Prosecution Insights
Last updated: August 17, 2026
Application No. 18/154,985

RESOURCE AWARE DATA MINING AND ANALYSIS

Non-Final OA §103
Filed
Jan 16, 2023
Examiner
HO, ANDREW N
Art Unit
2169
Tech Center
2100 — Computer Architecture & Software
Assignee
International Business Machines Corporation
OA Round
3 (Non-Final)
61%
Grant Probability
Moderate
3-4
OA Rounds
4m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
138 granted / 226 resolved
+6.1% vs TC avg
Strong +31% interview lift
Without
With
+31.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
9 currently pending
Career history
245
Total Applications
across all art units

Statute-Specific Performance

§101
21.3%
-18.7% vs TC avg
§103
61.4%
+21.4% vs TC avg
§102
9.8%
-30.2% vs TC avg
§112
6.1%
-33.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 226 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-6, 8, 11-16, and 19-20 are pending in this application. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on April 20th, 2026 has been entered. Response to Amendment This Office Action is in response to applicant’s communication filed on April 20th, 2026. The applicant’s remark and amendments to the claims were considered with the results that follow. In response to the last Office Action, claims 1, 12, and 19-20 have been amended. Claims 7, 9-10, and 17-18 have been canceled. As a result, claims 1-6, 8, 11-16, and 19-20 are pending in this application. Response to Arguments Applicant’s arguments with respect to claims 1, 12, and 20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 8, 12-13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over U.S Patent Application Publication 2017/0052831 issued to Wu et al. (hereinafter as "Wu") in view of U.S Patent Application Publication 2022/0210004 issued to MOSER et al. (hereinafter as "MOSER") in view of U.S Patent Application Publication 2020/0314083 issued to David Greetham (hereinafter as "Greetham") in further view of U.S Patent Application Publication 2016/0357961 issued to Shaan Mulchandani (hereinafter as "Mulchandani"). Regarding claim 1, Wu teaches a computer-implemented method of automatically generating and implementing a resource aware dynamic operational data collection and analysis plan in a technical environment (Wu: [0021]; The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time), the method comprising: monitoring, by one or more processors (Wu: [0015]; Moreover, those skilled in the art will appreciate that embodiments may be practiced with other computer system configurations, including hand-held devices, multiprocessor systems, microprocessor-based or programmable consumer electronics), one or more objects comprising the technical environment, to collect real-time operational data of the one or more objects (Wu: [0021]; The data collection rules may indicate one or more types of data to be collected, types of operations to be performed on data to be collected, an amount of data to be collected, a time at which the data is to be collected, a frequency at which the data is to be collected, and/or operating conditions of the device 102 under which the data is to be collected, for example. The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); obtaining, by the one or more processors (Wu: [0015]; Moreover, those skilled in the art will appreciate that embodiments may be practiced with other computer system configurations, including hand-held devices, multiprocessor systems, microprocessor-based or programmable consumer electronics), historical operational data of the technical environment and historical resource data of the technical environment, wherein the historical operational data and the historical resource data were generated by the one or more objects (Wu: [0021]; For example, the telemetry module 108 may receive instructions, which may be a data collection pattern comprised of one or more data collection rules, from the service provider 114. [0024]; the data collection and analysis engine integrated with the application 106 may be employed to collect, analyze, and report application data from the device 102. [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); generating, by the one or more processors (Wu: [0015]; Moreover, those skilled in the art will appreciate that embodiments may be practiced with other computer system configurations, including hand-held devices, multiprocessor systems, microprocessor-based or programmable consumer electronics), based on the historical operational data and the historical resource data, one or more models to evaluate health states and resource states of the one or more objects (Wu: [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern comprised of one or more data collection rules 216 provided by the service provider 220. [0034]; The telemetry module 306 may provide and/or report the collected and analyzed data to a service provider associated with the application. Upon receipt of the collected and analyzed data, the service provider may efficiently implement processes to address issues); generating, by the one or more processors (Wu: [0015]; Moreover, those skilled in the art will appreciate that embodiments may be practiced with other computer system configurations, including hand-held devices, multiprocessor systems, microprocessor-based or programmable consumer electronics), the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Wu: [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example). Wu does not explicitly teach applying, by the one or more processors, the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects, wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states, wherein the identifying comprises determining a risk level for the at least on object; obtaining, by the one or more processors, a topology of the technical environment; utilizing, by the one or more processors, the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology, wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment; However, MOSER teaches applying, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system, log data describing the operating conditions of monitored components in textual form, change event data describing changes of the monitored environment, as e.g. the update of software or hardware components of the monitored environment. [0019]; measurements may be monitored in detail (e.g. by using automated baseline value calculation mechanisms) to identify abnormal operating conditions of transactions, like increased transaction response times or failure rates. [0049]; monitor performance and functionality of services provided by the monitored environment and used by the executed transaction. This monitoring data may be continuously analyzed to identify abnormal operating conditions. Still another portion of the monitoring data may be used to describe resource utilization, availability and communication activities of elements of the monitored environment), wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states (MOSER: [0014]-[0015]; The monitoring system may integrate received topology-related data into a unified topology model of the monitored environment. The topology model may consist in an instance layer, which describes individual elements of the monitored system, like host computing systems, processes executing on those host computing systems and services provided by those processes. [0019]; As transaction trace data also contains topology location data, a location in the instance layer of topology model can be assigned to those identified abnormal operation conditions…the monitoring system or measures describing communication activities between components of the monitored system may be analyzed to identify unexpected and abnormal changes. Besides transaction related measures, also non-transaction related measures, like measured describing the resource consumption of processes or host computing systems… may be analyzed to identify unexpected and abnormal changes), wherein the identifying comprises determining a risk level for the at least on object (MOSER: [0052]; the next goal is to identify one or more root cause conditions that caused all other causal related abnormal operating conditions, as due to their causal relationships, fixing those root cause abnormal operating conditions most probably also fixes all other causally related abnormal operating conditions. [0054]; As an example, an abnormal operating condition may show an increased memory consumption of a specific process. [0056]; ranks the identified root cause groups according to a root cause rank derived from the abnormal operating conditions contained in the individual root cause groups. [0062]; Identified abnormal operating conditions may also be referred to as evidences. Evidences may contain but are not limited to a type describing what type of change occurred (e.g. CPU usage increase), an amount (e.g. percentage of CPU usage increase), a topology location (e.g. on which process or host computing system was the increase observed) and temporal data (i.e. when was the increase first observed and how long did it last)); utilizing, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology (MOSER: [0051]; The result of such analyses typically consists of sets of identified abnormal operating conditions that are causally related…identify causal directions between events in form of cause and effect relations. Those embodiments may provide directed graphs of abnormal operating conditions, where the nodes of the graph identify abnormal operating conditions and the edges between the nodes represent causal relationships), wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system. [0022]; The identified, causally related abnormal operating conditions may in a next step be grouped according to their resource and code execution dependencies. The resource dependency grouping may be performed by identifying evidences that occurred on the same vertical topology instance stack. [0158]; The identification of root cause groups and the ranking of those groups according to a root cause relevance score is performed in a sequence of steps, where each step creates intermediate groupings and data structures that may be used as input by a subsequent step); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER because one of ordinary skill in the art would have been motivated to make such a combination of understanding monitoring information and establish a plan to identify abnormal activities to fix abnormal conditions to improve the performance of the system (See MOSER: [0052]-[0053]). In addition, the references (Wu and MOSER) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu and MOSER are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu and MOSER does not explicitly teach generating, by the one or more processors, the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects; automatically generating, by the one or more processors, based on the resource aware dynamic operational data collection plan, command files to implement the resource aware dynamic operational data collection plan within the technical environment; deploying, by the one or more processors, the command files to the technical environment. Greetham teaches generating, by the one or more processors (Greetham: [0049]; It may include one or more processors, and one or more memory units, including volatile memory and non-volatile memory), the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), automatically generating, by the one or more processors (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0155]; Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to processor 604 for execution), based on the resource aware dynamic operational data collection plan (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), command files to implement the resource aware dynamic operational data collection plan within the technical environment (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150); deploying, by the one or more processors, the command files to the technical environment (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150. [0105]; install the collector on target system 150, and/or to initiate execution of the collector on target system 150); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham because one of ordinary skill in the art would have been motivated to make such a combination of providing a customized collection system to improve the process of collecting data customized for a specific target system (See Greetham: [0032]). In addition, the references (Wu, MOSER, and Greetham) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, and Greetham are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu, MOSER, and Greetham does not explicitly teach a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level. However, Mulchandani teaches a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level (Mulchandani: [0004]-[0005]; The system may then generate a resource allocation priority based on the likelihoods that the processes are malicious process. An allocation of resources, identifying other processes executing on the system, determining, for each of the processes, a risk score that reflects a likelihood that the process is a malicious process, determining a resource allocation priority based on the risk scores of each of the processes. [0018]; determine a risk score for a process based on characteristics of the process, e.g. name, hash of the file, resources requested, number of times run before, average of resources requested per run over the process' history and how it compares, e.g., what is the delta, to resources requested now, how many people have run this process before, and other information. [0024];The resource allocation prioritizer 120 may determine the resource allocation priority based on ranking the processes by risk score, and then determining the priority for allocation resources to the processes based on the ranking of the processes. [0027]; The resource allocator 130 may allocate physical and/or virtual resources based on an availability of resources on the system 100 {Examiner correlates the resource allocation priority as parameter in designating to the one or more processes associated to the physical resources on the system to determine a risk level}); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham and Mulchandani because one of ordinary skill in the art would have been motivated to make such a combination of providing a allocate processes based on priority to reduce the resource allocation to fulfill the request (See Mulchandani: [0051]). In addition, the references (Wu, MOSER, Greetham, and Mulchandani) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, Greetham, and Mulchandani are directed to data collecting and seeking opportunities to achieve computation results more efficiently. Regarding claim 2, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, and Wu further teaches the resource aware dynamic operational data collection comprises elements selected from the group consisting of: dynamic profiles, dynamic configuration files, dynamic scripts, and dynamic parameters (Wu: [0012]; The telemetry module may also include various specialized components configured to dynamically scale data collection and analysis performed by the data collection and analysis engine for a target device. For example, a scaling profile manager may be configured to receive a profile for a device on which the application is being executed from the service. The scaling profile manager may be further configured to determine one or more resources and capabilities of the device, compare the determined resources and capabilities to the criteria of the profile, and scale the data collection and analysis to be performed by the data collection and analysis engine based on the comparison. Scaling may include adjusting parameters of the data collection and analysis such that the parameters correspond to the resources and capabilities of the device). Regarding claim 8, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, and Wu further teaches the dynamic operational data collection plan includes additional parameters based on the determined risk level (Wu: [0033]; configured to determine one or more additional data collection rules based on the de-allocation. For example, the additional data collection rule may specify to only collect metadata associated with the device 202 as the amount of data that may he collected is limited, and the metadata associated with the device 202 is more important for analysis than usage and/or user information.[0037]; performed by the data collection and analysis engine 308. The criteria may include one or more triggers…The software events may include crashes, errors, warnings, and/or updated data collection patterns, for example. [0039]; determine whether the determined resources and capabilities of the device correspond to the triggers of the criteria for the sealing of the data collection and analysis), wherein the additional parameters are selected from the group consisting of: scope, frequency, and granularity of data collection (Wu: [0068]; In other embodiments, the data collection rules may indicate types of data to be collected, types of operations to be performed on data to be collected, an amount of data to be collected, a time at which data is to be collected, a frequency at which data is to be collected, and/or operating conditions of the computing device under which data is to be collected). Regarding claim 12, Wu teaches a computer system for automatically generating and implementing a resource aware dynamic operational data collection and analysis plan in a technical environment (Wu: [0021]; The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time), the computer system comprising: a memory (Wu: [0050]; the computing device 500 may include one or more processors 504 and a system memory 506); and one or more processors in communication with the memory (Wu: [0050]; the computing device 500 may include one or more processors 504 and a system memory 506), wherein the computer system is configured to perform a method, said method comprising: monitoring, by the one or more processors, one or more objects comprising the technical environment, to collect real-time operational data of the one or more objects (Wu: [0021]; The data collection rules may indicate one or more types of data to be collected, types of operations to be performed on data to be collected, an amount of data to be collected, a time at which the data is to be collected, a frequency at which the data is to be collected, and/or operating conditions of the device 102 under which the data is to be collected, for example. The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); obtaining, by the one or more processors, historical operational data of the technical environment and historical resource data of the technical environment, wherein the historical operational data and the historical resource data were generated by the one or more objects (Wu: [0021]; For example, the telemetry module 108 may receive instructions, which may be a data collection pattern comprised of one or more data collection rules, from the service provider 114. [0024]; the data collection and analysis engine integrated with the application 106 may be employed to collect, analyze, and report application data from the device 102. [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); generating, by the one or more processors, based on the historical operational data and the historical resource data, one or more models to evaluate health states and resource states of the one or more objects (Wu: [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern comprised of one or more data collection rules 216 provided by the service provider 220. [0034]; The telemetry module 306 may provide and/or report the collected and analyzed data to a service provider associated with the application. Upon receipt of the collected and analyzed data, the service provider may efficiently implement processes to address issues); and generating, by the one or more processors, the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Wu: [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example). Wu does not explicitly teach applying, by the one or more processors, the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects, wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states, wherein the identifying comprises determining a risk level for the at least on object; obtaining, by the one or more processors, a topology of the technical environment; utilizing, by the one or more processors, the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology, wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment; However, MOSER teaches applying, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system, log data describing the operating conditions of monitored components in textual form, change event data describing changes of the monitored environment, as e.g. the update of software or hardware components of the monitored environment. [0019]; measurements may be monitored in detail (e.g. by using automated baseline value calculation mechanisms) to identify abnormal operating conditions of transactions, like increased transaction response times or failure rates. [0049]; monitor performance and functionality of services provided by the monitored environment and used by the executed transaction. This monitoring data may be continuously analyzed to identify abnormal operating conditions. Still another portion of the monitoring data may be used to describe resource utilization, availability and communication activities of elements of the monitored environment), wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states (MOSER: [0014]-[0015]; The monitoring system may integrate received topology-related data into a unified topology model of the monitored environment. The topology model may consist in an instance layer, which describes individual elements of the monitored system, like host computing systems, processes executing on those host computing systems and services provided by those processes. [0019]; As transaction trace data also contains topology location data, a location in the instance layer of topology model can be assigned to those identified abnormal operation conditions…the monitoring system or measures describing communication activities between components of the monitored system may be analyzed to identify unexpected and abnormal changes. Besides transaction related measures, also non-transaction related measures, like measured describing the resource consumption of processes or host computing systems… may be analyzed to identify unexpected and abnormal changes), wherein the identifying comprises determining a risk level for the at least on object (MOSER: [0052]; the next goal is to identify one or more root cause conditions that caused all other causal related abnormal operating conditions, as due to their causal relationships, fixing those root cause abnormal operating conditions most probably also fixes all other causally related abnormal operating conditions. [0054]; As an example, an abnormal operating condition may show an increased memory consumption of a specific process. [0056]; ranks the identified root cause groups according to a root cause rank derived from the abnormal operating conditions contained in the individual root cause groups. [0062]; Identified abnormal operating conditions may also be referred to as evidences. Evidences may contain but are not limited to a type describing what type of change occurred (e.g. CPU usage increase), an amount (e.g. percentage of CPU usage increase), a topology location (e.g. on which process or host computing system was the increase observed) and temporal data (i.e. when was the increase first observed and how long did it last)); utilizing, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology (MOSER: [0051]; The result of such analyses typically consists of sets of identified abnormal operating conditions that are causally related…identify causal directions between events in form of cause and effect relations. Those embodiments may provide directed graphs of abnormal operating conditions, where the nodes of the graph identify abnormal operating conditions and the edges between the nodes represent causal relationships), wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system. [0022]; The identified, causally related abnormal operating conditions may in a next step be grouped according to their resource and code execution dependencies. The resource dependency grouping may be performed by identifying evidences that occurred on the same vertical topology instance stack. [0158]; The identification of root cause groups and the ranking of those groups according to a root cause relevance score is performed in a sequence of steps, where each step creates intermediate groupings and data structures that may be used as input by a subsequent step); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER because one of ordinary skill in the art would have been motivated to make such a combination of understanding monitoring information and establish a plan to identify abnormal activities to fix abnormal conditions to improve the performance of the system (See MOSER: [0052]-[0053]). In addition, the references (Wu and MOSER) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu and MOSER are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu and MOSER does not explicitly teach generating, by the one or more processors, the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects; automatically generating, by the one or more processors, based on the resource aware dynamic operational data collection plan, command files to implement the resource aware dynamic operational data collection plan within the technical environment; deploying, by the one or more processors, the command files to the technical environment. Greetham teaches generating, by the one or more processors (Greetham: [0049]; It may include one or more processors, and one or more memory units, including volatile memory and non-volatile memory), the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), automatically generating, by the one or more processors (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0155]; Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to processor 604 for execution), based on the resource aware dynamic operational data collection plan (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), command files to implement the resource aware dynamic operational data collection plan within the technical environment (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150); deploying, by the one or more processors, the command files to the technical environment (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150. [0105]; install the collector on target system 150, and/or to initiate execution of the collector on target system 150); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham because one of ordinary skill in the art would have been motivated to make such a combination of providing a customized collection system to improve the process of collecting data customized for a specific target system (See Greetham: [0032]). In addition, the references (Wu, MOSER, and Greetham) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, and Greetham are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu, MOSER, and Greetham does not explicitly teach a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level. However, Mulchandani teaches a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level (Mulchandani: [0004]-[0005]; The system may then generate a resource allocation priority based on the likelihoods that the processes are malicious process. An allocation of resources, identifying other processes executing on the system, determining, for each of the processes, a risk score that reflects a likelihood that the process is a malicious process, determining a resource allocation priority based on the risk scores of each of the processes. [0018]; determine a risk score for a process based on characteristics of the process, e.g. name, hash of the file, resources requested, number of times run before, average of resources requested per run over the process' history and how it compares, e.g., what is the delta, to resources requested now, how many people have run this process before, and other information. [0024];The resource allocation prioritizer 120 may determine the resource allocation priority based on ranking the processes by risk score, and then determining the priority for allocation resources to the processes based on the ranking of the processes. [0027]; The resource allocator 130 may allocate physical and/or virtual resources based on an availability of resources on the system 100 {Examiner correlates the resource allocation priority as parameter in designating to the one or more processes associated to the physical resources on the system to determine a risk level}); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham and Mulchandani because one of ordinary skill in the art would have been motivated to make such a combination of providing a allocate processes based on priority to reduce the resource allocation to fulfill the request (See Mulchandani: [0051]). In addition, the references (Wu, MOSER, Greetham, and Mulchandani) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, Greetham, and Mulchandani are directed to data collecting and seeking opportunities to achieve computation results more efficiently. Regarding claim 13, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, and Wu further teaches the resource aware dynamic operational data collection comprises elements selected from the group consisting of: dynamic profiles, dynamic configuration files, dynamic scripts, and dynamic parameters (Wu: [0012]; The telemetry module may also include various specialized components configured to dynamically scale data collection and analysis performed by the data collection and analysis engine for a target device. For example, a scaling profile manager may be configured to receive a profile for a device on which the application is being executed from the service. The scaling profile manager may be further configured to determine one or more resources and capabilities of the device, compare the determined resources and capabilities to the criteria of the profile, and scale the data collection and analysis to be performed by the data collection and analysis engine based on the comparison. Scaling may include adjusting parameters of the data collection and analysis such that the parameters correspond to the resources and capabilities of the device). Regarding claim 20, Wu teaches a computer program product for automatically generating and implementing a resource aware dynamic operational data collection and analysis plan in a technical environment (Wu: [0016]; Some embodiments may be implemented as a computer-implemented process (method), a computing system, or as an article of manufacture, such as a computer program product or computer readable media. The computer program product may be a computer storage medium readable by a computer system and encoding a computer program that comprises instructions. [0021]; The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time), the computer program product comprising: one or more computer readable storage media and program instructions collectively stored on the one or more computer readable storage media readable by at least one processing circuit to perform a method comprising (Wu: [0051]; Depending on the desired configuration, the processor 504 may be of any type, including but not limited to a microprocessor (μP), a microcontroller (μC), a digital signal processor (DSP), or any combination thereof. [0054]; The system memory 506, the removable storage devices 536 and the non-removable storage devices 538 are examples of computer storage media): monitoring, by the one or more processors, one or more objects comprising the technical environment, to collect real-time operational data of the one or more objects (Wu: [0021]; The data collection rules may indicate one or more types of data to be collected, types of operations to be performed on data to be collected, an amount of data to be collected, a time at which the data is to be collected, a frequency at which the data is to be collected, and/or operating conditions of the device 102 under which the data is to be collected, for example. The data collection and analysis engine may collect and analyze data of the application 106 according to the data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); obtaining, by the one or more processors, historical operational data of the technical environment and historical resource data of the technical environment (Wu: [0021]; For example, the telemetry module 108 may receive instructions, which may be a data collection pattern comprised of one or more data collection rules, from the service provider 114. [0024]; the data collection and analysis engine integrated with the application 106 may be employed to collect, analyze, and report application data from the device 102. [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time), wherein the historical operational data and the historical resource data were generated by the one or more objects (Wu: [0021]; For example, the telemetry module 108 may receive instructions, which may be a data collection pattern comprised of one or more data collection rules, from the service provider 114. [0024]; the data collection and analysis engine integrated with the application 106 may be employed to collect, analyze, and report application data from the device 102. [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern. [0069]; The telemetry module may further include a telemetry transport component configured to receive the data collection pattern. The telemetry module may further include a resource monitor configured to monitor the resources and capabilities of the computing device in real-time); generating, by the one or more processors, based on the historical operational data and the historical resource data, one or more models to evaluate health states and resource states of the one or more objects (Wu: [0027]; Data including log data, event data, performance data, and state data associated with the application 204, may be collected based on a data collection pattern comprised of one or more data collection rules 216 provided by the service provider 220. [0034]; The telemetry module 306 may provide and/or report the collected and analyzed data to a service provider associated with the application. Upon receipt of the collected and analyzed data, the service provider may efficiently implement processes to address issues); generating, by the one or more processors, the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Wu: [0024]; As a result, dynamic modification of the data collection pattern may enable optimized performance of data collection without negatively impacting other operations executed by the target device by controlling what types of data to collect, types of operations to be performed on data to be collected, how much data to collect, and how often to collect the data, for example). Wu does not explicitly teach applying, by the one or more processors, the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects, wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states, wherein the identifying comprises determining a risk level for the at least on object; obtaining, by the one or more processors, a topology of the technical environment; utilizing, by the one or more processors, the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology, wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment; However, MOSER teaches applying, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the models to the real-time operational data of the one or more objects to determine health states and resource states for the one or more objects (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system, log data describing the operating conditions of monitored components in textual form, change event data describing changes of the monitored environment, as e.g. the update of software or hardware components of the monitored environment. [0019]; measurements may be monitored in detail (e.g. by using automated baseline value calculation mechanisms) to identify abnormal operating conditions of transactions, like increased transaction response times or failure rates. [0049]; monitor performance and functionality of services provided by the monitored environment and used by the executed transaction. This monitoring data may be continuously analyzed to identify abnormal operating conditions. Still another portion of the monitoring data may be used to describe resource utilization, availability and communication activities of elements of the monitored environment), wherein the applying comprises identifying at least one object of the one or more objects as an abnormal component of the technical environment based on the health states or the resource states (MOSER: [0014]-[0015]; The monitoring system may integrate received topology-related data into a unified topology model of the monitored environment. The topology model may consist in an instance layer, which describes individual elements of the monitored system, like host computing systems, processes executing on those host computing systems and services provided by those processes. [0019]; As transaction trace data also contains topology location data, a location in the instance layer of topology model can be assigned to those identified abnormal operation conditions…the monitoring system or measures describing communication activities between components of the monitored system may be analyzed to identify unexpected and abnormal changes. Besides transaction related measures, also non-transaction related measures, like measured describing the resource consumption of processes or host computing systems… may be analyzed to identify unexpected and abnormal changes), wherein the identifying comprises determining a risk level for the at least on object (MOSER: [0052]; the next goal is to identify one or more root cause conditions that caused all other causal related abnormal operating conditions, as due to their causal relationships, fixing those root cause abnormal operating conditions most probably also fixes all other causally related abnormal operating conditions. [0054]; As an example, an abnormal operating condition may show an increased memory consumption of a specific process. [0056]; ranks the identified root cause groups according to a root cause rank derived from the abnormal operating conditions contained in the individual root cause groups. [0062]; Identified abnormal operating conditions may also be referred to as evidences. Evidences may contain but are not limited to a type describing what type of change occurred (e.g. CPU usage increase), an amount (e.g. percentage of CPU usage increase), a topology location (e.g. on which process or host computing system was the increase observed) and temporal data (i.e. when was the increase first observed and how long did it last)); utilizing, by the one or more processors (MOSER: [0237]; The techniques described herein may be implemented by one or more computer programs executed by one or more processors), the topology to identify a subset of the one or more objects which are impacted by the at least one object based on the topology (MOSER: [0051]; The result of such analyses typically consists of sets of identified abnormal operating conditions that are causally related…identify causal directions between events in form of cause and effect relations. Those embodiments may provide directed graphs of abnormal operating conditions, where the nodes of the graph identify abnormal operating conditions and the edges between the nodes represent causal relationships), wherein utilizing the topology to identify the subset of the one or more objects which are impacted by the at least one object comprises determining an impact scope of the abnormal component on the technical environment (MOSER: [0013]; The monitoring data may contain topology-related data describing structural aspects of the monitored system, resource utilization data describing the usage of resources like CPU cycles, memory (main memory and secondary memory), transaction trace data describing the execution of transactions executed by the monitored system. [0022]; The identified, causally related abnormal operating conditions may in a next step be grouped according to their resource and code execution dependencies. The resource dependency grouping may be performed by identifying evidences that occurred on the same vertical topology instance stack. [0158]; The identification of root cause groups and the ranking of those groups according to a root cause relevance score is performed in a sequence of steps, where each step creates intermediate groupings and data structures that may be used as input by a subsequent step); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER because one of ordinary skill in the art would have been motivated to make such a combination of understanding monitoring information and establish a plan to identify abnormal activities to fix abnormal conditions to improve the performance of the system (See MOSER: [0052]-[0053]). In addition, the references (Wu and MOSER) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu and MOSER are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu and MOSER does not explicitly teach generating, by the one or more processors, the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects; automatically generating, by the one or more processors, based on the resource aware dynamic operational data collection plan, command files to implement the resource aware dynamic operational data collection plan within the technical environment; deploying, by the one or more processors, the command files to the technical environment. Greetham teaches generating, by the one or more processors (Greetham: [0049]; It may include one or more processors, and one or more memory units, including volatile memory and non-volatile memory), the resource aware dynamic operational data collection plan based on the identified subset of the one or more objects (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), automatically generating, by the one or more processors (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0155]; Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to processor 604 for execution), based on the resource aware dynamic operational data collection plan (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. [0084]; Customization specification 300 includes information that describes types of data to be collected and resources of target system 150 from which the data is to be collected), command files to implement the resource aware dynamic operational data collection plan within the technical environment (Greetham: [0033]; Upon receiving the customization specification, the deployment engine uses the specification to generate the customized collector. The customized collector is specific to the computer resources of the target system. Customizing the collector and providing the customized collector to a custodian of the target system allows collecting only the requested data, and collecting the data in the way that is customized to the configuration of the target resources of the custodian. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150); deploying, by the one or more processors, the command files to the technical environment (Greetham: [0056]; For example, upon receiving instructions from deployment server 120, deployment engine 130 may use the instructions to generate a collector, determine a location for storing the collector, and use the determined location to store the collector as a collector 140A in cloud storage 140. [0086]; A customized collector is an executable program that is configured to perform data collection according to a customization specification. A collector may be generated by deployment engine 130 according to the customization specification…store the collector as collector 140A in cloud storage 140, and notify a custodian of workstation 151 in target system 150 that collector 140A is ready for downloading onto target system 150. [0105]; install the collector on target system 150, and/or to initiate execution of the collector on target system 150); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham because one of ordinary skill in the art would have been motivated to make such a combination of providing a customized collection system to improve the process of collecting data customized for a specific target system (See Greetham: [0032]). In addition, the references (Wu, MOSER, and Greetham) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, and Greetham are directed to data collecting and seeking opportunities to achieve computation results more efficiently. The modification of Wu, MOSER, and Greetham does not explicitly teach a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level. However, Mulchandani teaches a parameter designating one or more resources of the technical environment for use in data collection based on the determined risk level (Mulchandani: [0004]-[0005]; The system may then generate a resource allocation priority based on the likelihoods that the processes are malicious process. An allocation of resources, identifying other processes executing on the system, determining, for each of the processes, a risk score that reflects a likelihood that the process is a malicious process, determining a resource allocation priority based on the risk scores of each of the processes. [0018]; determine a risk score for a process based on characteristics of the process, e.g. name, hash of the file, resources requested, number of times run before, average of resources requested per run over the process' history and how it compares, e.g., what is the delta, to resources requested now, how many people have run this process before, and other information. [0024];The resource allocation prioritizer 120 may determine the resource allocation priority based on ranking the processes by risk score, and then determining the priority for allocation resources to the processes based on the ranking of the processes. [0027]; The resource allocator 130 may allocate physical and/or virtual resources based on an availability of resources on the system 100 {Examiner correlates the resource allocation priority as parameter in designating to the one or more processes associated to the physical resources on the system to determine a risk level}); It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the further teachings of Greetham and Mulchandani because one of ordinary skill in the art would have been motivated to make such a combination of providing a allocate processes based on priority to reduce the resource allocation to fulfill the request (See Mulchandani: [0051]). In addition, the references (Wu, MOSER, Greetham, and Mulchandani) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, Greetham, and Mulchandani are directed to data collecting and seeking opportunities to achieve computation results more efficiently. Claims 3, 5-6, 14, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over U.S Patent Application Publication 2017/0052831 issued to Wu et al. (hereinafter as "Wu") in view of U.S Patent Application Publication 2022/0210004 issued to MOSER et al. (hereinafter as "MOSER") in view of U.S Patent Application Publication 2020/0314083 issued to David Greetham (hereinafter as "Greetham") in view of U.S Patent Application Publication 2016/0357961 issued to Shaan Mulchandani (hereinafter as "Mulchandani") in further view of U.S Patent Application Publication 2018/0307734 issued to Bingham et al. (hereinafter as "Bingham"). Regarding claim 3, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach the models are selected from the group consisting of: health models and resource models. Bingham teaches the models are selected from the group consisting of: health models and resource models (Bingham: [0102]; an interface engine 375 that enables a reviewer 115 to request a performance report and/or receive a performance report. The report can include one or more statistics, states, and/or alarm statuses. The report can identify which component and/or time period are associated with the statistic, state and/or alarm status. Interface engine 375 can present most-recent or substantially real-time values (e.g., numerical statistics or states) and/or historical values). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the teachings of Greetham with the further teachings of Mulchandani and Bingham because one of ordinary skill in the art would have been motivated to make such a combination of appropriately improving the architecture and identifying and pinpointing a configuration change to give rise to the performance change (See Bingham: [0131]). In addition, the references (Wu, MOSER, Greetham, Mulchandani, and Bingham) teach features that are directed to analogous art and they are directed to the same field of endeavor as are directed to data collecting and seeking opportunities to achieve computation results more efficiently. Regarding claim 5, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach identifying the at least one object of the one or more objects as abnormal comprises determining that the at least one object is operating outside of expected parameters of a model of the one or more models. Bingham teaches identifying the at least one object of the one or more objects as abnormal comprises determining that the at least one object is operating outside of expected parameters of a model of the one or more models (Bingham: [0127]; A historical-host-performance section shows how a performance statistic has been changing over time. In the depicted instance, the historical statistics (which can include a final real-time statistic) are shown graphically, along with a “normal” threshold (shown as the bottom, dark dashed line) and a “critical” threshold (shown as the top, gray dashed line). [0092]-[0093]; A statistics generator 340 can access the collection of performance metrics and generate one or more performance statistics based on the values of one or more performance metrics. A performance statistic can pertain to any of the various types of performance metrics, such as a CPU usage, a memory usage, assigned tasks, a task-completion duration, etc…use the state criteria and the generated statistic to assign a state (e.g., to a component and/or time period)). Regarding claim 6, the modification of Wu, MOSER, Greetham, Mulchandani, and Bingham teaches claimed invention substantially as claimed, and Bingham further teaches generating the one or more models to evaluate health states and resource states of the one or more objects comprises utilizing the historical operational data and the historical resource data to establish the expected parameters (Bingham: [0093]; The state can then be stored (e.g., in association with a respective component and/or time period) in a state data store 360. State engine 350 can identify which component and/or time period are to be associated with the state based on what aggregation was performed. [0102]; an interface engine 375 that enables a reviewer 115 to request a performance report and/or receive a performance report. The report can include one or more statistics, states, and/or alarm statuses. The report can identify which component and/or time period are associated with the statistic, state and/or alarm status. Interface engine 375 can present most-recent or substantially real-time values (e.g., numerical statistics or states) and/or historical values. [0120]; Further, the historical plot may allow a reviewer 125 to notice a positive or negative trend in the values of one or more performance metrics, such that a problem can be remedied before it becomes serious. [0131]; One such comparison is an inter-system-component comparison, which can enable a reviewer 125 to identify a reasonableness of a performance metric and determine a level at which a problem could best be addressed). Regarding claim 14, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach the models are selected from the group consisting of: health models and resource models. Bingham teaches the models are selected from the group consisting of: health models and resource models (Bingham: [0102]; an interface engine 375 that enables a reviewer 115 to request a performance report and/or receive a performance report. The report can include one or more statistics, states, and/or alarm statuses. The report can identify which component and/or time period are associated with the statistic, state and/or alarm status. Interface engine 375 can present most-recent or substantially real-time values (e.g., numerical statistics or states) and/or historical values). Regarding claim 16, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach identifying the at least one object of the one or more objects as abnormal comprises determining that the at least one object is operating outside of expected parameters of a model of the one or more models. Bingham teaches identifying the at least one object of the one or more objects as abnormal comprises determining that the at least one object is operating outside of expected parameters of a model of the one or more models (Bingham: [0092]-[0093]; A statistics generator 340 can access the collection of performance metrics and generate one or more performance statistics based on the values of one or more performance metrics. A performance statistic can pertain to any of the various types of performance metrics, such as a CPU usage, a memory usage, assigned tasks, a task-completion duration, etc…use the state criteria and the generated statistic to assign a state (e.g., to a component and/or time period). [0127]; A historical-host-performance section shows how a performance statistic has been changing over time. In the depicted instance, the historical statistics (which can include a final real-time statistic) are shown graphically, along with a “normal” threshold (shown as the bottom, dark dashed line) and a “critical” threshold (shown as the top, gray dashed line)). Claims 4, 11, 15, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over U.S Patent Application Publication 2017/0052831 issued to Wu et al. (hereinafter as "Wu") in view of U.S Patent Application Publication 2022/0210004 issued to MOSER et al. (hereinafter as "MOSER") in view of U.S Patent Application Publication 2020/0314083 issued to David Greetham (hereinafter as "Greetham") in view of U.S Patent Application Publication 2016/0357961 issued to Shaan Mulchandani (hereinafter as "Mulchandani") in further view of U.S Patent Application Publication 2016/0349716 issued to SLESSMAN et al. (hereinafter as "SLESSMAN"). Regarding claim 4, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach the real-time operational data, the historical operational data, and the historical resource data are selected from the group consisting of power, bandwidth, space, computing, cost, and carbon footprint. Slessman teaches the real-time operational data, the historical operational data, and the historical resource data are selected from the group consisting of power, bandwidth, space, computing, cost, and carbon footprint (Slessman: [0123]; DCICS 105 can determine potential alternative data center assets based on one or more of the following: asset utilization, utilization forecasts, physical security, logical security, current latency; utility costs; power capacity or availability, power utilization effectiveness, cooling capability, physical space, network providers, network bandwidth, network redundancy and power redundancy). It would have been obvious to a person of ordinary skill in the art, before the effective filing date of the invention, to modify Wu with the teachings of MOSER with the teachings of Greetham with the further teachings of Mulchandani and Slessman because one of ordinary skill in the art would have been motivated to make such a combination of understanding the user query and providing relevant information by improving the training and operation of the computation models in improving the system security (See Slessman: [0109]). In addition, the references (Wu, MOSER, Greetham, Mulchandani, and Slessman) teach features that are directed to analogous art and they are directed to the same field of endeavor as Wu, MOSER, Greetham, Mulchandani, and Slessman are directed to data collecting and seeking opportunities to achieve computation results more efficiently. Regarding claim 11, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach automatically implementing, by the one or more processors, the command filed in the technical environment. Slessman teaches automatically implementing, by the one or more processors, the command filed in the technical environment (Slessman: [0094]; In various embodiments, the control instruction may include machine code instructions, an API call, an electrical signal, a trigger, object code, script, etc. [0145]; Computer programs are configured to enable online and automated functions such as, for example, sending and receiving messages, receiving query requests, configuring responses, dynamically configuring user interfaces, requesting data, sending control instructions, receiving data). Regarding claim 15, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach the real-time operational data, the historical operational data, and the historical resource data are selected from the group consisting of power, bandwidth, space, computing, cost, and carbon footprint. Slessman teaches the real-time operational data, the historical operational data, and the historical resource data are selected from the group consisting of power, bandwidth, space, computing, cost, and carbon footprint (Slessman: [0123]; DCICS 105 can determine potential alternative data center assets based on one or more of the following: asset utilization, utilization forecasts, physical security, logical security, current latency; utility costs; power capacity or availability, power utilization effectiveness, cooling capability, physical space, network providers, network bandwidth, network redundancy and power redundancy). Regarding claim 19, the modification of Wu, MOSER, Greetham, and Mulchandani teaches claimed invention substantially as claimed, however the modification of Wu, MOSER, Greetham, and Mulchandani does not explicitly teach automatically implementing, by the one or more processors, the command files in the technical environment. Slessman teaches automatically implementing, by the one or more processors, the command files in the technical environment (Slessman: [0094]; In various embodiments, the control instruction may include machine code instructions, an API call, an electrical signal, a trigger, object code, script, etc. [0145]; Computer programs are configured to enable online and automated functions such as, for example, sending and receiving messages, receiving query requests, configuring responses, dynamically configuring user interfaces, requesting data, sending control instructions, receiving data). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S Patent Application Publication 2023/0016199 issued to Jividen et al. (hereinafter as “Jividen”) teaches determining a root cause of anomalous events in a networked computing environment. U.S Patent 11,126,492 issued to Graklanoff et al. (hereinafter as “Graklanoff”) teaches root causes of anomalies in computing environment and performing anomaly analysis on the receiving topology map and determining the anomaly status of the topology map. U.S Patent Application Publication 2009/0172687 issued to BOBAK et al. (hereinafter as “BOBAK”) teaches the scope and impact of an invent to determine failures and identify resources affected by the event. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANDREW N HO whose telephone number is (571)270-0590. The examiner can normally be reached Tuesday and Thursday 10:00-6:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Sherief Badawi can be reached at (571) 272-9782. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 7/21/2026 /ANDREW N HO/Examiner Art Unit 2169 /SON T HOANG/Primary Examiner, Art Unit 2169
Read full office action

Prosecution Timeline

Jan 16, 2023
Application Filed
Jun 26, 2025
Non-Final Rejection mailed — §103
Sep 26, 2025
Response Filed
Jan 20, 2026
Final Rejection mailed — §103
Apr 20, 2026
Request for Continued Examination
Apr 24, 2026
Response after Non-Final Action
Jul 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12670196
CANDIDATE DATA RANKING METHOD USING PREVIOUSLY SELECTED CANDIDATE DATA
3y 10m to grant Granted Jun 30, 2026
Patent 12541533
DATA SYNCHRONIZATION ERROR RESOLUTION
3y 9m to grant Granted Feb 03, 2026
Patent 12524423
Systems and Methods for Using Multiple Aggregation Levels in a Single Data Visualization
3y 9m to grant Granted Jan 13, 2026
Patent 12511265
DEDUPLICATION FOR DATA TRANSFERS TO PORTABLE STORAGE DEVICES
3y 6m to grant Granted Dec 30, 2025
Patent 12475002
SYSTEM AND METHOD FOR EFFICIENT BLOCK LEVEL GRANULAR REPLICATION
4y 7m to grant Granted Nov 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
61%
Grant Probability
92%
With Interview (+31.0%)
3y 11m (~4m remaining)
Median Time to Grant
High
PTA Risk
Based on 226 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month