US 11,863,583 B2
Generating action recommendations for courses of action used for incident response
Oliver Friedrichs, Woodside, CA (US); Atif Mahadik, Fremont, CA (US); Govind Salinas, Sunnyvale, CA (US); and Sourabh Satish, Fremont, CA (US)
Assigned to Splunk Inc., San Francisco, CA (US)
Filed by Splunk Inc., San Francisco, CA (US)
Filed on May 21, 2021, as Appl. No. 17/327,098.
Application 17/327,098 is a continuation of application No. 16/051,247, filed on Jul. 31, 2018, granted, now 11,038,915.
Prior Publication US 2021/0281602 A1, Sep. 9, 2021
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 9/00 (2022.01); G06F 21/55 (2013.01)
CPC H04L 63/1441 (2013.01) [G06F 21/55 (2013.01); H04L 9/002 (2013.01); H04L 63/029 (2013.01); H04L 63/1491 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method, comprising:
causing display of a first version of a course of action comprising a plurality of actions used to respond to an occurrence of a first type of incident in an information technology (IT) environment, wherein the course of action defines an operational flow of the plurality of actions, and wherein the IT environment includes a plurality of types of services;
obtaining input requesting addition of a new action to the course of action, wherein the new action is to be linked to an action of the plurality of actions, and wherein the new action is to be executed during execution of the course of action according to the operational flow of the plurality of actions;
determining a suggested action based on a type of service from the plurality of types of services, wherein execution of the suggested action involves interacting with a service of the type of service in the IT environment;
causing display of the suggested action;
obtaining input selecting the suggested action;
causing display of a second version of the course of action, wherein the second version of the course of action is used to respond to the occurrence of the first type of incident in the IT environment, and wherein the second version of the course of action updates the first version of the course of action to include the suggested action; and
executing the second version of the course of action to respond to the occurrence of the first type of incident in the IT environment.