US 11,811,587 B1
Generating incident response action flows using anonymized action implementation data
Oliver Friedrichs, Woodside, CA (US); Atif Mahadik, Fremont, CA (US); Govind Salinas, Sunnyvale, CA (US); and Sourabh Satish, Fremont, CA (US)
Assigned to Splunk Inc., San Francisco, CA (US)
Filed by Splunk Inc., San Francisco, CA (US)
Filed on Jan. 23, 2023, as Appl. No. 18/158,400.
Application 18/158,400 is a continuation of application No. 17/407,738, filed on Aug. 20, 2021, granted, now 11,588,678.
Application 17/407,738 is a continuation of application No. 16/926,907, filed on Jul. 13, 2020, granted, now 11,133,977, issued on Sep. 28, 2021.
Application 16/926,907 is a continuation of application No. 16/051,183, filed on Jul. 31, 2018, granted, now 10,742,484, issued on Aug. 11, 2020.
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 41/0631 (2022.01); H04L 41/0654 (2022.01); H04L 41/14 (2022.01); H04L 9/40 (2022.01); H04L 41/22 (2022.01); H04L 41/5074 (2022.01); G06F 21/55 (2013.01); H04L 41/08 (2022.01)
CPC H04L 41/0631 (2013.01) [G06F 21/554 (2013.01); H04L 41/0654 (2013.01); H04L 41/0883 (2013.01); H04L 41/14 (2013.01); H04L 41/22 (2013.01); H04L 41/5074 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computer-implemented method, the method comprising:
obtaining, by an incident service, data identifying an incident occurring in an information technology (IT) environment, wherein the incident service is coupled to a plurality of IT environments including the IT environment;
obtaining, from a data store, anonymized action implementation data relevant to the incident, wherein the anonymized action implementation data describes past executions of actions by analyst systems running in one or more of the plurality of IT environments responsive to incidents identified in the plurality of IT environments;
identifying, based on the anonymized action implementation data, a plurality of action suggestions for responding to the incident; and
causing display of a flow diagram including the plurality of action suggestions, wherein the flow diagram indicates an order in which the plurality of action suggestions are to be executed.