Visual Playbook Editor for IT Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern IT environments face challenges in efficiently analyzing and managing massive quantities of machine-generated data, which can be time-consuming and complex due to the diverse types and formats of data generated from various components, necessitating innovative solutions for data intake and query systems to enhance incident response and automation.

Innovation Solution

The implementation of an Orchestration, Automation, and Response (OAR) platform with a visual playbook editor that enables users to create and execute digital playbooks, incorporating custom code and multi-prompt blocks, to automate responses to IT-related incidents across disparate IT assets, leveraging a unified security language and flexible schema for data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional data analysis methods are used to manage machine-generated data, then comprehensive data processing is achieved, but the time consumption and operational complexity increase significantly

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidtime consumption for data analysis
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements pre-configured playbook templates with predefined response actions for common incident types. These templates contain predetermined sequences of operations, data processing steps, and response protocols that are prepared in advance. When an incident is detected, the system automatically selects and executes the appropriate pre-configured playbook, eliminating the need to manually design and configure data processing workflows from scratch for each incident, thereby significantly reducing analysis time while maintaining comprehensive processing capabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs automated incident response playbooks that autonomously execute data processing, analysis, and response actions without requiring continuous human intervention. The playbooks automatically ingest machine-generated data, process it through predefined analytical steps, generate responses, and implement corrective actions. This self-service automation reduces both time consumption and operational complexity by replacing manual data analysis and response formulation with automated workflows that operate independently

Inventive Principle:
Principle #25Self-service

2Reliability

If customized playbooks are created to handle specific incident scenarios, then incident response effectiveness improves, but the complexity of playbook creation and management increases

Engineering Contradiction:
Improveincident response effectivenessVSAvoidplaybook creation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent structures playbooks as modular sequences of discrete, independently configurable steps or blocks. Each playbook consists of segmented operations such as data ingestion steps, analysis steps, decision points, and response actions that can be individually configured and combined. This segmentation allows users to create customized incident response playbooks by assembling pre-built modular components rather than designing entire workflows from scratch, reducing creation complexity while maintaining the ability to handle specific incident scenarios effectively

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal playbook templates that can be adapted to multiple incident types and scenarios through configurable parameters. A single playbook template structure serves multiple functions by accepting different input data types, applying configurable processing rules, and generating context-specific responses. This multi-functionality reduces the number of separate playbooks needed and simplifies management by allowing administrators to maintain a library of versatile templates that can be instantiated and customized for various incident scenarios without creating entirely separate workflows for each case

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If extensive coding is required to automate IT operations, then automation capability is achieved, but the ease of operation and accessibility to non-programmers deteriorates

Engineering Contradiction:
Improveautomation capabilityVSAvoidaccessibility to non-programmers
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent introduces a visual playbook editor interface that serves as an intermediary between users and the underlying code execution system. The editor provides a graphical user interface where users can design, configure, and modify playbook workflows through point-and-click interactions, drag-and-drop operations, and form-based configurations. This intermediary layer translates user-friendly visual specifications into executable automation code, enabling non-programmers to create and manage sophisticated automated incident response playbooks without needing to write or understand programming code, thus maintaining full automation capability while dramatically improving ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10795649B1Custom code blocks for a visual playbook editor
Publication Date: 2020.10.06 CISCO TECHNOLOGY INC
  • US10795649B1 patent drawing
  • US10795649B1 patent drawing
  • US10795649B1 patent drawing

AI summary

Techniques are described for enabling users to add custom code function blocks and multi-prompt blocks to customizable playbooks that can be executed by an orchestration, automation, and response (OAR) platform. At a high level, a playbook comprises computer program code and possibly other data that can be executed by an OAR platform to carry out an automated set of actions. A playbook is comprised of one or more functions or codeblocks, where each codeblock contains program code that performs defined functionality when the codeblock is encountered during execution of the playbook of which it is a part. For example, a first codeblock may implement an action that is performed relative to one or more IT assets, another codeblock might filter data generated by the first codeblock in some manner, and so forth.