Program, analysis assistance device, analysis assistance system, and analysis assistance method

The program and system address the inefficiencies in analyzing PLC log data by providing tailored analytical know-how based on feature data and similarity calculations, enhancing maintenance efficiency in factory automation sites.

WO2026022877A1PCT designated stage Publication Date: 2026-01-29MITSUBISHI ELECTRIC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/026084
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-22
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

Existing analysis techniques for log data from programmable logic controllers (PLCs) in factory automation sites are inadequate as they do not account for the unique environmental and operational variations of equipment, leading to inefficient problem-solving processes.

Method used

A program and system that extracts and presents analysis processes based on the characteristics of log data using feature data acquisition, similarity calculation, and extraction methods to provide analytical know-how tailored to the specific context of the PLC and controlled devices.

Benefits of technology

Facilitates efficient analysis of log data by presenting relevant past analysis processes as know-how, improving maintenance efficiency and problem-solving effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024026084_29012026_PF_FP_ABST
    Figure JP2024026084_29012026_PF_FP_ABST
Patent Text Reader

Abstract

This program causes a computer to function as: a feature data acquisition unit (103) that acquires feature data (205) indicating features of device log data (201) of a PLC or a controlled device, or features of event log data (202) of the PLC or the controlled device; a similarity calculation unit (106) that determines the similarity between the feature data (205) acquired by the feature data acquisition unit (103) and feature data (205) stored in a database (200) in association with analysis process data (204) indicating analysis processes; an extraction unit (107) that, on the basis of the similarity, extracts analysis process data (204) from the database (200) that are associated with feature data (205) that are similar to the feature data (205) acquired by the feature data acquisition unit (103); and a presentation unit (108) that presents the extracted analysis process data (204) to a user as analysis know-how.
Need to check novelty before this filing date? Find Prior Art

Description

Program, analysis support device, analysis support system, and analysis support method

[0001] The present disclosure relates to a program, an analysis support device, an analysis support system, and an analysis support method.

[0002] When a problem occurs in a wide variety of devices connected to a programmable logic controller (PLC), the PLC outputs log data necessary for analyzing the problem. A maintenance technician who handles the problem must first analyze the log data, but this analysis can take a long time. To address this issue, various techniques for supporting the analysis of log data are known. For example, Patent Literature 1 discloses a technique for extracting from a database the history of analysis processes that use analysis tools similar to the type of log data to be analyzed, and providing the extracted history as analysis support information.

[0003] Japanese Patent Application Laid-Open No. 2016-29516

[0004] While the history of the above-mentioned analysis process is useful as analytical know-how, in factory automation sites, even the same equipment or equipment with the same model number does not necessarily cause the same problem depending on the environment in which the equipment is installed, the conditions under which the equipment is used, etc. For this reason, analysis processes in which only the type of log data to be analyzed and the analysis tools are similar may not be useful for the log data that maintenance personnel are trying to analyze.

[0005] The present disclosure has been made in consideration of the above circumstances, and aims to provide a program, an analysis support device, an analysis support system, and an analysis support method that are capable of presenting data indicating past analysis processes extracted based on the characteristics of log data as analysis know-how.

[0006] In order to achieve the above-mentioned object, the program of the present disclosure causes a computer to function as: a feature data acquisition means for acquiring feature data indicating features of device log data in which values ​​of devices used in a programmable logic controller or a controlled device of the programmable logic controller are recorded, or feature data indicating features of event log data in which values ​​indicating events that have occurred in the programmable logic controller or the controlled device are recorded; a similarity calculation means for calculating the similarity between feature data stored in a database in association with analysis process data indicating the process of analysis performed on the device log data or the event log data, and feature data acquired by the feature data acquisition means; an extraction means for extracting, from the database, analysis process data associated with feature data similar to the feature data acquired by the feature data acquisition means, based on the similarity calculated by the similarity calculation means; and a presentation means for presenting the analysis process data extracted by the extraction means as analysis know-how.

[0007] According to the present disclosure, it is possible to provide a program, an analysis support device, an analysis support system, and an analysis support method that can present data indicating past analysis processes extracted based on the characteristics of log data as analysis know-how.

[0008] FIG. 1 is a diagram showing an analysis support system according to an embodiment; FIG. 1 is a block diagram showing a hardware configuration of an information processing device according to an embodiment; FIG. 2 is a diagram showing details of the functional configuration of the analysis support device according to an embodiment and data stored in a database; FIG. 3 is a diagram showing an example of device log data according to an embodiment; FIG. 4 is a diagram showing an example of event log data according to an embodiment; FIG. 5 is a diagram showing an example of a graphical display of device log data according to an embodiment; FIG. 6 is a diagram showing an example of a graphical display of correlation of device log data according to an embodiment;

[0009] An analysis support system according to an embodiment is a system that presents analytical know-how to a user. Fig. 1 shows an analysis support system 1 according to the embodiment. The analysis support system 1 includes an analysis support device 100 and a database 200. The analysis support device 100 is communicably connected to a PLC 300 via a wired or wireless communication network 500.

[0010] Analysis support device 100 is a device for analyzing log data of PLC 300 and controlled device 400. Analysis support device 100 is used, for example, by a maintenance technician for PLC 300 and controlled device 400, or a designer of a line layout including PLC 300 and controlled device 400. Analysis support device 100 also presents analysis processes that have been performed in the past to the user as analysis know-how.

[0011] Database 200 is a device that stores data used in analysis by analysis support device 100 and data indicating past analysis steps. The data used in analysis by analysis support device 100 is, for example, log data including device log data and event log data, which will be described later, and video data of lines. The data indicating past analysis steps is, for example, data indicating past analysis steps performed on log data by a veteran maintenance technician.

[0012] The PLC 300 is a device that controls the controlled device 400. When a problem occurs in the PLC 300 or the controlled device 400, the PLC 300 outputs log data of the PLC 300 and the controlled device 400.

[0013] The controlled device 400 is a factory automation (FA) device controlled by the PLC 300, and also includes an expansion unit connected to the PLC 300. The controlled device 400 is, for example, a programmable display, a servo, an inverter, a robot, a motion unit, a camera linkage function unit, or the like.

[0014] FIG. 2 shows an example of the hardware configuration of an information processing device 10 in which the analysis support device 100 is realized.

[0015] The information processing device 10 has a processor 11 that executes various processes, a main memory unit 12 used as a work area for the processor 11, an auxiliary memory unit 13 that stores various data used in the processes of the processor 11, a communication unit 14 for communicating with external devices, an input unit 15 that acquires input information, and an output unit 16 that presents various information. The main memory unit 12, the auxiliary memory unit 13, the communication unit 14, the input unit 15, and the output unit 16 are all connected to the processor 11 via a bus 17.

[0016] The processor 11 includes a CPU (Central Processing Unit). The processor 11 executes programs stored in the auxiliary storage unit 13 to realize various functions of the information processing device 10.

[0017] The main memory unit 12 includes a RAM (Random Access Memory). Programs are loaded into the main memory unit 12 from the auxiliary memory unit 13. The main memory unit 12 is used as a working area for the processor 11.

[0018] The auxiliary storage unit 13 includes a non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read-Only Memory). In addition to programs, the auxiliary storage unit 13 stores various data used in the processing of the processor 11. In accordance with instructions from the processor 11, the auxiliary storage unit 13 supplies the processor 11 with data used by the processor 11 and stores the data supplied from the processor 11.

[0019] The communication unit 14 includes a network interface circuit for communicating with an external device. The communication unit 14 receives a signal from the external device and outputs data indicated by the signal to the processor 11. The communication unit 14 also transmits a signal indicating the data output from the processor 11 to the external device.

[0020] The input unit 15 includes input devices such as input keys, a pointing device, a microphone, a camera, etc. The input unit 15 acquires information input by the user of the information processing device 10 and notifies the processor 11 of the acquired information.

[0021] The output unit 16 includes output devices such as an LCD (Liquid Crystal Display) and a speaker. The output unit 16 may be configured as a touch screen integrally formed with a pointing device constituting the input unit 15. The output unit 16 presents various information to the user in accordance with instructions from the processor 11.

[0022] FIG. 3 shows the functional configuration of the analysis support device 100 of this embodiment and details of the data stored in the database 200.

[0023] functionally, the analysis support device 100 of FIG. 3 comprises an analysis operation unit 101 that accepts user operations for analysis, an analysis process acquisition unit 102 that acquires analysis process data indicating the process of analysis by the user, a feature data acquisition unit 103 that acquires feature data of log data to be analyzed, an analysis result acquisition unit 104 that acquires analysis result data indicating the results of the analysis, a countermeasure process acquisition unit 105 that acquires countermeasure process data indicating the process of countermeasures taken for the PLC 300 or the controlled device 400, a similarity calculation unit 106 that calculates the similarity between the feature data of the log data to be analyzed and the feature data of the log data stored in the database 200, an extraction unit 107 that extracts analysis process data from the database 200, a presentation unit 108 that presents the extracted analysis process data as analysis know-how, and an analysis application unit 109 that applies the analysis of the process indicated by the selected analysis process data to the log data to be analyzed.

[0024] The database 200 stores device log data 201 and event log data 202 output from the PLC 300, related data 203 related to the analysis of the log data, analysis process data 204 indicating the analysis process, feature data 205 acquired by the feature data acquisition unit 103, analysis result data 206 indicating the results of the analysis, countermeasure process data 207 indicating the countermeasure process, and similarity calculation method data 208 indicating the method for calculating the similarity described below.

[0025] The analysis operation unit 101 provides the user with an analysis tool for performing analysis using device log data 201, event log data 202, and related data 203, and accepts analysis operations from the user. The analysis operation unit 101 then executes analysis processing based on the accepted operations. The analysis operation unit 101 is realized by the processor 11, the communication unit 14, the input unit 15, and the output unit 16.

[0026] The device log data 201 is data that records values ​​of devices used in the PLC 300 and the controlled device 400. For example, the device log data 201 is time-series data of values ​​of devices used in the control program of the PLC 300.

[0027] Fig. 4 shows an example of device log data 201. In the device log data 201 in Fig. 4, values ​​of devices such as "Sensor A," "Sensor B," "Device A," and "Device B" are recorded in chronological order. Note that the device log data 201 in Fig. 4 is just an example, and depending on the PLC 300, values ​​of tens of thousands to hundreds of thousands of devices may be included, and further, the number of records may be in the order of tens of millions.

[0028] The event log data 202 is data in which values ​​indicating events that have occurred in the PLC 300 and the controlled device 400 are recorded. For example, the event log data 202 is time-series data of events such as a change in an input value of the controlled device 400, writing of firmware, and an error notification from another unit.

[0029] Fig. 5 shows an example of the event log data 202. In the event log data 202 of Fig. 5, events that occurred for "sensor A" and "sensor B" are recorded in chronological order. Note that the event log data 202 of Fig. 5 is an example, and depending on the PLC 300, a large number of event types and records may be included.

[0030] The related data 203 is data related to the analysis of the device log data 201 and the event log data 202 and is useful for analyzing the device log data 201 and the event log data 202. For example, the related data 203 may be a video of a line including the PLC 300 or the controlled device 400 to which the device log data 201 and the event log data 202 are output, project data executed by the PLC 300, the device configuration of the system including the PLC 300 and the controlled device 400, a parts list, a device simulation, etc. The video of the line may be, for example, a device monitoring video for monitoring the device. The device configuration includes information indicating the roles of the PLC 300 and the controlled device 400 in the system including the PLC 300 and the controlled device 400. The information indicating the roles may be, for example, information indicating that the PLC 300 is a PLC that performs I / O processing or information indicating that the PLC is a PLC that controls other PLCs in an integrated manner. The device simulation is data for simulating the operation of the PLC 300 and the controlled device 400, for example, project data for 3D simulator software.

[0031] The analysis tool is a tool for analyzing the device log data 201, the event log data 202, and the related data 203. For example, the analysis tool is a tool capable of performing various numerical analyses such as correlation analysis, frequency analysis, clustering, and maximum value detection, a spreadsheet tool, a video playback tool, etc.

[0032] For example, when the analysis operation unit 101 receives from the user a designation of a time range of the device log data 201 and event log data 202 to be analyzed, the analysis operation unit 101 stores the device log data 201 and event log data 202 within the designated time range as the device log data 201 and event log data 202 to be analyzed in the database 200. Furthermore, when the analysis operation unit 101 receives from the user a designation of related data 203 to be analyzed, the analysis operation unit 101 associates the designated related data 203 with the device log data 201 and event log data 202 to be analyzed and stores the associated data in the database 200. Then, when the analysis operation unit 101 receives from the user an analysis operation such as graph display or display of correlations between data, the analysis operation unit 101 executes analysis processing such as graph display or display of correlations between data on the device log data 201 and event log data 202 to be analyzed.

[0033] For example, when "user X" specifies a time range in response to a system trouble, the analysis operation unit 101 stores the device log data 201 and event log data 202 for the specified time range in the database 200. Hereinafter, it is assumed that "user X" specifies a time range from "January 15, 2024, 8:00:00" to "January 15, 2024, 9:00:00" for the device log data 201 in FIG. 4 and the event log data 202 in FIG. 5 . Furthermore, when "user X" specifies related data 203, such as information indicating the device monitoring video and the roles of the PLC 300 and the controlled device 400, the analysis operation unit 101 associates the specified related data 203 with the device log data 201 and event log data 202 to be analyzed, and stores the associated data 203 in the database 200. Next, "user X" tried to check the device monitoring video of the related data 203, but the device monitoring video was long and he did not know which part to check. In this situation, an example will be described in which "user X" performs "analysis X" consisting of the following analysis steps (1) to (4).

[0034] "User X" used a spreadsheet tool to graphically display the portion of the device log data 201 in Fig. 4 for which a time range was specified (analysis step (1)). Fig. 6 shows an example of the device log data 201 graphically displayed in the analysis step (1).

[0035] "User X" checked the graph display of the device log data 201 in Fig. 6, and focused on the relationship between "Device A" and "Device B," and used a spreadsheet tool to graph the correlation between "Device A" and "Device B" (analysis step (2)). Fig. 7 shows an example of the correlation graph displayed in the analysis step (2).

[0036] “User X” used a spreadsheet tool to display the event log data 202 in FIG. 5 at the point corresponding to the time when the correlation between the values ​​of “Device A” and “Device B” changed, i.e., around the time “January 15, 2024, 8:59:40” (analysis step (3)).

[0037] "User X" confirmed that there was a relationship between the values ​​of "Sensor A" and "Sensor B" and the values ​​of "Device A" and "Device B" because the relationship between the event values ​​of "Sensor A" and "Sensor B" changed at the time the correlation between the values ​​of "Device A" and "Device B" changed in the event log data 202. Therefore, "User X" used a video playback tool to play back the device monitoring video of "Sensor A" and "Sensor B" from around "8:59:40 on January 15, 2024," when the relationship between the event values ​​changed, and confirmed their operation (analysis step (4)). As a result, "User X" confirmed that the indicator for "Sensor B" had not changed since the time confirmed in the event log data 202.

[0038] The analysis process acquisition unit 102 acquires the operation received by the analysis operation unit 101 as analysis process data 204 indicating the analysis process. Then, the analysis process acquisition unit 102 associates the acquired analysis process data 204 with the device log data 201 and event log data 202 that were the analysis targets, and stores the data in the database 200. The analysis process acquisition unit 102 is realized by the processor 11 and the communication unit 14.

[0039] The analysis process data 204 indicates the content of the analysis performed by the user, and includes information identifying the data that was the subject of the analysis, information identifying the analysis tool used for the analysis, the order of the analysis operations, and information indicating the time when the analysis was performed.

[0040] An example of the analysis process data 204 is shown in Fig. 8. The analysis process data 204 in Fig. 8 was acquired by the analysis process acquisition unit 102 for "analysis X" performed by "user X," and the analysis process is shown in the form of a flowchart. Steps S101 to S104 in the flowchart in Fig. 8 correspond to analysis processes (1) to (4).

[0041] For example, the analysis process acquisition unit 102 acquires the analysis process data 204 for "Analysis X" based on the analysis operation performed by "User X," and stores the analysis process data 204 for "Analysis X" in the database 200 in association with the device log data 201 and event log data 202 to be analyzed.

[0042] The feature data acquisition unit 103 acquires feature data 205 indicating features of the device log data 201 or the event log data 202 to be analyzed. Then, the feature data acquisition unit 103 associates the acquired feature data 205 with analysis process data 204 indicating the process of analysis performed on the device log data 201 and the event log data 202 to be analyzed, and stores the data in the database 200. The feature data acquisition unit 103 is realized by the processor 11. The feature data acquisition unit 103 is an example of feature data acquisition means.

[0043] The feature data 205 is data indicating features of the device log data 201 or event log data 202 to be analyzed. For example, the feature data 205 includes at least one of data indicating the type of device, data indicating features of time-series changes in the value of the device, data indicating the association between the device and other devices, data indicating the type of event, data indicating time-series changes in the value indicating the event, data indicating the association between the occurrence time of the event and the occurrence time of other events, data indicating the association between the occurrence frequency of the event and the occurrence frequency of other events, and data indicating the association between the time-series changes in the value of the device and the time-series changes in the value indicating the event.

[0044] The type of device is, for example, a bit device, a word device, etc. The relationship between a device and another device is, for example, the correlation between the time change of the device value and the time change of the other device value. The type of event is, for example, a value change, a firmware update, a PLC program write, an error, etc. The relationship between the occurrence time of an event and the occurrence time of another event is the correlation between the occurrence time of the event and the time change of the other event. The relationship between the occurrence frequency of an event and the occurrence frequency of the other event is, for example, the correlation between the occurrence frequency of the event and the time change of the value indicating the event. The relationship between the time change of the device value and the time change of the value indicating the event is, for example, the relationship indicating whether the change of the device value and the change of the value indicating the event are synchronized.

[0045] For example, the feature data acquisition unit 103 acquires feature data 205 of the device log data 201 or event log data 202 that “user X” has targeted for analysis, and stores the acquired feature data 205 in the database 200 in association with the device log data 201 and event log data 202 targeted for analysis.

[0046] The analysis result acquisition unit 104 acquires analysis result data 206 indicating the results of the analysis. Then, the analysis result acquisition unit 104 associates the acquired analysis result data 206 with the analysis process data 204 and stores it in the database 200. The analysis result acquisition unit 104 is realized by the processor 11, the communication unit 14, and the input unit 15.

[0047] The analysis result data 206 is data indicating whether the analysis performed by the user was successful. Whether the analysis was successful is determined by the user who performed the analysis. For example, the user may determine whether the analysis was successful based on whether the countermeasures taken to address the problem after the analysis were successful.

[0048] For example, when "user X" inputs data indicating that "analysis X" of analysis steps (1) to (4) was successful to analysis support device 100, analysis result acquisition unit 104 acquires analysis result data 206 indicating that "analysis X" was successful. Then, analysis result acquisition unit 104 associates analysis result data 206 indicating that "analysis X" was successful with analysis step data 204 for "analysis X" and stores it in database 200.

[0049] The countermeasure process acquisition unit 105 acquires countermeasure process data 207 indicating the process of countermeasures taken by the user on the PLC 300 or the controlled device 400. Then, the countermeasure process acquisition unit 105 associates the acquired countermeasure process data 207 with the analysis process data 204 and stores it in the database 200. The countermeasure process acquisition unit 105 is realized by the processor 11, the communication unit 14, and the input unit 15.

[0050] The countermeasure process data 207 indicates the content of the countermeasure that the user has taken for the PLC 300 or the controlled device 400. The countermeasures include, for example, stopping the PLC 300 or the controlled device 400, replacing the PLC 300 or the controlled device 400, test running the PLC 300 or the controlled device 400 after replacement, checking the log data during the test run, updating the parts list, updating the firmware of the PLC 300, changing the device configuration, etc.

[0051] In the following, an example will be described in which "user X" performs "analysis X" and then "measure X" consisting of countermeasure steps (1) to (5).

[0052] "User X" stopped "sensor B" and the device related to "sensor B" in order to replace "sensor B" (countermeasure step (1)).

[0053] "User X" replaced "sensor B" (measure step (2)).

[0054] After replacing "Sensor B," "User X" performed a trial run of "Sensor B" and the equipment related to "Sensor B" to confirm whether the replaced "Sensor B" was operating correctly (countermeasure step (3)).

[0055] "User X" confirmed that the replaced "sensor B" was operating correctly in the log data during the test run (measures step (4)).

[0056] "User X" updated the information of "sensor B" before replacement to the information of "sensor B" after replacement in the parts list (measure step (5)).

[0057] 9 shows an example of the countermeasure process data 207. The countermeasure process data 207 in FIG. 9 was acquired by the countermeasure process acquisition unit 105 for "Countermeasure X" taken by "User X," and the countermeasure process is shown in the form of a flowchart. Steps S201 to S205 in the flowchart in FIG. 9 correspond to countermeasure processes (1) to (5).

[0058] For example, when "user X" inputs data indicating the contents of countermeasure steps (1) to (5) into the analysis support device 100, the countermeasure step acquisition unit 105 acquires countermeasure step data 207 for "countermeasure X." Then, the countermeasure step acquisition unit 105 associates the countermeasure step data 207 for "countermeasure X" with the analysis step data 204 for "analysis X," and stores them in the database 200.

[0059] The similarity calculation unit 106 calculates the similarity between the feature data 205 stored in the database 200 in association with analysis process data 204 indicating the process of analysis performed on the device log data 201 or the event log data 202, and the feature data 205 acquired by the feature data acquisition unit 103. The similarity calculation unit 106 is realized by the processor 11, the communication unit 14, and the input unit 15. The similarity calculation unit 106 is an example of a similarity calculation means.

[0060] For example, when "user Y" specifies a time range from "February 25, 2024, 8:00:00" to "February 25, 2024, 9:00:00" in response to a system problem, the analysis operation unit 101 stores the device log data 201 and event log data 202 for the specified time range in the database 200 as the device log data 201 and event log data 202 to be analyzed. FIG. 10 shows the device log data 201 for the time range specified by "user Y". FIG. 11 shows the event log data 202 for the time range specified by "user Y". When "user Y" specifies related data 203 such as device monitoring video and information indicating the roles of the PLC 300 and the controlled device 400, the analysis operation unit 101 associates the specified related data 203 with the device log data 201 and event log data 202 to be analyzed, and stores the specified related data 203 in the database 200.

[0061] Next, when "user Y" selects a button in analysis support device 100 to request the presentation of analytical know-how, feature data acquisition unit 103 acquires feature data 205 indicating the features of device log data 201 and the features of event log data 202 for the time range specified by "user Y." Then, similarity calculation unit 106 calculates the similarity between feature data 205 stored in database 200 and feature data 205 indicating the features of device log data 201 or the features of event log data 202 for the time range specified by "user Y," in accordance with the method indicated in similarity calculation method data 208.

[0062] The similarity calculation method data 208 indicates a method for calculating the similarity, and is set by a user of the analysis support device 100. For example, the similarity calculation method data 208 indicates a method in which, in feature data 205 indicating the characteristics of the device log data 201 or the event log data 202 to be analyzed by the user and feature data 205 stored in the database 200, “1” is added each time there is data that is determined to be the same based on a criterion predetermined by the user, among data (1) indicating the type of device, data (2) indicating the characteristics of time-series changes in the value of the device, data (3) indicating the association between the device and other devices, data (4) indicating the type of event, data (5) indicating the time-series changes in the value indicating the event, data (6) indicating the association between the occurrence time of an event and the occurrence time of other events, data (7) indicating the association between the occurrence frequency of an event and the occurrence frequency of other events, and data (8) indicating the association between the time-series changes in the value of the device and the time-series changes in the value indicating the event.

[0063] For example, if the similarity calculation unit 106 determines that all of the above data (1) to (8) match between the feature data 205 associated with the device log data 201 and event log data 202 that the user is analyzing and the feature data 205 stored in the database 200, the similarity calculation unit 106 calculates the similarity as "8".

[0064] The similarity calculation unit 106 corrects the similarity based on information indicating the roles of the PLC 300 and the controlled device 400 in the system including the PLC 300 and the controlled device 400 .

[0065] For example, the similarity calculation method data 208 indicates a method of adding "1" when the same role is indicated in the information indicating the role included in the related data 203. For example, if the information indicating the role included in the related data 203 associated with the device log data 201 and event log data 202 to be analyzed and the information indicating the role included in the associated data 203 associated with the device log data 201 and event log data 202 for which the similarity "8" is calculated and stored in the database 200 both indicate that the PLC controls other PLCs in an integrated manner, the similarity calculation unit 106 adds "1" to the similarity "8" to obtain a similarity of "9".

[0066] The similarity calculation unit 106 corrects the similarity based on the analysis result data 206 indicating whether the analysis of the process indicated by the analysis process data 204 was successful or not.

[0067] For example, the similarity calculation method data 208 further indicates a method of adding "1" when the analysis result data 206 indicates that the analysis was successful. For example, when the analysis result data 206 indicating that the analysis was successful is associated with the analysis step data 204 of the device log data 201 and the event log data 202 for which the similarity "9" stored in the database 200 has been found, the similarity calculation unit 106 adds "1" to the similarity "9" to find a similarity of "10."

[0068] The similarity calculation unit 106 corrects the similarity based on information indicating the time when the analysis of the process indicated by the analysis process data 204 was performed.

[0069] For example, the similarity calculation method data 208 may further indicate a method of adding "1" when the information indicating the time when the analysis was performed, which is included in the analysis process data 204, indicates the time closest to the present, i.e., when the analysis process data 204 is the most recent. For example, when the analysis process data 204 of the most recent analysis is associated with the device log data 201 and event log data 202 stored in the database 200 for which the similarity "10" has been calculated, the similarity calculation unit 106 adds "1" to the similarity "10" to calculate a similarity "11".

[0070] The extraction unit 107 extracts, from the database 200, analysis process data 204 associated with feature data similar to the feature data 205 acquired by the feature data acquisition unit 103, based on the similarity calculated by the similarity calculation unit 106. The extraction unit 107 is realized by the processor 11, the communication unit 14, and the input unit 15. The extraction unit 107 is an example of an extraction means.

[0071] For example, the extraction unit 107 extracts, from the database 200, analysis process data 204 associated with feature data 205 that has a similarity equal to or greater than a predetermined threshold value with respect to feature data 205 of device log data 201 and event log data 202 that are the analysis targets of “user Y.” The threshold value is set by the user of the analysis support device 100.

[0072] The presentation unit 108 presents, as analytical know-how, the analysis process data 204 extracted by the extraction unit 107. The presentation unit 108 is realized by the processor 11, the communication unit 14, the input unit 15, and the output unit 16. The presentation unit 108 is an example of a presentation means.

[0073] The analytical know-how is information that is useful when a user analyzes log data. In addition to the analytical process data 204 extracted by the extraction unit 107, the presentation unit 108 may present, as analytical know-how, the device log data 201, the event log data 202, the related data 203, and the feature data 205 associated with the analytical process data 204. The data that the presentation unit 108 presents as analytical know-how can be specified by the user.

[0074] Here, the presenting unit 108 displays a list of analytical know-how in order of similarity.

[0075] For example, suppose that the extraction unit 107 extracts a plurality of analysis process data 204-1 to 204-10, and the similarities calculated for the feature data 205 associated with the device log data 201 and the event log data 202 of the analysis process data 204-1 to 204-10 are "S1" to "S10." In this case, the presentation unit 108 displays a list of the analysis know-how including the analysis process data 204-1 to 204-10 in descending order of similarity "S1" to "S10."

[0076] Furthermore, the presentation unit 108 presents the countermeasure process data 207 associated with the analysis process data 204 extracted by the extraction unit 107 .

[0077] For example, when the analysis process data 204-1 is selected by the user from among the analysis process data 204-1 to 204-10 presented as analysis know-how, the presentation unit 108 acquires the countermeasure process data 207-1 associated with the selected analysis process data 204-1 from the database 200 and presents the countermeasure process data 207-1 to the user.

[0078] The analysis application unit 109 applies the analysis of the process indicated by the analysis process data 204 selected by the user from among the analysis process data 204 presented as analytical know-how to the device log data 201 or the event log data 202 from which the feature data 205 has been acquired by the feature data acquisition unit 103. The analysis application unit 109 is realized by the processor 11, the communication unit 14, the input unit 15, and the output unit 16. The analysis application unit 109 is an example of an analysis application means.

[0079] For example, when "User Y" selects analysis process data 204-1 from among analysis process data 204-1 to 204-10 included in the displayed list of analytical know-how, the analysis application unit 109 applies the analysis of the process of the analysis process data 204-1 to the device log data 201 and event log data 202 that "User Y" is to analyze. For example, if the analysis processes of the analysis process data 204-1 are analysis processes (1) to (4) of "Analysis X," the analysis application unit 109 applies analysis process (1) of "Analysis X" to the device log data 201 and event log data 202 that "User Y" is to analyze, and displays a graph similar to that of FIG. 6, as shown in FIG. 12. Furthermore, the analysis application unit 109 applies analysis process (2) of "Analysis X" to the device log data 201 and event log data 202 that "User Y" is to analyze, and displays a graph similar to that of FIG. 7, as shown in FIG. 13. The analysis application unit 109 also applies the analysis step (3) of "Analysis X" to the device log data 201 and event log data 202 that "User Y" is analyzing, and displays the event log data 202 in Fig. 11 using a spreadsheet tool. The analysis application unit 109 also applies the analysis step (4) of "Analysis X" to the device log data 201 and event log data 202 that "User Y" is analyzing, and puts the video playback tool on standby so that the device monitoring videos of "Sensor A" and "Sensor B" can be played back from around "February 25, 2024, 8:59:40," when the relationship between the event values ​​changed.

[0080] Next, the analytical know-how accumulation process performed by the analysis support device 100 according to this embodiment will be described with reference to the flowchart in Fig. 14. The accumulation process in Fig. 14 is executed, for example, when a user starts an analysis using the analysis support device 100.

[0081] The analysis operation unit 101 associates the device log data 201 and event log data 202 for a time range specified by the user with the related data 203 specified by the user and stores them in the database 200 (step S301). Next, the analysis process acquisition unit 102 acquires the operation accepted by the user at the analysis operation unit 101 as analysis process data 204 indicating the analysis process, and stores the acquired analysis process data 204 in association with the device log data 201 and event log data 202 to be analyzed in the database 200 (step S302). Furthermore, the feature data acquisition unit 103 acquires feature data 205 indicating the features of the device log data 201 or the event log data 202 to be analyzed, and stores the acquired feature data 205 in association with the device log data 201 and event log data 202 to be analyzed in the database 200 (step S303). Then, the analysis result acquiring unit 104 acquires analysis result data 206 indicating the results of the analysis, and stores the acquired analysis result data 206 in the database 200 in association with the analysis process data 204 (step S304). Furthermore, the countermeasure process acquiring unit 105 acquires countermeasure process data 207 indicating the process of the countermeasure taken by the user for the PLC 300 or the controlled device 400, and stores the acquired countermeasure process data 207 in the database 200 in association with the analysis process data 204 (step S305).

[0082] For example, the analysis operation unit 101 stores the device log data 201 and event log data 202 for the time range from "January 15, 2024, 8:00:00" to "January 15, 2024, 9:00:00" specified by "User X" and the specified related data 203 in the database 200. Next, the analysis process acquisition unit 102 acquires analysis process data 204 for "Analysis X" based on the analysis operation performed by "User X", associates the analysis process data 204 for "Analysis X" with the device log data 201 and event log data 202 to be analyzed, and stores the data in the database 200. In addition, the analysis process acquisition unit 102 acquires feature data 205 of the device log data 201 or event log data 202 that "User X" has targeted for analysis, and stores the acquired feature data 205 in the database 200, associates the device log data 201 and event log data 202 to be analyzed. The analysis result acquisition unit 104 acquires analysis result data 206 indicating that "analysis X" was successful based on the input of "user X", and stores the data in the database 200 in association with the analysis process data 204 of "analysis X". Furthermore, the countermeasure process acquisition unit 105 acquires countermeasure process data 207 indicating the details of "countermeasure X" based on the input of "user X", and stores the acquired countermeasure process data 207 of "countermeasure X" in the database 200 in association with the analysis process data 204 of "analysis X".

[0083] Next, the analytical know-how utilization process executed by the analysis support device 100 according to this embodiment will be described with reference to the flowchart in Fig. 15. The utilization process in Fig. 15 is executed, for example, when a user stores the device log data 201 and event log data 202 to be analyzed and the related data 203, and selects a button requesting the presentation of analytical know-how.

[0084] The feature data acquisition unit 103 acquires feature data 205 indicating features of the device log data 201 or event log data 202 to be analyzed, and stores the acquired feature data 205 in the database 200 (step S401). The similarity calculation unit 106 calculates the similarity between the feature data 205 acquired in step S401 and the feature data 205 stored in the database 200 (step S402). The extraction unit 107 extracts, based on the similarity calculated in step S402, analysis process data 204 associated with feature data similar to the feature data 205 acquired in step S401 from the database 200 (step S403). The presentation unit 108 presents the analysis process data 204 extracted in step S403 as analysis know-how (step S404). The analysis application unit 109 applies the analysis of the process indicated by the analysis process data 204 selected by the user from the analysis process data 204 presented as analytical know-how in step S404 to the device log data 201 and event log data 202 from which feature data was acquired in step S401 (step S405). Furthermore, the presentation unit 108 presents the countermeasure process data 207 associated with the analysis process data 204 extracted in step S403 (step S406).

[0085] For example, the feature data acquisition unit 103 acquires feature data 205 indicating the features of the device log data 201 and the features of the event log data 202 for the time range from "February 25, 2024, 8:00:00" to "February 25, 2024, 9:00:00" specified by "User Y." The similarity calculation unit 106 calculates the similarity between the acquired feature data 205 and the feature data 205 stored in the database 200 according to the method indicated in the similarity calculation method data 208. The extraction unit 107 extracts, from the database 200, the analysis process data 204 associated with the feature data 205 for which a similarity equal to or greater than a predetermined threshold is calculated for the acquired feature data 205. Then, the presentation unit 108 displays a list of analysis know-how including the analysis process data 204-1 to 204-10 in descending order of similarity "S1" to "S10." Furthermore, when the analysis process data 204-1 is selected by "user Y" from the analysis process data 204-1 to 204-10, the presentation unit 108 acquires the countermeasure process data 207-1 associated with the selected analysis process data 204-1 from the database 200 and presents the countermeasure process data 207-1. When the analysis know-how including the analysis process data 204-1 is selected by "user Y", the analysis application unit 109 applies the analysis of the process of the analysis process data 204-1 to the device log data 201 and event log data 202 that are the analysis targets of "user Y".

[0086] According to this embodiment, a user can check the analysis steps performed in the past as analytical know-how. As a result, for example, a novice maintenance technician can perform an analysis and deal with a problem by referring to the analysis steps performed in the past by a veteran maintenance technician, thereby shortening the time required to resolve the problem.

[0087] Furthermore, according to this embodiment, the analysis steps performed on log data having characteristics similar to those of the log data that the user is trying to analyze are presented to the user, allowing the user to confirm analytical know-how that is useful for the analysis that the user is performing.

[0088] Furthermore, according to this embodiment, the similarity used to extract the analysis process data is corrected based on the role of the programmable logic controller or controlled device, which allows, for example, the presentation of analytical know-how performed on programmable logic controllers or controlled devices with the same role in the system to be prioritized.

[0089] Furthermore, according to this embodiment, the similarity used to extract the analysis process data is corrected based on whether or not the previous analysis was successful, which allows for preferential presentation of analytical know-how that was successfully performed on a programmable logic controller or a controlled device, for example.

[0090] Furthermore, according to this embodiment, the similarity used to extract the analysis process data is corrected based on the time when the analysis was performed, which allows for the presentation of analytical know-how based on more recent analyses performed on programmable logic controllers or controlled devices, for example.

[0091] Furthermore, according to this embodiment, analytical know-how is displayed in a list in order of similarity, which allows the user to easily check and compare multiple analytical know-how.

[0092] Furthermore, according to this embodiment, analytical know-how selected by the user is applied to new log data, thereby enabling the analysis to be performed automatically.

[0093] Furthermore, according to this embodiment, measures taken based on past analyses are presented to the user, allowing the user to easily check measures taken in the past and shortening the time it takes to consider measures that the user should take.

[0094] (Modifications) Although the embodiments of the present disclosure have been described above, various modifications and applications are possible when implementing the present disclosure.

[0095] In the above embodiment, the analysis support system 1 shown in FIG. 1 is described as including the analysis support device 100 and the database 200 as separate devices, but they may also be configured as a single device.

[0096] In the above embodiment, the related data 203 is stored in the database 200 in response to a user's designation, but this is not limited to this. When the analysis operation unit 101 receives a designation of the time range of the device log data 201 and the event log data 202, the related data 203 related to the device log data 201 and the event log data 202 may be automatically acquired and stored in the database 200.

[0097] In the above embodiment, the flowchart of the accumulation process executed by the analysis support device 100 is shown in Fig. 14, but the order of the processes of the respective steps is not limited to this. For example, the order of steps S302 and S303 in Fig. 14 may be interchanged. Furthermore, the order of steps S304 and S305 in Fig. 14 may be interchanged.

[0098] In the above embodiment, the flowchart of the utilization process executed by the analysis support device 100 is shown in Fig. 15, but the order of the processes of the respective steps is not limited to this. For example, the order of steps S405 and S406 in Fig. 15 may be reversed.

[0099] In addition, by applying an operating program that defines the operation of the analysis support device 100 according to the above embodiment to an existing personal computer or information terminal device, it is possible to make the personal computer or information terminal device function as the analysis support device 100 according to the embodiment.

[0100] Furthermore, the method of distribution of such a program is arbitrary; for example, it may be stored on a computer-readable recording medium such as a CD-ROM (Compact Disk Read-Only Memory), a DVD (Digital Versatile Disk), or a memory card and distributed, or it may be distributed via a communication network such as the Internet.

[0101] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope of the present disclosure. Furthermore, the above-described embodiments are intended to explain the present disclosure and do not limit the scope of the present disclosure. That is, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the meaning of equivalent disclosures are considered to be within the scope of the present disclosure.

[0102] According to the present disclosure, it is possible to provide a program, an analysis support device, an analysis support system, and an analysis support method that can present data indicating past analysis processes extracted based on the characteristics of log data as analysis know-how.

[0103] 1 Analysis support system, 10 Information processing device, 11 Processor, 12 Main memory unit, 13 Auxiliary memory unit, 14 Communication unit, 15 Input unit, 16 Output unit, 17 Bus, 100 Analysis support device, 101 Analysis operation unit, 102 Analysis process acquisition unit, 103 Feature data acquisition unit, 104 Analysis result acquisition unit, 105 Countermeasure process acquisition unit, 106 Similarity calculation unit, 107 Extraction unit, 108 Presentation unit, 109 Analysis application unit, 200 Database, 201 Device log data, 202 Event log data, 203 Related data, 204 Analysis process data, 205 Feature data, 206 Analysis result data, 207 Countermeasure process data, 208 Similarity calculation method data, 300 PLC, 400 Controlled device, 500 Communication network.

Claims

1. A program that causes a computer to function as: feature data acquisition means for acquiring feature data indicating features of device log data in which values ​​of devices used in a programmable logic controller or a controlled device of the programmable logic controller are recorded, or feature data indicating features of event log data in which values ​​indicating events that have occurred in the programmable logic controller or the controlled device are recorded; similarity calculation means for calculating the similarity between feature data stored in a database in association with analysis process data indicative of the process of analysis performed on the device log data or the event log data, and feature data acquired by the feature data acquisition means; extraction means for extracting, based on the similarity calculated by the similarity calculation means, analysis process data associated with feature data similar to the feature data acquired by the feature data acquisition means from the database; and presentation means for presenting the analysis process data extracted by the extraction means as analysis know-how.

2. The program of claim 1, wherein the characteristic data includes at least one of data indicating the type of the device, data indicating characteristics of time-series changes in the value of the device, data indicating the relationship between the device and other devices, data indicating the type of the event, data indicating time-series changes in the value indicating the event, data indicating the relationship between the occurrence time of the event and the occurrence time of other events, data indicating the relationship between the occurrence frequency of the event and the occurrence frequency of other events, and data indicating the relationship between the time-series changes in the value of the device and the time-series changes in the value indicating the event.

3. The program according to claim 1 or 2, wherein the similarity calculation means corrects the similarity based on information indicating the role of the programmable logic controller or the controlled device in a system including the programmable logic controller and the controlled device.

4. The program according to any one of claims 1 to 3, wherein the similarity calculation means corrects the similarity based on analysis result data indicating whether the analysis of the process indicated by the analysis process data was successful or not.

5. The program according to any one of claims 1 to 4, wherein the similarity calculation means corrects the similarity based on information indicating when the analysis of the process indicated by the analysis process data was performed.

6. The program according to any one of claims 1 to 5, wherein the presentation means displays the analytical know-how in a list in order of the degree of similarity.

7. A program according to any one of claims 1 to 6 that causes the computer to function as an analysis application means that applies an analysis of a process indicated by analysis process data selected by a user from among the analysis process data presented as the analysis know-how to device log data or event log data whose feature data has been acquired by the feature data acquisition means.

8. A program as claimed in any one of claims 1 to 7, wherein the database stores countermeasure process data indicating the process of countermeasures taken by a user on the programmable logic controller or the controlled device, in association with the analysis process data, and the presentation means presents the countermeasure process data associated with the analysis process data extracted by the extraction means.

9. An analysis support device comprising: a feature data acquisition means for acquiring feature data indicating features of device log data in which values ​​of devices used in a programmable logic controller or a controlled device of the programmable logic controller are recorded, or feature data indicating features of event log data in which values ​​indicating events that have occurred in the programmable logic controller or the controlled device are recorded; a similarity calculation means for calculating the similarity between feature data stored in a database in association with analysis process data indicating a process of analysis performed on the device log data or the event log data, and feature data acquired by the feature data acquisition means; an extraction means for extracting, based on the similarity calculated by the similarity calculation means, analysis process data associated with feature data similar to the feature data acquired by the feature data acquisition means from the database; and a presentation means for presenting the analysis process data extracted by the extraction means as analysis know-how.

10. An analysis support system comprising: feature data acquisition means for acquiring feature data indicating features of device log data in which values ​​of devices used in a programmable logic controller or a controlled device of the programmable logic controller are recorded, or feature data indicating features of event log data in which values ​​indicating events that have occurred in the programmable logic controller or the controlled device are recorded; similarity calculation means for calculating the similarity between feature data acquired by the feature data acquisition means and feature data stored in a database in association with analysis process data indicative of a process of analysis performed on the device log data or the event log data; extraction means for extracting from the database analysis process data associated with feature data similar to the feature data acquired by the feature data acquisition means based on the similarity calculated by the similarity calculation means; presentation means for presenting the analysis process data extracted by the extraction means as analysis know-how; and the database in which the device log data, the event log data, the analysis process data, and the feature data are stored in association with each other as the analysis know-how.

11. An analysis support method executed by an analysis support device, wherein the analysis support device: acquires feature data indicating features of device log data in which values ​​of devices used in a programmable logic controller or a controlled device of the programmable logic controller are recorded, or feature data indicating features of event log data in which values ​​indicating events that have occurred in the programmable logic controller or the controlled device are recorded; calculates the similarity between the acquired feature data and feature data stored in a database in association with analysis process data indicating the process of analysis performed on the device log data or the event log data; extracts from the database analysis process data associated with feature data similar to the acquired feature data based on the similarity; and presents the extracted analysis process data as analysis know-how.

Citation Information

Patent Citations

  • Diagnosis support system

    JP2007072825A

  • Information provision device, information provision method, and program

    JP2017045146A