US 11,675,900 B2
Generating suggested courses of actions for incidents based on previous incident handling
Sourabh Satish, Fremont, CA (US); Trenton John Beals, Hayward, CA (US); Glenn Gallien, San Francisco, CA (US); and Govind Salinas, Sunnyvale, CA (US)
Assigned to Splunk Inc., San Francisco, CA (US)
Filed by Splunk Inc., San Francisco, CA (US)
Filed on Jan. 28, 2021, as Appl. No. 17/161,309.
Application 17/161,309 is a continuation of application No. 16/051,278, filed on Jul. 31, 2018, granted, now 10,936,716.
Prior Publication US 2021/0150026 A1, May 20, 2021
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/55 (2013.01); H04L 9/40 (2022.01); G06F 9/451 (2018.01); G06F 11/07 (2006.01); H04L 41/0631 (2022.01); G06F 11/34 (2006.01)
CPC G06F 21/554 (2013.01) [G06F 9/453 (2018.02); G06F 11/0793 (2013.01); G06F 11/3438 (2013.01); H04L 41/0631 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/1441 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method, comprising:
identifying, by an incident handling system, an incident in an information technology (IT) environment, wherein the incident is associated with a plurality of incident characteristics;
identifying a plurality of previous incidents handled by the incident handling system that are similar to the incident, wherein each of the plurality of previous incidents is identified by searching incident handling information for incidents associated with least one of the plurality of incident characteristics;
identifying a plurality of courses of action executed by the incident handling system to respond to the plurality of previous incidents, wherein a course of action of the plurality of courses of action includes a defined set of actions that are executable by the incident handling system;
selecting, from the plurality of courses of action, a set of actions to include in a suggested course of action to be used to respond to the incident;
determining, based on the plurality of courses of action, an order in which to execute the set of actions during execution of the suggested course of action; and
executing, by the incident handling system, the suggested course of action in the IT environment.