Prosecution Insights
Last updated: September 17, 2026
Application No. 19/311,347

Targeting System State Context in a Search Process in an Observability Pipeline System

Non-Final OA §101§103§112§DOUBLEPATENT
Filed
Aug 27, 2025
Priority
May 23, 2022 — provisional 63/344,864 +4 more
Examiner
PYO, MONICA M
Art Unit
Tech Center
Assignee
Cribl Inc.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
2y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
519 granted / 626 resolved
+22.9% vs TC avg
Strong +35% interview lift
Without
With
+35.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
15 currently pending
Career history
642
Total Applications
across all art units

Statute-Specific Performance

§101
20.8%
-19.2% vs TC avg
§103
46.4%
+6.4% vs TC avg
§102
10.4%
-29.6% vs TC avg
§112
14.2%
-25.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 626 resolved cases

Office Action

§101 §103 §112 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 2. Claims 1-20 are present for examination. Double Patenting 3. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. 4. Claims 5, 12 and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 6 and 11 of U.S. Patent No. 12,405,958. Although the claims at issue are not identical, they are not patentably distinct from each other because the claimed invention of the instant application is a similar version of the claimed invention of the above identified U.S. Patent with the similar intended scope as shown below: Instant Application Patent No. 12,405,958 Claim 1. A search method comprising: at a computer node in a computer system, receiving a search query from a leader role of an observability pipeline system, the search query representing a request to search event data at the computer node, the search query comprising a plurality of search operators, the plurality of search operators comprising: a first search operator that specifies a system state context criterion; and a second search operator that specifies an event criterion; configuring an observability pipeline process according to the search query; obtaining search results based on applying the observability pipeline process at the computer node, wherein applying the observability pipeline process comprises: determining that a current system state of the computer node matches the system state context criterion specified by the first search operator, wherein the system state context criterion includes a target value of a system state context associated with hardware on the computer node, and determining that the current system state of the computer node matches the system state context criterion specified by the first search operator includes: identifying a current value of a system state parameter for the hardware on the computer node; and determining that the current value of the system state parameter for the hardware matches the target value of the system state context; and in response to the determination, searching the event data on the computer node using the event criterion specified by the second search operator to identify a subset of event data that matches the event criterion; and [Claim 5. The method of claim 1, wherein searching the event data on the computer node comprises searching events from one or more log files, and wherein the subset of event data comprises a subset of the events from the one or more log files.] sending the search results to the leader role, wherein the search results include the subset of event data. Claim 1. A search method for searching event data in an observability pipeline system, the search method comprising: at a computer node in a computer system, receiving a search query from a leader role of the observability pipeline system, the search query representing a request to search the event data at the computer node, the search query comprising a plurality of search operators, the plurality of search operators comprising: a first search operator that specifies a system state context criterion; and a second search operator that specifies an event criterion; configuring an observability pipeline process according to the search query; obtaining search results based on applying the observability pipeline process at the computer node, wherein applying the observability pipeline process comprises: determining whether a current system state of the computer node matches the system state context criterion specified by the first search operator, wherein the system state context criterion comprises a target value of a system of a system state context associated with processes on the computer node, and determining whether the current state of the computer node matches the system state criterion comprises: identifying current values of system state parameters for processes that are currently running on the computer node, and determining whether the current values of the system state parameters for a subset of the processes match the target value of the system state context; and only upon determining that the current system state of the computer node matches the system state context criterion specified by the first search operator, searching the event data from log files on the computer node using the event criterion specified by the second search operator to identify a subset of the event data on the computer node that matches the event criterion specified by the second search operator and including the subset of the event data from the log files in the search results, wherein the subset of the event data is generated by the subset of processes; and sending the search results to the leader role. It is noted that claims 8 and 15 recite the similar limitations of claim 1, and is rejected due to the similar reasons set forth above. Claim Rejections - 35 USC § 112 5. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 6. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claims 1, 8 and 15, these claims recite the claim limitation of “in response to the determination, searching the event data on the computer node…” in line 21 of claims 1, 8 and 15. However, since claims 1, 8 and 15 recite the limitations of “determining that…” in line 11 and line 19, respectively, it is unclear what the limitation of “in response to the determination, searching the event data on the computer node…” refers to. Clarification is required. Regarding claims 2, 9 and 16, these claims recite the claim limitation of “wherein the system state context criterion comprises a target value of a system state context” [emphasis added] in lines 1-2. However, it is unclear how the claimed the limitation of “a target value of a system state context” in claims 2, 9 and 16 are related to the limitation of “a target value of a system state context” in line 13 of claims 1, 9 or 16. Are they referring to the same thing? Clarification is required. Claims not specifically mentioned above are also rejected by virtue of their dependency on a rejected claim. Claim Rejections - 35 USC § 101 7. 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. 8. Claims 8-14 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter. Regarding claims 8-14, these claims are not statutory because these claims lack the necessary physical articles or objects to constitute a machine or a manufacture within the meaning of 35 U.S.C. 101. These claims are, at best, functional descriptive material (i.e., software) per se. Claim Rejections - 35 USC § 103 9. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 10. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 11. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over US 2021/0133650 (hereinafter Cella) in view of U.S. 2023/0367871 (hereinafter Ko). Regarding claims 1, 8 and 15, as far as the claim is understood, Cella discloses a search method comprising: at a computer node in a computer system ([0552]; “…The machine learning model 3000 may be based on a collection of connected units and/or nodes that may act like artificial neurons that may in some ways emulate neurons in a biological brain. The units and/or nodes may each have one or more connections to other units and/or nodes. The units and/or nodes may be configured to transmit information, e.g. one or more signals, to other units and/or nodes, process signals received from other units and/or nodes, and forward processed signals to other units and/or nodes…”), receiving a search query from a leader role of an observability pipeline system, the search query representing a request to search event data at the computer node ([0098, 0795 and 1258]; “Further provided herein are methods and systems for enterprise control towers by which executive leaders can, through various interfaces, including executive digital twins, dashboards, and similar systems, obtain timely information (often in real-time or near real-time) that is curated to invoke relevant awareness, support effective decisions and enable operational control…”; “…For example, machine datastore 5202 may store data related to machine identification and attributes, machine state and event data, data from maintenance records, historical operating data, notes from machine operator, etc…”; and “…This may allow a CTO to optimize initiatives in real-time without having to manually request such real-time technical performance data; the CTO digital twin 8310 may automatically present such information and related/necessary alerts as configured by the organization, CTO, or some other interested party”), the search query comprising a plurality of search operators, the plurality of search operators comprising: a first search operator that specifies a system state context criterion ([0573]; “…The coordinated intelligence system may classify, predict or perform some other intelligent analytics, in combination, for the purpose of, for example, determining a state of a machine, such as a machine in a deteriorated state, in an at-risk state, or some other state. The determination of a state may cause a control system to alter a control regime, for example, slowing or shutting down a machine that is in a deteriorating state…”); and a second search operator that specifies an event criterion ([1123]; “…In these embodiments, the client application 8052 may further record and report features relating to the interaction, such as any stimuli or inputs that were presented to the user, what the user was viewing at the time of the interaction, the type of interaction, the role of the user, whether the interaction was requested by someone else, the role of the individual that requested the interaction, contextual information, state information, workflow information, event information, and the like…”); configuring an observability pipeline process according to the search query; obtaining search results based on applying the observability pipeline process at the computer node ([0094]; “One path to distilling information is digital twin technology, which can present large amounts of data in a digestible format that represents salient characteristics of an item, often updated in real time or near real time as the twin is updated to reflect the current state based on a pipeline of data about a represented item…”), wherein applying the observability pipeline process comprises: determining that a current system state of the computer node matches the system state context criterion specified by the first search operator ([0559]; “…In some embodiments, the machine learning model 3000 may learn by performing cluster analysis, such as by assigning a set of observations into subsets, i.e. clusters, according to one or more predesignated criteria, such as according to a similarity metric of which internal compactness, separation, estimated density, and/or graph connectivity are factors”), wherein the system state context criterion includes a target value of a system state context associated with [hardware on] the computer node, and determining that the current system state of the computer node matches the system state context criterion specified by the first search operator includes ([0429 and 1347]; “…In embodiments, an artificial intelligence-based system may determine an acceptable range of outcome variance and apply that range to measures of a select set of value chain network entities, such as entities that share one or more similarities, to facilitate detection of a problem state. In embodiments, an acceptable range of outcome variance may indicate a problem state trigger threshold that may be used by a local instance of artificial intelligence to signal a problem state. In such a scenario, a problem state may be detected when at least one measure of the value chain activity/entity and the like is greater than the artificial intelligence-determined problem state threshold…”): identifying a current value of a system state parameter for [the hardware] on the computer node ([1111]; “…Each information technology component or system may be depicted in the role-based digital twin, along with related data, such as specifications, configuration parameters and settings, processing capabilities, along with its relationship to other components, such as representing data and networking connectivity to other components or systems…”); and determining that the current value of the system state parameter [for the hardware] matches the target value of the system state context ([0358]; “…an opportunity matching application 884 (such as for matching one or more demand factors with one or more supply factors, for matching needs and capabilities of value chain network entities 652, for identifying reverse logistics opportunities, for identifying opportunities for inputs to enrich analytics, artificial intelligence and/or automation, for identifying cost-saving opportunities, for identifying profit and/or arbitrage opportunities, and many others)…”); and in response to the determination, searching the event data on the computer node using the event criterion specified by the second search operator to identify a subset of event data that matches the event criterion ([0365 and 0542]; “…event data 1034 ((such as with respect to any of a wide range of events, including operational data, transactional data, workflow data, maintenance data, and many other types of data that includes or relates to events that occur within a value chain network 668 or with respect to one or more applications 630…”; and “…The machine learning model 3000 may, for example, receive state data 1140 and event data 1034 related to a particular value chain entity 652 of the plurality of value chain entities 652 and perform a series of operations on the state data 1140 and the event data 1034 to format the state data 1140 and the event data 1034 into a format suitable for use by the digital twin system 1700 in creation of a digital replica of the value chain entity 652…”); and sending the search results to the leader role, wherein the search results include the subset of event data ([0559]; “…In some embodiments, the machine learning model 3000 may learn by performing cluster analysis, such as by assigning a set of observations into subsets, i.e. clusters, according to one or more predesignated criteria, such as according to a similarity metric of which internal compactness, separation, estimated density, and/or graph connectivity are factors”). Cella does not explicitly disclose the feature of the method including hardware on the computer node. However, Ko discloses that “…An individual node is referred to as an internet of things device 218 or IoT device 218. Such nodes may be examples of computer systems as defined herein, and may include or be referred to as a “smart” device, “endpoint”, “chip”, “label”, or “tag”, for example, and…” ([0143]) and it would have been obvious for one with ordinary skill in the art to utilize the teachings of Ko in the system of Cella in view of the desire to enhance the information technology process by detecting a trigger event resulting in improving the efficiency of producing the search results. In addition, Cella discloses a non-transitory computer-readable medium storing instructions that are operable when executed by data processing apparatus to perform operations ([1574]). Regarding claims 2, 9 and 16, as far as the claim is understood, Cella in view of Ko discloses the method wherein the system state context criterion comprises a target value of a system state context associated with at least one of: processes on the computer node; listening ports on the computer node; logged-in users on the computer node; or network interfaces on the computer node (Cella: [1351 and 1383]; “…However, the output layer in the auto-encoder may have the same number of units as the input layer, where the purpose of the MLP neural network may be to reconstruct its own inputs (rather than just emitting a target value)…”; and “…For example, the recurrent neural network may be used to anticipate the state (such as a maintenance state, a fault state, an operational state, or the like), of an industrial machine, such as one performing a dynamic process or action…”). Regarding claims 3, 10 and 17, Cella in view of Ko discloses the method wherein the observability pipeline process comprises pipelines and routes, and applying the observability process to the event data comprises: routing the event data by operation of the routes; and by operation of the pipelines, generating structured output data from the routed event data (Cella: [1118, 0662, 0670]; “In embodiments, the adaptive intelligent systems layer 614 may further include a set of routing facilities 1720 that generate a set of routing instructions for routing information among a set of nodes in the value chain network, such as based on processing current status information 1730, a set of application outputs and/or a set of outcomes 1040, or other information collected by or used in the VCNP 102…”). Regarding claims 4, 11 and 18, Cella in view of Ko discloses the method wherein the system state parameter for the hardware on the computer node comprises at least one of a current temperature of a hardware component or a current rotational speed of a fan (Cella: [0349 and 0542]; “…The digital twin simulation 1700 may use the simulation data to create one or more digital replicas of the robot, the simulation including for example metrics including temperature, wear, speed, rotation, and vibration of the robot and components thereof…”). Regarding claims 5, 12 and 19, Cella in view of Ko discloses the method wherein searching the event data on the computer node comprises: searching events from one or more log files, and wherein the subset of event data comprises a subset of the events from the log files (Cella: [0181 and 1145]; “…In embodiments, the digital twin I/O system 8104 may subscribe to or otherwise automatically receive data streams (e.g., publicly available data streams, such as RSS feeds, news streams, event streams, log streams, sensor system streams, and the like) on behalf of an enterprise…”) and (Ko: [0090]; “…One feature is a self-service experience of real-time query language (e.g., KQL, SQL, or another language 316) queries 318 on streams 418… Another example is using Windows Management Instrumentation (WMI) and log events in real-time…”). Therefore, the limitations of claims 5, 12 and 19 are also rejected in the analysis of claims 1, 8 or 15, and the claims are rejected on that basis. Regarding claims 6, 13 and 20, Cella in view of Ko discloses the method wherein the event data comprises at least one of structured data, semi-structured data, or unstructured data (Cella: [0435]; “…Other exemplary artificial intelligence-based influences on automated coordination of value chain network entity activities include machine learning-based information routing and recommendations thereto, semi-sentient problem recognition based on both structured (e.g., production data) and unstructured (e.g., human emotions) sources, and the like…”). Regarding claims 7 and 14, Cella in view of Ko discloses the method wherein the search query is based on Kusto Query Language (Ko: [0200]; “316 query language, e.g., Kusto Query Language (KQL), Structured Query Language (SQL) or another language suitable for managing data, or for searching data in a database or stream”). Conclusion 12. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONICA M PYO whose telephone number is (571)272-8192. The examiner can normally be reached Monday-Friday 8am-4pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, APU MOFIZ can be reached at 571-272-4080. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MONICA M PYO/ Primary Examiner, Art Unit 2161
Read full office action

Prosecution Timeline

Aug 27, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724766
SYSTEMS AND METHODS FOR WRITING UPDATES TO AND/OR READING PREVIOUSLY STORED UPDATES OF ASSETS IMPLEMENTED AS SMART CONTRACTS ON A DECENTRALIZED DATABASE
1y 8m to grant Granted Sep 01, 2026
Patent 12717685
DISTRIBUTED TRANSACTION MANAGEMENT DEVICE AND DISTRIBUTED TRANSACTION MANAGEMENT METHOD
2y 6m to grant Granted Aug 25, 2026
Patent 12711167
SYSTEMS AND METHODS FOR AUTOMATIC GENERATION OF DATASETS FOR RECORD OBJECTS USING MACHINE LEARNING ARCHITECTURES
2y 0m to grant Granted Aug 18, 2026
Patent 12688436
ARTIFICIAL INTELLIGENCE ADVISORY SYSTEMS AND METHODS FOR BEHAVIORAL PATTERN MATCHING AND LANGUAGE GENERATION
2y 2m to grant Granted Jul 21, 2026
Patent 12688210
PRIVATE ARTIFICIAL INTELLIGENCE (AI) SEARCHING ON A DATABASE USING A LARGE LANGUAGE MODEL
2y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+35.3%)
3y 1m (~2y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 626 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month