Prosecution Insights
Last updated: October 02, 2026
Application No. 19/076,410

EXECUTING MODULAR ALERTS AND ASSOCIATED SECURITY ACTIONS

Non-Final OA §101§102
Filed
Mar 11, 2025
Priority
Sep 26, 2016 — continuation of 10/771,479 +2 more
Examiner
ZHU, ZHIMEI
Art Unit
Tech Center
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
230 granted / 296 resolved
+17.7% vs TC avg
Strong +37% interview lift
Without
With
+37.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
9 currently pending
Career history
306
Total Applications
across all art units

Statute-Specific Performance

§101
10.3%
-29.7% vs TC avg
§103
49.5%
+9.5% vs TC avg
§102
10.4%
-29.6% vs TC avg
§112
18.9%
-21.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 296 resolved cases

Office Action

§101 §102
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claims 5, 7, 11, 13, 17 and 19 are objected to because of the following informalities: claims 5, 11 and 17 recite “wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on concurrently arriving raw machine data.” Using …and providing… are plural. Therefore, “happens” is recommended to be changed to “happen”. claims 7, 13 and 19 recite “wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on saved raw machine data.” Using …and providing… are plural. Therefore, “happens” is recommended to be changed to “happen”. Appropriate correction is required. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 14-19 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claims 14-19 recite a volatile computer-readable media. Volatile computer-readable media include signals, which are nonstatutory. To overcome this rejection, "A volatile computer-readable media" may be amended to "A non-transitory computer-readable medium". Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 120 as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994). The disclosure of the prior-filed application, Application No. 15/276,756 (U.S. Patent No. 10,771,479), fails to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. Regarding independent claims 2, 8 and 14, the specification of Application No. 15/276,756 only discloses the following: [0047] In the SPLUNK® ENTERPRISE system, a field extractor may be configured to automatically generate extraction rules for certain field values in the events when the events are being created, indexed, or stored, or possibly at a later time. Alternatively, a user may manually define extraction rules for fields using a variety of techniques. In contrast to a conventional schema for a database system, a late-binding schema is not defined at data ingestion time. Instead, the late-binding schema can be developed on an ongoing basis until the time a query is actually executed. This means that extraction rules for the fields in a query may be provided in the query itself, or may be located during execution of the query. Hence, as a user learns more about the data in the events, the user can continue to refine the late-binding schema by adding new fields, deleting fields, or modifying the field extraction rules for use the next time the schema is used by the system. [0151] In contrast, the SPLUNK® APP FOR ENTERPRISE SECURITY system stores large volumes of minimally processed security-related data at ingestion time for later retrieval and analysis at search time when a live security threat is being investigated. To facilitate this data retrieval process, the SPLUNK® APP FOR ENTERPRISE SECURITY provides pre-specified schemas for extracting relevant values from the different types of security-related event data and enables a user to define such schemas. The specification of Application No. 15/276,756 fails to provide adequate support for the following limitations of claims 2, 8 and 14: “using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events; providing the one or more structured events to a user; receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule; saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline”. Accordingly, claims 2, 8, 14 and their dependent claims 3-7, 9-13 and 15-19 are not entitled to the benefit of the prior application. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 2-19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Kinsely (US 2015/0039651). Regarding claims 2, 8 and 14, Kinsely teaches A method comprising: receiving, at a data intake and query system, raw machine data produced by one or more components of an information technology environment (see [0058]: “FIG. 1 shows a block diagram of an example data intake and query system 100, similar to that found in SPLUNK.RTM. ENTERPRISE. Generally, the system 100 includes one or more forwarders 101 that collect data received or retrieved from a variety of different data sources 105, and one or more indexers 102 that store, process, and/or perform operations with respect to the data. … The data typically includes streams of time-series data. In this context, time-series data refers to any data that can be segmented such that each segment can be associated with a time stamp. The data can be structured, unstructured, or semi-structured, and can come from files and directories.” And see [0052]: "time-series data" and "time-series machine data" may include, among other elements, a series or sequence of data points generated by one or more data sources, computing devices, or sensors. And see [0083]: “FIG. 10 is a block diagram that illustrates a subsystem 1000 comprising components configured to execute search requests, or portions thereof, that reference fields defined using extraction rules, according to an embodiment. Subsystem 1000 may be, for instance, a set of components within data intake and query system 100… Subsystem 1000 comprises a data server 1010”); automatically generating one or more extraction rules for extracting event attributes from the raw machine data (see [0048]: “an event is a data item that typically contains a portion of raw data (or a transformed version of such). To run certain types of queries against these and other data items, a schema can be developed. A schema includes field definition data that defines a set of named fields, or properties, for which each data item in a repository may have a value. …A late-binding schema, by contrast, is not necessarily pre-defined when data items are stored. Rather, the field definition data in a late-binding schema includes extraction rules for deriving values for the fields from a rawer format that is not necessarily optimized for access using the semantics of the schema.” And see [0133] and Fig. 13: “Block 1330 comprises generating field definition data defining a field that has a particular field name from the set of field names in the identified template. The field definition data comprises a field extraction rule for deriving values for the field from the data items.” And see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template.”); using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events (see [0040]: “For example, suppose that the ordering data within a template associated a field named "color" with a third index position. Further suppose that a "comma" delimiter had been specified for the template. In the data item "12-10-2009,10.0.0.1,red,25,2.99", the value of "red" would be said to belong to the field named "color." According to the techniques described herein, an extraction rule would be generated based on the template and the delimiter, by which the third chunk in each of a plurality of data items would likewise be extracted as the value for the "color" field with respect to those data items.” And see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. The user interface allows a user to select a template, select and/or modify a delimiter to associate with the template, and generate field extraction rules based on the selections.”); providing the one or more structured events to a user (see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template. In another embodiment, upon selecting a template, a user is provided with a control to request creation of field definition data for some or all of the field names. The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” The Examiner interprets allowing a user to preview the effects of the extraction rules that will be generated on sample data taught by [0134] as providing the one or more structured events to a user. And see [0171] and Fig. 4A: “The field preview area 420 includes sample data for row 220A. In the example illustrated, the sample data item may have been derived, for example, from a time-stamped event reading as follows: "115.234.212.124,R1,[24/MAY/2012:07:56:13],200". This sample data item 422 has been broken into its constituent elements, or "chunks." These chunks, represented within the interface using chunk indicators 422, are "115.234.212.124," "R1," "[24/MAY/2012:07:56:13]," and "200".”); receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule (see [0134] and Fig. 13: “block 1330 is performed responsive to input, in a user interface, that identifies the template and the delimiter. For instance, upon selecting a template and a delimiter, the field definition data may automatically be created, along with field definition data for any other field names that are associated with index positions within the template. In another embodiment, upon selecting a template, a user is provided with a control to request creation of field definition data for some or all of the field names. The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” And see [0176] and FIG. 4A: “field name indicators, such as field name indicator 430, may be moved from one field definition input control 424 to another field definition input control 424, thus associating the corresponding field name with a new index position. In this manner, a user may modify the ordering data of a template, effectively redefining the fields that will be generated from the template.” The Examiner interprets allowing a user to manipulate field names and/or ordering data before requesting creation of extraction rule(s) taught by [0134] as receiving an input from the user modifying one or more of the automatically generated extraction rules to generate a refined extraction rule.); saving one or more extraction rules including the refined extraction rule as part of a data processing pipeline (see [0133] and Fig. 13: “Block 1330 comprises generating field definition data defining a field that has a particular field name from the set of field names in the identified template. The field definition data comprises a field extraction rule for deriving values for the field from the data items.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s). Optionally, any modifications made through the interface may be saved for use in future templates. In an embodiment, once generated, the field definition data for the particular field name, and any other field names that may have been associated with index positions, is then saved in a repository such as knowledge base 1190.” Also see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. The user interface allows a user to select a template, select and/or modify a delimiter to associate with the template, and generate field extraction rules based on the selections. In various embodiments, the user interface may further include controls for modifying some or all of the ordering data from a template, add additional field names, define transformations or other post-processing instructions, preview application of the field extraction rules on one or more example data items, and/or save new templates. The field extraction rules generated via the user interface may be saved for future use in executing search queries on the data items.”); using the data processing pipeline to process raw machine data (see [0042]: “a user interface is provided to assist in defining the field extraction rules through the field extraction templates. … The field extraction rules generated via the user interface may be saved for future use in executing search queries on the data items.”). Regarding claims 3, 9 and 15, Kinsely further teaches wherein providing the one or more structured events to a user includes displaying the results via a graphical user interface (see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data, manipulate field names and/or ordering data, define post-processing instructions, and/or make other various modifications before requesting creation of extraction rule(s).” And see [0171] and Fig. 4A: “The field preview area 420 includes sample data for row 220A. In the example illustrated, the sample data item may have been derived, for example, from a time-stamped event reading as follows: "115.234.212.124,R1,[24/MAY/2012:07:56:13],200". This sample data item 422 has been broken into its constituent elements, or "chunks." These chunks, represented within the interface using chunk indicators 422, are "115.234.212.124," "R1," "[24/MAY/2012:07:56:13]," and "200".”). Regarding claims 4, 10 and 16, Kinsely further teaches wherein the raw machine data produced by one or more components of an information technology environment includes one of system logs, network packet data, sensor data, application program data, error logs, stack traces, and system performance data (see [0047]: “For example, at a high level, SPLUNK.RTM. ENTERPRISE can take raw data, unstructured data, or machine data such as data in Web logs, syslogs, sensor readings, etc., divide the data up into portions, and optionally transform at least part of the data in these portions to produce time-stamped events.” And see [0056]: “In some embodiments, data generated by various data sources may be collected and segmented into discrete events, each event corresponding to data from a particular point in time. Examples of such data sources include, but are not limited to, web servers, application servers, databases, firewalls, routers, operating systems, software applications executable at one or more computing devices within the enterprise data system, mobile devices, sensors, etc. The types of data generated by such data sources may be in various forms including, for example and without limitation, server log files, activity log files, configuration files, messages, network packet data, performance measurements or metrics, sensor measurements, etc.”). Regarding claims 5, 11 and 17, Kinsely further teaches wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on concurrently arriving raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data”). Regarding claims 6, 12 and 18, Kinsely further teaches saving a portion of the raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.”). Regarding claims 7, 13 and 19, Kinsely further teaches wherein using the one or more automatically generated extraction rules to transform the raw machine data into one or more structured events and providing the one or more structured events to a user happens on saved raw machine data (see [0054]: “In an example, a field extractor within an enterprise network environment may be configured to automatically identify (e.g., using regular expression-based rules, delimiter-based rules, etc.) certain fields in the events while the events are being created, indexed, and/or stored.” And see [0134] and Fig. 13: “The user interface may optionally allow a user to preview the effects of the extraction rules that will be generated on sample data”). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHIMEI ZHU whose telephone number is (571)270-7990. The examiner can normally be reached 10am-6pm Monday-Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ZHIMEI ZHU/Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Mar 11, 2025
Application Filed
Aug 25, 2026
Non-Final Rejection mailed — §101, §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726825
AUTOMATED SUSPECT DEVICE FILTERING ON EQUIPMENT IDENTITY REGISTERS
2y 5m to grant Granted Sep 01, 2026
Patent 12726821
SECURE RANGING SYSTEM
2y 3m to grant Granted Sep 01, 2026
Patent 12693994
METHOD FOR REDUCING FALSE-POSITIVES FOR IDENTIFICATION OF DIGITAL CONTENT
2y 10m to grant Granted Jul 28, 2026
Patent 12677150
STATEFUL MULTI-PRIVILEGED SD-WAN CONTROL CONNECTIONS
2y 8m to grant Granted Jul 07, 2026
Patent 12671674
DYNAMIC BYPASS
1y 10m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+37.1%)
2y 8m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 296 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month