Prosecution Insights
Last updated: October 02, 2026
Application No. 19/084,981

OBSERVATION STREAM ENGINE IN A SECURITY MANAGEMENT SYSTEM

Final Rejection §103
Filed
Mar 20, 2025
Priority
Apr 29, 2022 — continuation of 12/271,385
Examiner
ELLIS, MATTHEW J
Art Unit
2153
Tech Center
2100 — Computer Architecture & Software
Assignee
Microsoft Technology Licensing, LLC
OA Round
2 (Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
1y 10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
230 granted / 331 resolved
+14.5% vs TC avg
Strong +30% interview lift
Without
With
+30.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
12 currently pending
Career history
350
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
59.4%
+19.4% vs TC avg
§102
13.8%
-26.2% vs TC avg
§112
6.0%
-34.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 331 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA and is in response to communications filed on 6/11/2026 in which claims 1-20 are presented for examination. Priority Acknowledgment is made of parent Application No. 17/733155, filed on 4/29/2022. Drawings Drawings have been acknowledged and are acceptable for examination purposes. Specification Specification has been acknowledged and is acceptable for examination purposes. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. U.S. 20190109868 (hereinafter referred to as “Muddu”) in view of Muddu. As per claim 1, Muddu teaches: A computerized system comprising: one or more computer processors; and computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations comprising: …, wherein the query-authoring interface comprises interface portions for inputting the parameters of the observation stream query to query (Muddu, [0323] – Query) a plurality of security data sources and perform dynamic tracking of a security incident (Muddu, [0702], [0638]), and wherein the observation stream query is executable (Muddu, [0174] – The SQL store 378 that stores information accessible by scripted query language (SQL), a time series database. See also [0203]. [0248] – Late binding schema) and comprises the parameters that collectively define data retrieval operations across a plurality of security data sources (Muddu, [0195] – Various data connectors 802 can be employed by the security platform (e.g., at the data intake stage) to support various data sources. Embodiments of the data connectors 802 can provide support for accessing/receiving indexed data, unindexed data (e.g., data directly from a machine at which an event occurs), data from a third-party provider (e.g., threat feeds such as Norse™, or messages from AWS™ CloudTrail™), or data from a distributed file system (e.g., HDFS™)– The data generated by such data sources can include, for example, server log files, activity log files, configuration files, ..., etc. See also [0143] – The security platform …, from multiple data sources. [0167] – Configurable properties… (i) parse events, (ii) correlate between users and IP address, and/or (iii) correlate between one attribute with another attribute in the event data or an external attribute); communicating the observation stream query to an observation stream engine to cause generation of observation stream data (Muddu, [0149]), the observation stream data provides an observation stream timeline (Muddu, [0453]) associated with dynamic tracking of the security incident based on the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data (Muddu, [0671] fig. 57, 58); receiving the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data (Muddu, [0671] fig. 57, 58); and causing display, via a view interface, of the observation stream data (Muddu, Fig. 2). Muddu does explicitly teach receiving, via a query-authoring interface, parameters of an observation stream query, wherein the query-authoring interface comprises interface portions for inputting the parameters. receiving, via a query-authoring interface (Muddu, [0206] – The security platform can prompt (e.g., through a user interface) the administrator to specify the data format), parameters of an observation stream query (Muddu, [0646] [0654] – Parameters) It would have been obvious to a person having ordinary skill in the art at the time the invention was made to have modified Muddu by the teaching of Muddu to include receiving, via a query-authoring interface parameters of an observation stream query wherein the query-authoring interface comprises interface portions for inputting the parameters with the motivation to provide better monitoring as taught by Muddu ([0006]). As per claim 2, Muddu as modified teaches: The system of claim 1, the operations further comprising: accessing, at the observation stream engine, the observation stream query, wherein the observation stream query is a user-generated observation stream query; causing execution of the observation stream query against the plurality of data security sources based on the parameters (parameters. [0646] [0654][0657] fig.73); generating the observation stream data associated with the observation stream query (generating the observation stream data associated with the observation stream query,[0646] [0654][0657] fig.73), the observation stream data comprising security incidents ([0702][0638]) with corresponding timestamps and user-defined interpretation data ([0671] fig. 57, 58), wherein the user-defined interpretation data is generated based on a parameter from the observation stream query, wherein generating the user-defined interpretation data comprises extracting a portion of raw observation stream data associated with monitoring the security incident across a plurality of computing resources ([0646] [0654][0657] fig.73); and communicating the observation stream data to cause display of the observation stream data on an observation stream interface comprising graphical interface elements associated with the observation stream data (fig. 2 and ([0671] fig. 57, 58). As per claim 3, Muddu as modified teaches: The system of claim 2, wherein causing execution of the observation stream query comprises: causing execution of a first query portion that is a real-time query to receive a first set of event data; causing execution of a second query portion that is a query-on-timer query to receive a second set of event data ([0147]); generating the raw observation stream data based on the first set of event data and the second set of event data ([0147]). As per claim 4, Muddu as modified teaches: The system of claim 2, wherein generating observation stream data associated with the observation stream query further comprises one of: based on the parameters of the observation stream query, classifying an event in the observation stream data with a classification type, wherein the classification type is associated with interface highlighting element ([0477]); tagging the event with the interface highlight element to cause presentation of the event based on the interface highlight element ([0477]); and identifying a presentation setting parameter associated with the user-defined interpretation data and mapping the presentation setting parameter with the user-defined parameter to cause presentation of the user-defined interpretation data based on the presentation setting parameter ([0517] and [0477]). As per claim 5, Muddu as modified teaches: The system of claim 1, wherein the observation stream query is associated with an observation stream query-type of a plurality of observation stream query-types, wherein observation stream query-types are selectable predefined security sensors comprising parameters for retrieving raw observation stream data and generating user-defined interpretation data ([0638[0517] [0477]). As per claim 6, Muddu as modified teaches: The system of claim 1, wherein the plurality of security data sources include a first data source that is configured for real-time queries and a second data source that is configured for query-on-timer queries, the first data source is associated with a first schema for storing event data and the second data source is associated with a second schema for storing event data ([0638[0517] [0477]); and wherein the observation stream query comprises a first query portion having a real-time query for the first data source and a second query portion having a query-on-time query for the second data source ([0638[0517] [0477]). As per claim 7, Muddu as modified teaches: The system of claim 1, wherein the view interface comprises interface portions for presenting timestamps, an observation type corresponding to an observation stream query-type and details comprising the user-defined interpretation data ([0638[0517] [0477]). As to claims 8-20, the limitations of these claims have been noted in the rejection above. They are therefore rejected as set forth above. Response to Arguments Based on the Terminal Disclaimer filed by Applicant on 6/11/2026, the double patenting rejection is withdrawn. Applicant’s arguments, see Remarks, filed 6/11/2026, with respect to the 103 rejection have been fully considered but they aren’t persuasive. Further search and consideration of Muddu shows that the amendments made to the claims are also taught in paragraphs [0174] – The SQL store 378 that stores information accessible by scripted query language (SQL), a time series database. See also [0203]. [0248] – Late binding schema. See also, [0195] – Various data connectors 802 can be employed by the security platform (e.g., at the data intake stage) to support various data sources. Embodiments of the data connectors 802 can provide support for accessing/receiving indexed data, unindexed data (e.g., data directly from a machine at which an event occurs), data from a third-party provider (e.g., threat feeds such as Norse™, or messages from AWS™ CloudTrail™), or data from a distributed file system (e.g., HDFS™)– The data generated by such data sources can include, for example, server log files, activity log files, configuration files, ..., etc. See also [0143] – The security platform …, from multiple data sources. [0167] – Configurable properties… (i) parse events, (ii) correlate between users and IP address, and/or (iii) correlate between one attribute with another attribute in the event data or an external attribute. To specifically address Applicant’s point about the application having an authored interface, the GUI in [0440]-[0442] is interpreted as more precisely teaching this type of interface because it allows users to filter out data which is an authored query by a user. To specifically address Applicant’s point about the claims being directed to dynamic display of security threats and stream data, Muddu teaches in [0322] – The event processing engine in the real-time path operates in a real-time mode to process unbounded, streaming data that enters the security platform. In conclusion, the prior art of record teaches the claimed limitations. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Al-Fuqaha et al. 2015, “Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications” Makaremi et al. US 20190236210 A1 teaches a query building component may elicit search criteria via the user interface using a natural language interface, construct a proper query therefrom (Abstract). Rathod et al. US 20110276396 A1 teaches dynamically monitoring, tracking, storing, processing & presenting physical or digital activities, actions, locations, behavior & status with dynamically attached active links (Abstract). Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to the current examiner working on this case, name: Matthew Ellis, telephone number: (571)270-3443, email: matthew.ellis@uspto.gov, normal business hours Monday-Friday 8AM-5PM EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kavita Stanley can be reached on (571) 272-8352. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. September 16, 2026 /MATTHEW J ELLIS/Primary Examiner, Art Unit 2153
Read full office action

Prosecution Timeline

Mar 20, 2025
Application Filed
Dec 27, 2025
Non-Final Rejection (signed) — §103
Feb 12, 2026
Non-Final Rejection mailed — §103
May 05, 2026
Interview Requested
May 11, 2026
Applicant Interview (Telephonic)
May 11, 2026
Examiner Interview Summary
Jun 11, 2026
Response Filed
Sep 18, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737392
Generating Machine Learning Model Prompts for Analyzing Collections of Unstructured Data
1y 3m to grant Granted Sep 15, 2026
Patent 12694070
VERIFICATION METHOD AND SYSTEM IN ARTIFICIAL NEURAL NETWORK ARRAY
3y 7m to grant Granted Jul 28, 2026
Patent 12694058
INTERACTIVE REAL-TIME VIDEO SEARCH BASED ON KNOWLEDGE GRAPH
2y 8m to grant Granted Jul 28, 2026
Patent 12681933
SYSTEMS AND METHODS FOR DYNAMIC QUERY OPTIMIZATION
2y 8m to grant Granted Jul 14, 2026
Patent 12675470
Techniques for generating natural language context in an issue tracking system
2y 1m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+30.3%)
3y 5m (~1y 10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 331 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month