IP Library › Granted Patent US 12,598,218
Granted Patent B2
US 12,598,218 · App. 19/001,194 · Granted Apr 7, 2026

Hybrid execution of custom playbook codeblocks

Inventors: Chakravarthy Sridhar (Campbell, CA); Minjie Qiu (San Jose, CA); Atif Mahadik (Fremont, CA)
Assignee: Cisco Technology, Inc.
H04L63/20G06F8/34H04L41/0681H04L41/0816H04L41/0886H04L41/0894H04L41/20H04L41/22H04L63/0263H04L63/0281H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,218
App. No.
19/001,194
Granted
Apr 7, 2026
Kind
B2
Abstract

Techniques are described for enabling a cloud-based IT and security operations application to execute playbooks containing custom code in a manner that mitigates types of risk related to the misuse of cloud-based resources and security of user data. Users use a client application to create and modify playbooks and, upon receiving input to save a playbook, the client application determines whether the playbook includes custom code. If the client application determines that the playbook includes custom code, the client application establishes a connection with a proxy application (also referred to as an “automation broker”) running in the user's own on-premises network and sends a representation of the playbook to the proxy application. The client application further sends to the IT and security operations application an identifier of the playbook and an indication that the playbook (or the custom code portions of the playbook) is stored within the user's on-premises network.

Claims (32)

1 . A computer-implemented method comprising:

sending, by an information technology (IT) and security operations application executing in a cloud provider network, resources to facilitate configuring of a playbook, wherein the configured playbook identifies a plurality of code blocks that define operations to be performed to respond to an identification of an incident occurring in an IT environment associated with a user, and the plurality of code blocks comprises custom code provided by the user;

causing, by the IT and security operations application, at least part of the configured playbook, including the custom code, to be stored in a user's network in preparation for future execution of the at least part of the configured playbook, wherein the user's network is external to the cloud provider network; and

consequent to a detection of the incident in the IT environment, sending, to a proxy application executing in the user's network, a request to execute the at least part of the configured playbook, wherein the request causes execution of the at least part of the configured playbook, including the custom code, in the user's network.

2 . The computer-implemented method as recited in claim 1 , wherein a client device establishes a connection to the proxy application using a tunnel bridge that establishes a secure connection between the client device and the tunnel bridge and between the tunnel bridge and the proxy application in the user's network.

3 . The computer-implemented method as recited in claim 1 , wherein the request to execute the at least part of the configured playbook is generated automatically responsive to the IT and security operations application identifying the incident.

4 . The computer-implemented method as recited in claim 1 , wherein the at least part of the configured playbook is stored in a version-control system repository in the user's network.

5 . The computer-implemented method as recited in claim 1 , wherein the execution of the at least part of the configured playbook comprises performing an action that involves interaction with a computing resource running in the cloud provider network.

6 . The computer-implemented method as recited in claim 1 , wherein the user's network is associated with a first tenant of the IT and security operations application, and wherein the playbook was created by a second tenant of the IT and security operations application that is different from the first tenant.

7 . The computer-implemented method as recited in claim 1 , further comprising:

upon a detection of a different type of incident in the IT environment, initiating execution, by the IT and security operations application, of a different playbook entirely within the cloud provider network.

8 . A non-transitory, computer-readable medium having stored thereon instructions which, when executed by one or more processors, cause a system in a cloud provider network to perform operations comprising:

sending resources to facilitate configuring of a playbook, wherein the configured playbook identifies a plurality of code blocks that define operations to be performed to respond to an identification of an incident occurring in an information technology (IT) environment associated with a user, and the plurality of code blocks comprises custom code provided by the user;

causing at least part of the configured playbook, including the custom code, to be stored in a user's network in preparation for future execution of the at least part of the configured playbook, wherein the user's network is external to the cloud provider network; and

consequent to a detection of the incident in the IT environment, sending, to a proxy application executing in the user's network, a request to execute the at least part of the configured playbook, wherein the request causes execution of the at least part of the configured playbook, including the custom code, in the user's network.

9 . The non-transitory, computer-readable medium as recited in claim 8 , wherein a client device establishes a connection to the proxy application using a tunnel bridge that establishes a secure connection between the client device and the tunnel bridge and between the tunnel bridge and the proxy application in the user's network.

10 . The non-transitory, computer-readable medium as recited in claim 8 , wherein the request to execute the at least part of the configured playbook is generated automatically responsive to the IT and security operations application identifying the incident.

11 . The non-transitory, computer-readable medium as recited in claim 8 , wherein the at least part of the configured playbook is stored in a version-control system repository in the user's network.

12 . The non-transitory, computer-readable medium as recited in claim 8 , wherein the execution of the at least part of the configured playbook comprises performing an action that involves interaction with a computing resource running in the cloud provider network.

13 . The non-transitory, computer-readable medium as recited in claim 8 , wherein the user's network is associated with a first tenant of the IT and security operations application, and wherein the playbook was created by a second tenant of the IT and security operations application that is different from the first tenant.

14 . The non-transitory, computer-readable medium as recited in claim 8 , the operations further comprising:

upon a detection of a different type of incident in the IT environment, initiating execution of a different playbook entirely within the cloud provider network.

15 . A system comprising:

one or more processing devices to implement an information technology (IT) and security operations application executing in a cloud provider network and perform operations comprising:

sending resources to facilitate configuring of a playbook, wherein the configured playbook identifies a plurality of code blocks that define operations to be performed to respond to an identification of an incident occurring in an IT environment associated with a user, and the plurality of code blocks comprises custom code provided by the user;

causing at least part of the configured playbook, including the custom code, to be stored in a user's network in preparation for future execution of the at least part of the configured playbook, wherein the user's network is external to the cloud provider network; and

consequent to a detection of the incident in the IT environment, sending, to a proxy application executing in the user's network, a request to execute the at least part of the configured playbook, wherein the request causes execution of the at least part of the configured playbook, including the custom code, in the user's network.

16 . The system as recited in claim 15 , wherein a client device establishes a connection to the proxy application using a tunnel bridge that establishes a secure connection between the client device and the tunnel bridge and between the tunnel bridge and the proxy application in the user's network.

17 . The system as recited in claim 15 , wherein the request to execute the at least part of the configured playbook is generated automatically responsive to the IT and security operations application identifying the incident.

18 . The system as recited in claim 15 , wherein the at least part of the configured playbook is stored in a version-control system repository in the user's network.

19 . The system as recited in claim 15 , wherein the execution of the at least part of the configured playbook comprises performing an action that involves interaction with a computing resource running in the cloud provider network.

20 . The system as recited in claim 15 , wherein the user's network is associated with a first tenant of the IT and security operations application, and wherein the playbook was created by a second tenant of the IT and security operations application that is different from the first tenant.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2026
From: SRIDHAR, CHAKRAVARTHY; QI, MINJIE; MAHADIK, ATIF
To: SPLUNK INC.
Reel/Frame 073965/0871 →
Continuity (6)
Continuation 18630909 · Apr 9, 2024
Continuation 18318536 · May 16, 2023
Continuation 17960310 · Oct 5, 2022
Continuation 17222789 · Apr 5, 2021
Continuation 16863896 · Apr 30, 2020
Related Publication 20250132993A1 · Apr 24, 2025
References Cited (4)
US 10439884B1 · Forte · 2019 [cited by examiner]
US 20140237585A1 · Khan · 2014 [cited by examiner]
US 20210173710A1 · Crossley · 2021 [cited by examiner]
US 20210176261A1 · Yavo · 2021 [cited by examiner]