DETAILED ACTION
This Office action is in response to the application filed on 06/30/2023.
Claims 1-20 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 06/30/2023 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Interpretation
Regarding claims 11-17, they recite in part “A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”, without describing the computer program product or the storage media to exclude signals per se. However, a review of the specification in para.0016 “A computer readable storage medium, as that term is used in the present disclosure, is not to be construed as storage in the form of transitory signals per se”, shows that computer readable storage media excludes signals per se.
Therefore Claims 11-17 are not rejected under 35 USC 101 statutory class in view of para.0016 of specification showing the computer readable storage medium as excluding transitory signals per se.
Claim Objections
Claims 1, 11, and 18 are objected to because of the following informalities:
Each of these claims recite in part “correlate the source codes in the static application log”, however “the source codes” does not refer back to a previous instance of source codes. This should be corrected to “source codes” to avoid antecedent basis issues.
Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-9, 11-16, 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Regarding Claims 1, 11, and 18, they recite in part “extracting, by the processor set, business events and IT events from the business logs and the IT logs, respectively; relating, by the processor set, the business events to the IT events to provide an organized log; correlating, by the processor set, the source codes in the static application log with the business event and the IT events in the organized log to provide an event log; and using, by the processor set, the event log to automatically anticipate or resolve an error in the mainframe.”
The limitations as drafted above is a process that under broadest reasonable interpretation covers performance of the limitations in the mind but for generic computer components and extra solution activities. That is, other than “A computer-implemented method, comprising the steps of: retrieving, by a processor set, business logs and information technology logs (IT logs) from a mainframe; retrieving, by the processor set, a static application log from the mainframe”, “A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”, and “A system comprising a processor set, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”, the claims comprise limitations that can be performed in the human mind, and/or with pen and paper. In this case, a person can reasonably identify related events in a plurality of logs of information, and use that related information to predict when similar events would occur and/or identify related errors. If a claim under its broadest reasonable interpretation covers performance in the mind but for recitation of generic computer components and extra solution activities, then it falls within mental process grouping of abstract idea. Accordingly the claims recite an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claims only recite the additional limitations of “A computer-implemented method, comprising the steps of: retrieving, by a processor set, business logs and information technology logs (IT logs) from a mainframe; retrieving, by the processor set, a static application log from the mainframe”, “A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”, and “A system comprising a processor set, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”. Regarding the hardware elements of mainframe, a computer program product, computer readable storage medium and processor, they are generic computer components recited as performing routine activities. Regarding the retrieving steps, they are extra solution activities that are used to obtain the information used during the judicial exception. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are therefore directed to an abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed in respect to the integration of the abstract idea into a practical application, the elements of “A computer-implemented method, comprising the steps of: retrieving, by a processor set, business logs and information technology logs (IT logs) from a mainframe; retrieving, by the processor set, a static application log from the mainframe”, “A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:”, and “A system comprising a processor set, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:” amount to no more than mere instructions to apply the abstract idea to generic computer elements and extra solution activities. Mere instructions to apply the abstract idea to generic/well known elements and extra solution activities cannot provide an invention concept. The claims are not patent eligible.
Regarding Claims 2-9, 12-16, and 19-20, they recite in part “wherein the relating comprises relating the business events to the IT events based on time proximity.”, “wherein the relating comprises relating the business events to the IT events based on occurring within a predefined time period of each other.”, “mining the event log.” “mine the event log to anticipate errors or to provide solution for errors.”
The limitations as drafted above is a process that under broadest reasonable interpretation covers performance of the limitations in the mind but for generic computer components and extra solution activities. That is, other than “wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation.”, “wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log, application logs, security logs, network logs, and database logs.” “wherein the IT events comprise one or more selected from the group consisting of system events, errors, and warnings.” “wherein the event log is presented as lookup table.”, “wherein the mining comprises saving the event log in a knowledge base database (KDB).” the claims comprise limitations that can be performed in the human mind, and/or with pen and paper. In this case, a person can reasonably identify related events in a plurality of logs of information using time proximity, and analyze that related information to predict when similar events would occur and/or identify related errors. If a claim under its broadest reasonable interpretation covers performance in the mind but for recitation of generic computer components and extra solution activities, then it falls within mental process grouping of abstract idea. Accordingly the claims recite an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claims only recite the additional limitations of “wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation.”, “wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log, application logs, security logs, network logs, and database logs.” “wherein the IT events comprise one or more selected from the group consisting of system events, errors, and warnings.” “wherein the event log is presented as lookup table.”, “wherein the mining comprises saving the event log in a knowledge base database (KDB).” Regarding the limitations of “wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation.”, “wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log, application logs, security logs, network logs, and database logs.” “wherein the IT events comprise one or more selected from the group consisting of system events, errors, and warnings.”, these limitations merely describe the type of data that is being analyzed in the abstract idea. Regarding the lookup table, it is merely a table that may be searched and is a generic computing data structure. Regarding the knowledge data database, under broadest reasonable interpretation, it is merely a database comprising knowledge and the storing operation is merely an extra solution activity that stored the result of the abstract idea. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are therefore directed to an abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed in respect to the integration of the abstract idea into a practical application, the elements of “wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation.”, “wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log, application logs, security logs, network logs, and database logs.” “wherein the IT events comprise one or more selected from the group consisting of system events, errors, and warnings.” “wherein the event log is presented as lookup table.”, “wherein the mining comprises saving the event log in a knowledge base database (KDB).” amount to no more than mere instructions to apply the abstract idea to generic computer elements and extra solution activities. Mere instructions to apply the abstract idea to generic/well known elements and extra solution activities cannot provide an invention concept. The claims are not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 2, 4, 7-9, 11, 14-16, 18, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ramaiah (hereinafter Ram, US 2013/0339801 A1) in view of Jamieson et al. (hereinafter Jamieson, US 2022/0188283 A1).
Regarding Claim 1, Ram discloses A computer-implemented method (Ram: para.0001 method), comprising the steps of:
retrieving, by a processor set (Ram: para.0017 multiple processors), business logs and information technology logs (IT logs) from a mainframe (Ram: para.0018 “Referring to FIGS. 3A, 3B, and 3C, at 305, a plurality of system logs and a plurality of system traces are maintained in a computer storage device.” Para.0024 “Moreover, those skilled in the art will appreciate that the invention may be practiced with other computer system configurations, including … mainframe computers” para.0018 “ At 310, data is extracted from the plurality of system logs and system traces.”. the system logs are stored in a computer storage device of a mainframe, and retrieved in step 310 for processing. The logs include IT logs such as logs 220-235 for database logs, infrastructure logs etc. and the business logs include the application logs para.0008 “Currently, there are no systems that provide a single and centralized mechanism or solution to gather all relevant log and trace files for end to end business applications or end to end information technology (IT) scenarios”, see also para.0012);
extracting, by the processor set, business events and IT events from the business logs and the IT logs, respectively (Ram: para.0018 “ At 310, data is extracted from the plurality of system logs and system traces.” Events from each log is extracted, business events from the application logs, and IT events from the other IT logs.);
relating, by the processor set, the business events to the IT events to provide an organized log (Ram: para.0018 “At 315, the extracted data is combined into centralized history of system logs and system traces. At 320, the centralized history of system logs and system traces is automatically examined to identify issues and problems in the associated system.” The extracted data from each of the logs is consolidated into a single centralized history of system logs and traces.);
using, by the processor set, the organized log to automatically anticipate or resolve an error in the mainframe (Ram: para.0018 “ At 320, the centralized history of system logs and system traces is automatically examined to identify issues and problems in the associated system. At 325, the issues and problems that require attention are automatically identified. At 330, a person or a group that is responsible for the identified issues and problems is automatically identified. And at 335, a message is transmitted to the identified person or group informing the identified person or group of the identified issues and problems.” The organized log, i.e. the centralized history of system logs and traces is used to revolve detected issues in the system, i.e. mainframe para.0024).
However Ram does not explicitly disclose retrieving, by the processor set, a static application log from the mainframe; correlating, by the processor set, the source codes in the static application log with the business event and the IT events in the organized log to provide an event log; and using, by the processor set, the event log to automatically anticipate or resolve an error in the mainframe.
Jamieson discloses retrieving, by the processor set, a static application log from the system (Jamieson: para.0111 “Thus, XP-Functions may be defined based on associated fields such as task type, timestamp, date, system identifier, client identifier, or any suitable combination thereof. Log file entries may be correlated with database records for XP-Functions to determine which XP-Function is referred to by each log file entry. Since log files may be periodically deleted (e.g., every 24 or 48 hours), data regarding discovered XP-Functions, XP-Chains, or processes may be stored in a database using the schema 300 of FIGS. 3-9 for persistent storage. In some example embodiments, a UI is presented to a user that presents a relationship between XP-Functions and executables.” A static application log, in this case a set of database records for XP-functions, is obtained from a database of the system to be correlated to log file entries. For example, Fig. 5 510 shows an XP function table 510. Examiner notes that this is the same as the static log as described in para.0036 of applicant’s specification that describes which functions are launched for certain tasks para.0036 “The application log 264 refers to a static log that indicates the application source code that is called for a business event. For example, if a purchase order enters the system, the application log indicates that source codes, e.g., 1, 3, and 6, are launched to complete the purchase order.”);
correlating, by the processor set, the source codes in the static application log with the business event in the organized log to provide an event log (Jamieson: para.0111 “Thus, XP-Functions may be defined based on associated fields such as task type, timestamp, date, system identifier, client identifier, or any suitable combination thereof. Log file entries may be correlated with database records for XP-Functions to determine which XP-Function is referred to by each log file entry.” Para.0099 “The headers 1530-1580 indicate that each of the result rows 1590A-1590D includes information for an XP-Function: the name of the function, the XP-Chain the XP-Function is a part of, the sequential position of the XP-Function in the XP-Chain, the XP-Cell corresponding to the XP-Function, and the key executable object providing the XP-Function. Additionally, the headers 1520 and 1525 indicate that the functional process and process set for the XP-Chain are provided.” As seen in Fig. 14-15, each event is correlated with an XP function); and
using, by the processor set, the event log to automatically anticipate or resolve an error in the mainframe (Jamieson: Fig. 18, para.0038 “If all test scripts execute successfully, software deployment continues. Otherwise, administrators or developers are notified of the errors so that the release-candidate software can be updated before deployment.” para.0117 “After the testing script is created, the communication module 210 provides the testing script to a test server or test client (e.g., the client device 160B). Thereafter, the testing script is automatically executed to detect errors in the discovered process.” In figure 18, each log is used to create a testing script that is used to detect and resolve errors.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate retrieving, by the processor set, a static application log from the mainframe; correlating, by the processor set, the source codes in the static application log with the business event in the organized log to provide an event log; and using, by the processor set, the event log to automatically anticipate or resolve an error in the mainframe, and further apply this concept to the IT events in the organized log as in Ram such that for each event, associated functions that are called for that operation are marked.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Regarding Claim 2, Ram-Jamieson discloses claim 1 as set forth above.
However Ram does not further disclose wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation.
Jamieson discloses wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation (Jamieson: para.0025 “An XP-Function comprises one or more operations that create, modify, or delete a business object. A business object is an object (in the Object-Oriented Programming sense of the word) or data structure that represents a business entity. A business entity is any person, place, thing, document, or service that relates to a business. Example business entities include users (e.g., employees), customers, companies, sales orders, invoices, products, and services. A business object has a lifecycle in which the business object is created, used, and destroyed. For example, a business object for an employee is created when the employee is hired, maintained and modified during the employee's term of employment, and may be deleted or archived when the relationship with the employee is severed. A business process may correlate to a part of (or the entirety of) the lifecycle of a business object. For example, an individual sales order may be created, changed, and deleted and XP-Functions reflect and visualize these operations for the individual sales order. By way of example, the methods and systems described herein operate on business processes and business objects, but the inventive subject matter is not so limited.” See also Fig. 14-15, the events include any changes or creations to business entities including sales, purchases, invoices.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate wherein the business events comprise one or more selected from the group consisting of sales, purchase orders, inventory requests, inventory listing, and invoice creation, and apply this to the business log of Ram. Ram discloses broadly events that occur for businesses in its application log, and it would be obvious to consider events that are integral to a business such as ones listed in Jamieson.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Regarding Claim 4, Ram-Jamieson discloses claim 1 as set forth above.
Ram further discloses wherein the IT events comprise one or more selected from the group consisting of system events, errors (Ram: para.0016 “The BI tool can key on error codes in the logs and traces and execute predefined actions based on those error codes” para.0018 “ At 315, the extracted data is combined into centralized history of system logs and system traces. At 320, the centralized history of system logs and system traces is automatically examined to identify issues and problems in the associated system.” System events in the system log, and/or error codes contained in the logs are system events and errors.), and warnings.
Regarding Claim 7, Ram-Jamieson discloses claim 1 as set forth above.
However Ram does not explicitly disclose wherein the event log is presented as lookup table.
Jamieson discloses wherein the event log is presented as lookup table (Jamieson: para.0111 “Thus, XP-Functions may be defined based on associated fields such as task type, timestamp, date, system identifier, client identifier, or any suitable combination thereof. Log file entries may be correlated with database records for XP-Functions to determine which XP-Function is referred to by each log file entry.” Para.0099 “The headers 1530-1580 indicate that each of the result rows 1590A-1590D includes information for an XP-Function: the name of the function, the XP-Chain the XP-Function is a part of, the sequential position of the XP-Function in the XP-Chain, the XP-Cell corresponding to the XP-Function, and the key executable object providing the XP-Function. Additionally, the headers 1520 and 1525 indicate that the functional process and process set for the XP-Chain are provided.” As seen in Fig. 14-15, each event is correlated with an XP function. Para.0058-0059 “The format 480 of the business object table 470 includes an object identifier field and an object type field. Thus, the object type for a business object can be determined by looking up the object identifier in the business object table 470. ” the tables in Jamieson are set up as look up tables, as seen in Fig. 14-15 they are set up in the same manner as that of fig. 4-5, and are also considered to be look up tables.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate wherein the event log is presented as lookup table.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Regarding Claim 8 Ram-Jamieson discloses claim 1 as set forth above.
However Ram does not explicitly disclose mining the event log.
Jamieson discloses mining the event log (Jamieson: Fig. 15, Fig. 18, para.0114 “In operation 1830, the process discovery module 230 accesses, from a second log file of a second application server (e.g., the application server 120B), second data that identifies a second process step, the second data showing a second change to the document. For example, data corresponding to the XP-Function element 1740 of FIG. 14 may be accessed. The XP-Function func002 is part of the XP-Chain chain001, which is part of the end-to-end process E2E001, as shown by FIGS. 16-17. In some example embodiments, the accessed data is text that identifies a key executable object, a function name, and a document. For example, and with reference to the result row 1590B of FIG. 15: “Dialog Change Order, MTO Standard Order, Standard Item; VA02.”” The event log in that of fig 14 or 15 is mined to obtain second data).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate mining the event log.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Regarding Claim 9, Ram-Jamieson discloses Claim 8 as set forth above.
However Ram does not explicitly disclose wherein the mining comprises saving the event log in a knowledge base database (KDB).
Jamieson discloses wherein the mining comprises saving the event log in a knowledge base database (KDB) (Jamieson: para.0024 “The automatic process discovery server reconstructs end-to-end processes out of XP-Chains, even when the XP-Chains are executed on different application servers, based on log files and XP-Cells. Data regarding the end-to-end processes is stored in a process repository that links objects with processes. The log files and databases may be regularly monitored and the end-to-end process data may be updated without interrupting the applications provided by the application servers.” The generated end to end process data generated from the log files such as in Fig. 14-15, are stored in a database, i.e. knowledge base database.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate wherein the mining comprises saving the event log in a knowledge base database (KDB).
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Regarding Claims 11, 14-16, they teach all of the same elements as claims 1, 7-9, but in A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to: (Ram: para.0028), therefore the supporting rationale for the rejection to claims 1, 7-9 apply equally as well to that of claims 11, 14-16.
Regarding Claim 18, it teaches all of the same elements as claim 1 but in A system comprising a processor set, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to: (Ram: para.0026-0028), Therefore the supporting rationale for the rejection to claim 1 applies equally as well to that of claim 18.
Regarding Claim 20, Ram-Jamieson discloses claim 18 as set forth above.
However Ram does not explicitly disclose mine the event log to anticipate errors or to provide solution for errors.
Jamieson further discloses mine the event log to anticipate errors or to provide solution for errors (Jamieson: Fig. 15, Fig. 18, para.0114 “In operation 1830, the process discovery module 230 accesses, from a second log file of a second application server (e.g., the application server 120B), second data that identifies a second process step, the second data showing a second change to the document. For example, data corresponding to the XP-Function element 1740 of FIG. 14 may be accessed. The XP-Function func002 is part of the XP-Chain chain001, which is part of the end-to-end process E2E001, as shown by FIGS. 16-17. In some example embodiments, the accessed data is text that identifies a key executable object, a function name, and a document. For example, and with reference to the result row 1590B of FIG. 15: “Dialog Change Order, MTO Standard Order, Standard Item; VA02.”” The event log in that of fig 14 or 15 is mined to obtain second data. Fig. 18, para.0038 “If all test scripts execute successfully, software deployment continues. Otherwise, administrators or developers are notified of the errors so that the release-candidate software can be updated before deployment.” para.0117 “After the testing script is created, the communication module 210 provides the testing script to a test server or test client (e.g., the client device 160B). Thereafter, the testing script is automatically executed to detect errors in the discovered process.” In figure 18, each log is used to create a testing script that is used to detect and resolve errors.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram with Jamieson in order to incorporate mine the event log to anticipate errors or to provide solution for errors.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving business function by determining issues using log information (Jamieson: para.0038).
Claim(s) 3 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ramaiah (hereinafter Ram, US 2013/0339801 A1) in view of Jamieson et al. (hereinafter Jamieson, US 2022/0188283 A1) in view of Grantham (US 2018/0300186 A1).
Regarding Claim 3, Ram-Jamieson discloses claim 1 as set forth above.
Ram further discloses wherein the IT logs comprise application logs, security logs, network logs, and database logs (Ram: para.0015 “ The centralized log system 210 receives input from several entities, including application logs and traces 215, database logs and traces 220, operating system logs and traces 225, infrastructure (e.g., firewall, antivirus, Citrix®, VMware®, etc.) logs and traces 230, and other information source (FileSystem, legacy systems, etc.) logs and traces 235.” VMware logs, i.e. application log, Database logs, infrastructure logs for firewall antivirus etc, i.e. security logs, and logs regarding the network in para.0010 “Logs and traces are meant to be end to end (that is, from a client (such as a browser) to a network, from the network to a database” are obtained.).
However while Ram discloses generally system logs, operation logs, error logs in general in para.0015-0016, Ram-Jamieson does not explicitly disclose wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log.
Grantham discloses wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log (Grantham: para.0042 “ Data collector 207 receives and/or fetches a data stream from mainframe OS 205 with mainframe log records in near real-time without disrupting the mainframe 101 operating environment. In some implementations data collector 207 can receive or fetch data in the order of terabytes including multiple log types. Some examples of mainframe logs include SYSLOGs, Job logs, OPERLOGs, Logrec Error Recording, Console Logs, Hardcopy Logs, and other suitable logs.” Syslog, operlog, logrec, and hard copy logs are obtained from the mainframe.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram-Jamieson with that of Grantham in order to incorporate wherein the IT logs comprise system logs (SYSLOG), job log, operation log (OPERLOG), error log (LOGREC), hard-copy log.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving mainframe event analysis by improving cost effectiveness and utilization (Grantham: para.0002-0004).
Claim(s) 5-6, 12-13, 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ramaiah (hereinafter Ram, US 2013/0339801 A1) in view of Jamieson et al. (hereinafter Jamieson, US 2022/0188283 A1) in view of Mack et al. (hereinafter Mack, US 2022/0321551 A1).
Regarding Claim 5, Ram-Jamieson disclose claim 1 as set forth above.
Ram further discloses relating the business events to the IT events based on time proximity (Ram: para.0011 “The BI features and functionalities can then be used to analyze the data and issues recorded in the logs and traces. This analysis gives an idea of the issues that users are experiencing, and the analysis can allow a system administrator to respond to such issues, and plan to prevent or avoid such issues in the future. Moreover, this analysis can create intelligence by co-relating logs and traces. This co-relating results in the expedient acquisition of useful information and an effective solving of issues in the IT landscape. For example, the co-relating can correlate the timestamps of the various system and log messages, which allows the correlation of an incident or event across the various logs and traces. ” timestamps are used to determine related events in each log).
However, while Ram discloses generally relating the data from various logs, this occurs after the generation of the organized log, therefore Ram-Jamieson does not explicitly disclose wherein the relating comprises relating the business events to the IT events based on time proximity.
Mack discloses wherein the relating comprises relating the events to another logs events based on time proximity (Mack: para.0057-0058 “A resource with more advance capabilities will have a more expansive event record and multiple event logs. Event records generated by each source may have a unique format, amplifying the difficulty of tracing the action incidence using the event records. … In response, the log correlation protocol may be configured to cluster the one or more event records into one or more groups based on the one or more action incidences. Once clustered, the log correlation protocol may be configured to generate a representative event record for each of the one or more groups based on at least one or more log correlation rules. As an example, log correlation rules specifies which sequences of event records should be indicative of a particular action incidence, specific time windows during which event records are recorded that are identifiable based on individual time stamps, specific types of event records that in combination identify the specific type of action incidence, and/or the like.” Events from a plurality of logs are correlated based on time windows.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram-Jamieson with that of Mack in order to incorporate wherein the relating comprises relating the events to another logs events based on time proximity when generating an organized log using business and IT events in Ram, such as in step 308 in Fig. 3 of Mack.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved identification of related events (Mack: para.0058).
Regarding Claim 6, Ram-Jamieson-Mack discloses claim 5 as set forth above.
However Ram-Jamieson does not explicitly disclose wherein the relating comprises relating the business events to the IT events based on occurring within a predefined time period of each other
Mack discloses wherein the relating comprises relating the events to another logs events based on occurring within a predefined time period of each other (Mack: para.0057-0058 “A resource with more advance capabilities will have a more expansive event record and multiple event logs. Event records generated by each source may have a unique format, amplifying the difficulty of tracing the action incidence using the event records. … In response, the log correlation protocol may be configured to cluster the one or more event records into one or more groups based on the one or more action incidences. Once clustered, the log correlation protocol may be configured to generate a representative event record for each of the one or more groups based on at least one or more log correlation rules. As an example, log correlation rules specifies which sequences of event records should be indicative of a particular action incidence, specific time windows during which event records are recorded that are identifiable based on individual time stamps, specific types of event records that in combination identify the specific type of action incidence, and/or the like.” Events from a plurality of logs are correlated and clustered based on a specific time window, i.e. events occurring within a time period of each other.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram-Jamieson with that of Mack in order to incorporate wherein the relating comprises relating the events to another logs events based on occurring within a predefined time period of each other when generating an organized log using business and IT events in Ram, such as in step 308 in Fig. 3 of Mack.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved identification of related events (Mack: para.0058).
Regarding Claims 12-13, 19, they do not teach nor further define over the limitations of claims 5-6, therefore the supporting rationale for the rejection of claims 5-6 apply equally as well to that of claims 12-13, 19.
Claim(s) 10, 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ramaiah (hereinafter Ram, US 2013/0339801 A1) in view of Jamieson et al. (hereinafter Jamieson, US 2022/0188283 A1) in view of Chen et al. (hereinafter Chen, US 2021/0377288 A1).
Regarding Claim 10, Ram-Jamieson discloses claim 9 as set forth above.
However Ram-Jamieson does not explicitly disclose wherein the mining comprises using pattern recognition machine learning to anticipate errors or to resolve errors.
Chen discloses wherein the mining comprises using pattern recognition machine learning to anticipate errors or to resolve errors (Chen: para.0065 “At step 426, log signatures are generated for the additional logs. The log signatures may be generated in the same manner as discussed in FIG. 4A, for example, by calculating variances, spreads, and aggregates for each data field in the additional network traffic logs. Where the analysis of the additional network traffic logs is occurring in real-time for live network traffic, the portion of the additional network traffic logs that was sampled from the incoming traffic may be used for the additional log signature generation. In various embodiments, a machine learning model may also be utilized to generate and determine the log signatures, for example, using aggregate value weights determined by the machine learning model based on training data. For example, the machine learning model may be trained using malicious network traffic logs, where the aggregate values may be determined using different weights and/or attributes trained from the malicious network traffic log.” Para.0020 “In some embodiments, this may also be done for randomly sampled logs in order to detect the similarity of those logs to other logs, which may be required if a particular network traffic log is causing an error or to check various statistics and extent of certain traffic logs. This may include where a merchant, user, or other entity utilizing the service provider may be encountering particular issues or other requirements to track a particular log and check for errors.” Para.0011 “In order to identify, remedy, stop, and/or prevent these computing attacks and other abuses of the service providers” Log signatures are generated for each log using a machine learning model to detect malicious traffic causing errors and solve the issues).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Ram-Jamieson with that of Chen in order to incorporate wherein the mining comprises using pattern recognition machine learning to anticipate errors or to resolve errors.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved log analysis by using a machine learning model (Chen: para.0065).
Regarding Claim 17, it does not teach nor further define over the limitations of claim 10, therefore the supporting rationale for the rejection to claim 10 applies equally as well to that of claim 17.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Singh US 2023/0042425 A1 see claim 4, para.0034, wherein errors logs and transaction logs are correlated using machine learning in para.0006.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EUI H KIM whose telephone number is (571)272-8133. The examiner can normally be reached 7:30-5 M-R, M-F alternating.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal B Divecha can be reached at 5712725863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EUI H KIM/ Examiner, Art Unit 2453
/KAMAL B DIVECHA/Supervisory Patent Examiner, Art Unit 2453