Prosecution Insights
Last updated: October 02, 2026
Application No. 18/776,188

LOG ANOMALY DETECTION BASED ON GOLDEN SIGNAL TEMPLATES

Non-Final OA §101§112
Filed
Jul 17, 2024
Examiner
CHU, GABRIEL L
Art Unit
2114
Tech Center
2100 — Computer Architecture & Software
Assignee
International Business Machines Corporation
OA Round
3 (Non-Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
6m
Est. Remaining
77%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
368 granted / 467 resolved
+23.8% vs TC avg
Minimal -2% lift
Without
With
+-2.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
10 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
16.1%
-23.9% vs TC avg
§103
30.8%
-9.2% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
22.4%
-17.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 467 resolved cases

Office Action

§101 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-4, 6-11, 13-18, 20 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Referring to claims 1, 8, 15, and consequently their dependent claims, it is unclear where original support lies for “receiving a new log file from one of the distributed system of multiple computing nodes or the cloud computing nodes; detecting, by the trained second ML model, the anomaly within the new log file, associated with the computing device, based on a comparison of the count of the one or more instances of each log template of the second set of log templates in the new log file to a baseline count, from the baseline counts, of a respective log template of the second set of log templates”. It is both unclear where the specification originally discloses a new log file and that the trained second ML model detects the anomaly based on a comparison of the count of the one or more instances of each log template of “the second set of log templates in the new log file” to a baseline count. Recall that the second set of log templates refers to those templates generated based on “the filtering of the plurality of log templates” which is referring to those templates included “the log file” (not the new log file). Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-4, 6-11, 13-18, 20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. At step 1, if no statutory category rejection was given above, then the claims have been determined to have a statutory category. At step 2a, prong one, referring to claim 1, as emphasized, there is disclosed a computer implemented method for: receiving a log from a node of a distributed or cloud system, identifying log templates from a log file, such identifying “based on” executing a first machine learning model, determining a first set of log templates not matching golden signals of a golden signal dictionary (this dictionary corresponding to metrics), filtering a plurality of log templates based on the golden signal dictionary, generating a second set of log templates corresponding to golden signals, determining “using” the first ML model a count of instances of log templates; training a second ML model based on baseline counts, receiving a new log from a node of a distributed or cloud system, detecting an anomaly by the second ML model by comparing a count to a baseline count, and retraining the second ML model from updated baseline counts. Claim 1 recited, “A computer-implemented method, comprising: receiving a log file from one of a distributed system of multiple computing nodes or cloud computing nodes; identifying one or more instances of each log template of a plurality of log templates included in the log file based on execution of a first machine learning (ML) model on the log file; determining, using a golden signal dictionary, a first set of log templates, from the plurality of log templates, that does not match golden signals, wherein the golden signals correspond to a set of key metrics indicating at least one of a performance of a computing device associated with the log file, a reliability of the computing device, or a storage capacity of the computing device; filtering the plurality of log templates based on the golden signal dictionary; generating, based on the filtering of the plurality of log templates, a second set of log templates that corresponds to the golden signals, respectively; determining, using the first ML model, a count of the one or more instances of each log template of the second set of log templates within the log file; training a second ML model based on baseline counts of each log template of the second set of log templates that corresponds to the golden signals, to detect an anomaly; receiving a new log file from one of the distributed system of multiple computing nodes or the cloud computing nodes; detecting, by the trained second ML model, the anomaly within the new log file, associated with the computing device, based on a comparison of the count of the one or more instances of each log template of the second set of log templates in the new log file to a baseline count, from the baseline counts, of a respective log template of the second set of log templates; and retraining the second ML model based on an update of the baseline counts, wherein the update of the baseline counts is based on the count of the one or more instances.” Claims 8 and 15 are similar. The limitations of identifying, determining, filtering, generating, determining, training, detecting, and retraining as crafted, are processes that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of additional elements that do not integrate the judicial exception into a practical application. That is, nothing in these claim elements as emphasized precludes the step from practically being performed in the mind, possibly with the aid pen and paper. For example, these steps perform steps of observation, evaluation, judgment, or opinion. At step 2a, prong two, this judicial exception is not integrated into a practical application. In particular the claim additionally recites a generic computer, receiving data from a node in a distributed or cloud system, and the use of a machine learning model. The computer is recited at a high level of generality. The computer is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using a generic computer. See MPEP 2106.05(f). The limitations of receiving data are mere data gathering and output recited at a high level of generality, and thus are insignificant extra-solution activity. See MPEP 2106.05(g) (“whether the limitation is significant”). In addition, all uses of the recited judicial exceptions require such data gathering and output, and, as such, these limitations do not impose any meaningful limits on the claim. These limitations amount to necessary data gathering and outputting. See MPEP 2106.05. A node in a cloud or distributed system serves as a source of that data. The limitation of applying an ML model (execution of a first ML model, using the first ML model, detecting by the trained second ML model) provides nothing more than mere instructions to implement an abstract idea on a generic computer. See MPEP 2106.05(f). MPEP 2106.05(f) provides the following considerations for determining whether a claim simply recites a judicial exception with the words “apply it” (or an equivalent), such as mere instructions to implement an abstract idea on a computer: (1) whether the claim recites only the idea of a solution or outcome i.e., the claim fails to recite details of how a solution to a problem is accomplished; (2) whether the claim invokes computers or other machinery merely as a tool to perform an existing process; and (3) the particularity or generality of the application of the judicial exception. The model is used to generally apply the abstract idea without placing any limits on how the model functions and does not include details about how the execution is accomplished. Even when viewed in combination, these additional elements do not integrate the recited judicial exception into a practical application, and the claim is directed to the judicial exception. These additional elements merely serve to automate the method using a generic computer, receive data prior to its processing, and performs that processing using a ML model. At step 2b, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, there are the additional elements of a generic computer, receiving data from a node in a distributed or cloud system, and the use of a machine learning model. The limitations regarding use of a computer amounts to no more than mere instructions to apply the exception using a generic computer component. See MPEP2106.05(d), for example TLI Communications, Flook, Alice Corp, and Versata. The limitation of receiving data is recited at a high level of generality. These elements amount to receiving or transmitting data over a network and are well-understood, routine, conventional activity. See MPEP 2106.05(d), subsection II. See MPEP 2106.05(g). Further regarding reception of data from a distributed or cloud system, see US 20230142895 A1 paragraph 29, US 20180246797 A1 paragraph 159, US 20150347264 A1 paragraph 4, US 20150229546 A1 paragraph 32, US 20250117315 A1 paragraph 44, US 20200201699 A1 paragraph 16. The recitation of applying a model is at best mere instructions to “apply” the abstract ideas, which cannot provide an inventive concept. See MPEP 2106.05(f). See MPEP 2106.05(g) In re Brown and Ameranth and MPEP 2106.05(d) Flook. However, further, machine learning, including both it’s training and application, is well understood, routine, and conventional. See for example US 20200389478 A1 paragraph 66, US 20150055858 A1 paragraph 5, US 20220319658 A1 paragraph 122, US 20250209347 A1 paragraph 23, US 20230205740 A1 paragraph 42. Even when considered in combination, these additional elements represent mere instructions to implement an abstract idea or other exception on a computer and insignificant extra-solution activity, which do not provide an inventive concept. Further referring to claim 2, this merely further claims conventional machine learning. Further referring to claim 3, this performs steps of observation, evaluation, judgment, or opinion. Further referring to claim 4, this performs steps of observation, evaluation, judgment, or opinion and further claims conventional machine learning. Further referring to claim 6, this performs steps of observation, evaluation, judgment, or opinion and further claims conventional machine learning. Further referring to claim 7, the claim additionally claims a generic UI to present information. All uses of the recited judicial exceptions require such data gathering and output, and, as such, these limitations do not impose any meaningful limits on the claim. These limitations amount to necessary data gathering and outputting. See MPEP 2106.05. This does not integrate the abstract idea into practical application. Such interfaces are well understood, routine, and conventional. With respect to the generic interface, see for example US 20050010416 to Anderson (paragraph 125), US 20090150812 to Baker (paragraph 3), US 20130007655 to Bridgen (paragraph 4). Even when considered in combination, these additional elements represent mere instructions to implement an abstract idea or other exception on a computer and insignificant extra-solution activity, which do not provide an inventive concept. Referring to claims 9-11, 13, 14, 16-18, 20, see rejections above. Response to Arguments Applicant's arguments filed 19 June 2026 have been fully considered but they are not persuasive. Regarding Applicant’s argument (page 13) that the log is a stream of data, this is not claimed. However, had it been claimed, this appears to be arguing for an amount of data generated in a period of time rather than a complexity of data or analysis. Generic processors are known to be able to process such data. Regarding this data’s source, this is also known. See rejection above. Regarding Applicant’s argument that machine learning is not performed in the mind, the use of machine learning itself was recognized above and previously as an additional element. See rejection above. Regarding Applicant’s argument (page 14) regarding the analysis of “large volumes” of data, this too was not claimed. However even had Applicant claimed this, depending on the particular data and the analysis thereof, “large” volumes too may be within the realm of complexity performable by a human mind. Regarding Applicant’s (page 15) extensive citation of the specification, much of this does not appear to be claimed. Regarding Applicant’s argument (page 16) pointing out “large, continuously generated stream of messages”, again, this is not claimed, see above. Applicant further argues that the log file is received from ONE of the nodes in a cloud or distributed system and “thus includes large volumes of data”. It is not clear how Applicant draws this conclusion. Regarding Applicant’s argument (page 16) that “technical problems” are solved by the method steps, the analysis performed is regarding technology but does not itself improve technology. The analysis itself covers concepts performed in the human mind including observation evaluation, judgment and opinion. Examiner has separately identified additional elements that do not integrate this abstract idea into practical application. Applicant further refers to “high template diversity” and “extremely large instance counts”, again unclaimed. To be clear, even had Applicant used this language to claim, it is unclear what words such as “high” and “extremely large” mean in terms of an actual amount or complexity. Applicant should also consult MPEP 2173.05(b) regarding “relative terminology”. Regarding Applicant’s argument (page 17) that the invention is similar to Ex Parte Desjardins as there are “technological improvements in log analysis”, such an improvement would not show improvement to the computer or model itself. At best this is an analytical improvement, not an improvement to technology per se. It is unclear how the underlying computer, for example, is itself improved. Instead, the computer is merely used as a tool to implement the analysis. Similarly, machine learning is not itself improved, but rather used as a tool to implement the analysis. Regarding the affidavit, it is unclear how Inventor Paradkar’s technological expertise is relevant to the legal issues surrounding the 101 rejection. Examiner notes the similarity between the affidavit and the arguments above. For example, both argue unclaimed elements, for example “high-volume” log data. As another example, both conflate aspects of the claim’s nonconventionality with eligibility and fail to address the rejection as delineated along abstract and additional elements. For example, in bullet 5, the inventor argues that identifying a static part and a dynamic part of the plurality of templates is not generic or conventional. This was identified as abstract so it is unclear what relevance arguing its conventionality serves. In bullet 6, the inventor argues that the invention results in improvements in system performance. Besides not being evident in the claims, any resulting system improvements appear to merely follow on from the particular analysis. As an analogy, if I figured out a faster, shorter route from point a to point b, is this an abstract mental idea? Would having a faster, shorter route also save wear and tear on my car and the road, save gas, save the environment, and increase my useable lifespan? Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to GABRIEL L CHU whose telephone number is (571)272-3656. The examiner can normally be reached weekdays 8 am to 5 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ashish Thomas can be reached at (571)272-0631. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GABRIEL CHU/Primary Examiner, Art Unit 2114
Read full office action

Prosecution Timeline

Show 3 earlier events
Jan 12, 2026
Examiner Interview Summary
Jan 23, 2026
Response Filed
Feb 26, 2026
Final Rejection mailed — §101, §112
Apr 27, 2026
Response after Non-Final Action
Jun 19, 2026
Response after Non-Final Action
Jun 19, 2026
Request for Continued Examination
Jun 24, 2026
Response after Non-Final Action
Jul 24, 2026
Non-Final Rejection mailed — §101, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737253
FAILURE REMEDY IN COMPUTING SYSTEMS USING ACTION PATTERN DATABASE
2y 2m to grant Granted Sep 15, 2026
Patent 12730702
EARLY ROOT CAUSE LOCALIZATION
1y 9m to grant Granted Sep 08, 2026
Patent 12724658
USING THREAD CPU UTILIZATION PATTERNS TO ANALYZE STORAGE NODE PERFORMANCE PROBLEMS
2y 7m to grant Granted Sep 01, 2026
Patent 12639179
MEDIATOR ASSISTED SWITCHOVER BETWEEN CLUSTERS
1y 10m to grant Granted May 26, 2026
Patent 12625782
TECHNIQUES FOR REPLICATING STATE INFORMATION FOR HIGH AVAILABILITY
1y 5m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
77%
With Interview (-2.2%)
2y 9m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 467 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month