DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending in this office action.
Claim Objections
Claims 1 and 10 are objected to because of the following informalities: Claims 1 and 10 recites “calculates the similarity between to two or more server log strings to determine…” in lines 10,11 respectively, it may be a typo error. Appropriate correction is required.
Information Disclosure Statement
The information disclosure statement filed 09/18/2024 fails to comply with the provisions of 37 CFR 1.97, 1.98 and MPEP § 609 because: NPL entries 1, 2 and 3 lack a corresponding date. It has been placed in the application file, but the information referred to therein has not been considered as to the merits. Applicant is advised that the date of any re-submission of any item of information contained in this information disclosure statement or the submission of any missing element(s) will be the date of submission for purposes of determining compliance with the requirements based on the time of filing the statement, including all certification requirements for statements under 37 CFR 1.97(e). See MPEP § 609.05(a).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 6-16 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Pilkington et al US20200073981A1 in view of Tatiraju et al US20240231754A1 and further in view of Gaudin et al US11494275B1
As per claim 1, Pilkington discloses a computer – implemented method, comprising:
providing the QLA with a rules engine based upon an optimized server log string database for comparison with the plurality of application code generated server log strings:
[0045] “At step 330, the method receives a new event for the log file, for example from one of a plurality of event sources, as described above. At optional step 340, the method determines whether the log level of the new event is above the current overwrite log level”;
wherein the QLA, calculates similarities between the plurality of application code server log strings and scores the application code server log strings based upon their similarities with the optimized server log string database:
[0043] “At step 310, the method identifies existing event entries in the log file having log levels up to and including the threshold log level. For example, step 310 may determine the log level for the existing event entries and identify the existing entries having log levels up to and including the threshold level. In example implementations, step 310 may identify existing event entries having each log level, from the lowest log level up to and including the threshold log level. Optionally, step 310 may also determine the data size of the identified existing entries and other relevant parameters, according to application and/or scheme requirements”;
and invoking a log analyzer suggestion module (LASM) from inside the QLA plugin during the developer application code runtime to identify issues with the application code for the server log:
[0016] “Event generation and logging is commonly used in the field of computing to capture information about the operation of a computing system. For example, event logging techniques may be used to monitor the operation of a computing system, application, service or the like, and to generate events in response to detection of predefined actions or conditions. Generated events are typically stored or “logged” in a log in data storage, for use by a user to analyze the operation and identify and diagnose problems that may arise”.
and using the application code server log scores to determine which application code server log strings can be optimized to reduce use of a server log
memory:
[0019] The present disclosure provides methods, systems and computer program products for improved management of size-limited log files for storing data entries such as event data. Example implementations of the present disclosure maintain the size of the log file within a defined size limit, whilst prioritizing the retention of more significant and/or useful entries. Thus, the data stored in the log file is optimized (e.g., by retaining significant event entries and associated event data)”
[0046]”If step 340 determines that the new event has a log level equal to the current overwrite log level, the method proceeds to step 350 which discards the new event. In particular, in accordance with an overwriting scheme implementing optional step 340, event entries with log levels equal to the current overwrite log level are not retained, and so the new event is not stored in the log file
But not explicitly:
importing, by a processor, a quality log analyzer (QLA) plugin into an integrated developer environment (IDE);
compiling developer application code within the IDE.
wherein during a developer application code runtime, the application code generates a plurality of server log string entries.
and wherein the QLA, analyzes the developer application code to parse portions of the application code that generates server log strings.
analyzes the plurality of server log strings for similarities and calculates the similarity between two or more server log strings to determine if they are identical, similar, or unrelated.
provide suggestions for duplicate application code server log strings to be removed.:
Tatiraju discloses:
analyzes the plurality of server log strings for similarities and calculates the similarity between two or more server log strings to determine if they are identical, similar, or unrelated.
titaruja[0115]” In the case that the sentence-embedding vectors contain only positive real numbers and the real number 0, as a result of the particular approach used to compute them, an angular similarity is computed according to expression 3420. Otherwise, an angular similarity is computed according to expression 3422. The computed angular similarity 3424 is then used to determine whether or not the semantic content of the two log/event messages are similar 3426 or dissimilar 3428 by comparing the computed angular similarity to a threshold value. In alternative implementations, other related similarity metrics can be computed from the two sentence-vectors and compared to corresponding threshold values. “;
provide suggestions for duplicate application code server log strings to be removed.:
[0127] “Clearly, log/event-message aggregation is associated with computational overheads, but these computational overheads can often be outweighed by avoiding much larger computational, networking, and storage overheads involved with processing and storing unnecessarily high volumes of log/event messages. Furthermore, removing redundant, similar log/event messages can greatly increase the efficiency for analyzing log/event messages to detect, diagnose, and ameliorate anomalous operational behaviors within distributed computer systems
.
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to combine the teachings of cited references. One of ordinary skill in the art before the effective filling date of the claimed invention would have been motivated to incorporate the teachings of Tatiraju into teachings of Pilkington to processing and storing log/event messages. The log/event-message subsystem provides query-based access to stored log/event messages. Semantic-similarity-based log/event-message aggregators are incorporated into log/event-message subsystems, receive the log/event messages, identify groups of the received log/event messages that are mutually semantically similar and that are temporally proximate and aggregate the identified groups of the log/event messages to generate an aggregate log message that is output to downstream components of the log/event-message subsystems.[Tatiraju 0073].
But not explicitly:
importing, by a processor, a quality log analyzer (QLA) plugin into an integrated developer environment (IDE);
compiling developer application code within the IDE.
wherein during a developer application code runtime, the application code generates a plurality of server log string entries.
and wherein the QLA, analyzes the developer application code to parse portions of the application code that generates server log strings.
Gaudin discloses:
importing, by a processor, a quality log analyzer (QLA) plugin into an integrated developer environment (IDE):
Col 4 lines “During software application development (e.g., at build time), developers include log messages in program code of a computer program (e.g., source code) to configure program statements to generate alerts if and when the computer program is subsequently executed.”;
Col 10 lines 48 “Providing these log statement models to log entry analyzer 225 at build time permits log entry analyzer 225 to manage updates (e.g., updates 255(1)-(N)) to log search engine 230, log alerting engine 235, and anomaly detection engine 240 using update manager 245.
compiling developer application code within the IDE:
Col 5 lines 12-16 “Buildtime engine 120 monitors, manages, and configures the buildtime phase of the program code (e.g., facilitating the tracking of changes or modifications made to log statements by a developer—at buildtime)”.
wherein during a developer application code runtime, the application code generates a plurality of server log string entries:
Col 3-6” A log statement is a type or form of a program statement that is configured to interact with log data generated by computing devices. Log statements can be used to record valuable runtime information about applications. “;
and wherein the QLA, analyzes the developer application code to parse portions of the application code that generates server log strings.
Col 8 lines 60-67 “Log statement 170(1) includes log format string 175(1) (as shown in FIG. 2A) and log statement 170(1) is part of program code (e.g., source code) associated with computer program 165. The execution of log statement 170(1) (e.g., by computer program 165) generates log string 190(1) (e.g., a log line), and log string 190(1) is associated with trigger pattern 155(1) of alert configuration 150(1).
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to combine the teachings of cited references. One of ordinary skill in the art before the effective filling date of the claimed invention would have been motivated to incorporate the teachings of Gaudin into teachings of Pilkington and Tatiraju to storing and managing data entries in a size-limited log and to optimize the data stored in the log. data entries may be selected in accordance with a described techniques threshold and deleted from the log file instead of being overwritten. Thus, the overall size of the log file is reduced so that it can be stored in the target, smaller storage space without loss of significant data. [Pilkington0055].
As per claim 2, the rejection of claim 1 is incorporated and furthermore Pilkington discloses:
wherein identified issues with the application server log can include: log entry repetitions, needless key value pairs, verbosity, lengthy log, length limits on parameters, printing headers, caching, usage of package names, and validation of logging levels:
[0035] “At step 240, the method 200 stores or “logs” new event entries in the log file by overwriting existing entries having log levels up to and including the threshold log level. In particular, step 240 may select existing event entries having log levels up to and including the threshold log level, for overwriting with new event entries.”;
See also Tatiraju [0127] for duplicate rule.
As per claim 3, the rejection of claim 1 is incorporated and furthermore Pilkington discloses:
wherein the QLA validates each line of the application code server log strings and their contents based on the rule’s engine.
[0035] “At step 240, the method 200 stores or “logs” new event entries in the log file by overwriting existing entries having log levels up to and including the threshold log level. In particular, step 240 may select existing event entries having log levels up to and including the threshold log level, for overwriting with new event entries.”;
As per claim 4, the rejection of claim 1 is incorporated and furthermore Pilkington discloses:
the LASM provides optimization suggestions based upon the rules engine:
[0046]”If step 340 determines that the new event has a log level equal to the current overwrite log level, the method proceeds to step 350 which discards the new event. In particular, in accordance with an overwriting scheme implementing optional step 340, event entries with log levels equal to the current overwrite log level are not retained, and so the new event is not stored in the log file
But not explicitly:
wherein the QLA scans every application code server log strings for issues and post processing
Tatiraju discloses:
wherein the QLA scans every application code server log strings for issues and post processing:
[0068]“the log/event messages generally include both text and numeric values and represent various types of information, including notification of completed actions, errors, anomalous operating behaviors and conditions, and various types of computational events, warnings, and other such information. The log/event messages are transmitted to message collectors, generally running within servers of local data centers, which forward collected log/event messages to message-ingestion-and-processing components that collect and store log/event messages in message databases. Log/event-message query-processing subsystems provide, to administrators and managers of distributed computer systems, query-based access to log/event messages in message databases. The message-ingestion-and-processing components may additionally provide a variety of different types of services, including automated generation of alerts, filtering, and other message-processing services.”
As per claim 6, the rejection of claim 1 is incorporated and furthermore Pilkington discloses:
wherein the QLA scans every application code server log string to highlight noisy attributes:
Col 10 lines 43-50 “Program statements 305(1) and 305(2) are log statements that can be generated by a client device. For example, program statement 305(1) is LOGGER.critical(“There'll be {} green bottles hanging on the wall”, bottleAmount). This program can be modified at buildtime as follows to create program statement 305(2): LOGGER.critical(“{} green bottles hanging on the wall”, bottleAmount), and would cause an alert mismatch”.
As per claim 7, the rejection of claim 6 is incorporated and furthermore Pilkington discloses:
wherein the noisy attributes and their optimization recommendations are identified based upon the rule’s engine.:
col 2 lines 30-35” In other embodiments, the method involves determining that the fixed part or the variable part of the log format string has been modified and creating a map file that indicates a mapping correlation between the trigger pattern of the alert configuration and the log statement.”
As per claim 8, the rejection of claim 7 is incorporated and furthermore Pilkington discloses:
wherein the QLA scans every application code server log strings for violations of the rules engine and prevents an application code final compilation until the violations are corrected:
col 13 lines 25-30 “…to track (all subsequent) changes to fixed part 205(1) (e.g., as 205(1)(a), 205(1)(b), and the like, as shown in FIG. 2A) at build time (in coordination with buildtime engine 120 of log data manager 110). At 625, the process tracks modifications to the fixed part of the log format string that causes alert mismatch. 625, the process tracks modifications to the fixed part of the log format string that causes alert mismatch, and at 630, updates the trigger pattern of the alert configuration associated with the log line (generated by the log statement in question). The process ends at 635 by determining if there is more log data. If there is more log data, the process loops to 605. Otherwise, the process ends”;
Claims 10,11,12, 13, 14, 15, 16 are the system claims corresponding to method claims 1, 2, 3, 4, 6, 7, 8 and rejected under the same rational set forth in connection with the rejection of claims 1, 2, 3, 4, 6, 7, 8 above.
Claim 9 is the system claim corresponding to method claim 1 and rejected under the same rational set forth in connection with the rejection of claim 1above.
As per claim 19 the rejection of claim 10 is incorporated and furthermore Pilkington discloses:
wherein the rules engine includes scoring rules for the plurality of application code server log strings that are based upon the length of characters in certain server log strings; duplicate words in the server log strings; log health check; masking rules; parameters related to the final log entry; HTTP pooling; caching; jdbc statistics; and/or payload requests.
[0043] “At step 310, the method identifies existing event entries in the log file having log levels up to and including the threshold log level. For example, step 310 may determine the log level for the existing event entries and identify the existing entries having log levels up to and including the threshold level. In example implementations, step 310 may identify existing event entries having each log level, from the lowest log level up to and including the threshold log level. Optionally, step 310 may also determine the data size of the identified existing entries and other relevant parameters, according to application and/or scheme requirements.
As per claim 20 the rejection of claim 19 is incorporated and furthermore Pilkington does not explicitly disclose:
wherein the rules engine compares a target value of the server log string scores with an actual value for the server log string scores to determine outliers in the server log strings that can be optimized for better storage and processing.
Tatiraju discloses:
wherein the rules engine compares a target value of the server log string scores with an actual value for the server log string scores to determine outliers in the server log strings that can be optimized for better storage and processing:
[0115] “The computed angular similarity 3424 is then used to determine whether or not the semantic content of the two log/event messages are similar 3426 or dissimilar 3428 by comparing the computed angular similarity to a threshold value. In alternative implementations, other related similarity metrics can be computed from the two sentence-vectors and compared to corresponding threshold values. Thus, two log/event messages are semantically similar when a semantic-similarity metric computed from semantic content extracted from them, such as the angular distance or cosine similarity, has a value that, when compared to a threshold value, indicates that the two words are similar.”
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to combine the teachings of cited references. One of ordinary skill in the art before the effective filling date of the claimed invention would have been motivated to incorporate the teachings of Tatiraju into teachings of Pilkingtonand and Gaudin to processing and storing log/event messages. The log/event-message subsystem provides query-based access to stored log/event messages. Semantic-similarity-based log/event-message aggregators are incorporated into log/event-message subsystems, receive the log/event messages, identify groups of the received log/event messages that are mutually semantically similar and that are temporally proximate and aggregate the identified groups of the log/event messages to generate an aggregate log message that is output to downstream components of the log/event-message subsystems.[Tatiraju 0073].
Claims 5, 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Pilkington et al US20200073981A1 in view of Tatiraju et al US20240231754A1 and further in view of Gaudin et al US11494275B1 and Avagyan et al US9898515B1.
As per claim 5, the rejection of claim 1 is incorporated and furthermore Pilkington does not explicitly disclose:
wherein the QLA uses a variant of the Jaro similarity algorithm to compare two application code server log strings character by character and take into account a number of matching characters and a number of transpositions needed to transform one application code server log string into the other:
wherein distance ranges from 0 for a different application code server log string to 1 indicating an identical application code server log string:
Avagyan discloses:
wherein the QLA uses a variant of the Jaro similarity algorithm to compare two application code server log strings character by character and take into account a number of matching characters and a number of transpositions needed to transform one application code server log string into the other:
Col 9 lines 64-67” the Jaro-Winkler metric combines the similarity of both the characters and position of those characters between two strings. The formulae for the metric are below, followed by definitions of the symbols
wherein distance ranges from 0 for a different application code server log string to 1 indicating an identical application code server log string.
col 10 lines47-55 “In an embodiment, Boolean location match features may be defined for location information such as city and country. The values for city and country as extracted from the raw text by location resolution may be compared to the city and country values associated with a candidate entity. For each piece of location information (e.g. city and country, treated separately), the values resolved from the raw text are compared to the candidate location values. Exact matches receive a value of 1, otherwise 0.
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to combine the teachings of cited references. One of ordinary skill in the art before the effective filling date of the claimed invention would have been motivated to incorporate the teachings of Avagyan into teachings of Pilkington, Gaudin and Tatiraju to measure the similarity of two strings at different grain sizes (e.g., characters vs. words) using one or more methods while processing raw data from multiple and disparate data sources. Furthermore, avoiding limit in analyzing data by removing ambiguity in unstructured and heterogeneous data [Avagyan col 10 lines 20-25].
Claim 17 is the system claim corresponding to method claim 5 and rejected under the same rational set forth in connection with the rejection of claim 5 above.
As per claim 18, the rejection of claim 17 is incorporated and furthermore Pilkington does not explicitly disclose:
wherein the variant of the Jaro similarity algorithm is a Jaro-Winkler distance algorithm that adds a prefix bonus to the Jaro similarity score, giving additional weight to matching characters that appear at the beginning of the application code server logs being compared, such that distance is defined as the inversion of the value (distance = 1 – similarity).
Avagyan discloses:
wherein the variant of the Jaro similarity algorithm is a Jaro-Winkler distance algorithm that adds a prefix bonus to the Jaro similarity score, giving additional weight to matching characters that appear at the beginning of the application code server logs being compared, such that distance is defined as the inversion of the value (distance = 1 – similarity):
Col 9 line 63-67 “(62) The Jaro-Winkler metric combines the similarity of both the characters and position of those characters between two strings. The formulae for the metric are below, followed by definitions of the symbols.
(63) JaroWinkler(s,t)=Jaro(s,t)+P’/10(1-Jaro(s,t))
P′=min(P,4)
P=LongestCommonPrefix(s,t);
Examiner interpretation: see col 10 for equation explanation.
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to combine the teachings of cited references. One of ordinary skill in the art before the effective filling date of the claimed invention would have been motivated to incorporate the teachings of Avagyan into teachings of Pilkington, Gaudin and Tatiraju to measure the similarity of two strings at different grain sizes (e.g., characters vs. words) using one or more methods while processing raw data from multiple and disparate data sources. Furthermore, avoiding limit in analyzing data by removing ambiguity in unstructured and heterogeneous data [Avagyan col 10 lines 20-25].
Pertinent arts:
US20220365957A1:
Specifically, the logs to be parsed are input one by one in a streaming manner, and the input logs are analyzed and compared with the plurality of existing log clusters, and an adaptive similarity threshold for the input logs and the log clusters participating in the comparison is determined by using the quality score in the analysis process, so as to implement the parsing of the input logs.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRAHIM BOURZIK whose telephone number is (571)270-7155. The examiner can normally be reached Monday-Friday (8-4:30).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Wei Y Mui can be reached at 571-270-2738. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRAHIM BOURZIK/ Examiner, Art Unit 2191
/WEI Y MUI/ Supervisory Patent Examiner, Art Unit 2191