IP Library › Granted Patent US 12,591,676
Granted Patent B1
US 12,591,676 · App. 18/169,063 · Granted Mar 31, 2026

Translating result data formats for nested courses of action executed by an incident service

Inventors: Glenn Gallien (San Francisco, CA); Sourabh Satish (Fremont, CA)
Assignee: Cisco Technology, Inc.
G06F21/568G06F21/554G06F21/561H04L63/1416H04L63/20G06F16/29G06F16/9537
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,591,676
App. No.
18/169,063
Filed
Feb 14, 2023
Granted
Mar 31, 2026
Kind
B1
Examiner
ZHU, ZHIMEI
Art Unit
2495
USPC
726/23
Abstract

Described herein are systems and methods for improving incident response in an information technology (IT) environment. In one implementation, an incident service initiates execution of a course of action and identifies a step in the first course of action that determines data in a first format. The incident service further determines a format requirement for a second step in the course of action and translates the data from the first format to the second format in accordance with the format requirement.

Claims (55)

1 . A computer-implemented method comprising:

receiving input defining a first course of action, wherein the first course of action includes a first plurality of steps to respond to incidents occurring in information technology (IT) environments, wherein a first step of the first plurality of steps represents a call to a second course of action;

initiating execution of the first course of action;

identifying, during execution of the first course of action, the first step of the first plurality of steps representing the call to the second course of action;

initiating execution of the second course of action;

obtaining result data based on the execution of the second course of action;

identifying a first format of the result data;

determining that a second step of the first plurality of steps uses as input result data in a second format that is different from the first format at least by a level of accuracy;

translating the result data from the first format to the second format, wherein one of the first format or the second format corresponds to location information for an Internet Protocol address associated with an incident where the location information is in a form of a geographical code, and the other of the first format or the second format corresponds to geographical coordinates; and

executing, based on the second format of the result data, the second step of the first plurality of steps of the first course of action to respond to the incident occurring in an IT environment, wherein the second step comprises comparing the result data with one or more criteria.

2 . The method of claim 1 , further comprising:

receiving, via a graphical user interface provided by an incident service, input defining the first course of action, wherein the input defines a graphical diagram indicative of sequencing for the first plurality of steps; and

storing data defining the first course of action in a course of action database managed by the incident service.

3 . The method of claim 1 , wherein the result data comprises addressing data for the incident occurring in the IT environment.

4 . The method of claim 1 , wherein the second step comprises a step to compare the result data with a threshold.

5 . The method of claim 1 , wherein the first course of action includes a plurality of operations each corresponding to a different data format, and wherein translating the result data from the first format to the second format includes executing an operation of the plurality of operations associated with the first format.

6 . The method of claim 1 , further comprising:

receiving, via a graphical user interface, input defining the second course of action; and

storing data defining the second course of action in a course of action database.

7 . The method of claim 1 , further comprising:

in response to encountering the first step of the first plurality of steps during execution of the first course of action, pausing execution of the first course of action; and

in response to obtaining the result data, resuming execution of the first course of action.

8 . The method of claim 1 , wherein the first course of action involves modifying configuration of a component in an IT environment.

9 . A computing device comprising:

a processor; and

a non-transitory, computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

receiving input defining a first course of action, wherein the first course of action includes a first plurality of steps to respond to incidents occurring in information technology (IT) environments, wherein a first step of the first plurality of steps represents a call to a second course of action;

initiating execution of the first course of action;

identifying, during execution of the first course of action, the first step of the first plurality of steps representing the call to the second course of action;

initiating execution of the second course of action;

obtaining result data based on the execution of the second course of action;

identifying a first format of the result data;

determining that a second step of the first plurality of steps uses as input result data in a second format that is different from the first format at least by a level of accuracy;

translating the result data from the first format to the second format, wherein one of the first format or the second format corresponds to location information for an Internet Protocol address associated with an incident where the location information is in a form of a geographical code, and the other of the first format or the second format corresponds to geographical coordinates; and

executing, based on the second format of the result data, the second step of the first plurality of steps of the first course of action to respond to the incident occurring in an IT environment, wherein the second step comprises comparing the result data with one or more criteria.

10 . The computing device of claim 9 , wherein the instructions, when executed by the processor, further cause the processor to perform operations including:

receiving, via a graphical user interface provided by an incident service, input defining the first course of action, wherein the input defines a graphical diagram indicative of sequencing for the first plurality of steps; and

storing data defining the first course of action in a course of action database managed by the incident service.

11 . The computing device of claim 9 , wherein the result data comprises addressing data for the incident occurring in the IT environment.

12 . The computing device of claim 9 , wherein the result data comprises geographic location information.

13 . A non-transitory, computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause a system to perform operations including:

receiving input defining a first course of action, wherein the first course of action includes a first plurality of steps to respond to incidents occurring in information technology (IT) environments, wherein a first step of the first plurality of steps represents a call to a second course of action;

initiating execution of the first course of action;

identifying, during execution of the first course of action, the first step of the first plurality of steps representing the call to the second course of action;

initiating execution of the second course of action;

obtaining result data based on the execution of the second course of action;

identifying a first format of the result data;

determining that a second step of the first plurality of steps uses as input result data in a second format that is different from the first format at least by a level of accuracy;

translating the result data from the first format to the second format, wherein one of the first format or the second format corresponds to location information for an Internet Protocol address associated with an incident where the location information is in a form of a geographical code, and the other of the first format or the second format corresponds to geographical coordinates; and

executing, based on the second format of the result data, a second step of the first plurality of steps of the first course of action to respond to the incident occurring in an IT environment, wherein the second step comprises comparing the result data with one or more criteria.

14 . The non-transitory, computer-readable medium of claim 13 , wherein the instructions, when executed by the processor, further cause the processor to perform operations including:

receiving, via a graphical user interface provided by an incident service, input defining the first course of action, wherein the input defines a graphical diagram indicative of sequencing for the first plurality of steps; and

storing data defining the first course of action in a course of action database managed by the incident service.

15 . The non-transitory, computer-readable medium of claim 13 , wherein the result data comprises addressing data for the incident occurring in the IT environment.

16 . The non-transitory, computer-readable medium of claim 13 , wherein the result data comprises geographic location information.

Assignments (2)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
Continuity (1)
Continuation 16119954 · Aug 31, 2018
References Cited (26)
US 8739278B2 · Varghese · 2014 [cited by examiner]
US 9229953B2 · Reinart · 2016 [cited by examiner]
US 9866574B1 · Tonn · 2018 [cited by examiner]
US 10091230B1 · Machani et al. · 2018 [cited by applicant]
US 10394802B1 · Porath · 2019 [cited by examiner]
US 10743046B1 · Sahni et al. · 2020 [cited by applicant]
US 11604877B1 · Gallien · 2023 [cited by examiner]
US 20050086635A1 · Parikh · 2005 [cited by examiner]
US 20090089869A1 · Varghese · 2009 [cited by examiner]
US 20140279829A1 · Reinart · 2014 [cited by examiner]
US 20150254276A1 · Oliver · 2015 [cited by examiner]
US 20150365438A1 · Carver et al. · 2015 [cited by applicant]
US 20170024088A1 · La Pean · 2017 [cited by examiner]
US 20170365027A1 · Hein · 2017 [cited by examiner]
US 20180262519A1 · Arunkumar · 2018 [cited by examiner]
US 20190132224A1 · Verma · 2019 [cited by examiner]
US 20190213016A1 · Raghunath et al. · 2019 [cited by applicant]
WO WO2016126415A1 · 2016 [cited by examiner]
WO WO2017147411A1 · 2017 [cited by examiner]
P Cichonski, “Computer Security Incident Handling Guide”, National Institute of Standards and Technology Special Publication 800-61 Revision 2, obtained online from <https://nvlpubs.nist.gov/nistpubs/specialpublications… [cited by examiner]
M. Elkhodr, S. Shahrestani and H. Cheung, “A contextual-adaptive Location Disclosure Agent for general devices in the Internet of Things,” 38th Annual IEEE Conference on Local Computer Networks—Workshops, Sydney, NSW, A… [cited by examiner]
Chris Simmons, “Playbook Series: Creating Nested Playbooks for Responding to Malware Incidents”, Dec. 8, 2016, obtaine online from <https://www.splunk.com/en_us/blog/security/playbook-series-creating-nested-playbooks-fo… [cited by applicant]
Final Office Action, U.S. Appl. No. 16/119,954, filed Feb. 7, 2022, 43 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/119,954, filed Jul. 23, 2021, 24 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 16/119,954, filed May 25, 2022, 31 pages. [cited by applicant]
5 Notice of Allowance, U.S. Appl. No. 16/119,954, filed Nov. 16, 2022, 18 pages. [cited by applicant]