Prosecution Insights
Last updated: August 17, 2026
Application No. 19/215,038

NOTIFICATION SERVICE IMPLEMENTATION

Non-Final OA §101§102§103§112
Filed
May 21, 2025
Priority
Jun 10, 2020 — continuation of 12/355,608
Examiner
TALIOUA, ABDELBASST
Art Unit
Tech Center
Assignee
Microsoft Technology Licensing, LLC
OA Round
1 (Non-Final)
59%
Grant Probability
Moderate
1-2
OA Rounds
1y 9m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
67 granted / 113 resolved
-0.7% vs TC avg
Strong +35% interview lift
Without
With
+35.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
25 currently pending
Career history
149
Total Applications
across all art units

Statute-Specific Performance

§101
3.3%
-36.7% vs TC avg
§103
72.5%
+32.5% vs TC avg
§102
10.6%
-29.4% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 113 resolved cases

Office Action

§101 §102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is responsive to application filed on May 21st, 2025, which is a CON of 16/898,107, filed on June 10th, 2020 (now Patent No. 12,355,608). In this office action: Claims 1-20 are pending. Claims 1-20 are rejected. Drawings The drawings submitted on May 21st, 2025 have been considered and accepted. Claim Objections Claim 7 is objected to because of the following informality: “The apparatus according to claim 6” should read (Examiner’s suggestion) “The apparatus according to claim 6,” Appropriate correction(s) is/are required. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using webscreens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-20 are rejected on the ground of the nonstatutory double patenting as being unpatentable over claims 1-2, 4, 6-14, 16 of Patent No. US 12,355,608. Although the claims at issue are not identical, they are not patentably distinct from each other as illustrated in the table below. The subject matter claimed in the instant application is fully disclosed in the referenced patent since the referenced patent and the instant application are claiming common subject matter, as shown in Table below. Regarding Claim 1 This application 19/215,038 Patent US 12,355,608 1. An apparatus comprising: a processor; and a computer readable medium on which is stored machine readable instructions that cause the processor to: detect, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity; generate, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident; and determine, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster. Claim 6. An apparatus comprising: a processor; and a computer readable medium on which is stored machine readable instructions that cause the processor to: detect, by a notification service of a plurality of notification services that are each geographically located at different geographic locations, based on an analysis of signals received at an activity event hub of an internal incident management service of an entity, at least one incident associated with activities of the entity, wherein each of the plurality of notification services are located in different geographically distributed clusters in a cloud to notify the entity of the at least one detected incident; ... generate, by the notification service, based on the received information related to the at least one detected incident, a notification object to notify the entity of the at least one detected incident; determine, by the notification service, based on a unique identifier related to the at least one detected incident, by utilizing a database that is commonly used for storage by the plurality of notification services, whether the notification object to notify the entity of the at least one detected incident is a unique notification object, which is not a duplicate notification object generated by another notification service of the plurality of notification services; ... Regarding Claim 2 This application 19/215,038 Patent US 12,355,608 2. wherein the instructions to detect the incident associated with activities of the monitored entity further cause the processor to: detect the incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the monitored entity Claim 7. wherein the instructions to detect by the notification service of the plurality of notification services, based on the analysis of signals received at the activity event hub of the internal incident management service of the entity, the at least one incident associated with the activities of the entity further cause the processor to: detect, with respect to the notification service of the plurality of notification services, based on the analysis of signals received at the activity event hub of the internal incident management service of the entity, the at least one incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the entity. Regarding Claim 3 This application 19/215,038 Patent US 12,355,608 3. wherein the instructions further cause the processor to determine, based on the analysis of the incident, whether the incident is actionable Claim 8. wherein the instructions further cause the processor to: determine, based on an analysis of the at least one detected incident, whether the at least one detected incident is actionable by analyzing an event type associated with the at least one detected incident. Regarding Claim 4 This application 19/215,038 Patent US 12,355,608 4. wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze a plurality of previously detected incidents that includes at least one previously detected incident that is actionable and at least one previously detected incident that is non-actionable Claim 8. wherein the instructions further cause the processor to: determine, based on an analysis of the at least one detected incident, whether the at least one detected incident is actionable by analyzing an event type associated with the at least one detected incident. Regarding Claim 5 This application 19/215,038 Patent US 12,355,608 5. wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze an event type associated with the incident Claim 8. wherein the instructions further cause the processor to: determine, based on an analysis of the at least one detected incident, whether the at least one detected incident is actionable by analyzing an event type associated with the at least one detected incident. Regarding Claim 6 This application 19/215,038 Patent US 12,355,608 6. wherein the instructions further cause the processor to request, from an incident management service for the monitored entity, information related to the incident Claim 9. wherein the instructions further cause the processor to: request, from a data endpoint, the information related to the at least one detected incident that includes an indication of whether an action is to be performed with respect to the at least one detected incident. Regarding Claim 7 This application 19/215,038 Patent US 12,355,608 7. wherein the information includes an indication of whether an action is to be performed with respect to the incident Claim 9. wherein the instructions further cause the processor to: request, from a data endpoint, the information related to the at least one detected incident that includes an indication of whether an action is to be performed with respect to the at least one detected incident. Regarding Claim 8 This application 19/215,038 Patent US 12,355,608 8. wherein the instructions to generate the notification object for the incident further cause the processor to: generate, based on received information related to the incident, the notification object that specifies details of the incident and an indication of a communication technique that is to be utilized to communicate the incident to the monitored entity Claim 10. wherein the instructions to generate, based on the received information related to the at least one detected incident, the notification object to notify the entity of the at least one detected incident further cause the processor to: generate, based on the received information related to the at least one detected incident, the notification object that specifies details of the at least one detected incident and an indication of a communication technique that is to be utilized to communicate the at least one detected incident to the entity. Regarding Claim 9 This application 19/215,038 Patent US 12,355,608 9. wherein the instructions further cause the processor to perform the communication technique to communicate the incident to the monitored entity Claim 11. ... cause the processor to: ... perform the communication technique to communicate the at least one detected incident to the entity Regarding Claim 10 This application 19/215,038 Patent US 12,355,608 10. wherein the instructions further cause the processor to store information related to the incident in a not only structured query language ('NoSQL') database Claim 12. wherein the instructions to store, with respect to the notification service, by utilizing the database that is commonly used for storage by the plurality of notification services, the unique identifier related to the at least one detected incident further cause the processor to: store, with respect to the notification service, by utilizing a geo-distributed NoSQL database Regarding Claim 11 This application 19/215,038 Patent US 12,355,608 11. wherein the NoSQL database is a geo- distributed NoSQL database. Claim 14. ... the database that includes a geo-distributed not only structured query language (NoSQL) database ... Regarding Claim 12 This application 19/215,038 Patent US 12,355,608 12. wherein the instructions to detect the incident associated with the activities of the monitored entity further cause the processor to: detect, with respect to a notification service of a plurality of notification services that are each geographically located at different geographic locations, the incident Claim 13. wherein the instructions to detect by the notification service of the plurality of notification services that are each geographically located at different geographic locations, based on the analysis of signals received at the activity event hub of the internal incident management service of the entity, the at least one incident associated with the activities of the entity further cause the processor to: detect, with respect to the notification service of the plurality of notification services that include at least three notification services, based on the analysis of signals received at the activity event hub of the internal incident management service of the entity, the at least one incident associated with the activities of the entity Regarding Claim 13 This application 19/215,038 Patent US 12,355,608 13. A computer-implemented method comprising: detecting, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity; generating, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident; and determining, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster. Claim 1. A computer-implemented method comprising: detecting, by at least one processor of a notification service of a plurality of notification services that are each geographically located at different geographic locations, based on an analysis of signals received at an activity event hub associated with the notification service, at least one incident associated with activities of an entity, wherein each of the plurality of notification services are located in different geographically distributed clusters in a cloud to notify the entity of the at least one detected incident; ... generating, by the at least one processor of the notification service of the plurality of notification services, based on the received information related to the at least one detected incident, a notification object to notify the entity of the at least one detected incident, the notification object being correlated with a unique identifier related to the at least one detected incident; determining, by the at least one processor of the notification service of the plurality of notification services, based on the unique identifier related to the at least one detected incident, that the notification object to notify the entity of the at least one detected incident is a unique notification object, which is not a duplicate notification object generated by another notification service of the plurality of notification services; ... Regarding Claim 14 This application 19/215,038 Patent US 12,355,608 14. wherein detecting the incident associated with activities of the monitored entity further comprises: detecting the incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the entity. Claim 2. ... detecting, by the at least one processor of the notification service of the plurality of notification services, with respect to the notification service of the plurality of notification services that are each geographically located at different geographic locations, based on the analysis of signals received at the activity event hub associated with the notification service, the at least one incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the entity. Regarding Claim 15 This application 19/215,038 Patent US 12,355,608 15. wherein detecting the incident associated with activities of the monitored entity further comprises determining, based on the analysis of the incident, whether the incident is actionable. Claim 8. ... determine, based on an analysis of the at least one detected incident, whether the at least one detected incident is actionable by analyzing an event type associated with the at least one detected incident. Regarding Claim 16 This application 19/215,038 Patent US 12,355,608 16. wherein detecting the incident associated with activities of the monitored entity further comprises determining, based on the analysis of the incident, whether the incident is non-actionable Claim 8. ... determine, based on an analysis of the at least one detected incident, whether the at least one detected incident is actionable by analyzing an event type associated with the at least one detected incident. Regarding Claim 17 This application 19/215,038 Patent US 12,355,608 17. request, from an incident management service for the monitored entity, information related to the incident. Claim 9. ... request, from a data endpoint, the information related to the at least one detected incident that includes an indication of whether an action is to be performed with respect to the at least one detected incident. Regarding Claim 18 This application 19/215,038 Patent US 12,355,608 18. generating, based on received information related to the incident, the notification object that specifies details of the incident and an indication of a communication technique that is to be utilized to communicate the incident to the monitored entity. Claim 10. ... generate, based on the received information related to the at least one detected incident, the notification object that specifies details of the at least one detected incident and an indication of a communication technique that is to be utilized to communicate the at least one detected incident to the entity. Regarding Claim 19 This application 19/215,038 Patent US 12,355,608 19. storing information related to the incident in a not only structured query language ('NoSQL') database. Claim 4. ... storing, with respect to the notification service of the plurality of notification services, by utilizing a database that includes a geo-distributed not only structured query language (NoSQL) database ... Regarding Claim 20 This application 19/215,038 Patent US 12,355,608 20. A non-transitory computer readable medium on which is stored machine- readable instructions that when executed by a processor, cause the processor to: detect, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity; generate, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident; and determine, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster. Claim 16. A non-transitory computer readable medium on which is stored machine readable instructions that when executed by a processor, cause the processor to: Claim 6. detect, by a notification service of a plurality of notification services that are each geographically located at different geographic locations, based on an analysis of signals received at an activity event hub of an internal incident management service of an entity, at least one incident associated with activities of the entity, wherein each of the plurality of notification services are located in different geographically distributed clusters in a cloud to notify the entity of the at least one detected incident; ... generate, by the notification service, based on the received information related to the at least one detected incident, a notification object to notify the entity of the at least one detected incident; determine, by the notification service, based on a unique identifier related to the at least one detected incident, by utilizing a database that is commonly used for storage by the plurality of notification services, whether the notification object to notify the entity of the at least one detected incident is a unique notification object, which is not a duplicate notification object generated by another notification service of the plurality of notification services; ... Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 3-5 and 15-16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 3 and 15 recite the term “the analysis” in “determine, based on the analysis of the incident, whether the incident is actionable” The term “the analysis” has never been introduced in the instant claim or in base claim. Therefore, there is insufficient antecedent basis for this limitation in the claim. Claim 4 recites the term “the analysis” in “determine, based on the analysis of the incident, whether the incident is actionable ...” The term “the analysis” has never been introduced in the instant claim or in base claim. Therefore, there is insufficient antecedent basis for this limitation in the claim. Claim 5 recites the term “the analysis” in “determine, based on the analysis of the incident, whether the incident is actionable ...” The term “the analysis” has never been introduced in the instant claim or in base claim. Therefore, there is insufficient antecedent basis for this limitation in the claim. Claim 16 recites the term “the analysis” in “determining, based on the analysis of the incident, whether the incident is non-actionable” The term “the analysis” has never been introduced in the instant claim or in base claim. Therefore, there is insufficient antecedent basis for this limitation in the claim. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-5, 8-16, and 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 13, and 20 recite in part process steps which, under the broadest reasonable interpretation, are a series of mental processes including an observation, evaluation, judgment or opinion that could be performed in the human mind or with the aid of pencil and paper. If a claim, under its broadest reasonable interpretation, covers a mental process or a mathematical concept but for the recitation of generic computer components, then it falls within the "Mental Process" grouping of abstract ideas. The claim recites in part: detect, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity. The “detect” an incident is reasonably interpreted by the Examiner as observing data and making a judgment based on the observed/gathered data. The claim does not provide any details on how the data is detected or any details on the detected data. Under its broadest reasonable interpretation when read in light of the specification, the claimed “detect” encompasses making a judgment based on observed/gathered data. Additionally, it is noted that even mental processes which may need the physical aids such as pen and paper can be still mental processes (see MPEP §2106.04(a)(2)(III)(B)) and even the fact that the claimed invention is performing steps on a computer does not prevent the function from being a mental process (see MPEP §2106.04(a)(2)(III)(C)). As result, the limitation recites a mental process. generate, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident. The “generate” is reasonably interpreted by the Examiner as making a judgment. Under its broadest reasonable interpretation when read in light of the specification, the claimed “generate” encompasses observing and making a judgement. Additionally, it is noted that even mental processes which may need the physical aids such as pen and paper can be still mental processes (see MPEP §2106.04(a)(2)(III)(B)) and even the fact that the claimed invention is performing steps on a computer does not prevent the function from being a mental process (see MPEP §2106.04(a)(2)(III)(C)). As result, the limitation recites a mental process. determine, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster. The “determine” is reasonably interpreted by the Examiner as making a judgment. Under its broadest reasonable interpretation when read in light of the specification, the claimed “determine” encompasses observing and making a judgement. Additionally, it is noted that even mental processes which may need the physical aids such as pen and paper can be still mental processes (see MPEP §2106.04(a)(2)(III)(B)) and even the fact that the claimed invention is performing steps on a computer does not prevent the function from being a mental process (see MPEP §2106.04(a)(2)(III)(C)). As result, the limitation recites a mental process. Therefore, claims 1, 13, and 20 recite an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claims only recite one additional element - when executed by a processor to detect an incident, generate a notification object, and determine that the notification object is a unique notification object. The processor is recited at a high-level of generality (i.e., as a generic computer to detect an incident, generate a notification object, and determine that the notification object is a unique notification object), such that it amounts no more than mere instructions to apply the exception using a generic computer component. As described in MPEP 2106.0S(g), limitations that amount to merely adding insignificant extra-solution activity to a judicial exception cannot integrate a judicial exception into a practical application. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claims 1, 13, and 20 are directed to a judicial exception. Claims 1, 13, and 20 do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above, the additional elements of the processor to detect an incident, generate a notification object, and determine that the notification object is a unique notification object to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Claims 1, 13, and 20 are not patent eligible. Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 2 depends on claim 1, and it further recites “wherein the instructions to detect the incident associated with activities of the monitored entity further cause the processor to: detect the incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the monitored entity.” The claim further limiting the incident, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 2 is not patent eligible. Claim 3 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 3 depends on claim 1, and it further recites “wherein the instructions further cause the processor to determine, based on the analysis of the incident, whether the incident is actionable.” The “determine” is reasonably interpreted by the Examiner as making a judgment. Under its broadest reasonable interpretation when read in light of the specification, the claimed “determine” encompasses observing and making a judgement, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 3 is not patent eligible. Claim 4 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 4 depends on claim 3, and it further recites “wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze a plurality of previously detected incidents that includes at least one previously detected incident that is actionable and at least one previously detected incident that is non-actionable.” The “detect” is reasonably interpreted by the Examiner as observing data and making a judgment, and the “determine” is reasonably interpreted by the Examiner as making a judgment, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 4 is not patent eligible. Claim 5 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 5 depends on claim 3, and it further recites “wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze an event type associated with the incident.” The “determine” is reasonably interpreted by the Examiner as making a judgment. Under its broadest reasonable interpretation when read in light of the specification, the claimed “determine” encompasses observing and making a judgement, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 5 is not patent eligible. Claim 8 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 8 depends on claim 1, and it further recites “wherein the instructions to generate the notification object for the incident further cause the processor to: generate, based on received information related to the incident, the notification object that specifies details of the incident and an indication of a communication technique that is to be utilized to communicate the incident to the monitored entity.” The “generate” is reasonably interpreted by the Examiner as making a judgment. Under its broadest reasonable interpretation when read in light of the specification, the claimed “generate” encompasses observing and making a judgement, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 8 is not patent eligible. Claim 9 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 9 depends on claim 8, and it further recites “wherein the instructions further cause the processor to perform the communication technique to communicate the incident to the monitored entity.” The “communicate the incident” is reasonably interpreted by the Examiner as reporting the incident, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 9 is not patent eligible. Claim 10 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 10 depends on claim 1, and it further recites “wherein the instructions further cause the processor to store information related to the incident in a not only structured query language ('NoSQL') database.” The claim is further limiting the database, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 10 is not patent eligible. Claim 11 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 11 depends on claim 10, and it further recites “wherein the NoSQL database is a geo- distributed NoSQL database.” The claim is further limiting the NoSQL database, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 11 is not patent eligible. Claim 12 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 12 depends on claim 1, and it further recites “wherein the instructions to detect the incident associated with the activities of the monitored entity further cause the processor to: detect, with respect to a notification service of a plurality of notification services that are each geographically located at different geographic locations, the incident.” The “detect” the incident is reasonably interpreted by the Examiner as observing data and making a judgment based on the observed/gathered data, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 12 is not patent eligible. Claim 14 is rejected under Double Patenting, as described for claim 2. Claim 15 is rejected under Double Patenting, as described for claim 3. Claim 16 is rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 16 depends on claim 13, and it further recites “wherein detecting the incident associated with activities of the monitored entity further comprises determining, based on the analysis of the incident, whether the incident is non-actionable.” The “determining” is reasonably interpreted by the Examiner as making a judgment, which does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claim 16 is not patent eligible. Claim 18 is rejected under Double Patenting, as described for claim 8. Claim 19 is rejected under Double Patenting, as described for claim 10. Examiner’s note: Claim 6-7 and 17 are integrated into practical applications which are NOT a series of mental processes including an observation, evaluation, judgment or opinion that could be performed in the human mind or with the aid of pencil and paper. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-9, 12-18, and 20 are rejected under 35 U.S.C. 102 (a)(1) as being anticipated by Siddiqui (Pub. No. US 10,476,906). Claim 1. Siddiqui discloses [a]n apparatus comprising: a processor; and a computer readable medium on which is stored machine readable instructions that cause the processor (See Fig. 3) to: detect, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity (See Col. 12 lines 39-63; the malware detection system 100 features one or more sensors (notification services) 110.sub.1-110.sub.M, each sensor 110.sub.1-110.sub.M is configured to receive information that includes at least metadata 202 and a corresponding object 204. Upon receipt of the information 200, a sensor (e.g., sensor 110.sub.1) (a notification service instance) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious (e.g., meets a first level of likelihood that the object is associated with malware) ... See Col. 34 lines 59-60; sensors enrolled with a cluster can be deployed in different geographical locations (a geographically distributed cluster of notification services) ... See also Col. 4 lines 3-11); generate, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident (See Col. 16 lines 1-15; Upon detecting the object 204 is suspicious, the processor 300 (“Sensor,” See Fig. 3) processes the metadata extraction logic 360 that, during such processing, extracts the metadata 202 from the received information 200 and assigns the object identifier 211 for the metadata 202 and the suspicious object 204, which may be unique for the cluster (referred to as “universally unique identifier” or “UUID”) ...); and determine, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 13 lines 39-49; no prior preliminary analysis of the object 204 has occurred (the notification object is a unique notification object which is not a duplicate notification object)). Claim 2. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui further discloses wherein the instructions to detect the incident associated with activities of the monitored entity further cause the processor to: detect the incident from a set of incident states that include an add incident state, an edit incident state, and a mitigate incident state associated with the activities of the monitored entity (See Col. 12 lines 39-63; Upon receipt of the information 200, a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious (e.g., meets a first level of likelihood that the object is associated with malware). The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (i) deviations in messaging practices (e.g., non-compliance in communication protocols, message formats or ordering, and/or payload parameters including size); (ii) presence of content within the object that is highly susceptible to malicious attack; (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis, and if so, whether or not such malware analysis has been completed (e.g., completed, experienced timeout event, awaiting processing, etc.) or the like). Claim 3. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui further discloses wherein the instructions further cause the processor to determine, based on the analysis of the incident, whether the incident is actionable (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 13 lines 39-49). Claim 4. Siddiqui discloses [t]he apparatus according to claim 3, Siddiqui further discloses wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze a plurality of previously detected incidents that includes at least one previously detected incident that is actionable and at least one previously detected incident that is non-actionable (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 12 lines 54-67, Col. 13 lines 1-67, and Col. 14 lines 1-8). Claim 5. Siddiqui discloses [t]he apparatus according to claim 3, Siddiqui further discloses wherein the instructions to determine, based on the analysis of the incident, whether the incident is actionable further cause the processor to analyze an event type associated with the incident (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 19 lines 14-34; the metadata 206 may provide information that identifies the suspicious object 204 is a type of object for which further in-depth malware analysis is not currently targeting or has little significance when compared to other types of objects ... the metadata 206 may identify that the suspicious object 204 is associated with a particular software profile that is different from objects with certain software profiles that are now more frequently under attack). Claim 6. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui further discloses wherein the instructions further cause the processor to request, from an incident management service for the monitored entity, information related to the incident (See Col. 19 lines 35-58; the results 545 of the analysis may be obtained from the distributed data store 170.sub.1 by the sensor 110.sub.1 utilizing the UUID 540 associated with the previously analyzed object or received via the object analysis system conducting an analysis of the suspicious object 204. See Fig. 5A). Claim 7. Siddiqui discloses [t]he apparatus according to claim 6 Siddiqui further discloses wherein the information includes an indication of whether an action is to be performed with respect to the incident (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See also Col. 12 lines 54-67, Col. 13 lines 1-67, and Col. 14 lines 1-8). Claim 8. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui further discloses wherein the instructions to generate the notification object for the incident further cause the processor to: generate, based on received information related to the incident, the notification object that specifies details of the incident and an indication of a communication technique that is to be utilized to communicate the incident to the monitored entity (See Col. 16 lines 1-15; Upon detecting the object 204 is suspicious, the processor 300 (“Sensor,” See Fig. 3) processes the metadata extraction logic 360 that, during such processing, extracts the metadata 202 from the received information 200 and assigns the object identifier 211 for the metadata 202 and the suspicious object 204, which may be unique for the cluster (referred to as “universally unique identifier” or “UUID”) ... See Col. 43 lines 26-41). Claim 9. Siddiqui discloses [t]he apparatus according to claim 8, Siddiqui further discloses wherein the instructions further cause the processor to perform the communication technique to communicate the incident to the monitored entity (See Col. 43 lines 26-41; Based on the content of the aggregated analysis results 1650, the management system 185 may generate an alert 1660 via a wired or wireless transmitter (not shown) to notify a network administrator (see FIG. 1) or other entities as to the detection of malware. Additionally, or in the alternative, the management system 185 may provide at least a portion of the results 1600 to another management system (not shown) that monitors the health and operability of the network 120 or to a forensics analysis system for further detailed analysis as to confirm that the suspicious object is associated with malware and the nature of the malware. Also, the management system 185 may receive a signature generated by the computing node 160.sub.2 during analysis of the suspicious object as part of the aggregated analysis results 1650, or may generate a signature for propagation through the enterprise network 120 of FIG. 1). Claim 12. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui further discloses wherein the instructions to detect the incident associated with the activities of the monitored entity further cause the processor to: detect, with respect to a notification service of a plurality of notification services that are each geographically located at different geographic locations, the incident (See Col. 12 lines 39-63; the malware detection system 100 features one or more sensors (notification services) 110.sub.1-110.sub.M, each sensor 110.sub.1-110.sub.M is configured to receive information that includes at least metadata 202 and a corresponding object 204. Upon receipt of the information 200, a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious (e.g., meets a first level of likelihood that the object is associated with malware) ... See Col. 34 lines 59-60; sensors enrolled with a cluster can be deployed in different geographical locations ... See also Col. 4 lines 3-11. See also Col. 13 lines 14-24;). Claim 13. Siddiqui discloses [a] computer-implemented method comprising: detecting, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity (See Col. 12 lines 39-63; the malware detection system 100 features one or more sensors (notification services) 110.sub.1-110.sub.M, each sensor 110.sub.1-110.sub.M is configured to receive information that includes at least metadata 202 and a corresponding object 204. Upon receipt of the information 200, a sensor (e.g., sensor 110.sub.1) (a notification service instance) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious (e.g., meets a first level of likelihood that the object is associated with malware) ... See Col. 34 lines 59-60; sensors enrolled with a cluster can be deployed in different geographical locations (a geographically distributed cluster of notification services) ... See also Col. 4 lines 3-11); generating, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident (See Col. 16 lines 1-15; Upon detecting the object 204 is suspicious, the processor 300 (“Sensor,” See Fig. 3) processes the metadata extraction logic 360 that, during such processing, extracts the metadata 202 from the received information 200 and assigns the object identifier 211 for the metadata 202 and the suspicious object 204, which may be unique for the cluster (referred to as “universally unique identifier” or “UUID”) ...); and determining, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 13 lines 39-49; no prior preliminary analysis of the object 204 has occurred (the notification object is a unique notification object which is not a duplicate notification object)). Claim 14 is taught by Siddiqui as described for claim 2. Claim 15 is taught by Siddiqui as described for claim 3. Claim 16. Siddiqui discloses [t]he computer-implemented method according to claim 13, Siddiqui further discloses wherein detecting the incident associated with activities of the monitored entity further comprises determining, based on the analysis of the incident, whether the incident is non-actionable (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 12 lines 54-67, Col. 13 lines 1-67, and Col. 14 lines 1-8). Claim 17 is taught by Siddiqui as described for claim 6. Claim 18 is taught by Siddiqui as described for claim 8. Claim 20. Siddiqui discloses [a] non-transitory computer readable medium on which is stored machine-readable instructions that when executed by a processor (See Fig. 3), cause the processor to: detect, by a notification service instance operating within a geographically distributed cluster of notification services, an incident associated with activities of a monitored entity (See Col. 12 lines 39-63; the malware detection system 100 features one or more sensors (notification services) 110.sub.1-110.sub.M, each sensor 110.sub.1-110.sub.M is configured to receive information that includes at least metadata 202 and a corresponding object 204. Upon receipt of the information 200, a sensor (e.g., sensor 110.sub.1) (a notification service instance) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious (e.g., meets a first level of likelihood that the object is associated with malware) ... See Col. 34 lines 59-60; sensors enrolled with a cluster can be deployed in different geographical locations (a geographically distributed cluster of notification services) ... See also Col. 4 lines 3-11); generate, by the notification service instance, a notification object for the incident, wherein the notification object includes a unique identifier for the incident (See Col. 16 lines 1-15; Upon detecting the object 204 is suspicious, the processor 300 (“Sensor,” See Fig. 3) processes the metadata extraction logic 360 that, during such processing, extracts the metadata 202 from the received information 200 and assigns the object identifier 211 for the metadata 202 and the suspicious object 204, which may be unique for the cluster (referred to as “universally unique identifier” or “UUID”) ...); and determine, by the notification service instance, that the notification object is a unique notification object which is not a duplicate notification object generated by another notification service instance of the geographically distributed cluster (See Col. 12 lines 39-63; a sensor (e.g., sensor 110.sub.1) separates the metadata 202 from the object 204 and conducts a preliminary analysis to determine whether the object 204 is suspicious. The preliminary analysis may include one or more checks (real-time analyses) being conducted on the metadata 202 and/or object 204 without execution of the object 204. Examples of the checks may include bit pattern comparisons of content forming the metadata 202 or object 204 with pre-stored bit patterns to uncover (iii) prior submission via the sensor of certain types of objects (or an object that is highly correlated upon determining shared prescribed amount of similar data) to a cluster for malware analysis. See Col. 13 lines 14-24; this preliminary analysis may involve a comparison between a representation of the object 204 (e.g., bit pattern representation as a hash of the object 204 or portions of the object 204, certain content of the object 204, etc.) and stored representations of previously analyzed objects. Optionally, the preliminary analysis may further involve a comparison between the representation of the object 204 and representations of other objects analyzed by the cluster 150.sub.1 (or even other clusters) that have been determined to be benign (whitelist) or malicious (blacklist). See also Col. 13 lines 39-49; no prior preliminary analysis of the object 204 has occurred (the notification object is a unique notification object which is not a duplicate notification object)). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 10-11 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Siddiqui (Pub. No. US 10,476,906); in view of Gordon et al. (Pub. No. US 2018/0150683), hereinafter Gordon. Claim 10. Siddiqui discloses [t]he apparatus according to claim 1, Siddiqui doesn’t explicitly disclose wherein the instructions further cause the processor to store information related to the incident in a not only structured query language ('NoSQL') database. However, Gordon wherein the instructions further cause the processor to store information related to the incident in a not only structured query language ('NoSQL') database (See Parag. [0112]; When the details of an incident have been entered into the user interface 200, the user may select a button such as a ‘submit report’ button, which causes the web application to save the information that has been input as an event data object. Each event data object may be stored in a database, such as a relational database, a NoSQL database, a graphing database, or any other known type of database). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the data store for storing information related to the incident, taught by Siddiqui, to include a not only structured query language ('NoSQL') database, as taught by Gordon. This would be convenient to provide flexible scalability because NoSQL databases are highly scalable and can be modified to meet the unique scaling needs of business. Claim 11. Siddiqui in view of Gordon discloses [t]he apparatus according to claim 10, Siddiqui further discloses wherein the database is a geo-distributed database (See Col. 10 lines 48-67 and Col. 11 lines 1-7; the distributed data store 170 and the distributed queue 175 may be provided as a collection of synchronized memories within the computing nodes 160.sub.1-160.sub.P (e.g., synchronized data stores 170.sub.1-170.sub.P that collectively form distributed data store 170; synchronized queues 175.sub.1-175.sub.P that collectively form distributed queue 175 where each of the queues 175.sub.1-175.sub.P is synchronized to store the same information), each accessible by the computing nodes 160.sub.1-160.sub.P respectively. The distributed data store 170 (formed by local data stores 170.sub.1-170.sub.P operating in accordance with a selected memory coherence protocol) are accessible by the computing nodes 160.sub.1-160.sub.P, and thus, data stores 170.sub.1-170.sub.P may be configured to store the same information. Alternatively, the data stores 170.sub.1-170.sub.P may be configured to store different information, provided the collective information is available to all of the computing nodes 160.sub.1-160.sub.P in the same cluster 150.sub.1 ... See Col. 34 lines 48-67; ... computing node in same geographic region as the sensor ...). Siddiqui doesn’t explicitly disclose the database is the NoSQL database. However, Gordon discloses the NoSQL database (See Parag. [0112]; Each event data object may be stored in a database, such as a relational database, a NoSQL database, a graphing database, or any other known type of database). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the data store for storing information related to the incident, taught by Siddiqui, to include a not only structured query language ('NoSQL') database, as taught by Gordon. This would be convenient to provide flexible scalability because NoSQL databases are highly scalable and can be modified to meet the unique scaling needs of business. Claim 19 is taught by Siddiqui and Gordon as described for claim 10. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Borkar et al. (Pub. No. US 2020/0394084) – Related art in the area of controlling delivery of notifications, (Abstract; Systems and method for controlling delivery of notifications on a per user basis. An agent, executed by a virtual machine, can establish one or more hooks to intercept notifications from an operating system of the virtual machine and one or more virtualized applications executed by the virtual machine accessible by a plurality of users. The agent can intercept, via the one or more hooks, a plurality of notifications for a plurality of users generated by the one or more virtualized applications or the operating system. The plurality of notifications can be sorted on a per user basis. The agent can communicate each user's notifications to a notification service to sort and aggregate the notifications with notifications from a plurality of applications used by each of the plurality of users. The notification service can select one or more notifications to provide to at least one device of a user). Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDELBASST TALIOUA whose telephone number is (571)272-4061. The examiner can normally be reached on Monday-Thursday 7:30 am - 5:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie can be reached on 571-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Abdelbasst Talioua/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

May 21, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683852
Root Cause and Impact Determination Based on Automated Service Identification
2y 6m to grant Granted Jul 14, 2026
Patent 12671621
System, Method, and Computer Program Product for Detecting an Anomaly in Network Activity
2y 4m to grant Granted Jun 30, 2026
Patent 12652251
SYSTEMS, METHODS, AND DEVICES FOR LOAD BALANCING IN MULTIPLANE NETWORKS
3y 2m to grant Granted Jun 09, 2026
Patent 12652324
METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR PRESERVING NETWORK BANDWIDTH DURING NETWORK ADDRESS TRANSLATION (NAT) DEVICE UNAVAILABILITY OR AFTER NAT DEVICE REBOOT
2y 5m to grant Granted Jun 09, 2026
Patent 12652213
SYSTEMS AND METHODS FOR ERROR CODE ANALYTICS IN TELECOMMUNICATIONS NETWORKS
2y 8m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
59%
Grant Probability
94%
With Interview (+35.0%)
3y 0m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 113 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month