini et al. · 2015 [cited by applicant]
US 20170061338A1 · Mack et al. · 2017 [cited by applicant]
US 20170090736A1 · King et al. · 2017 [cited by applicant]
US 20180091528A1 · Shahbaz et al. · 2018 [cited by applicant]
US 20190230003A1 · Gao et al. · 2019 [cited by applicant]
US 20190391892A1 · Sabharwal et al. · 2019 [cited by applicant]
US 20190392310A1 · Sabharwal et al. · 2019 [cited by applicant]
US 20200004618A1 · Thornhill et al. · 2020 [cited by applicant]
US 20200136928A1 · Sethi · 2020 [cited by examiner]
US 20200167255A1 · Gudka et al. · 2020 [cited by applicant]
US 20200204428A1 · Sasidharan et al. · 2020 [cited by applicant]
US 20200349042A1 · Gudka et al. · 2020 [cited by applicant]
US 20210191769A1 · Eschinger et al. · 2021 [cited by applicant]
US 20210279160A1 · Huang et al. · 2021 [cited by applicant]
US 20210333953A1 · Fitzgerald et al. · 2021 [cited by applicant]
US 20220067620A1 · Thornhil et al. · 2022 [cited by applicant]
US 20220342796A1 · Cui et al. · 2022 [cited by applicant]
US 20220414571A1 · Buggins et al. · 2022 [cited by applicant]
US 20230034173A1 · Russell et al. · 2023 [cited by applicant]
US 20230062588A1 · Patti et al. · 2023 [cited by applicant]
US 20240012917A1 · Milito et al. · 2024 [cited by applicant]
US 20240280973A1 · Nalam · 2024 [cited by applicant]
WO 2015065356A1 · 2015 [cited by applicant]
“Assigning System Center Orchestrator Runbooks Permissions”, Retrieved at https://docs.flexera.com/appportal2017/Content/helplibrary/AP_ConnectMSOrch.htm, Retrieved on May 2022, 2 Pages. [cited by applicant]
“Automation Hybrid Runbook Worker overview”, Retrieved at https://docs.microsoft.com/en-us/azure/automation/automation-hybrid-runbook-worker, Retrieved on Apr. 29, 2022, 11 Pages. [cited by applicant]
“AWS Systems Manager Automation”, Retrieved at https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-automation.html, Retrieved at May 2022, 4 Pages. [cited by applicant]
“Build & Run Remediation Runbook”, Retrieved at https://wellarchitectedlabs.com/operational-excellence/200_labs/200_automating_operations_with_playbooks_and_runbooks/4_build_run_remediation_runbook/, Retrieved on May 20… [cited by applicant]
“Complex deployments made easy”, Retrieved at https://octopus.com/, Retrieved on May 2022, 6 Pages. [cited by applicant]
“Configure runbook output and message streams”, Retrieved at https://docs.microsoft.com/en-us/azure/automation/automation-runbook-output-and-messages, Jul. 10, 2021, 17 Pages. [cited by applicant]
“Datasheet-NetBrain-Integrated-Edition-7.0”, Retrieved at https://www.netbraintech.com/wp-content/uploads/2017/09/Datasheet-NetBrain-Integrated-Edition-7.0.pdf, Retrieved at May 2022, 2 Pages. [cited by applicant]
“DRYiCE iAutomate v5.0”, Retrieved at https://www.dryice.ai/releases/dryice-iautomate-v50, Retrieved on May 2020, 7 Pages. [cited by applicant]
“DRYiCE iAutomate” Retrieved at https://www.dryice.ai/resource/brochure/dryice-iautomate, Retrieved on May 2022, 2 Pages. [cited by applicant]
“DRYiCE iAutomate”, Retrieved at https://www.dryice.ai/products-and-platforms/iautomate, Retrieved on May 2022, 7 Pages. [cited by applicant]
“Evolution of Artificial Intelligence for IT Operations”, Retrieved at https://www.siliconindia.com/viewpoints/cxoinsights/evolution-of-artificial-intelligence-for-it-operations-nwid-10000.html, Retrieved on May 2022, 4… [cited by applicant]
“HCL Hero—Workload Automation”, Retrieved at https://solutions.hcldoc.com/HCL_HERO/!SSL!/Responsive_HTML5/Overview/Product_Overview.htm, Retrieved on May 2022, 2 Pages. [cited by applicant]
“How a Simple Misconfiguration Can Ruin Everyone's Day—NetBrain”, Retrieved at https://www.netbraintech.com/blog/human-error-the-forgotten-single-point-of-failure/, Apr. 28, 2017, 7 Pages. [cited by applicant]
“IBM Runbook Automation and IBM Alert Notification deliver more agile, automated operations management”, Retrieved at https://www.ibm.com/common/ssi/ShowDoc.wss?docURL=/common/ssi/rep_ca/1/897/ENUS216-031/index.html, Fe… [cited by applicant]
“IBM Runbook Automation Guide”, Retrieved at https://webcache.googleusercontent.com/search?q=cache:jZ5yusTVFAEJ:https://www.ibm.com/support/knowledgecenter/SSZQDR/com.ibm.rba.doc/rba_pdf_guide.pdf+&cd=11&hl=en&ct=clnk&g… [cited by applicant]
“Manage role permissions and security in Automation”, Retrieved at https://docs.microsoft.com/en-us/azure/automation/automation-role-based-access-control, Sep. 26, 2021, 30 Pages. [cited by applicant]
“Microsoft Azure Automation _ Netreo”, Retrieved at https://www.netreo.com/wpsandbox/solutions/microsoft-azure-automation/, Retrieved at May 2022, 5 Pages. [cited by applicant]
“Octopus Deploy 2019.11: Operations Runbooks RTW”, Retrieved at https://octopus.com/blog/octopus-release-2019.11, Dec. 18, 2019, 4 Pages. [cited by applicant]
“Octopus Deploy Documentation—Runbooks”, Retrieved at https://octopus.com/docs/runbooks, Retrieved on May 2022, 2 Pages. [cited by applicant]
“Runbook Automation (Rundeck)”, Retrieved at https://www.pagerduty.com/resources/learn/aiops-incident-management-2021/, Retrieved on May 2022, 8 Pages. [cited by applicant]
“Runbooks permissions”, Retrieved at https://octopus.com/docs/runbooks/runbook-permissions, Retrieved at May 2022, 2 Pages. [cited by applicant]
“The Guide to Automating Runbook Execution—Shoreline”, Retrieved at https://shoreline.io/blog/the-guide-to-automating-runbook-execution, Feb. 25, 2021, 9 Pages. [cited by applicant]
“Troubleshoot Azure Automation runbook issues_Microsoft Docs”, Retrieved at https://docs.microsoft.com/en-us/azure/automation/troubleshoot/runbooks, Sep. 24, 2021, 26 Pages. [cited by applicant]
“Use runbooks to automate operations activities”, Retrieved at https://www.ibm.com/garage/method/practices/manage/runbooks-to-automate-operations/, Retrieved on May 2022, 9 Pages. [cited by applicant]
“What is Azure Automation Management—Netreo Newtork Moniroting Tool”, Retrieved at https://www.netreo.com/cloud-automation/what-is-azure-automation-management/, Sep. 9, 2015, 2 Pages. [cited by applicant]
“What is Runbook Automation?”, Retrieved at https://www.rundeck.com/what-is-runbook-automation, Retrieved on May 2022, 10 Pages. [cited by applicant]