Prosecution Insights
Last updated: October 01, 2026
Application No. 19/423,524

FLASH SYSTEM WITH INTEGRATED LOG ANALYTICS AND ANOMALY DETECTION

Final Rejection §101§103
Filed
Dec 17, 2025
Priority
Oct 19, 2017 — provisional 62/574,534 +9 more
Examiner
PARK, GRACE A
Art Unit
2144
Tech Center
2100 — Computer Architecture & Software
Assignee
Pure Storage Inc.
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
2y 6m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
437 granted / 573 resolved
+21.3% vs TC avg
Strong +18% interview lift
Without
With
+17.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
17 currently pending
Career history
596
Total Applications
across all art units

Statute-Specific Performance

§101
11.2%
-28.8% vs TC avg
§103
56.6%
+16.6% vs TC avg
§102
15.5%
-24.5% vs TC avg
§112
10.2%
-29.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 573 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment and Arguments Claims 1-20 are pending and are being examined in this application. Applicant’s arguments with respect to the 101 and 103 rejections have been fully considered, but are unpersuasive for at least the following reasons: Regarding the 101 rejection, applicant disagrees that the claimed analytics operation and pattern recognition operation can be performed mentally by reviewing log data. In particular, applicant argues “The claims are directed to machine-generated operational data associated with a computing system and recite analytics and pattern-recognition processing to identify anomalous behaviors of that computing system. These operations are fundamentally different from a person merely observing information and forming a judgment. The claimed embodiments recite computer-implemented processing of machine-generated log data and therefore do not fall within the mental process grouping of abstract ideas.” Remarks, pg. 7. It is preliminarily noted that the claim limitation “receiving…log data generated by a computing system” was identified under Step 2A, Prong Two as being extra-solution activity, not as a mental process under Step 2A, Prong One. Also, the claimed “processing device,” which is used to perform the executing and applying steps, amounts to no more than mere instructions to apply the exception using a generic computer. See MPEP 2106.05(f). Thus, the fact that a computer is required to implement the executing and applying steps is insufficient to support a conclusion that the claimed invention as a whole is directed to a practical application under Step 2A, Prong Two or significantly more under Step 2B. With respect to the executing and applying steps, which were identified as mental processes in Step 2A, Prong One, it is unclear why both steps cannot be performed mentally. For example, if there is log data recording recently received data requests, a person can review such log data and determine if any of the data requests are identical (i.e., perform a pattern analytic). The person can then review the identical data requests and determine that receiving over 100 identical data requests per second constitutes a DDOS attack (i.e., perform pattern recognition to identify anomalous behavior). Applicant further argues that the executing and applying steps improve monitoring and management of computing systems and thus recite a practical application and significantly more than the abstract idea. Remarks, pgs. 7 and 8. In particular, applicant describes various features recited throughout the claims as providing the improvement and further states “The claims recite a specific ordered combination of… [the various features]. This is not a generic computer implementation of an abstract concept, but rather a specific technological approach for monitoring and managing computing systems.” It is unclear what specific order and exactly what combination the various features are required to provide the improvement or the specific technical approach. Merely providing a list of features or an idea of a technical solution is insufficient. Thus, claims 1, 2, 7-9, 11, 12, 17-19, and 20 are included in the 101 rejection, but claims 3-6, 10, and 13-16 (more detailed) are not included in the 101 rejection. Regarding the 103 rejection, applicant argues “The portions of Karpistsenko relied upon by the Office Action do not teach or suggest applying pattern recognition associated with log data to identify anomalous behaviors of the computing system. Rather, Karpistsenko describes monitoring information generated during execution of computational models in order to evaluate operation and performance of those computational models. Although the Office Action characterizes these disclosures as identifying "anomalous behaviors," the cited portions of Karpistsenko merely describe monitoring information associated with execution of computational models. The cited portions do not teach or suggest applying pattern recognition associated with log data to identify anomalous behaviors of the computing system as recited by claim 1.” Remarks, pg. 10. However, Karpistsenko discloses that input data is received from a data source (e.g., logs generated by a predictive model) [pars. 35, 42, 44, 52, and 86]. Logs generated by a predictive model are considered to teach “log data generated by a computing system” since predictive models are implemented using computing systems. Karpistsenko also discloses using an anomaly detection algorithm to detect model performance decay, address concept drift, outliers, and/or external events, which are all considered to be anomalous behaviors of the predictive model (i.e., computing system). Pattern recognition is disclosed by Chen, in combination with Karpistsenko. In response to applicant's arguments against the references individually (i.e., Karpistsenko), one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). As such, Karpistsenko and Chen clearly teach applying pattern recognition associated with log data to identify anomalous behaviors of the computing system as recited by claim 1.” Applicant also argues that the cited references do not teach or suggest "comparing the log data to a plurality of stored fingerprints representing known behaviors of the computing system” as recited in claims 2 and 12. In particular, applicant argues “The portions of Chen relied upon by the Office Action do not teach or suggest stored fingerprints representing known behaviors of a computing system. Rather, Chen describes comparing monitored performance data against pattern signatures so that a monitoring framework may adapt its monitoring behavior responsive to detected operating conditions. Chen's pattern signatures therefore represent monitored operating conditions used to modify operation of the monitoring framework, not known behaviors of a computing system against which log data is compared.” Remarks, pg. 11. However, in response to applicant's arguments against the references individually (i.e., Chen), one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). As explained above and in the 103 rejection with respect to claim 1, the combination of Karpistsenko and Chen teaches “applying pattern recognition associated with the log data to identify anomalous behaviors of the computing system.” With respect to claim 2, Chen discloses that received data is compared against previously developed pattern signatures [pars. 45 and 46], which means that pattern recognition is implemented using signatures of known patterns. Thus, in combination with Karpistsenko, Chen teaches "comparing the log data to a plurality of stored fingerprints representing known behaviors of the computing system” as recited in claims 2 and 12. Applicant further argues that the cited references do not teach or suggest "receiving log data from a plurality of data producers" and "allocating separate processing resources to analyze the log data of each data producer" as recited in claims 4 and 14. In particular, applicant argues “Davila describes dynamically assigning processors to I/O resources, such as host bus adapters and device adapters, based on utilization of those I/O resources so that the processors service corresponding I/O requests. Claim 4, however, allocates separate processing resources so that the processing resources analyze the log data of each data producer. Accordingly, Davila's processor allocation is based on servicing hardware I/O resources, not analyzing the log data of respective data producers as recited by claim 4.” Remarks, pg. 12. However, in response to applicant's arguments against the references individually (i.e., Davila), one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). As explained above and in the 103 rejection, Karpistsenko teaches “receiving, by a processing device, log data generated by a computing system” and “executing an analytics operation on the log data” as recited in claim 1. Karpistsenko also discloses that such data (i.e., log data) comprises data from a plurality of data stores [pars. 35, 42, 44, 52, 86]. Note that, per the mappings with respect to Karpistsenko, the claimed “data producers” may refer to the plurality of data stores (claim 4), to the predictive models (claim 1), or both since the claim language of claims 1 and 2 reciting “log data generated by a computing system” and “log data from a plurality of data producers,” respectively, can be interpreted very broadly. Cited paragraph 36 of Chen discloses: [0036] FIG. 3 illustrates a block diagram 300 that shows indicators associated with a CPU 302 that is allocated for an I/O resource, in accordance with certain embodiments. The indicator “CPU group” indicates a group to which the CPU 302 belongs, and the indicator “dedicated or reserved” 306 indicates whether the CPU 302 is a dedicated CPU or a reserved CPU. The CPU adjustment application 126 generates a group of CPUs for each I/O resource included in the I/O resources 116. Each CPU in a group may be either dedicated or reserved. If a CPU is indicated as dedicated for a group, then the CPU is allocated for processing the tasks of the I/O resource for which the group has been formed. If a CPU is indicated as reserved for a group, then the CPU is allowed to be used by tasks other than the tasks of the I/O resource for which the group has been formed, if CPU utilization for the group is sufficiently low (e.g., below a predetermined threshold). If a CPU is indicated as reserved for a group, then if the CPU utilization for the group is sufficiently high (e.g., above a predetermined threshold), then the reserved CPU may stop executing other tasks and return to the processing of tasks of the I/O resource for which the group was formed. In other words, Davila discloses that a group of CPUs (i.e., a separate processing resource) is allocated for processing tasks of each I/O resource, which means that separate processing resources are allocated to processing tasks of each I/O resource. In the context of the combination of Davila with Karpistsenko and Chen, the claimed “data producer” may read on the processing tasks of an I/O resource of Davila, the I/O resource of Davila, the predictive model of Karpistsenko, the data store of Karpistsenko, or any combination. Cited paragraph 64 of Davila discloses that such processing tasks include data analytics processing. As such, Davila, in combination with Karpistsenko and Chen, clearly teaches "receiving log data from a plurality of data producers" and "allocating separate processing resources to analyze the log data of each data producer" as recited in claims 4 and 14. Applicant further argues that the cited references do not teach or suggest "detecting that execution of the analytics operation has failed" and "reallocating processing resources to continue the analytics operation on the log data” as recited in claims 5 and 15. In particular, applicant argues “The portions of Sinha relied upon by the Office Action do not teach or suggest detecting failure of an analytics operation. Rather, Sinha describes detecting failures associated with electronic control units (ECUs) and tasks executed by those ECUs so that a reconfiguration strategy may be generated for continued operation of a vehicle control system. Likewise, the cited portions do not teach or suggest reallocating processing resources to continue execution of an analytics operation on log data. Rather, Sinha describes reassigning vehicle-control tasks among available ECUs following failure of an ECU or associated task so that the vehicle control system continues operating.” Remarks, pgs. 13 and 14. However, in response to applicant's arguments against the references individually (i.e., Sinha), one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). As explained above and in the 103 rejection, Karpistsenko teaches “executing an analytics operation on the log data” as recited in claim 1. Sinha discloses that upon detecting failure of one or more tasks, a reconfiguration strategy is generated to reconfigure a task which failed on a working ECU (e.g., due to resource limitations) to execute on another ECU [col. 1, lines 13-54]. As such, Sinha’s disclosure of detecting failure of one or more tasks, in combination with Karpistsensko and Chen, clearly teaches "detecting that execution of the analytics operation has failed" as recited in claims 5 and 15. Also, Sinha’s disclosure of reconfiguring a task which failed on a working ECU (e.g., due to resource limitations) to execute on another ECU, in combination with Karpistsenko and Chen, clearly teaches "reallocating processing resources to continue the analytics operation on the log data” as recited in claims 5 and 15. Claim Rejections - 35 USC § 101 - Alice 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 2, 7-9, 11, 12, 17-19, and 20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. [CLAIM 1] A method comprising: (a) receiving, by a processing device, log data generated by a computing system; (b) executing an analytics operation on the log data; and (c) applying pattern recognition associated with the log data to identify anomalous behaviors of the computing system. Claim interpretation: Under the broadest reasonable interpretation, the terms of the claim are presumed to have their plain meaning consistent with the specification as it would be interpreted by one of ordinary skill in the art. See Manual of Patent Examining Procedure (MPEP) 2111. The broadest reasonable interpretation of claim 1 is a method of receiving data stored (i.e., logged) by a computer system, performing analytics on the data, and reviewing the data for patterns to identify anomalous behaviors of the computing system. These steps are recited as being performed by a processing device. Both the computer system and the processing device are recited at a high level of generality, i.e., as generic computers performing generic computer functions. Step 1: This part of the eligibility analysis evaluates whether the claim falls within any statutory category. See MPEP 2106.03. The claim recites a method. Thus, the claim is to a process, which is one of the statutory categories of invention. (Step 1: YES, also applicable to dependent claims 2 and 7-9). Step 2A, Prong One: This part of the eligibility analysis evaluates whether the claim recites a judicial exception. As explained in MPEP 2106.04, subsection II, a claim “recites” a judicial exception when the judicial exception is “set forth” or “described” in the claim. (b) executing an analytics operation on the log data – Step (b) may be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the executing an analytics operation can be performed mentally (or with the aid of pen and paper) by reviewing (i.e., observing) the log data. Thus, this limitation falls within the mental processes grouping of abstract ideas; (c) applying pattern recognition associated with the log data to identify anomalous behaviors of the computing system – Step (c) may be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the applying pattern recognition can be performed mentally (or with the aid of pen and paper) by reviewing (i.e., observing) the log data for patterns and determining (i.e., judging) whether the patterns are associated with anomalous behaviors. Thus, this limitation falls within the mental processes grouping of abstract ideas. As explained in the MPEP, when a claim recites multiple abstract ideas that fall in the same or different groupings, examiners should consider the limitations together as a single abstract idea, rather than as a plurality of separate abstract ideas to be analyzed individually. See MPEP 2106.04, subsection II.B. As the steps (b)-(g) fall within the same grouping of abstract ideas (i.e., mental processes), these limitations are considered together as a single abstract idea for further analysis. (Step 2A, Prong One: YES). Step 2A, Prong Two: This part of the eligibility analysis evaluates whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by (1) identifying whether there are any additional elements recited in the claim beyond the judicial exception, and (2) evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. See MPEP 2106.04(d). The claim recites an additional limitation in step (a) receiving, by a processing device, log data generated by a computing system. This limitation is mere data gathering recited at a high level of generality, and thus is insignificant extra-solution activity. See MPEP 2106.05(g) (“whether the limitation is significant”). In addition, all uses of the recited judicial exceptions require such data gathering, and, as such, this limitation does not impose any meaningful limits on the claim. This limitation amounts to necessary data gathering and outputting. See MPEP 2106.05. Further, steps (a)-(c) are recited as being performed by a processing device. The processing device is recited at a high level of generality and used as a tool to perform generic computer functions. See MPEP 2106.05(f). In these limitations, the processing device is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using a generic computer. See MPEP 2106.05(f). Even when viewed in combination, the above-noted additional limitations do not integrate the recited judicial exception into a practical application (Step 2A, Prong Two: NO), and the claim is directed to the judicial exception. (Step 2A: YES). Step 2B: This part of the eligibility analysis evaluates whether the claim as a whole amounts to significantly more than the recited exception i.e., whether any additional element, or combination of additional elements, adds an inventive concept to the claim. See MPEP 2106.05. Also, as explained with respect to Step 2A, Prong Two, the additional limitation in step (a) was found to be insignificant extra-solution activity because it was determined to be necessary data gathering. However, a conclusion that an additional limitation is insignificant extra-solution activity in Step 2A, Prong Two should be re-evaluated in Step 2B. See MPEP 2106.05, subsection I.A. At Step 2B, the evaluation of the insignificant extra-solution activity consideration takes into account whether or not the extra-solution activity is well understood, routine, and conventional in the field. See MPEP 2106.05(g). Here, the additional limitations are recited at a high level of generality and amount to receiving or transmitting data over a network and is thus well-understood, routine, conventional activity. See MPEP 2106.05(d)(II)(i). See also TLI Communications LLC v. AV Auto. LLC, 823 F.3d 607, 610, 118 USPQ2d 1744, 1745 (Fed. Cir. 2016) (using a telephone for image transmission); OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015) (sending messages over a network); buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355, 112 USPQ2d 1093, 1096 (Fed. Cir. 2014) (computer receives and sends information over a network). Here, the additional limitations are recited at a high level of generality and also amounts to storing and retrieving information in memory. See MPEP 2106.05(d)(II)(iv). See also Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015); OIP Techs., 788 F.3d at 1363, 115 USPQ2d at 1092-93. Further, as discussed in Step 2A, Prong Two above, the recitation of a processing device to perform limitations (a)-(c) amounts to no more than mere instructions to apply the exception using a generic computer component. Even when considered in combination, the above-noted additional limitations represent mere instructions to implement an abstract idea or other exception on a computer, which do not provide an inventive concept. (Step 2B: NO). [CLAIM 2] Step 2A, Prong One: wherein applying pattern recognition to the log data comprises comparing the log data to a plurality of stored fingerprints representing known behaviors of the computing system – Merely elaborates on step (c) of claim 1 and may be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the comparing can be performed mentally by reviewing (i.e., observing) both the log data and the stored fingerprints for similarities or differences. Thus, this limitation falls within the mental processes grouping of abstract ideas. (Step 2A, Prong One: YES). Step 2A, Prong Two: No further additional limitation recited. Step 2B: No further additional limitations recited. [CLAIM 7] Step 2A, Prong One: generating auditing information for the analytics operation executed on the log data – May be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the generating can be performed mentally by reviewing (i.e., observing) and determining (i.e., judging) whether the log data satisfies requirements. Thus, this limitation falls within the mental processes grouping of abstract ideas. (Step 2A, Prong One: YES). Step 2A, Prong Two: No further additional limitation recited. Step 2B: No further additional limitations recited. [CLAIM 8] Step 2A, Prong One: generating trending information for the analytics operation executed on the log data – May be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the generating can be performed mentally by reviewing (i.e., observing) and determining (i.e., judging) if there are any trends in the log data and. Thus, this limitation falls within the mental processes grouping of abstract ideas. (Step 2A, Prong One: YES). Step 2A, Prong Two: No further additional limitation recited. Step 2B: No further additional limitations recited. [CLAIM 9] Step 2A, Prong One: wherein applying pattern recognition to the log data comprises: correlating anomalous behaviors identified in the log data with anomalous behaviors identified in other datasets – Merely elaborates on step (c) of claim 1 and may be practically performed in the human mind using observation, evaluation, judgment, and/or opinion. For example, the correlating can be performed mentally by comparing (i.e., observing) the anomalous behaviors identified from the log data and the anomalous behaviors identified in the other datasets and determining (i.e., judging) if there are any correlations. Thus, this limitation falls within the mental processes grouping of abstract ideas. (Step 2A, Prong One: YES). Step 2A, Prong Two: No further additional limitation recited. Step 2B: No further additional limitations recited. [CLAIMS 11, 12, 17-19] Step 1: The claims are directed to an apparatus comprising: a memory; and a processing device, operatively coupled to the memory. Thus, the claims are to a machine, which is one of the statutory categories of invention. (Step 1: YES). Step 2A, Prong One: See the analysis provided above for claims 1, 2, 7-9 which are substantially similar. Step 2A, Prong Two: See the analysis provided above for claims 1, 2, 7-9 which are substantially similar. Claim 11 further recites the additional limitation: a memory for performing the claimed steps. is recited at a high level of generality and used as a tool to perform generic computer functions. See MPEP 2106.05(f). In these limitations, the memory is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using generic computer components. See MPEP 2106.05(f). Even when viewed in combination, the above-noted additional limitation does not integrate the recited judicial exception into a practical application (Step 2A, Prong Two: NO), and the claim is directed to the judicial exception. (Step 2A: YES). Step 2B: See the analysis provided above for claims See the analysis provided above for claims 1, 2, 7-9 which are substantially similar. Further, as discussed in Step 2A, Prong Two above, the recitation of a memory amounts to no more than mere instructions to apply the exception using a generic computer component. Even when considered in combination, the above-noted additional limitation represents mere instructions to implement an abstract idea or other exception on a computer, which does not provide an inventive concept. (Step 2B: NO). [CLAIM 20] Step 1: The claim recites a non-transitory computer readable storage medium storing instructions. Thus, the claim is to a manufacture, which is one of the statutory categories of invention. (Step 1: YES). Step 2A, Prong One: See the analysis provided above for claim 1, which is substantially similar. Step 2A, Prong Two: See the analysis provided above for claim 1, which is substantially similar. Claim 20 further recites the additional limitation: A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to performing the claimed steps. The computer readable storage medium is recited at a high level of generality and used as a tool to perform generic computer functions. See MPEP 2106.05(f). In these limitations, the computer readable storage medium is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using generic computer components. See MPEP 2106.05(f). Even when viewed in combination, the above-noted additional limitation does not integrate the recited judicial exception into a practical application (Step 2A, Prong Two: NO), and the claim is directed to the judicial exception. (Step 2A: YES). Step 2B: See the analysis provided above for claim 1, which is substantially similar. Further, as discussed in Step 2A, Prong Two above, the recitation of a computer readable storage medium to amounts to no more than mere instructions to apply the exception using a generic computer component. Even when considered in combination, the above-noted additional limitation represents mere instructions to implement an abstract idea or other exception on a computer, which does not provide an inventive concept. (Step 2B: NO). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 6-13, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Karpistsenko et al. (US Pub. 20180101529) in view of Chen (US Pub. 20050182582). Referring to claim 1, Karpistsenko discloses A method comprising: receiving, by a processing device, log data generated by a computing system [pars. 35, 42, 44, 52, and 86; input data is received from a data source (e.g., logs generated by a predictive model)]; executing an analytics operation on the log data [pars. 35 and 42; data processing is performed on the input data; the data processing comprises interacting with the predictive model to perform analytics relating to the input data]; and applying…associated with the log data to identify anomalous behaviors of the computing system [pars. 5 and 88; an anomaly detection algorithm is applied to the input data to detect model performance decay, address concept drift, outliers, and/or external events such as marketing campaign system usage activity (i.e., anomalous behaviors of the predictive model)]. Karpistsenko does not appear to explicitly disclose applying pattern recognition. However, Chen discloses applying pattern recognition [pars. 45 and 46; a performance monitoring system compares received data against previously developed pattern signatures]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the data processing taught by Karpistsenko so that the input data is compared against pattern signatures as taught by Chen, with a reasonable expectation of success. The motivation for doing so would have been to predict the behavior of various applications and preemptively adapt a monitoring scheme in anticipation of that behavior [Chen, par. 46]. Referring to claim 2, Chen discloses The method of claim 1, wherein applying pattern recognition to the log data comprises comparing the log data to a plurality of stored fingerprints representing known behaviors of the computing system [pars. 45 and 46; note the comparing of the received data against the previously developed pattern signatures]. Referring to claim 3, Karpistsenko discloses The method of claim 1, further comprising: receiving unstructured log data from the computing system; and converting the unstructured log data into a structured dataset prior to executing the analytics operation [pars. 36, 37, and 42-44, 48, 52, 55, 60, and 68; pre-processing of the input data includes formatting the input data into a useable data and storing the pre-processed data in an intermediate dataset such as a directory or sub-directory of a file storage (i.e., structured data)]. Referring to claim 6, Karpistsenko discloses The method of claim 1, further comprising: detecting that additional processing resources are required for the analytics operation; and allocating the additional processing resources to the analytics operation [par. 107; runtime optimization may confiture the number of server instances based on performance metrics]. Referring to claim 7, Karpistsenko discloses The method of claim 1, further comprising: generating auditing information for the analytics operation executed on the log data [pars. 5, 29, 44, 45, 52, 77, 86-88, and 107; data related to the data processing includes output data (e.g., model performance decay, concept drift, outliers, performance data, visualization data, training progression metrics, run-time performance metrics)]. Referring to claim 8, Karpistsenko discloses The method of claim 1, further comprising: generating trending information associated with the analytics operation executed on the log data [pars. 29, 77, and 104; note the tracking or improvement of models over time based on performance metrics quantified over a time period of statistical analysis of historical data]. Referring to claim 9, Chen discloses The method of claim 1, wherein applying pattern recognition to the log data comprises: correlating anomalous behaviors identified in the log data with anomalous behaviors identified in other datasets [par. 45-47; note the comparing of the received data with the previously developed pattern signatures; see also Karpistsenko, par. 88, disclosing anomaly detection]. Referring to claim 10, Chen discloses The method of claim 1, further comprising: determining, based on the log data, a predicted resource requirement for completing the analytics operation; and allocating processing resources according to the predicted resource requirement [pars. 5, 44-46, 58, and 164; the performance monitoring system detects performance patterns based on the previously developed pattern signatures; the performance patterns are used to predict the behavior (e.g., resource utilization) of applications, preemptively adapt the monitoring scheme in anticipation of that behavior, and take corrective action (e.g., perform load balancing, allocate another processing node)]. Referring to claim 11, see at least the rejection for claim 1. Karpistsenko further discloses An apparatus comprising: a memory; and a processing device, operatively coupled to the memory, configured to perform the claimed steps [fig. 9, computer system 900, processor 902, RAM 904, computer-readable storage medium 910 comprising functional modules]. Referring to claim 12 see the rejection for claim 2. Referring to claim 13 see the rejection for claim 3. Referring to claim 16 see the rejection for claim 6. Referring to claim 17 see the rejection for claim 7. Referring to claim 18 see the rejection for claim 8. Referring to claim 19 see the rejection for claim 9. Referring to claim 20, see at least the rejection for claim 1. Karpistsenko further discloses A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to perform the claimed steps [fig. 9, computer system 900, processor 902, RAM 904, computer-readable storage medium 910 comprising functional modules]. Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Karpistsenko and Chen in view of Davila et al. (US Pub. 20190065257). Referring to claim 4, Karpistsenko discloses The method of claim 1, further comprising: receiving log data from a plurality of data producers [pars. 35, 42, 44, 52, and 86; the input data comprises data from a plurality of data stores]. Karpistsenko and Chen do not appear to explicitly disclose allocating separate processing resources to analyze the log data of each data producer. However, Davila discloses allocating separate processing resources to analyze the log data of each data producer [pars. 36 and 64; a set of dedicated CPUs are allocated for processing tasks (e.g., data analytics processing tasks) of an I/O resource]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the data processing taught by the combination of Karpistsenko and Chen so that a set of dedicated CPUs are allocated to processing data from each data source, with a reasonable expectation of success. The motivation for doing so would have been to meet performance requirements and yet allow optimal use of CPU resources [Davila, par. 23]. Referring to claim 14 see the rejection for claim 4. Claims 5 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Karpistsenko and Chen in view of Sinha et al. (US Pat. 8452465). Referring to claim 5, Karpistsenko does not appear to explicitly disclose The method of claim 1, further comprising: detecting that execution of the analytics operation has failed; and reallocating processing resources to continue the analytics operation on the log data. However, Sinha discloses The method of claim 1, further comprising: detecting that execution of the analytics operation has failed; and reallocating processing resources to continue the analytics operation on the log data [col. 1, lines 13-54; upon detecting failure of one or more tasks, a reconfiguration strategy is generated to reconfigure a task which failed on a working ECU (e.g., due to resource limitations) to execute on another ECU]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the data processing taught by the combination of Karpistsenko and Chen so that when tasks fail due to resource limitations, the tasks are reconfigured based on a reconfiguration strategy as taught by Sinha, with a reasonable expectation of success. The motivation for doing so would have been to keep a system operational upon failure to execute a task [Sinha, col. 1, lines 24-26]. Referring to claim 15 see the rejection for claim 5. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to GRACE PARK whose telephone number is (571)270-7727. The examiner can normally be reached M-F 8AM-5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, TAMARA KYLE can be reached at (571)272-4241. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Grace Park/Primary Examiner, Art Unit 2144
Read full office action

Prosecution Timeline

Dec 17, 2025
Application Filed
Apr 15, 2026
Non-Final Rejection mailed — §101, §103
Jul 14, 2026
Response Filed
Aug 04, 2026
Final Rejection mailed — §101, §103
Sep 10, 2026
Applicant Interview (Telephonic)
Sep 10, 2026
Examiner Interview Summary

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748944
SYSTEM AND METHOD FOR MACHINE LEARNING ARCHITECTURE FOR OUT-OF-DISTRIBUTION DATA DETECTION
4y 8m to grant Granted Sep 29, 2026
Patent 12748819
REDUCING UTILIZATION OF COMPUTATIONAL RESOURCES ASSOCIATED WITH SEGMENTING DATASETS VIA A CLUSTER- ENSEMBLE MODEL SYSTEMS AND METHODS
2y 11m to grant Granted Sep 29, 2026
Patent 12737646
TIERED ANOMALY DETECTION
3y 3m to grant Granted Sep 15, 2026
Patent 12711430
PROCESSORS AND METHODS FOR SELECTING A TARGET MODEL FOR AN UNLABELED DATASET
3y 7m to grant Granted Aug 18, 2026
Patent 12694259
LOW POWER MULTI-STAGE SELECTABLE NEURAL NETWORK SUPPRESSION
4y 10m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
94%
With Interview (+17.6%)
3y 4m (~2y 6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 573 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month