Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to application filed 07/21/2026.
Claims 1-18 are pending in this application.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/21/2026 has been entered.
Response to Arguments
Applicant’s arguments have been considered but are moot because the new ground of rejection. Regarding claims 1 and 12, upon further consideration, a new ground(s) of rejection is made over Sachan et al. (US 2020/0293946 A1) in view of Li et al. (US 2020/0250022 A1) in further view of Raj et al. (US 2021/0397903 A1). Regarding independent claim 8, a new ground(s) of rejection is made over Sachan et al. (US 2020/0293946 A1) in view of Li et al. (US 2020/0250022 A1) in further view of Shahul Hameed et al. (herein after Shahul, US 2023/0275912 A1).
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-7 and 12-18 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 1 has been amended to recite, inter alia,
“prioritizing,…one of the incident tickets in one of the common incident clusters having the velocity that exceeds the threshold over other incident tickets in the common incident cluster”
“periodically resetting…the velocity for each of the common incident clusters.”
Regarding the prioritizing limitation, the originally filed specification discloses “ranking or prioritizing the incident clusters based on the number of incident tickets in the clusters” ([0061]). In other words, the specification discloses prioritizing incident cluster, but it does not disclose prioritizing one incident ticket over other incident tickets within the same cluster based on velocity.
Regarding the resetting limitation, the originally filed specification discloses “clusters may be reset periodically, in response to no incident tickets being added to the cluster for a certain period of time….”([0063]). In other words, the specification discloses resetting a cluster based on no incident tickets added in a period of time, but it does not disclose resetting the velocity for each incident cluster.
Regarding claim 12, the claim is rejected for the same reasons as describe in claim 1.
Regarding dependent claims 2-7, and 13-18, the claims are rejected based on their dependency with claims 1 and 12 respectively. Therefore, claims 1-7 and 12-18 are rejected for failing to meet the written description requirements of 35 U.S.C. 112(a).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-2, 6-7, 12-13, 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Sachan et al. (US 2020/0293946 A1) in view of Li et al. (US 2020/0250022 A1) in further view of Raj et al. (US 2021/0397903 A1).
Regarding claim 1, Sachan discloses a method for incident response using artificial intelligence for information technology operations ([0023]: methods for machine learning based incident classification and resolution), comprising:
receiving, by an incident response computer program executed by an electronic device ([0029], [0031]: utilizing a machine learning based incident classification model that is trained on historical incident tickets, where each such historical incident tickets may be labeled as actionable or non-actionable…Incident category may represent the high-level categorization of incident tickets that is aligned with an organization. [0049]: The incident recommender 122 may determine, based on the key phrases associated with the incident 110, a historical incident, from a plurality of historical incidents), a plurality of incident tickets for incidents involving computer products or computer system within an organization from a service management platform for the computer products or the computer systems ([0024]: the incident ticket may be created using incident management tools such as ServiceNow (SNOW), Incident Management (ICM), etc. Personnel in charge of analyzing the incident ticket may attempt to determine a severity or priority of an incident (or underlying issue) specified in the incident ticket. The incident ticket may be thereafter routed to an appropriate location for resolution);
clustering, by the incident response computer program, the plurality of incident tickets into common incident clusters according to categories for the incidents ([0196]: the incident ticket router 112 may identify a similar behavior or pattern that exists between the new incident identified in the new incident ticket and historical incidents (that are member of the clusters identified at block 1404). In order to find similar behavior existing between the incident and the identified cluster members, a determination may be made as to how many incidents have similar severity (e.g., impact of the incident such as Sev1, Sev2, Sev3, etc.), how many incidents are impacting similar applications such as App1, App2, App3, etc., how many incidents have similar issue type such as network issues, database issues, etc.);
providing, by the incident response computer program, incident information from the prioritized incident ticket to a trained incident response machine learning engine, wherein the trained incident response machine learning engine is trained to predict a solution for the incident based on historical incident data ([0030]: any issue for which resolution steps are present may be an appropriate candidate for automated resolution. In this regard, resolution as disclosed herein may be a configurable process that includes an indication of whether a process or a component may include a set of parameters that are appropriate for resolution of a potential incident. If the issue (or associated potential incident) is determined to be appropriate for resolution, once the specified resolution steps have been implemented, a determination may be made as to whether an underlying issue associated with a potential incident is resolved. [0031]: An incident resolution recommendation may specify details of similar historical incidents that may be referred to for solving a current incident. An incident knowledge base article recommendation may provide details of knowledge base articles that may be referred to for solving a current incident);
receiving, by the incident response computer program and from the trained incident response machine learning engine, a predicted solution for the incident ([0034]: This information may be fed to a machine learning based automated incident resolution model that has been continuously trained or historical data that led to the creation of incidents. When the machine learning based automated incident resolution model predicts that the information supplied to it is a potential candidate of turning into an incident, a determination may be made as to whether automated resolution has been configured to resolve this scenario); and
providing, by the incident response computer program, the predicted solution to the service management platform; wherein the service management platform provides the predicted solution to the computer product or the computer system ([0041]: determine, based on the analysis of the issue 104 and based on a machine learning based automated incident resolution model 108, whether the issue 104 is appropriate for automated resolution. Based on a determination that the issue 104 is appropriate for automated resolution, the automated incident resolver 106 may implement automated resolution of the issue 104 to resolve the issue 104 associated with performance of the task or operation of the application or the device).
However, Sachan does not disclose predicting, by the incident response computer program, a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident, and a geography for each incident; determining, by the incident response computer program, that a velocity of incident tickets in one of the common incident clusters exceeds a threshold; prioritizing, by the incident response computer program, one of the incident tickets in one of the common incident clusters having the velocity that exceeds the threshold over other incident tickets in the common incident cluster.
In an analogous art, Li disclose predicting, by the incident response computer program, a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident and a geography for each incident (fig. 8, 362; [0025], [0072]: determine, at each level of the decision tree, whether each resulting group of incidents is under a threshold percentage of incident…splits the group of incidents that occur in the Eastern U.S. (e.g. geographic location) into resulting groups of those affected by a configuration item (e.g. application) printer (e.g. system) (76%) and those not affected by a configuration item printer (14%). [0010], [0043]: features of incidents may be quickly and conveniently extracted and analyzed to correlate whether the incidents are related to existing problems(e.g. category/cluster). Moreover, predictions may be made as to whether new incidents are associated with an existing problem. For example, the user interface 230 illustrates a time range 234 of the problem 232, a first incident 236 associated with the problem 232, a last or most recently reported incident 238 associated with the problem 232, a geographical location 240 from where incidents associated with the problem 232 are reported, days of the week 242 that incidents associated with the problem 232 are reported, and durations (e.g., lifetimes) 244 of the incidents associated with the problem 232); determining, by the incident response computer program, that a velocity of incident tickets in one of the common incident clusters exceeds a threshold ([0026]: incidents (e.g., INTs or “child incidents”) may be associated with or caused by a major incident or problem (PRB) of the platform that has been previously identified or recognized. A major incident may be defined as an elevated level incident that is reported an excessive number of times within a relatively short period of time (e.g. velocity/frequency of incidents); prioritizing, by the incident response computer program, one of the incident tickets in one of the common incident clusters having the velocity that exceeds the threshold over other incident tickets in the common incident cluster ([0046]: where an actual problem is an elevated level incident that is reported an excessive number of times, regardless of time, and a major incident is an elevated level incident (e.g. prioritize) that is reported an excessive number of times within a relatively short period of time (e.g. velocity/frequency exceed threshold).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan to comprise “predicting, by the incident response computer program, a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident, and a geography for each incident; determining, by the incident response computer program, that a velocity of incident tickets in one of the common incident clusters exceeds a threshold; prioritizing, by the incident response computer program, one of the incident tickets in one of the common incident clusters having the velocity that exceeds the threshold over other incident tickets in the common incident cluster” taught by Li.
One of ordinary skilled in the art would have been motivated because it would have enabled to determine the relationship between incidents and common problems, thus enabling quicker identification and response to recurring incidents as they arise, while reducing uncertainty of the source or cause of incidents (Li, [0010]).
However, Sachan-Li does not disclose periodically resetting, by the incident response computer program, the velocity for each of the common incident clusters.
In an analogous art, Raj discloses periodically resetting, by the incident response computer program, the velocity for each of the common incident clusters ([0065]-[0067], [0069]: algorithms can adapt to concept drift without separate training. An admin may get notification of anomaly. When the data distribution changes, thus rendering the learned model obsolete, concept drift is said to have occurred. Concept drift can be handled externally by running the algorithm at regular intervals and comparing the clusters produced. When clusters remain inactive over an extended period, i.e., no points were added in that period, a cluster can be removed from the list of existing clusters (e.g. resetting); this process is called cluster death. Cluster death happens if nobody is in the cluster. Because data distribution could be changed with time, recent points could be given more weight).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan-Li to comprise “periodically resetting, by the incident response computer program, the velocity for each of the common incident clusters” taught by Raj.
One of ordinary skilled in the art would have been motivated because it would have enabled to remove a clusters when the cluster remains inactive over an extended period of time and no points were added in that period (Raj, [0069]).
Regarding claim 2, Sachan-Li-Raj discloses the method of claim 1, wherein the incident ticket identifies a description of the incident (Sachan, [0086]: a description and short description for the incident that is being analyzed may be obtained from incident data) and/or a labelling of product/incident type (Sachan, [0186]: The issue may thus be labeled as “incident worthy” or “incident not worthy”. Thus a label data set may be created to use for machine learning based model training).
Regarding claim 6, Sachan-Li-Raj discloses the method of claim 1, wherein the predicted solution comprises a self-service troubleshooting guide for the predicted solution, product frequently asked questions (FAQs) for the predicted solution, solution instructions for the predicted solution, scripts for the predicted solution, patches for the predicted solution, configurations for the predicted solution, and/or solution articles for the predicted solution (Sachan [0141]: Incident resolution recommendations may be displayed, for example, for support personnel in a format as shown in a “Similar Historical Incidents” section 1000 of FIG. 10. Incident knowledge base article recommendations may be displayed, for example, for support personnel in a format as shown in a “Recommended KB Articles”).
Regarding claim 7, Sachan-Li-Raj discloses the method of claim 1, further comprising: receiving, by the incident response computer program, feedback for the predicted solution; and re-training, by the incident response computer program, the trained incident response machine learning engine with the feedback (Sachan, [0141]: The proactive Bot may also collect feedback data from a user, and use the feedback data to determine the relevance percentage of recommendations in order to better train and/or retrain the machine learning based models as disclosed herein).
Regarding claim 12; the claim is interpreted and rejected for the same reason as set forth in claim 1.
Regarding claim 13; the claim is interpreted and rejected for the same reason as set forth in claim 2.
Regarding claim 17; the claim is interpreted and rejected for the same reason as set forth in claim 6.
Regarding claim 18; the claim is interpreted and rejected for the same reason as set forth in claim 7.
Claims 3-5, 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Sachan in view of Li in view of Raj, as applied to claim 1, in further view of Murthy et al. (US 10,860,451 B1).
Regarding claim 3, Sachan-Li-Raj discloses the method of claim 1.
However, Sachan-Li-Raj does not disclose further comprising training the trained incident response machine learning engine, comprising: retrieving, by the incident response computer program, the historical incident data comprising a plurality of prior incidents; training, by the incident response computer program, the trained incident response machine learning engine using a first portion of the historical incident data; verifying, by the incident response computer program, the training of the trained incident response machine learning engine using a second portion of the historical incident data; and deploying, by the incident response computer program, the verified incident response machine learning engine to a production environment.
In an analogous art, Murthy discloses further comprising training the trained incident response machine learning engine, comprising: retrieving, by the incident response computer program, the historical incident data comprising a plurality of prior incidents (column 1, 57-61: The meta-model can be trained on historical data and deployed in real time to process incoming log data from multiple computing modules to detect issues in the larger computing system); training, by the incident response computer program, the trained incident response machine learning engine using a first portion of the historical incident data; verifying, by the incident response computer program, the training of the trained incident response machine learning engine using a second portion of the historical incident data (column 9, 15-22: data can be stored as a training data set for the incidents in a defined generic data model, e.g., the log meta model discussed above. This step can be a continual step applied for the training data set, for example to be split 80/20:80% of the data can be used for generating the pattern and 20% of the historical data can be used for validating the generated pattern and refining before applying it to the real time data); and deploying, by the incident response computer program, the verified incident response machine learning engine to a production environment (column 9, 29-32 For a given new rolling window, for data that is flowing inward, the model is executed, and any detection of an issue is registered as an incident ticketing system).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan-Li-Raj to comprise “further comprising training the trained incident response machine learning engine, comprising: retrieving, by the incident response computer program, the historical incident data comprising a plurality of prior incidents; training, by the incident response computer program, the trained incident response machine learning engine using a first portion of the historical incident data; verifying, by the incident response computer program, the training of the trained incident response machine learning engine using a second portion of the historical incident data; and deploying, by the incident response computer program, the verified incident response machine learning engine to a production environment” taught by Murthy.
One of ordinary skilled in the art would have been motivated because it would have enabled to using historical computer log data for multiple computing system modules to predict and prevent issues across the computing system (Murthy, column 1, 10-12).
Regarding claim 4, Sachan-Li-Raj-Murthy discloses the method of claim 3, wherein the historical incident data comprises, for each of the plurality of prior incidents, a description of the prior incident, a labelling of a product involved in the prior incident, a system involved in the prior incident, an individual involved in the prior incident, a team involved in the prior incident, a time and date of the prior incident, solutions to the prior incident, and/or results of the solution (Murthy, column 7, 24-33: a set of incident management tickets 202 is received for a set of computing system issues (e.g., from an incident ticketing system database) that has occurred in past. The tickets 202 can be classified according to the nature of issue that occurred. The tickets 202 can then be arranged into groups (or “buckets”), with each group associated with a particular computing system issue, and the tickets within groups ordered chronologically. Buckets corresponding to particular issues can be defined using short descriptions, e.g., “fileAlerts, Pluggable database, etc.). The same rationale applies as in claim 3.
Regarding claim 5, Sachan-Li-Raj-Murthy discloses he method of claim 4, wherein the historical incident data further comprises, for the plurality of prior incidents, network environment data at the time of the prior incident (Murthy, column 7, 38-42: a set of computer log files 212, again from history for the date range corresponding to the date ranges of issues, can be received for multiple modules of the computing system (e.g., a database log, a network log, and a system log. Column 7, 61-66: date and/or timestamp information can be extracted from each ticket. Since there may or may not be a textual similarity between incident tickets and the associated log information, time slicing along with a time window helps establish a correlation of cause and effect between the tickets and the associated log entries). The same rationale applies as in claim 3.
Regarding claim 14; the claim is interpreted and rejected for the same reason as set forth in claim 3.
Regarding claim 15; the claim is interpreted and rejected for the same reason as set forth in claim 4.
Regarding claim 16; the claim is interpreted and rejected for the same reason as set forth in claim 5.
Claims 8-11 are rejected under 35 U.S.C. 103 as being unpatentable over Sachan et al. (US 2020/0293946 A1) in view of Li et al. (US 2020/0250022 A1) in further view of Shahul Hameed et al. (herein after Shahul, US 2023/0275912 A1).
Regarding claim 8, Sachan discloses a method for incident response using artificial intelligence for information technology operations ([0023]: methods for machine learning based incident classification and resolution), comprising:
receiving, by an incident response computer program executed by an electronic device, a plurality of incident tickets for incidents involving computer products or computer systems within an organization from a service management platform for the computer products or the computer systems ([0029], [0031]: utilizing a machine learning based incident classification model that is trained on historical incident tickets, where each such historical incident tickets may be labeled as actionable or non-actionable…Incident category may represent the high-level categorization of incident tickets that is aligned with an organization. [0049]: The incident recommender 122 may determine, based on the key phrases associated with the incident 110, a historical incident, from a plurality of historical incidents);
predicting, by the incident response computer program executed by an electronic device and using a trained incident response machine learning engine that is trained to predict a category for each incident ticket, a category for each of the plurality of incident tickets ([0031]: The incident nature recommendation may be determined, for example, by using a machine learning based incident nature model to predict various incident features such as incident category, subcategory, assignment group, application name, severity, etc., based on the historical incident information);
clustering, by the incident response computer program, the plurality of incident tickets into common incident clusters according to the categories ([0196]: the incident ticket router 112 may identify a similar behavior or pattern that exists between the new incident identified in the new incident ticket and historical incidents (that are member of the clusters identified at block 1404). In order to find similar behavior existing between the incident and the identified cluster members, a determination may be made as to how many incidents have similar severity (e.g., impact of the incident such as Sev1, Sev2, Sev3, etc.), how many incidents are impacting similar applications such as App1, App2, App3, etc., how many incidents have similar issue type such as network issues, database issues, etc.).
However, Sachan does not discloses a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident, and a geography for each incident; determining, by the incident response computer program, a velocity of incident tickets in the common incident clusters exceeds a threshold; ranking, by the incident response computer program, the common incident clusters based the velocities.
In an analogous art, Li disclose a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident, and a geography for each incident (fig. 8, 362; [0025], [0072]: determine, at each level of the decision tree, whether each resulting group of incidents is under a threshold percentage of incident…splits the group of incidents that occur in the Eastern U.S. (e.g. geographic location) into resulting groups of those affected by a configuration item (e.g. application) printer (e.g. system) (76%) and those not affected by a configuration item printer (14%). [0010], [0043]: features of incidents may be quickly and conveniently extracted and analyzed to correlate whether the incidents are related to existing problems(e.g. category/cluster). Moreover, predictions may be made as to whether new incidents are associated with an existing problem. For example, the user interface 230 illustrates a time range 234 of the problem 232, a first incident 236 associated with the problem 232, a last or most recently reported incident 238 associated with the problem 232, a geographical location 240 from where incidents associated with the problem 232 are reported, days of the week 242 that incidents associated with the problem 232 are reported, and durations (e.g., lifetimes) 244 of the incidents associated with the problem 232); determining, by the incident response computer program, a velocity of incident tickets in the common incident clusters exceeds a threshold; ranking, by the incident response computer program, the common incident clusters based the velocities ([0026]: incidents (e.g., INTs or “child incidents”) may be associated with or caused by a major incident or problem (PRB) of the platform that has been previously identified or recognized. A major incident may be defined as an elevated level incident that is reported an excessive number of times within a relatively short period of time (e.g. velocity/frequency of incidents).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan to comprise “a category for each of the plurality of incident tickets based on a program involved in each incident, a computer system involved in each incident, and a geography for each incident; determining, by the incident response computer program, a velocity of incident tickets in the common incident clusters exceeds a threshold; ranking, by the incident response computer program, the common incident clusters based the velocities” taught by Li.
One of ordinary skilled in the art would have been motivated because it would have enabled to determine the relationship between incidents and common problems, thus enabling quicker identification and response to recurring incidents as they arise, while reducing uncertainty of the source or cause of incidents (Li, [0010]).
However, Sachan-Li does not disclose prioritizing, by the incident response computer program, improvement of production quality for programs or applications based on the ranking.
In an analogous art, Shahul discloses prioritizing, by the incident response computer program, improvement of production quality for programs or applications based on the ranking ([0007]: A listing of the nodes within the highest-ranking cluster or clusters may be provided as output to a security analyst, or to a software tool, to facilitate further analysis and/or inform the selection and/or execution of risk-mitigating actions).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan-Li to comprise “prioritizing, by the incident response computer program, improvement of production quality for programs or applications based on the ranking” taught by Shahul.
One of ordinary skilled in the art would have been motivated because it would have enabled an incident analysis tool to output a listing of the nodes associated with the highest-ranking cluster(s), which can be reviewed by security analysists or further processed automatically, and which may prompt mitigating actions to be performed (Shahul, [0013]).
Regarding claim 9, Sachan-Li-Shahul discloses the method of claim 8, wherein the incident ticket identifies a description of the incident (Sachan, [0086]: a description and short description for the incident that is being analyzed may be obtained from incident data) and/or a labelling of product/incident type (Sachan, [0186]: The issue may thus be labeled as “incident worthy” or “incident not worthy”. Thus a label data set may be created to use for machine learning based model training).
Regarding claim 10, Sachan-Li-Shahul discloses the method of claim 8.
Sachan discloses wherein the categories comprise a common issue ([0029]: learn incident ticket routing patterns from historical incident ticket assignments, and determine a correct assignment group for a new incident ticket based on prior assignment of similar incident tickets for the assigned group), a common software program, a common computer system ([0031]: using a machine learning based incident nature model to predict various incident features such as incident category, subcategory, assignment group, application name, severity, etc., based on the historical incident information. Incident category may represent the high-level categorization of incident tickets that is aligned with an organization, such as, “application and service”, “infrastructure and network”, etc. Incident subcategory may represent a next level categorization that represents a type of an incident ticket, such as, “configuration”, “functionality”, “data missing”, etc) and a common solution ([0031]: An incident resolution recommendation may specify details of similar historical incidents that may be referred to for solving a current incident. Assignment group may represent a group of people that may be assigned to an incident for resolution of the incident).
However, Sachan does not disclose wherein the categories comprise a common geography.
In an analogous art, Li discloses wherein the categories comprise a common geography (fig. 8, 362; [0025], [0072]: determine, at each level of the decision tree, whether each resulting group of incidents is under a threshold percentage of incident…splits the group of incidents that occur in the Eastern U.S. (e.g. geographic location) into resulting groups of those affected by a configuration item (e.g. application) printer (e.g. system) (76%) and those not affected by a configuration item printer (14%).
Therefore, it would have been obvious before the effective filed date of the claimed invention to a person having ordinary skill in the art to modify Sachan to comprise “wherein the categories comprise a common geography” taught by Li.
One of ordinary skilled in the art would have been motivated because it would have enabled to determine the relationship between incidents and common problems, thus enabling quicker identification and response to recurring incidents as they arise, while reducing uncertainty of the source or cause of incidents (Li, [0010]).
Regarding claim 11, Sachan-Li-Shahul discloses the method of claim 8, wherein the common incident clusters are further ranked based on a severity or impact of the incident in each common incident cluster (Shahul, [0007]: Using one or more graph-based clustering techniques, the multipartite graph is then broken up into clusters, which can be ranked by some metric quantifying the severity of the threat, such as based on the number of security alerts or indicators of compromise (IoCs) associated with each cluster). The same rationale applies as in claim 8.
Additional References
The prior art made of record and not relied upon is considered pertinent to applicants disclosure.
Sloane et al., US 11,620,182 B2: System for Resolution of Technical Issues Using Computing System-Specific Contextual Data.
Kapoor et al., US 10,346,851 B1: Automated Incident, Problem, Change Correlation Analysis System.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUAN C TURRIATE GASTULO whose telephone number is (571)272-6707. The examiner can normally be reached Monday - Friday 8 am-4 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571)272-3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/J.C.T/Examiner, Art Unit 2454
/DOUGLAS B BLAIR/Primary Examiner, Art Unit 2454