DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Objections
Claims 5, 7, 11, 13, 17 and 19 are objected to because of the following informalities: claims 5, 11 and 17 recite “wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on concurrently arriving raw machine data.” Using …and providing… are plural. Therefore, “happens” is recommended to be changed to “happen”. claims 7, 13 and 19 recite “wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on saved raw machine data.” Using …and providing… are plural. Therefore, “happens” is recommended to be changed to “happen”.
Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 14-19 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claims 14-19 recite a volatile computer-readable media. Volatile computer-readable media include signals, which are nonstatutory. To overcome this rejection, "A volatile computer-readable media" may be amended to "A non-transitory computer-readable medium".
Priority
Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 120 as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994).
The disclosure of the prior-filed application, Application No. 15/276,756 (U.S. Patent No. 10,771,479), fails to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application.
Regarding independent claims 2, 8 and 14, the specification of Application No. 15/276,756 only discloses the following:
[0047] In the SPLUNK® ENTERPRISE system, a field extractor may be configured to automatically generate extraction rules for certain field values in the events when the events are being created, indexed, or stored, or possibly at a later time. Alternatively, a user may manually define extraction rules for fields using a variety of techniques. In contrast to a conventional schema for a database system, a late-binding schema is not defined at data ingestion time. Instead, the late-binding schema can be developed on an ongoing basis until the time a query is actually executed. This means that extraction rules for the fields in a query may be provided in the query itself, or may be located during execution of the query. Hence, as a user learns more about the data in the events, the user can continue to refine the late-binding schema by adding new fields, deleting fields, or modifying the field extraction rules for use the next time the schema is used by the system.
[0151] In contrast, the SPLUNK® APP FOR ENTERPRISE SECURITY system stores large volumes of minimally processed security-related data at ingestion time for later retrieval and analysis at search time when a live security threat is being investigated. To facilitate this data retrieval process, the SPLUNK® APP FOR ENTERPRISE SECURITY provides pre-specified schemas for extracting relevant values from the different types of security-related event data and enables a user to define such schemas.
The specification of Application No. 15/276,756 fails to provide adequate support for the following limitations of claims 2, 8 and 14: “using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; providing the one or more structured events to a user; receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule; saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline”. Accordingly, claims 2, 8, 14 and their dependent claims 3-7, 9-13 and 15-19 are not entitled to the benefit of the prior application.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 2-19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Kinsely (US 2015/0039651).
Regarding claims 2, 8 and 14, Kinsely teaches A method comprising:
receiving, at a data intake and query system, raw machine data produced by one or more components of an information technology environment (see [0058]: “FIG. 1 shows a block diagram of an example data intake and query system 100, similar to that found in SPLUNK.RTM. ENTERPRISE. Generally, the system 100 includes one or more forwarders 101 that collect data received or retrieved from a variety of different data sources 105, and one or more indexers 102 that store, process, and/or perform operations with respect to the data. … The data typically includes streams of time-series data. In this context, time-series data refers to any data that can be segmented such that each segment can be associated with a time stamp. The data can be structured, unstructured, or semi-structured, and can come from files and directories.” And see [0052]: "time-series data" and "time-series machine data" may include, among other elements, a series or sequence of data points generated by one or more data sources, computing devices, or sensors. And see [0083]: “FIG. 10 is a block diagram that illustrates a subsystem 1000 comprising components configured to execute search requests, or portions thereof, that reference fields defined using extraction rules, according to an embodiment. Subsystem 1000 may be, for instance, a set of components within data intake and query system 100… Subsystem 1000 comprises a data server 1010”);
automatically generating one or more extraction rules for extracting event attributes from the raw machine data (see [0048]: “an event is a data item that typically contains a portion of raw data (or a transformed version of such). To run certain types of queries against these and other data items, a schema can be developed. A schema includes field definition data that defines a set of named fields, or properties, for which each data item in a repository may have a value. …A late-binding schema, by contrast, is not necessarily pre-defined when data items are stored. Rather, the field definition data in a late-binding schema includes extraction rules for deriving values for the fields from a rawer format that is not necessarily optimized for access using the semantics of the schema.” And see [0133] and Fig. 13: “Block 1330 comprises generating field definition data defining a field that has a particular field name from the set of field names in the identified template. The field definition data comprises a field extraction rule for deriving values for the field from the data items.” And see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template.”);
using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events (see [0040]: “For example, suppose that the ordering data within a template associated a field named "color" with a third index position. Further suppose that a "comma" delimiter had been specified for the template. In the data item "12-10-2009,10.0.0.1,red,25,2.99", the value of "red" would be said to belong to the field named "color." According to the techniques described herein, an extraction rule would be generated based on the template and the delimiter, by which the third chunk in each of a plurality of data items would likewise be extracted as the value for the "color" field with respect to those data items.” And see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. The user interface allows a user to select a template, select and/or modify a delimiter to associate with the template, and generate field extraction rules based on the selections.”);
providing the one or more structured events to a user (see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template. In another embodiment, upon selecting a template, a user is provided with a control to request creation of field definition data for some or all of the field names. The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” The Examiner interprets allowing a user to preview the effects of the extraction rules that will be generated on sample data taught by [0134] as providing the one or more structured events to a user. And see [0171] and Fig. 4A: “The field preview area 420 includes sample data for row 220A. In the example illustrated, the sample data item may have been derived, for example, from a time-stamped event reading as follows: "115.234.212.124,R1,[24/MAY/2012:07:56:13],200". This sample data item 422 has been broken into its constituent elements, or "chunks." These chunks, represented within the interface using chunk indicators 422, are "115.234.212.124," "R1," "[24/MAY/2012:07:56:13]," and "200".”);
receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule (see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template. In another embodiment, upon selecting a template, a user is provided with a control to request creation of field definition data for some or all of the field names. The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” And see [0176] and FIG. 4A: “field name indicators, such as field name indicator 430, may be moved from one field definition input control 424 to another field definition input control 424, thus associating the corresponding field name with a new index position. In this manner, a user may modify the ordering data of a template, effectively redefining the fields that will be generated from the template.” The Examiner interprets allowing a user to manipulate field names and/or ordering data before requesting creation of extraction rule(s) taught by [0134] as receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule.);
saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline (see [0133] and Fig. 13: “Block 1330 comprises generating field definition data defining a field that has a particular field name from the set of field names in the identified template. The field definition data comprises a field extraction rule for deriving values for the field from the data items.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s). Optionally, any modifications made through the interface may be saved for use in future templates. In an embodiment, once generated, the field definition data for the particular field name, and any other field names that may have been associated with index positions, is then saved in a repository such as knowledge base 1190.” Also see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. The user interface allows a user to select a template, select and/or modify a delimiter to associate with the template, and generate field extraction rules based on the selections. In various embodiments, the user interface may further include controls for modifying some or all of the ordering data from a template, add additional field names, define transformations or other post-processing instructions, preview application of the field extraction rules on one or more example data items, and/or save new templates. The field extraction rules generated via the user interface may be saved for future use in executing search queries on the data items.”);
using the data processing pipeline to process raw machine data (see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. … The field extraction rules generated via the user interface may be saved for future use in executing search queries on the data items.”).
Regarding claims 3, 9 and 15, Kinsely further teaches wherein providing the one or more structured events to a user includes displaying the results via a graphical user interface (see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” And see [0171] and Fig. 4A: “The field preview area 420 includes sample data for row 220A. In the example illustrated, the sample data item may have been derived, for example, from a time-stamped event reading as follows: "115.234.212.124,R1,[24/MAY/2012:07:56:13],200". This sample data item 422 has been broken into its constituent elements, or "chunks." These chunks, represented within the interface using chunk indicators 422, are "115.234.212.124," "R1," "[24/MAY/2012:07:56:13]," and "200".”).
Regarding claims 4, 10 and 16, Kinsely further teaches wherein the raw machine data produced by one or more components of an information technology environment includes one of system logs, network packet data, sensor data, application program data, error logs, stack traces, and system performance data (see [0047]: “For example, at a high level, SPLUNK.RTM. ENTERPRISE can take raw data, unstructured data, or machine data such as data in Web logs, syslogs, sensor readings, etc., divide the data up into portions, and optionally transform at least part of the data in these portions to produce time-stamped events.” And see [0056]: “In some embodiments, data generated by various data sources may be collected and segmented into discrete events, each event corresponding to data from a particular point in time. Examples of such data sources include, but are not limited to, web servers, application servers, databases, firewalls, routers, operating systems, software applications executable at one or more computing devices within the enterprise data system, mobile devices, sensors, etc. The types of data generated by such data sources may be in various forms including, for example and without limitation, server log files, activity log files, configuration files, messages, network packet data, performance measurements or metrics, sensor measurements, etc.”).
Regarding claims 5, 11 and 17, Kinsely further teaches wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on concurrently arriving raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data”).
Regarding claims 6, 12 and 18, Kinsely further teaches saving a portion of the raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.”).
Regarding claims 7, 13 and 19, Kinsely further teaches wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on saved raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data”).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHIMEI ZHU whose telephone number is (571)270-7990. The examiner can normally be reached 10am-6pm Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ZHIMEI ZHU/Examiner, Art Unit 2495