Event analyzer, event analysis method, and program

The event analyzer addresses the challenge of accurately determining event correlations by generating time series data and calculating correlation coefficients, resulting in precise correlation extraction and response time calculation.

JP2025076797APending Publication Date: 2025-05-16HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023188663
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-02
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately determine correlations between events in large datasets, leading to incorrect judgments of event correlation due to small time correlation coefficients.

Method used

An event analyzer that generates time series data for each event, calculates time series correlation coefficients for multiple time lags, and identifies the maximum correlation coefficient for each event pair, along with the response time, to accurately extract correlations and response times.

Benefits of technology

The solution accurately extracts event correlations and calculates response times with high accuracy, overcoming the limitations of existing technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025076797000001_ABST
    Figure 2025076797000001_ABST
Patent Text Reader

Abstract

To accurately extract the presence or absence of correlation between events.SOLUTION: An event analyzer comprises: a time series generation unit which, with respect to each event of a plurality of events, generates time series data where a bit at the time when the event has occurred is 1; a time difference correlation coefficient specification unit which, with respect to each event pair, calculates time difference correlation coefficients for a plurality of time lags on the basis of the time series data and specifies a maximal time difference correlation coefficient which is maximal among the time difference correlation coefficients; a number-of-links result value specification unit which, with respect to each event pair, calculates number-of-links result values for the plurality of time lags by inner products of the time series data and specifies a maximal number-of-links result value which is maximal among the number-of-links result values; and a correlation output unit which extracts an event pair in which the maximal time difference correlation coefficient is a first prescribed value or larger and the maximal number-of-links result value is a second prescribed value or larger, and outputs the maximal time difference correlation coefficient in the event pair and a response time being a time lag for the maximal time difference correlation coefficient, together with a correlation chart.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an apparatus, method and program for analyzing event data related to alarms and operations output by systems in plants in the fields of chemistry, water supply and the like. [Background technology]

[0002] Patent Document 1 discloses a technique for determining whether or not there is a correlation between two events related to an alarm occurring in a plant or an operation on instruments in the plant, based on the probability of independence. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2005-216148 A Summary of the Invention [Problem to be solved by the invention]

[0004] The technology disclosed in Patent Document 1 has a problem in that, when the number of occurrences of events is relatively large, those events are judged to be correlated even if the time difference correlation coefficient between events is very small (for example, approximately 0.02 or less). [Means for solving the problem]

[0005] In order to solve the above problems, the present invention provides an event analysis device for analyzing events related to alarms for a system to be monitored and controlled, or events related to operations on the system, the device comprising: a time series generation unit which generates time series data for each of a plurality of events, in which a bit indicating the time at which an event occurs is set to 1 and bits indicating other times are set to 0; a time lag correlation coefficient determination unit which calculates, for each event pair, a time lag correlation coefficient for a plurality of time lags based on the time series data and identifies a maximum time lag correlation coefficient which is the largest among the time lag correlation coefficients; a chain count actual value determination unit which calculates, for each event pair, an actual chain count value for a plurality of time lags by using an inner product of the time series data and identifies a maximum actual chain count value which is the largest among the actual chain count values; and a correlation output unit which extracts event pairs for which the maximum time lag correlation coefficient is equal to or greater than a first predetermined value and the maximum actual chain count value is equal to or greater than a second predetermined value, and outputs the maximum time lag correlation coefficient for the event pair and the response time which is the time lag when the maximum time lag correlation coefficient is reached, together with a correlation diagram. Effect of the Invention

[0006] According to the present invention, correlations between events can be extracted with high accuracy, and response times between events can also be calculated with high accuracy. [Brief description of the drawings]

[0007] [Figure 1] Event analysis device overall configuration diagram [Diagram 2] Functional configuration diagram of an event analysis device according to the first embodiment [Diagram 3] Event information stored in the database [Figure 4] Event details stored in the database [Diagram 5] Flowchart of the time series generation part [Figure 6] An example of an event timeline [Figure 7] A diagram showing how to calculate the time-difference correlation coefficient [Figure 8]Flowchart showing the process of calculating the time difference correlation coefficient and the actual value of the number of chains [Figure 9] An example of the calculation results of the time difference correlation coefficient between events and the actual number of chain events [Figure 10] Flowchart showing the process of creating a correlation table in the first embodiment [Figure 11] An example of a correlation table in the first embodiment [Figure 12] 1 is a flowchart showing the process of the correlation output unit in the first embodiment. [Figure 13] A correlation table that stores correlation information between events that are determined to be correlated [Figure 14] Example of correlation diagram [Figure 15] Functional configuration diagram of an event analysis device according to a second embodiment [Figure 16] Flowchart showing the process of calculating the time-lag correlation coefficient, the actual number of linkages, and the probability of independence [Figure 17] An example of calculation results for time-lag correlation coefficients between events, actual chain counts, and probability of independence [Figure 18] Flowchart showing the process of creating a correlation table in the second embodiment [Figure 19] An example of a correlation table in the second embodiment [Figure 20] 11 is a flowchart showing the process of the correlation output unit in the second embodiment. [Figure 21] An example of the distribution of time-lag correlation coefficients and actual chain count values [Figure 22] Flowchart showing the process of creating a correlation table in the third embodiment [Figure 23] A functional configuration diagram of an event analysis device according to a fourth embodiment. [Figure 24] Diagram of how alarm severity is calculated [Diagram 25] 1 is a flowchart showing a process for calculating an alarm importance by a importance calculation unit. [Figure 26] An example of a ranking table showing the calculation results of alarm importance [Figure 27] Diagram of calculation method for operation importance [Figure 28] A flowchart showing a process of calculating the importance of an operation by the importance calculation unit. [Figure 29] An example of a ranking table showing the calculation results of operation importance [Diagram 30] Diagram of the comprehensive correlation model [Diagram 31] Correlation model shown in correlation table [Diagram 32] A correlation network diagram representing the correlation table in Figure 31 [Diagram 33] A flowchart showing a process in which the correlation output unit constructs a comprehensive correlation model. [Diagram 34] Functional configuration diagram of an event analysis device according to a sixth embodiment [Diagram 35] An explanatory diagram for constructing a classification tree (operation judgment model) for determining whether or not an operation needs to be performed [Diagram 36] Data set used to build the operation judgment model [Figure 37] Flowchart of the operation judgment model creation section [Figure 38] Flowchart of the operation necessity determination section [Figure 39] Screen showing the result of the operation necessity judgment [Diagram 40] Functional configuration diagram of an event analysis device according to a seventh embodiment [Diagram 41] An explanatory diagram for constructing a model for determining whether an alarm has occurred (alarm determination model) [Diagram 42] Data set used to build alarm judgment model [Diagram 43] Flowchart of the alarm judgment model creation section [Diagram 44] Alarm presence / absence determination flow chart [Diagram 45] Screen showing alarm occurrence / non-existence judgment result DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0008] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. EXAMPLES

[0009] A first embodiment of the present invention will be described with reference to Figs. 1 to 14. In the first embodiment, correlation between events is determined based on time difference correlation analysis, and a correlation diagram is presented. Fig. 1 is an overall configuration diagram of an event analysis device. The event analysis device 1 is a device that analyzes events related to alarms for a system to be monitored and controlled, or events related to operations on the system. As shown in Fig. 1, the event analysis device 1 has a memory unit 11 including a RAM, a hard disk, etc., a control unit 12 including a CPU, etc., a man-machine interface such as a keyboard and a mouse, an input unit 13 including a network interface for importing data from an external network, and a display unit 14 such as a display. The control unit 12 calls and executes a calculation processing program 110 stored in the memory unit 11, and stores the calculation results in a database 120 or displays them on the display unit 14. During the program execution process, the data imported from the input unit 13 and various information stored in the database 120 are referred to as necessary and used for calculation processing.

[0010] FIG. 2 is a functional configuration diagram of the event analysis device according to the first embodiment. The event analysis device 1 of the first embodiment includes, as functional configuration, a time series generation unit 21, a time difference correlation coefficient identification unit 22, a chain count actual value identification unit 23, a correlation output unit 24, and a database 120. The time series generation unit 21 generates time series data for each of a plurality of events, in which the bit of the time of the event occurrence is set to 1 and the bits of the other times are set to 0. The time difference correlation coefficient identification unit 22 calculates the time difference correlation coefficient for a plurality of time lags based on the time series data for each event pair, and identifies the maximum time difference correlation coefficient that is the maximum of the time difference correlation coefficients. The chain count actual value identification unit 23 calculates the chain count actual value for a plurality of time lags by the inner product of the time series data for each event pair, and identifies the maximum chain count actual value that is the maximum of the chain count actual values. The correlation output unit 24 extracts an event pair whose maximum time difference correlation coefficient is equal to or greater than a first predetermined value and whose maximum actual number of chain events is equal to or greater than a second predetermined value, and outputs the maximum time difference correlation coefficient in the event pair and the response time, which is the time lag when the maximum time difference correlation coefficient is reached, together with a correlation diagram. The database 120 stores data such as event information 31, time series data 32, time difference correlation coefficient 33, and actual number of chain events 34.

[0011] A calculation processing program 110 for realizing the functions of the time series generating unit 21, the time difference correlation coefficient identifying unit 22, the chain count actual value identifying unit 23, and the correlation output unit 24 is stored in the storage unit 11. The calculation processing program 110 may be provided by being pre-installed in a ROM or the like, or may be provided or distributed by being recorded in a readable recording medium as a file in an installable or executable format. Furthermore, the calculation processing program 110 may be stored on a computer connected to a network, and provided or distributed by being downloaded via the network.

[0012] Figure 3 shows the event information stored in the database, and Figure 4 summarizes all the detailed event information used in this analysis. Events include alarms that are triggered when certain measurement information (variable values) exceed upper and lower limits, and information on operation operations by operators (manual setting of system operation quantities, control quantity target values, etc.). Each event is identified by a serial number or event name (abbreviation, A1, A2, ..., Ope1, ...). A represents an event related to an alarm (hereinafter, alarm event), and Ope represents an event related to an operation (hereinafter, operation event). In the example of Figure 4, serial numbers 1 to 700 are alarm events, with 700 types of alarms, and serial numbers 701 to 1000 are operation events, with 300 types of operations. These numbers change depending on the system scale and the number of alarm settings. Figure 3 records the occurrence and end times of alarm events, and the occurrence times of operation events (there is no end time for operation events). Here, the annual history from April 2022 to March 2023 is stored. The number of records (number of rows) is on the scale of tens of thousands to hundreds of thousands. The column of the number of event occurrences in FIG. 4 does not hold data in the initial state of the analysis. The number of occurrences is calculated by the time series generation unit 21 described later, and the data is stored. Fig. 5 is a flow chart of the time series generation unit, and Fig. 6 shows an example of an event time series. The time series is made up of a bit series of 0 and 1, with 1 set when an event occurs (when an alarm occurs or an operation is performed) and 0 otherwise. The time series has various increments, such as 1 minute or 10 minutes. If 1 minute increments are used, the number of bids per year will be approximately 525,000. In this embodiment, the following explanation will be given taking the case where 1 minute increments are used as an example.

[0013] First, in step S501, the time series generation unit 21 reads the event detail information (FIG. 4) from the database, and then in step S502, reads the event information (FIG. 3). Next, in step S503, the time series generation unit 21 assigns 1 to the variable I. The variable I corresponds to the event serial number described above. Thereafter, in step S504, the time series generation unit 21 judges whether I is greater than N0 (here, set to the total number of events, 1000), and if it is judged to be greater, it is determined that the generation process of the time series data of all events is completed, and ends the process. On the other hand, if it is judged that I is equal to or less than N0, in step S505, the time series generation unit 21 generates the time series data 32 of the I-th event (the event whose No. is I) in FIG. 4, and stores it in the database 120 in a pair with the event number I. The time series is generated by referring to the table in FIG. 3 to find out at what time the I-th event occurred, and setting the bit of that time to 1. Thereafter, in step S506, the time series generation unit 21 calculates the sum of the elements of the generated time series, i.e., the total number of bits 1, and in step S507 writes and saves this as the number of event occurrences in the table of Fig. 4. Note that if there are multiple events that occur very close to each other, they will be aggregated into one bit, but this does not pose a problem in terms of data analysis processing. Next, in step S508, the time series generation unit 21 increments the variable I by 1, and returns to the processing of step S504. By repeating the above processing, time series data 32 of all events is generated in the format of Fig. 6 and saved in the database 120.

[0014] FIG. 7 is an explanatory diagram showing a method of calculating the time difference correlation coefficient. The time difference correlation coefficient specification unit 22 gives various time lags m to two event time series 701, 702, and calculates the time difference correlation coefficient by formula 703 (time difference correlation coefficient C=covariance of S1 and S2 / (standard deviation of S1×standard deviation of S2)) using data at the time when the time series overlap. Graph 704 in FIG. 7 plots the time difference correlation coefficient C at various time lags m, and the magnitude of the correlation between the two events and the time difference (response time) between the occurrence of the events are determined by the time lag m* when the time difference correlation coefficient takes on the maximum time difference correlation coefficient C*. Note that formula 703 is an example of a formula for calculating the time difference correlation coefficient, and the time difference correlation coefficient may be calculated by other formulas.

[0015] 8 is a flowchart showing the process of calculating the time difference correlation coefficient and the actual value of the number of chain events. First, in step S801, the time difference correlation coefficient specifying unit 22 assigns 1 to the variable I. Next, in step S802, the time difference correlation coefficient specifying unit 22 judges whether I is greater than N0-1, and if it is judged to be greater, it is determined that the calculation of the time difference correlation coefficient is completed for all event pairs and ends the process. On the other hand, if it is judged that I is equal to or less than N0-1, in step S803, the time difference correlation coefficient specifying unit 22 assigns I+1 to the variable J. The variable J represents the serial number of another event that is the target of the calculation of the time difference correlation coefficient. After that, in step S804, the time difference correlation coefficient specifying unit 22 judges whether the variable J is greater than N0, and if it is judged to be greater, the process proceeds to step S807, increments the value of the variable I by 1, and returns to the process of step S802. On the other hand, if it is determined that the variable J is equal to or less than N0, the process proceeds to step S805, where the time difference correlation coefficient identifying unit 22 calculates the time difference correlation coefficient of the I-th and J-th events at various time lags (between -60 minutes and 60 minutes, in 1-minute increments). In this step S805, the chain count actual value identifying unit 23 calculates the inner product of the I-th and J-th events (the number of events where bit 1 overlaps, i.e., the chain count actual value of the two events) at various time lags. The time difference correlation coefficient 33 and the chain count actual value 34, which are the calculation results in step S805, are paired with the event pair (I, J) (the order of I and J is significant) and stored in the database 120. Next, in step S806, the variable J is incremented by 1, and the process returns to step S804. By repeating the above process, the time difference correlation coefficient and the chain count actual value are calculated for all event pairs (I, J) and stored in the database 120.

[0016] FIG. 9 shows an example of the calculation results of the time difference correlation coefficient between events and the actual value of the number of chain events. Here, a positive time lag indicates that, for two events (I, J), the occurrence of event J lags behind event I, and a negative time lag indicates that the occurrence of event I lags behind event J. In the example of events (A1, A2) in FIG. 7, it is assumed that the occurrence of event A2 lags behind the occurrence of event A1, and the time lag m is positive (2 minutes). In the example of FIG. 7, for each event, the first bit indicates the data of the current time, the second bit indicates the data of 1 minute later, and the third bit indicates the data of 2 minutes later, and this is because A1 at the current time corresponds to A2 2 minutes later.

[0017] Fig. 10 is a flow chart showing a process of creating a correlation table in the first embodiment. After steps S1001 to S1004, in step S1005, correlation information (calculation results shown in Fig. 9) for two events, event No. 1 and event No. 2, is read from database 120. Next, in step S1006, time difference correlation coefficient specifying unit 22 specifies the maximum time difference correlation coefficient among the read time difference correlation coefficients 33, and writes it into the correlation table of Fig. 11 together with the time lag (response time) at that time. In this step S1006, chain count actual value specifying unit 23 specifies the maximum chain count actual value among the read chain count actual values ​​34, and writes it into the correlation table of Fig. 11. Here, the time lag when the time difference correlation coefficient is maximum generally coincides with the time lag when the chain count actual value is maximum, but they may not coincide depending on the calculation method of the time difference correlation coefficient. If they do not match, a new column of the time lag (response time) corresponding to the maximum number of chains is provided in the correlation table of FIG. 11, and the time lag corresponding to the maximum number of chains is written therein. Although time lag information may be used in the process described later, if there are multiple time lags, the time lag corresponding to the maximum time difference correlation coefficient is used preferentially. Also, the number of events read from the event detail information table shown in FIG. 4 is written in the correlation table. Note that writing to the correlation table may be performed by a means other than the time difference correlation coefficient specifying unit 22 or the chain number actual value specifying unit 23. Thereafter, in step S1007, the variable J is incremented by 1, and the process returns to step S1004. By repeating the above process, the maximum time difference correlation coefficient, the maximum chain number actual value, and the like are specified for all event pairs, and the correlation table of FIG. 11 is completed and stored in the database 120.

[0018] FIG. 12 is a flowchart showing the process of the correlation output unit in the first embodiment. First, in step S1201, the correlation output unit 24 reads out the correlation table in FIG. 11. Next, in step S1202, the correlation output unit 24 refers to the correlation table and extracts event pairs whose maximum time difference correlation coefficient is equal to or greater than a first predetermined value (predetermined by the user, for example, 0.08) and whose maximum number of chain events actual value is equal to or greater than a second predetermined value. Here, if the maximum number of chain events actual value is 1, even if the maximum time difference correlation coefficient is high, it cannot be determined that there is a correlation between the two events, so it is preferable to set the second predetermined value to 2 or more. In addition, the event pairs extracted in step S1202 are configured as correlated event pair information in the form shown in FIG. 13 and are stored in the database 120. After that, in step S1203, the correlation output unit 24 outputs a correlation diagram in the form shown in FIG. 14 together with the maximum time difference correlation coefficient and response time based on the information in FIG. 13, and presents it to the user.

[0019] In FIG. 14, correlated events are connected by lines like a network, and the direction of the chain is indicated by an arrow. The maximum time difference correlation coefficient and response time are displayed on the lines as attribute information. In addition to this information, the chain probability may be added as example information. The chain probability can be calculated as Nc / Nb, where Nb is the number of events that are the starting point of the arrow, and Nc is the maximum number of chains between two events connected by an arrow. The information on Nb and Nc is obtained from the correlation table in FIG. 11. Also, by appropriately changing the first and second specified values, it is possible to output a simple correlation diagram with a small number of events, or conversely, a detailed correlation diagram with a large number of events. EXAMPLES

[0020] A second embodiment of the present invention will be described with reference to Figures 15 to 20. The second embodiment uses a time difference correlation coefficient and an independence probability in combination to accurately extract two events that are correlated with each other.

[0021] FIG. 15 is a functional configuration diagram of an event analysis device according to a second embodiment. The event analysis device 1 of the second embodiment is different from that of the first embodiment, and further includes an independence probability identification unit 25. The independence probability identification unit 25 calculates the independence probability for each event pair for a plurality of time lags, and identifies the minimum independence probability that is the smallest among the independence probabilities. Moreover, the correlation output unit 24 of the present embodiment extracts an event pair whose maximum time difference correlation coefficient is equal to or greater than a first predetermined value and whose minimum independence probability is equal to or less than a third predetermined value, instead of extracting an event pair whose maximum time difference correlation coefficient is equal to or greater than a first predetermined value and whose maximum chain number actual value is equal to or greater than a second predetermined value. Moreover, the database 120 of the second embodiment also stores an independence probability 35, unlike that of the first embodiment. The calculation processing program 110 for realizing the function of the independence probability identification unit 25 is stored in the storage unit 11.

[0022] FIG. 16 is a flowchart showing the process of calculating the time difference correlation coefficient, the actual number of chain events, and the independence probability, and corresponds to FIG. 8 in the first embodiment. The difference from FIG. 8 in the first embodiment is that in the process of step S1605, not only the time difference correlation count and the actual number of chain events, but also the independence probability is calculated and stored. Here, the independence probability is the probability that the number of chain events when it is assumed that the event pairs are independent of each other is equal to or greater than the actual number of chain events, and can be calculated from the occurrence counts of two events and the actual number of chain events written in the correlation table in FIG. 11. According to the flowchart shown in FIG. 16, the time difference correlation coefficient, the actual number of chain events, and the independence probability are calculated for all event pairs (I, J) and stored in the database 120.

[0023] Fig. 17 shows an example of the calculation results of the time difference correlation coefficient between events, the actual number of chain events, and the independence probability, and corresponds to Fig. 9 in Example 1. What is different from Fig. 9 in Example 1 is that in addition to the columns for storing the time difference correlation coefficient and the actual number of chain events, a column for storing the independence probability is provided.

[0024] FIG. 18 is a flowchart showing the process of creating a correlation table in the second embodiment, and corresponds to FIG. 10 in the first embodiment. The difference from FIG. 10 in the first embodiment is that in the process of step S1805, in addition to the correlation information and the number of events, the independence probability is read out. Also, in the process of step S1806, in addition to the maximum time difference correlation coefficient and the maximum number of chains actual value, the minimum independence probability is written into the correlation table in FIG. 19, which is also different from the first embodiment. The independence probability specification unit 25 in this embodiment specifies the minimum independence probability that is the smallest among the read independence probabilities, and writes it into the correlation table in FIG. 19. Here, the time lag when the time difference correlation coefficient is maximum and the time lag when the independence probability is minimum generally match, but they may not match depending on the calculation method of the time difference correlation coefficient. If they do not match, a column of the time lag (response time) corresponding to the minimum independence probability is newly provided in the correlation table in FIG. 19, and the time lag corresponding to the minimum independence probability is written in. In the processing described below, information on the time lag may be used, but when multiple time lags exist, the time lag corresponding to the maximum time difference correlation coefficient is used preferentially. The maximum time difference correlation coefficient, minimum independence probability, and the like are identified for all event pairs (I, J) according to the flowchart shown in Fig. 18, and the correlation table in Fig. 19 is completed and stored in the database 120.

[0025] FIG. 20 is a flowchart showing the process of the correlation output unit in the second embodiment. First, in step S2001, the correlation output unit 24 reads out the correlation table in FIG. 19. Next, in step S2002, the correlation output unit 24 refers to the correlation table and extracts event pairs whose maximum time difference correlation coefficient is equal to or greater than a first predetermined value (predetermined by the user, e.g., 0.08) and whose minimum independence probability is equal to or less than a third predetermined value (e.g., 0.005). The extracted event pairs are configured as correlated event pair information in the form shown in FIG. 13 in the first embodiment and are stored in the database 120. After that, in step S2003, the correlation output unit 24 outputs a correlation diagram in the form shown in FIG. 14 in the first embodiment together with the maximum time difference correlation coefficient and the response time based on the information in FIG. 13, and presents it to the user. Note that in the second embodiment, the event pairs are further restricted by the independence probability than in the first embodiment, so that the number of events may be smaller than that in the correlation diagram shown in FIG. 14. EXAMPLES

[0026] A third embodiment of the present invention will be described with reference to Figs. 21 and 22. In the first and second embodiments, correlation information between events (time difference correlation coefficient, actual number of chain events, probability of independence) and time lag were obtained based on the results of correlation analysis between events in Figs. 9 and 17. The time lag when the time difference correlation coefficient is at its maximum was taken as the response time between events. However, in reality, the distribution of the time difference correlation with respect to the time lag may be distorted, and in such cases, an accurate response time may not be calculated. The third embodiment provides a method for improving this.

[0027] FIG. 21 is an example of a graph of the time difference correlation coefficient and the actual number of chain events included in the correlation analysis result between two events (given in FIG. 9, FIG. 17, etc.). In this example, the distribution of the time difference correlation coefficient and the actual number of chain events is not symmetrical. According to the first and second embodiments, C1 is calculated as the maximum time difference correlation coefficient and T1 as the response time, but in the example of FIG. 21, since the distribution spreads in the positive direction, it is presumed that the calculated value T1 of the response time is not accurate. Therefore, in the case where there are multiple time lags where the time difference correlation coefficient is equal to or greater than a threshold value (here, the above-mentioned first predetermined value is adopted, but other values ​​may also be used), the time difference correlation coefficient specifying unit 22 in the third embodiment calculates the response time by a weighted average of the time lags with each time difference correlation coefficient as a weight, and updates the maximum time difference correlation coefficient by the sum of each time difference correlation coefficient. As a result, the accuracy of the maximum time difference correlation coefficient and the response time is improved.

[0028] In the example of Figure 21, there are two time difference correlation coefficients (C1 and C2) that are above the threshold (0.08), and the corresponding time lags are T1 and T2. Using this, the response time T can be calculated using the following (Equation 1).

[0029]

number

[0030] In addition, the final maximum time difference correlation coefficient C and the maximum number of linked cases N are approximately calculated using the following (Equation 2) and (Equation 3).

[0031]

number

[0032]

number

[0033] Here, N1 and N2 are the actual chain count values ​​that are greater than the threshold value (3 in FIG. 21) at which the independence probability becomes a third predetermined value (for example, 0.005). In the above example, two time difference correlation coefficients exceed the threshold, but even if there are three or more, the final response time can be calculated by taking a weighted average of the time lags with the time difference correlation coefficients as weights. In addition, three or more time difference correlation coefficients can be added to calculate the final maximum time difference correlation coefficient C, and three or more chain counts can be added to calculate the final maximum number of chain counts N.

[0034] Fig. 22 is a flow chart showing the process of creating a correlation table in the third embodiment, and corresponds to Fig. 10 in the first embodiment and Fig. 18 in the second embodiment. What is different from Fig. 10 in the first embodiment is that in the process of step S2206, the response time, maximum time difference correlation coefficient, and maximum number of chain events are calculated based on the above-mentioned (Formula 1), (Formula 2), and (Formula 3). In addition, in step S2207, these calculated values ​​are written in the row corresponding to the event (I, J) in the correlation table. In this way, in the third embodiment, it is possible to calculate the maximum time difference correlation coefficient, maximum number of chain events, and response time more accurately. EXAMPLES

[0035] A fourth embodiment of the present invention will be described with reference to Fig. 23 to Fig. 29. In the fourth embodiment, an alarm importance level and an operation importance level are calculated as an application example of the correlation analysis result.

[0036] 23 is a functional configuration diagram of an event analysis device according to a fourth embodiment. The event analysis device 1 of the fourth embodiment is different from that of the first embodiment, and further includes an importance calculation unit 26. The importance calculation unit 26 identifies an event pair in which an event related to an alarm and an event related to an operation are linked among the event pairs extracted by the correlation output unit 24, and calculates the importance of the alarm or the operation based on the maximum time difference correlation coefficient and the response time in the identified event pair. A calculation processing program 110 for realizing the function of the importance calculation unit 26 is stored in the storage unit 11.

[0037] First, the calculation method of alarm importance will be explained with reference to Figures 24 to 26. Alarm importance is calculated as a positive numerical value, and the higher the value, the higher the frequency (probability) that a response operation will be required when the corresponding alarm is issued, or the more urgent the response is deemed to be.

[0038] FIG. 24 is an explanatory diagram of a method for calculating the alarm importance. Many pairs of correlated alarm events and operation events are extracted by correlation analysis. Example 1 in FIG. 24 assumes that alarm event A1 and operation event Ope1 are determined to be correlated and extracted. In this case, the alarm importance is calculated using formula (2401). T1 is the response time, and C1 is the maximum time difference correlation coefficient. F is a monotonically decreasing function of T1 that always takes a positive value, and can be defined as, for example, F=1 (when T1≦2 minutes) or F=0.5 (when T1>2 minutes), but more simply, F=1 may be defined regardless of time T1. When the maximum time difference correlation coefficient is large, the frequency of response increases, and when the response time is small, a prompt response is required. Therefore, formula (2401) is intended to increase the importance in such cases.

[0039] In Example 2 of FIG. 24, it is assumed that alarm event A2 and operation events Ope2 and Ope3 are determined to be correlated and extracted. In this case, the alarm importance is calculated using formula (2402). T2 and T3 are response times, C2 and C3 are maximum time difference correlation coefficients, and F is the function mentioned above. As in Example 2 of FIG. 24, when multiple operation events are chained after an alarm event occurs, the final importance is basically calculated by adding up the individual importances. Note that in formulas (2401) and (2402), the maximum chain probability (= maximum number of chains / number of alarm occurrences), which is the maximum value of the chain probability, may be used instead of the maximum time difference correlation coefficient. This is because the time difference correlation coefficient and chain probability are almost equivalent variables.

[0040] Fig. 25 is a flow chart showing the process in which the importance calculation unit 26 calculates the alarm importance. First, in step S2501, the importance calculation unit 26 reads the correlation table (Figs. 11 and 19). In step S2502, the importance calculation unit 26 assigns 1 to the variable I. The variable I represents the serial number of the alarm. In step S2503, the importance calculation unit 26 judges whether I is greater than N1 (here, the total number of alarms, 700), and if it is judged to be greater, executes the process of step S2507. On the other hand, if it is judged that I is equal to or less than N1, the importance calculation unit 26 executes the process of step S2504. In step S2504, the importance calculation unit 26 refers to the correlation table and extracts an event pair for which the maximum time difference correlation coefficient for the I-th alarm event is equal to or greater than a first predetermined value, the maximum number of chain events is equal to or greater than a second predetermined value (or the independence probability is equal to or less than a third predetermined value), and the alarm event is the start point of the correlation diagram and some operation event is the end point. The processing in step S2504 corresponds to extracting examples 1 and 2 in FIG. 24. Next, in step S2505, the importance calculation unit 26 calculates the importance for the I-th alarm event based on the extracted result and temporarily saves it (saves it in a program variable). If no event pair is extracted, the importance for that alarm is not calculated (it is not considered to be an important alarm). In step S2506, the variable I is incremented by 1, and the process returns to step S2503. In step S2507, the importance calculation unit 26 creates and saves a ranking table of alarm importance assuming that importance calculation has been performed for all alarms, and presents it to the user.

[0041] Figure 26 shows an example of a ranking table that is the result of calculating the alarm importance. In Figure 26, alarms are ranked in descending order of importance and displayed in pairs with the alarm name. Of the total of 700 alarms, 155 have their importance calculated, and these alarms are deemed to be important alarms. The rest are considered to be unimportant alarms.

[0042] Next, the calculation method of the operation importance will be explained based on Figures 27 to 29. The operation importance is calculated as a positive numerical value, and the higher the value, the higher the frequency (probability) of an alarm occurring after the corresponding operation is performed, or the sooner it is determined that an alarm will occur. FIG. 27 is an explanatory diagram of a method for calculating the operation importance. Many pairs of correlated operation events and alarm events are extracted by correlation analysis. Example 1 in FIG. 27 assumes that the operation event Ope1 and the alarm event A1 are determined to be correlated and extracted. In this case, the operation importance is calculated using formula (2701). T1 is the response time, and C1 is the maximum time difference correlation coefficient. F is a monotonically decreasing function of T1, and always takes a positive value. For example, it can be defined as F=1 (when T1≦2 minutes), F=0.5 (when T1>2 minutes), but more simply, it can be defined as F=1 regardless of the time T1. When the maximum time difference correlation coefficient is large, the alarm occurrence frequency increases, and when the response time is small, the alarm is issued quickly, so formula (2701) is intended to increase the importance in such cases.

[0043] In Example 2 of FIG. 27, it is assumed that the operation event Ope2 and the alarm event A2 and alarm event A3 are determined to be correlated and extracted. In this case, the operation importance is calculated using formula (2702). T2 and T3 are response times, C2 and C3 are maximum time difference correlation coefficients, and F is the function mentioned above. As in Example 2 of FIG. 27, when multiple operation alarms are chained after an operation event occurs, the final importance is basically calculated by adding up the individual importances. Note that in formulas (2701) and (2702), the maximum chain probability (= maximum number of chains / number of operations), which is the maximum value of the chain probability, may be used instead of the maximum time difference correlation coefficient. This is because the time difference correlation coefficient and the chain probability are almost equivalent variables.

[0044] Fig. 28 is a flow chart showing the process of the importance calculation unit 26 calculating the operation importance. First, in step S2801, the importance calculation unit 26 reads the correlation table (Figs. 11 and 19). In step S2802, the importance calculation unit 26 assigns 701 (the first serial number corresponding to the operation event) to the variable I. The variable I represents the serial number of the event. In step S2803, the importance calculation unit 26 judges whether I is larger than N2 (here, the total number of events is 1000), and if it is judged to be larger, the importance calculation unit 26 executes the process of step S2807. On the other hand, if it is judged that I is equal to or smaller than N2, the importance calculation unit 26 executes the process of step S2804. In step S2804, the importance calculation unit 26 refers to the correlation table and extracts an event pair for which the maximum time difference correlation coefficient for the I-th operation event is equal to or greater than the first predetermined value, the maximum number of chain events is equal to or greater than the second predetermined value (or the independence probability is equal to or less than the third predetermined value), and the operation event is the start point of the correlation diagram and some alarm event is the end point. The process in step S2804 corresponds to extracting examples 1 and 2 in FIG. 27. Next, in step S2805, the importance calculation unit 26 calculates the importance for the I-th operation event based on the extracted result and temporarily saves it (saves it in a program variable). If no event pair is extracted, the importance for that operation is not calculated (it is not considered to be an important operation). In step S2805, the variable I is incremented by 1, and the process returns to step S2803. In step S2807, the importance calculation unit 26 creates and saves a ranking table of operation importance assuming that importance calculation has been performed for all operations, and presents it to the user.

[0045] Figure 29 shows an example of a ranking table that is the calculation result of the operation importance. In Figure 29, the operations are ranked in order of importance and are displayed in pairs with the operation names. The importance is calculated for 88 of the total 300 operations, and these operations are considered to be important operations. The rest are considered to be unimportant operations. EXAMPLES

[0046] A fifth embodiment of the present invention will be described with reference to Figures 30 to 33. In the fifth embodiment, a wider range of correlations is extracted by devising a method for using data.

[0047] FIG. 30 is an explanatory diagram of the comprehensive correlation model. FIG. 3 shows event occurrence data for a year, but in this embodiment, the data is divided into four parts for each season. The correlation output unit 24 of this embodiment performs the correlation analysis of the first to third embodiments using data for every three months, and constructs four short-term correlation models A (short-term correlation models 1 to 4). The correlation models correspond to the correlation table in FIG. 13 and the correlation diagram in FIG. 14. Meanwhile, the correlation output unit 24 of this embodiment performs the correlation analysis using annual data, and constructs a long-term correlation model B. In the water supply field, it is considered that correlation characteristics that appear in each season, such as heavy rainfall in summer, differ, so the correlations extracted will differ for the short-term correlation models 1 to 4. Meanwhile, the long-term correlation model is considered to include characteristics that often appear throughout the year, and shows correlation characteristics different from those of the short-term correlation model. When considering constructing and using a total of five correlation models, four short-term models and one long-term model, it is considered that they may include common correlations with each other, making it difficult to visually grasp the characteristics. Therefore, in this embodiment, in order to increase visibility, each model is integrated to construct an integrated correlation model C. Here, four short-term models and one long-term model may be integrated to construct one integrated correlation model, or each short-term model and long-term model may be integrated to construct four integrated correlation models.

[0048] Figure 31 shows the correlation model in a correlation table. Below, we will explain an example of how to construct an integrated correlation model by integrating short-term correlation model 1 (using data from April to June) and a long-term correlation model. Assume that short-term correlation model 1 and long-term correlation model are expressed in correlation tables 3101 and 3102, respectively. These are integrated to create a correlation table for the integrated correlation model, which becomes 3103. As can be seen from Figure 31, integration means simply merging correlation information. However, if there is overlapping information for the combination of events 1 and 2, only the maximum time difference correlation coefficient and response time are merged and shown in the form of a range, as shown within the dashed line in Figure 31.

[0049] Figure 32 shows the correlation table of Figure 31 expressed as a correlation network diagram. In the comprehensive correlation model, there is no overlap in the chains between A1 and A2, and it can be seen that visibility is improved compared to looking at the short-term model 1 and the long-term model individually. This example is a simple network diagram, but in reality it often becomes a complex network diagram with many correlations. Therefore, using a comprehensive correlation model as in this embodiment is useful for facilitating visual confirmation.

[0050] Fig. 33 is a flow chart showing the process of the correlation output unit constructing a comprehensive correlation model. First, in step S3301, the correlation output unit 24 reads the event detail information in Fig. 4. Furthermore, in step S3302, the correlation output unit 24 reads the event information in Fig. 3. After that, in step S3303, the correlation output unit 24 performs the correlation analysis of the first to third embodiments, constructs a short-term correlation model, and stores it as a correlation table such as 3101 in Fig. 31. Furthermore, in step S3304, the correlation output unit 24 similarly constructs a long-term correlation model and stores it as a correlation table such as 3102 in Fig. 31. Then, in step S3305, the correlation output unit 24 refers to a correlation table such as that shown in Fig. 31, and merges the maximum time lag correlation coefficient and response time in an event pair extracted using short-term time series data with the maximum time lag correlation coefficient and response time in an event pair extracted using long-term time series data to construct an overall correlation model, and stores it as a correlation table such as 3103 in Fig. 31. Finally, in step S3306, the correlation output unit 24 expresses the overall correlation model as a correlation diagram such as that shown in Fig. 32 and presents it to the user.

[0051] Next, an embodiment of modeling the condition in which two events are linked will be described based on Figures 34 to 45. When it is found that an alarm event and an operation event are correlated, modeling the condition in which these events are linked and presenting it to the user will be a driving support. EXAMPLES

[0052] A sixth embodiment of the present invention will be described with reference to Fig. 34 to Fig. 39. The sixth embodiment is intended to model the conditions in a case where an alarm event and an operation event are correlated and an operation is required after an alarm occurs. Here, the explanation is given assuming that an alarm event A and an operation event Ope are correlated, the time difference correlation coefficient is 0.1, the response time (time lag) is 1 minute, the number of occurrences of each event is 20 (the number of occurrences of each event may differ), and the number of chained events is 2 (there were two cases in which an operation occurred 1 minute after an alarm occurred).

[0053] FIG. 34 is a functional configuration diagram of an event analysis device according to a sixth embodiment. The event analysis device 1 of the sixth embodiment is different from that of the first embodiment, and further includes an explanatory variable calculation unit 27, an operation determination model creation unit 281, and an operation necessity determination unit 291. The explanatory variable calculation unit 27 calculates the value of an explanatory variable that influences the execution of an operation based on an alarm variable 36 (measured by a continuous variable for determining whether an alarm is issued or not, which here refers to the measured time series data of the variable) and an operation variable 37 (a continuous variable representing the amount of an operation performed in response to an alarm issuance, which here refers to the operation time series data) for an event pair in which an operation event occurs after an alarm event occurs among the event pairs extracted by the correlation output unit 24. The operation determination model creation unit 281 creates an operation determination model 381 that defines a condition in which an operation is required based on the value of the explanatory variable calculated by the explanatory variable calculation unit 27 and the value of the explained variable corresponding to that value (whether or not an operation is performed). The operation necessity determination unit 291 determines whether or not an operation needs to be performed based on the current explanatory variable values ​​calculated by the explanatory variable calculation unit 27 and the operation judgment model 381 created by the operation judgment model creation unit 281. The calculation processing program 110 for realizing the functions of the explanatory variable calculation unit 27, the operation judgment model creation unit 281, and the operation necessity determination unit 291 is stored in the storage unit 11.

[0054] Here, an alarm variable is a variable used to determine whether an alarm is necessary; for example, in the water supply industry, it is a measured value such as water quality or water volume. When an alarm variable reaches a specified threshold, a specified alarm occurs, and when the alarm variable does not reach the threshold, the alarm ends. The alarm occurrence and end times are recorded as discrete data as shown in FIG. 3. Meanwhile, alarm variables are recorded in database 120 as continuous data. Also, in the water supply industry, an manipulated variable is an manipulated variable such as the amount of chemical injected. When the manipulated variable is manually changed after an alarm occurs, the time of the change is recorded as shown in FIG. 3. Like alarm variables, manipulated variables are recorded in the database as continuous data.

[0055] FIG. 35 shows data 3501 to be used in modeling and a constructed model (classification tree) 3502. When an alarm occurs, variables that affect the operation execution include the alarm issuance time T (if an operation is performed, the time from the issuance to the operation execution), the difference Δx between the maximum value of the alarm variable and the threshold, the area S exceeding the threshold, the average value y0 of the operation variable during the alarm issuance, and the increment Δy of the operation variable during the same time (if an operation is performed, the average value y0 of the operation variable from the alarm issuance to the operation execution, and the increment Δy of the operation variable during the same time). If there are any other variables that affect the operation execution, they may be used as explanatory variables. The operation determination model creation unit 281 prepares a data set in which all of these variables are explanatory variables and the presence or absence of the operation execution (presence: z=1, absence: z=0) is the explained variable. The operation determination model creation unit 281 uses these data sets to model the conditions under which an operation is required, for example, with a classification tree, and stores the model in the database 120 as the operation determination model 381. An example of the operation judgment model 381 is shown in 3502 in Fig. 35. By following the decision tree according to the values ​​of the explanatory variables, it is possible to judge whether an operation is necessary (numeric value is 1) or not (numeric value is 0).

[0056] An example of a data set is shown in Fig. 36. In this example, 20 alarms occurred, and corresponding operations were carried out for two of them. There are 20 data sets, and the values ​​of the explanatory variables at the time of each alarm are calculated by the explanatory variable calculation unit 27 and stored in the database 120 in the form of a table shown in Fig. 36. The alarms that required operations are alarms No. 3 and No. 15, and the value of the explained variable z is 1.

[0057] Fig. 37 is a flowchart of a program (operation determination model creation unit) that constructs a classification tree using the data set in Fig. 36. In step S3701, the operation determination model creation unit 281 reads user-specified information (alarm name, operation name, analysis period, etc.). In step S3702, the operation determination model creation unit 281 reads a data set. In step S3703, the operation determination model creation unit 281 constructs a classification tree using a classification tree construction algorithm (such as a commercially available package), stores it in database 120 together with target event information, and terminates the process.

[0058] 38 is a flowchart of a program (operation necessity determination unit) that uses a constructed classification tree to determine whether or not an operation needs to be performed. In step S3801, the operation necessity determination unit 291 reads user-specified information (alarm name, operation name, analysis period, etc.). In step S3802, the operation necessity determination unit 291 calls up a classification tree corresponding to the user-specified information from database 120. In step S3803, the operation necessity determination unit 291 causes explanatory variable calculation unit 27 to calculate the current values ​​of the explanatory variables. Finally, in step S3804, the operation necessity determination unit 291 traverses the classification tree using the values ​​of the explanatory variables as input, determines the value of the explained variable z, and presents this to the user as 1 indicating that an operation is required or 0 indicating that no operation is required.

[0059] An example of a screen presented to the user is shown in Fig. 39. On a screen such as the display unit 14, the values ​​of explanatory variables are output in the upper area, a decision tree is output in the central area, and whether or not an operation is required is displayed in the lower area. In this example, the alarm issuance time is long at 3 minutes, and it is determined that an operation is required. EXAMPLES

[0060] A seventh embodiment of the present invention will be described with reference to Fig. 40 to Fig. 45. The seventh embodiment is intended to model the conditions in the case where an alarm event and an operation event are correlated and an alarm occurs after an operation is performed. Here, the explanation is given assuming that an alarm event A and an operation event Ope are correlated, the time difference correlation coefficient is 0.15, the response time (time lag) is 5 minutes, the number of operation event occurrences is 30, the number of alarm event occurrences is 10, and the number of chained events is 3 (there were 3 cases in which an alarm occurred 5 minutes after an operation was performed).

[0061] FIG. 40 is a functional configuration diagram of an event analysis device according to a seventh embodiment. The event analysis device 1 of the seventh embodiment is different from that of the first embodiment and further includes an explanatory variable calculation unit 27, an alarm determination model creation unit 282, and an alarm presence / absence determination unit 292. The explanatory variable calculation unit 27 of this embodiment calculates the value of an explanatory variable that influences the occurrence of an alarm based on an alarm variable 36 (measured with a continuous variable for determining whether or not an alarm is issued, here referring to the measured time series data of the variable) and an operation variable 37 (a continuous variable representing the amount of operation performed for the alarm issuance, here referring to the operation time series data) for an event pair in which an alarm event occurs after an operation event occurs among the event pairs extracted by the correlation output unit 24. The alarm determination model creation unit 282 creates an alarm determination model 382 that defines the condition for an alarm to occur based on the value of the explanatory variable calculated by the explanatory variable calculation unit 27 and the value of the explained variable corresponding to that value (whether or not an alarm occurs). The alarm presence / absence determination unit 292 determines whether an alarm has occurred based on the current explanatory variable values ​​calculated by the explanatory variable calculation unit 27 and the alarm determination model 382 created by the alarm determination model creation unit 282. The calculation processing program 110 for realizing the functions of the explanatory variable calculation unit 27, the alarm determination model creation unit 282, and the alarm presence / absence determination unit 292 is stored in the storage unit 11.

[0062] FIG. 41 shows data 4101 to be used in modeling and an example of a judgment model 4102. When an operation is performed, variables for determining whether it affects the occurrence of an alarm include the average value y0 of the operation variable from a specified time in the past to the operation, the increment Δy0 of the operation variable for the same time, the amount of operation Δy by the user, the average value x0 of the alarm variable for the same time, and the increment Δx0 of the alarm variable. If there are any other variables that affect the occurrence of an alarm, they may be used as explanatory variables. The alarm judgment model creation unit 282 prepares a data set in which all of these variables are explanatory variables and the presence or absence of an alarm occurrence after the operation (yes: z=1, no: z=0) is the explained variable. The alarm judgment model creation unit 282 uses these data sets to model the conditions for the occurrence of an alarm with a nonlinear model such as a classification tree, for example, and stores the model in the database 120 as an alarm judgment model 382. An example of the alarm judgment model 382 is shown in 4102 of FIG. 41. By substituting the values ​​of the explanatory variables into the model and calculating z, it is possible to determine whether an alarm will occur (the value is 1) or not (the value is 0).

[0063] An example of a data set is shown in Fig. 42. In this example, an operation occurs 30 times, and an alarm occurs in three of them. There are 30 data sets, and the values ​​of the explanatory variables at the time of each operation are calculated by the explanatory variable calculation unit 27 and stored in the database 120 in the form of a table shown in Fig. 42. The operations that caused an alarm were No. 2, No. 15, and No. 30, and the value of the explained variable z was 1.

[0064] Fig. 43 is a flowchart of a program (alarm determination model creation unit) that constructs a non-linear model using the data set in Fig. 42. In step S4301, the alarm determination model creation unit 282 reads user-specified information (alarm name, operation name, analysis period, etc.). In step S4302, the alarm determination model creation unit 282 reads the data set. In step S4303, the alarm determination model creation unit 282 constructs a determination model using a non-linear model construction algorithm (such as a commercially available package such as machine learning), stores it in the database 120 together with the target event information, and ends the process.

[0065] 44 is a flowchart of a program (alarm occurrence determination unit) that uses a construction determination model to determine whether an alarm has occurred. In step S4401, the alarm occurrence determination unit 292 reads user-specified information (alarm name, operation name, analysis period, etc.). In step S4402, the alarm occurrence determination unit 292 reads out the alarm determination model 382 corresponding to the user-specified information from the database 120. In step S4403, the alarm occurrence determination unit 292 has the explanatory variable calculation unit 27 calculate and grasp the state up to the present time (y0, Δy0, x0, Δx0). In step S4404, if the user wants to perform an operation at the present time, when the candidate Δy is determined, the alarm occurrence determination unit 292 inputs the candidate Δy of the operation amount change and the state up to the present time (y0, Δy0, x0, Δx0) to the alarm determination model 382. Finally, in step S4405, the result of the judgment made by the alarm judgment model 382, ​​whether or not to issue an alarm, is presented to the user.

[0066] An example of a screen presented to the user is shown in Fig. 45. On a screen such as the display unit 14, values ​​such as the current state are output in the upper area, a judgment model is output in the center area, and whether an alarm has occurred is displayed in the lower area. In this example, the change in the operation amount is large at 2.5, and it is judged that an alarm has occurred. [Explanation of symbols]

[0067] 1...Event analysis device, 120...Database

Claims

1. An event analysis device for analyzing an event related to an alarm for a system to be monitored and controlled or an event related to an operation for the system, comprising: a time series generating unit that generates time series data for each of a plurality of events, the time series data having a bit of 1 at the time of the event occurrence and a bit of 0 at other times; a time difference correlation coefficient specifying unit that calculates time difference correlation coefficients for a plurality of time lags based on the time series data for each event pair and specifies a maximum time difference correlation coefficient that is the maximum among the time difference correlation coefficients; a chain count actual value specification unit that calculates, for each event pair, actual chain count values ​​for a plurality of time lags by using an inner product of the time series data, and specifies a maximum actual chain count value that is the maximum of the actual chain count values; and a correlation output unit that extracts event pairs for which the maximum time difference correlation coefficient is equal to or greater than a first predetermined value and the maximum number of chain events actual value is equal to or greater than a second predetermined value, and outputs the maximum time difference correlation coefficient in the event pairs and a response time, which is the time lag when the maximum time difference correlation coefficient is reached, together with a correlation diagram.

2. In claim 1, The method further includes an independence probability specification unit that calculates, for each event pair, an independence probability, which is the probability that the number of chain events when the event pair is assumed to be independent of each other, will be equal to or greater than the actual number of chain events, for a plurality of time lags, and specifies a minimum independence probability that is the smallest of the independence probabilities, The correlation output unit Instead of extracting an event pair in which the maximum time difference correlation coefficient is equal to or greater than a first predetermined value and the maximum number of chain events is equal to or greater than a second predetermined value, An event analysis device characterized by extracting an event pair for which the maximum time difference correlation coefficient is equal to or greater than a first predetermined value and the minimum independence probability is equal to or less than a third predetermined value.

3. In claim 1 or 2, The time difference correlation coefficient specifying unit An event analysis device characterized in that, when there are multiple time lags for which the time difference correlation coefficient is equal to or greater than the first predetermined value, a response time is calculated by taking a weighted average of the time lags, with each of the time difference correlation coefficients as a weight, and the maximum time difference correlation coefficient is updated by the sum of each of the time difference correlation coefficients.

4. In claim 1 or 2, an event analysis device further comprising an importance calculation unit that identifies an event pair in which an event related to an alarm and an event related to an operation are linked from among the event pairs extracted by the correlation output unit, and calculates an importance related to the alarm or the operation based on the maximum time difference correlation coefficient and the response time in the identified event pair.

5. In claim 4, The importance calculation unit An event analysis device characterized in that the importance is calculated based on a maximum chain probability, which is a maximum value of chain probabilities calculated using the actual value of the number of chain events, instead of the maximum time difference correlation coefficient.

6. In claim 1 or 2, The correlation output unit The maximum time difference correlation coefficient and the response time in an event pair extracted using the short-term time series data; The maximum time difference correlation coefficient and the response time in an event pair extracted using the long-term time series data; and outputting the merged data together with the correlation diagram.

7. In claim 1 or 2, an explanatory variable calculation unit that calculates, for an event pair in which an event related to an operation occurs after an event related to an alarm occurs among the event pairs extracted by the correlation output unit, a value of an explanatory variable that affects the execution of the operation based on an alarm variable for determining whether or not the alarm is necessary and an operation variable that is an amount of operation of the operation; a model creation unit that creates a model of a condition in which the operation is required based on the values ​​of the explanatory variables calculated by the explanatory variable calculation unit and the values ​​of the explained variables corresponding to the values ​​of the explanatory variables; an operation necessity determination unit that determines whether or not the operation needs to be performed based on the current values ​​of the explanatory variables calculated by the explanatory variable calculation unit and the model created by the model creation unit.

8. In claim 1 or 2, an explanatory variable calculation unit that calculates, for an event pair in which an event related to an alarm occurs after an event related to an operation occurs among the event pairs extracted by the correlation output unit, a value of an explanatory variable that influences the occurrence of the alarm, based on an alarm variable for determining whether or not the alarm is necessary and an operation variable that is an amount of operation of the operation; a model creation unit that creates a model of conditions for generating the alarm based on the explanatory variable values ​​calculated by the explanatory variable calculation unit and the corresponding explained variable values; an alarm presence / absence determination unit that determines whether or not the alarm has occurred based on the current values ​​of the explanatory variables calculated by the explanatory variable calculation unit and the model created by the model creation unit.

9. An event analysis method for analyzing an event related to an alarm for a system to be monitored and controlled, or an event related to an operation for the system, comprising: generating time series data for each of a plurality of events, the time series data having a bit set to 1 at the time of the event occurrence and a bit set to 0 at other times; calculating a time difference correlation coefficient for each event pair for a plurality of time lags based on the time series data, and identifying a maximum time difference correlation coefficient that is the maximum among the time difference correlation coefficients; calculating, for each event pair, actual values ​​of the number of chain events for a plurality of time lags by using an inner product of the time series data, and identifying a maximum actual value of the number of chain events that is the maximum of the actual values ​​of the number of chain events; extracting event pairs for which the maximum time difference correlation coefficient is equal to or greater than a first predetermined value and the maximum number of chain events actual value is equal to or greater than a second predetermined value, and outputting the maximum time difference correlation coefficient in the event pairs and a response time, which is the time lag when the maximum time difference correlation coefficient is reached, together with a correlation diagram.

10. An event analysis device which is a computer that analyzes events related to alarms for a system to be monitored and controlled, or events related to operations for the system, a time series generating unit that generates time series data for each of a plurality of events, the time series data having a bit of 1 at the time of the event occurrence and a bit of 0 at other times; a time difference correlation coefficient specifying unit that calculates time difference correlation coefficients for a plurality of time lags based on the time series data for each event pair and specifies a maximum time difference correlation coefficient that is the maximum among the time difference correlation coefficients; a chain count actual value specification unit that calculates, for each event pair, actual chain count values ​​for a plurality of time lags by using an inner product of the time series data, and specifies a maximum actual chain count value that is the maximum of the actual chain count values; The program functions as a correlation output unit that extracts event pairs for which the maximum time difference correlation coefficient is equal to or greater than a first predetermined value and the maximum number of chain events actual value is equal to or greater than a second predetermined value, and outputs the maximum time difference correlation coefficient in the event pairs and the response time, which is the time lag when the maximum time difference correlation coefficient is reached, together with a correlation diagram.

Citation Information

Patent Citations

  • Alarm analyzer, analyzing method and program

    JP2005216148A