Information processing apparatus, information processing method, and information processing program

The information processing apparatus improves anomaly detection accuracy by comparing log information identifiers within a specified monitoring time with normal operation identifiers, effectively addressing challenges in detecting anomalies in existing systems.

JP2025084593AActive Publication Date: 2025-06-03OBIC CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023198609
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-06-03
Estimated Expiration
2043-11-22

AI Technical Summary

Technical Problem

Existing systems face challenges in accurately detecting anomalies based on log information, particularly when log information is missing or recorded in irregular patterns, making it difficult to determine system abnormalities.

Method used

An information processing apparatus that compares log information identifiers within a specified monitoring time with identifiers from normal operation times, outputs determination results, and uses these results to detect the state of the monitoring target, thereby improving anomaly detection accuracy.

Benefits of technology

The solution enhances the accuracy of anomaly detection by comparing log patterns during normal operation with actual recorded patterns, enabling the detection of internal abnormalities such as interrupted states, and facilitating various anomaly detection tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025084593000001_ABST
    Figure 2025084593000001_ABST
Patent Text Reader

Abstract

To improve accuracy in detection of abnormality based on log information such as events and so on.SOLUTION: According to an information processing apparatus, an acquiring unit acquires log information for monitoring time from time of a predetermined timing back to time by a designated time. A determination unit compares an identifier of each log information for a monitoring time with an identifier of the log information recorded in a normal time to output, with respect to each identifier, determination result indicating whether or not each log information for a monitoring time has log information having an identifier of the log information recorded in a normal state. A state detection unit, with reference to a basic pattern as combination of determination results as to each identifier set for each state of a monitoring target, detects a basic pattern matched with an occurrence pattern of the determination result as combination of the determination result of each identifier, to detect a state of a monitoring target corresponding to the occurrence pattern of the determination result. An event log information output unit detects, among event log information indicating each state, event log information corresponding to the detected state to supply it to a monitoring unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an information processing method, and an information processing program.

Background Art

[0002] Today, various services such as Web (World Wide Web) services or application services are provided. In such services, an abnormal state is monitored constantly or at predetermined time intervals, and an abnormality in the system is determined based on specific log information output.

[0003] For example, Patent Document 1 (Japanese Patent Application Laid-Open No. 2016-024786) discloses a log analysis device that analyzes logs of a plurality of applications to detect abnormal events. This log analysis device collects logs of a plurality of applications. Also, as an error log indicating a direct abnormal event, the similarity between a pre-registered log pattern and the log pattern of the collected log is calculated, where the log pattern is a combination of the error log and the warning log continuously output immediately before it. Then, based on the calculated similarity, the content of the abnormal event to be notified is determined.

[0004] Thereby, abnormal events can be detected based on the analysis results of logs of a plurality of applications.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] Here, there is a demand for the development of a device that improves the accuracy of detecting abnormalities based on log information such as events.

[0007] The present invention has been made in view of the above-described problems, and an object thereof is to provide an information processing apparatus, an information processing method, and an information processing program capable of improving the accuracy of anomaly detection based on log information such as events.

Means for Solving the Problems

[0008] In order to solve the above-described problems and achieve the object, an information processing apparatus according to the present invention compares an identifier of each piece of log information for a monitoring time, which is the time from the time at a predetermined timing to the time retroactively specified time, among the log information of a monitoring target stored with time information added in a storage unit, with an identifier of log information recorded during normal times, which is stored in advance in the storage unit, and outputs, for each identifier, a determination result indicating whether or not there is log information including an identifier of log information recorded during normal times in each piece of log information for the monitoring time. A determination unit, a state detection unit that detects a basic pattern corresponding to the occurrence pattern of the determination result by referring to a basic pattern in which the determination results for each identifier, set for each state of the monitoring target, stored in the storage unit are combined, and thereby detects the state of the monitoring target corresponding to the occurrence pattern of the determination result, and an event log information output unit that detects event log information corresponding to the detected state from among the event log information indicating each state, stored in the storage unit, and supplies it to a monitoring unit that monitors the normal operation of the monitoring target.

[0009] In addition, in order to solve the above problems and achieve the object, an information processing method according to the present invention includes: an acquisition unit compares identifiers of each piece of log information for a monitoring time, which is the time from the time at a predetermined timing to the time retroactively specified time, among the log information of a monitoring target stored in a storage unit with the time information added and stored, with identifiers of log information recorded during normal times, which are stored in the storage unit in advance, and outputs, for each identifier, a determination result indicating whether or not there is log information including an identifier of log information recorded during normal times in each piece of log information for the monitoring time; a state detection unit detects a basic pattern corresponding to the occurrence pattern of the determination result by referring to a basic pattern combining the determination results for each identifier, which is set for each state of the monitoring target and stored in the storage unit, and detects the state of the monitoring target corresponding to the occurrence pattern of the determination result; and an event log information output unit detects event log information corresponding to the detected state from among the event log information indicating each state, which is stored in the storage unit, and supplies it to a monitoring unit that monitors the normal operation of the monitoring target.

[0010] Also, in order to solve the above-described problems and achieve the object, the information processing program according to the present invention causes a computer to compare, among the log information of a monitoring target stored in a storage unit with time information added thereto, the identifier of each log information for a monitoring time, which is the time from the time at a predetermined timing to the time retrogressed by a designated time, with the identifier of the log information recorded during normal times, which is stored in the storage unit in advance, and output, for each identifier, a determination result indicating whether or not there is log information including the identifier of the log information recorded during normal times in each log information for the monitoring time; detect a basic pattern that matches the occurrence pattern of the determination result obtained by combining the determination results for each identifier, by referring to a basic pattern in which the determination results for each identifier, set for each state of the monitoring target, stored in the storage unit are combined, thereby detecting the state of the monitoring target corresponding to the occurrence pattern of the determination result; and function as an event log information output unit that detects the event log information corresponding to the detected state from among the event log information indicating each state, stored in the storage unit, and supplies it to a monitoring unit that monitors the normal operation of the monitoring target.

Advantages of the Invention

[0011] The present invention can improve the accuracy of anomaly detection based on log information such as events.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Figure 29

Figure 30

Figure 31

Figure 32

Figure 33

Figure 34

Figure 35

Figure 36

Figure 37

Figure 38

Figure 39

Figure 40

Figure 41

Figure 42

Figure 43

Figure 44

Figure 45

Figure 46

Figure 47

BEST MODE FOR CARRYING OUT THE INVENTION

[0013] Hereinafter, an information processing apparatus according to an embodiment to which the present invention is applied will be described in detail with reference to the drawings. Note that the present invention is not limited to the following embodiments.

[0014] [Overview] Among various services such as web services or application services, timely and accurate monitoring of fault occurrence and abnormal states is required to prevent major risks that may occur later.

[0015] Generally, system abnormalities are often determined based on specific output log information. However, when the log information that should originally be output is not output, there is no log information to refer to during the determination, making it difficult to determine system abnormalities.

[0016] Also, when the log recording order is different from the predetermined recording order, since the recorded log pattern is an irregular log pattern, there is a problem that it is difficult to detect system abnormalities.

[0017] Also, when system stoppage is detected in system liveness monitoring, an abnormal log is output. However, when the system is operating in appearance but the operation is actually interrupted midway, no abnormal log indicating this interrupted state is output, resulting in a problem that it is difficult to detect system abnormalities.

[0018] Note that even when the system is in an interrupted state and the log information that should originally be output is only output halfway, it is preferable to enable detection of system abnormalities.

[0019] The information processing apparatus according to the embodiment can detect abnormalities in the monitoring target and determine its state by comparing the log pattern that should be recorded during normal operation with the actually recorded log pattern.

[0020] This makes it possible to detect internal abnormalities that are difficult to judge from the appearance, such as an interrupted state, during system abnormality monitoring.

[0021] In addition, it is possible to perform various abnormality detections, such as whether there are any omissions in the procedures of the service restart sequence or application procedures (e.g., prepayment → payment closing process) after maintenance.

[0022] [Hardware Configuration] As shown in FIG. 1, the information processing apparatus 1 of the embodiment has the same configuration as a normal personal computer apparatus, and includes a storage unit 2, a control unit 3, a communication interface unit 4, and an input / output interface unit 5. An input device 6 and an output device 7 are connected to the input / output interface unit 5. As the output device 7, a display unit such as a monitor device (including a home television), a printing device, or a speaker device corresponds. As the input device 6, in addition to a keyboard device, a mouse device, and a microphone device, a monitor device that cooperates with the mouse device to realize a pointing device function can also be used. The communication interface unit 4 is connected to a network such as a wide area network such as the Internet or a private network such as a LAN (Local Area Network).

[0023] As the storage unit 2, for example, a storage device such as a ROM (Read Only Memory), a RAM (Random Access Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive) can be used. A general-purpose operation system and a monitoring program are stored in the storage unit 2.

[0024] As a general-purpose operating system, for example, widely used operating systems such as Windows (registered trademark), MacOS (registered trademark), Chrome OS (registered trademark), UNIX (registered trademark), Linux (registered trademark), Android (registered trademark), and iOS (registered trademark) can be used. In the information processing apparatus 1 of the embodiment, the control unit 3 functions as the monitoring unit 23 based on this general-purpose operating system, and monitors (detects) system anomalies based on the event log information generated by the determination unit 22.

[0025] The monitoring program is an example of an information processing program. Although details will be described later, the control unit 3 functions as the acquisition unit 21 and the determination unit 22 based on this monitoring program, detects the generation state of the log information based on the log information for the specified monitoring time, and generates event log information. The determination unit 22 supplies this event log information to the monitoring unit 23.

[0026] In addition, the storage unit 2 is provided with a monitoring code master 11, a status master 12, a log type master 13, a monitoring details master 14, a processing order master 15, a status determination master 16, a status determination breakdown master 17, an event log setting master 18, a monitoring performance table 19, and a determination result work table 20, each of which is a storage area.

[0027] Also, the storage unit 2 stores event log information, business application log information, and operation log information of various events generated by the event log generation unit 24.

[0028] As shown in FIG. 2, in the monitoring code master 11, a monitoring code (monitoring CD) and a monitoring time are set for each process (monitoring name) to be monitored. The "monitoring time" is the time from the time of a predetermined timing at which monitoring of the process starts to the time that is the specified time back. In other words, the "monitoring time" is the time of the log information acquired when monitoring the process.

[0029] For example, in the example of FIG. 2, the monitoring time of the session host abnormality check process is set to "90 minutes". In this case, the acquisition unit 21 acquires the log information having the time information from the time when the monitoring of the session host abnormality check process starts to the time 90 minutes back among the log information stored in the storage unit 2. Similarly, for example, in the example of FIG. 2, the monitoring time of the restart process is set to "60 minutes". In this case, the acquisition unit 21 acquires the log information having the time information from the time when the monitoring of the restart process starts to the time 60 minutes back among the log information stored in the storage unit 2. In this way, the monitoring code master 11 stores the monitoring time for each monitoring target.

[0030] As shown in FIG. 3, the status master 12 stores the status codes assigned to each status of the monitoring target. This example of FIG. 3 shows that when the monitoring target is in the "before monitoring" status, a status code of "0" is assigned, and when the monitoring target is in the "normal" status, a status code of "1" is assigned. Also, this example of FIG. 3 shows that when the monitoring target is in the "failed" status, a status code of "2" is assigned, and when the monitoring target is in the "partially failed" status, a status code of "3" is assigned.

[0031] For such a status master 12, it is possible to set status codes for several assumed statuses.

[0032] As shown in FIG. 4, the log type master 13 sets the acquisition source of the log information for each log type. This example of FIG. 4 shows that the log information of the log type of "Event Log" is set to be acquired from the "event log information" in the storage unit 2. Similarly, this example of FIG. 4 shows that the log information of the log type of "Business Application Log" is set to be acquired from the "business application log information" in the storage unit 2. Similarly, this example of FIG. 4 shows that the log information of the log type of "Operational Log" is set to be acquired from the "operational log information" in the storage unit 2.

[0033] In addition, the acquisition sources of the respective log information may be set to acquire from a plurality of services, a plurality of applications, and / or a plurality of infrastructures, respectively.

[0034] In the monitoring details master 14, individual processing is set for each monitoring target. Specifically, as shown in FIG. 5, in the monitoring details master 14, a monitoring code, a line number, a log type code, an identifier, and processing content are associated and stored respectively. This example of FIG. 5 shows that when monitoring "session host abnormality check" with a monitoring code of "1", the presence or absence of log information with an event identification number (event ID) of "1238" is detected from the event log information (Event Log), and individual processing of line number "1", and the presence or absence of log information with an event ID of "1231" is detected from the event log information (Event Log), and individual processing of line number "2" are performed.

[0035] Also, this example of FIG. 5 shows that when monitoring "cost calculation process" with a monitoring code of "3", the presence or absence of the identifier "Sitabarai" is detected from the business application log information (Aplication Log), and individual processing of line number "1", the presence or absence of the identifier "GenkaCalc" is detected from the business application log information (Aplication Log), and individual processing of line number "2", and the presence or absence of the identifier "1000" is detected from the event log information (Event Log), and individual processing of line number "3" are performed.

[0036] The identifier corresponds to the identification information (ID) of various log information of the above-mentioned general-purpose operation system. For example, when Windows (registered trademark) is provided as the general-purpose operation system, the identifier is set corresponding to the identification information (ID) of various log information of this Windows (registered trademark).

[0037] Also, the identifiers "Sitabarai" and "GenkaCalc" are examples of job IDs of business application log information.

[0038] In the processing sequence master 15, as shown in FIG. 6, the order of individual processing for each monitoring target is set. Specifically, for the individual processing (detection of the presence or absence of the event ID of 1238) with the line number "1" of the "session host abnormality check" where the monitoring code is "1", the processing order of "1" is set, and for the individual processing (detection of the presence or absence of the event ID of 1231) with the line number "2", the processing order of "2" is set.

[0039] Also, for the individual processing (detection of the presence or absence of prepayment input) with the line number "1" of the "cost calculation process" where the monitoring code is "3", the processing order of "1" is set, and for the individual processing (detection of the presence or absence of execution of the cost calculation process) with the line number "2", the processing order of "2" is set.

[0040] Also, for the individual processing (detection of the presence or absence of the event ID of 1000) with the line number "3" of the "cost calculation process" where the monitoring code is "3", the processing order of "0" is set. This processing order of "0" indicates that the processing order can be in any order as long as the event ID of 1000 is detected.

[0041] In the status determination master 16, as shown in FIG. 7, status codes are set for each pattern of the determination results of the monitoring targets. Specifically, as shown in FIG. 7, for the monitoring target with the monitoring code "1", for the pattern where the determination results of the individual processes with the line numbers "1" and "2" of the monitoring detail master 14 shown in FIG. 5 are both "true", the status code of "1" is set.

[0042] Also, for the monitoring target with the monitoring code "1", for the pattern where the determination results of the individual processes with the line numbers "1" and "2" of the monitoring detail master 14 shown in FIG. 5 are both "false", the status code of "2" is set.

[0043] Also, for the monitoring target with the monitoring code "3", when the determination results of each individual process of the line numbers "1", "2", and "3" of the monitoring detail master 14 shown in FIG. 5 are all "true", the status code "1" is set. Also, for the monitoring target with the monitoring code "3", when the determination results of each individual process of the line numbers "1", "2", and "3" of the monitoring detail master 14 shown in FIG. 5 are all "false", the status code "2" is set. Also, for the monitoring target with the monitoring code "3", when the determination results of each individual process of the line numbers "1", "2", and "3" of the monitoring detail master 14 shown in FIG. 5 are respectively "false", "true", and "false", the status code "3" is set.

[0044] As shown in FIG. 8, in the status determination breakdown master 17, patterns other than the pattern (basic pattern) of the status determination master 16 are set as necessary. That is, when multiple patterns are assumed for one status, one pattern is set in the status determination master 16 as described above, and the other patterns are set in this status determination breakdown master 17.

[0045] This status determination breakdown master 17 is referred to when the basic pattern corresponding to the "status" is detected from the status determination master 16. Then, from this status determination breakdown master 17, patterns other than the basic pattern detected from the status determination master 16 are detected.

[0046] Specifically, in this example of FIG. 8, for the monitoring code "3" and the status code "3", the patterns of line numbers "1" to "5" are set. The pattern of line number "1" of the status code "3" is the pattern where the determination results of each individual process of line numbers "1" to "3" of the monitoring code "3" in the process sequence master shown in FIG. 6 are respectively "true", "true", and "false".

[0047] Also, the pattern of line number "2" of the status code "3" is such that the determination results of each individual process from line number "1" to line number "3" of the monitoring code "3" in the process sequence master shown in FIG. 6 are "false", "false", and "true" respectively. Also, the pattern of line number "3" of the status code "3" is such that the determination results of each individual process from line number "1" to line number "3" of the monitoring code "3" in the process sequence master shown in FIG. 6 are "true", "false", and "true" respectively.

[0048] Also, the pattern of line number "4" of the status code "3" is such that the determination results of each individual process from line number "1" to line number "3" of the monitoring code "3" in the process sequence master shown in FIG. 6 are "false", "true", and "false" respectively. Also, the pattern of line number "5" of the status code "3" is such that the determination results of each individual process from line number "1" to line number "3" of the monitoring code "3" in the process sequence master shown in FIG. 6 are "true", "false", and "false" respectively.

[0049] As shown in FIG. 9, event log setting master 18 is set with event log information to be output according to the "status (determination result)" to be monitored. Specifically, for each combination of each monitoring code and status code in event log setting master 18, a log name, source name, event ID, classification, level, and message are set.

[0050] Specifically, in this example, when both the monitoring code and the status code are "1", the event log setting master 18 is configured to output event log information including the log name of "Application", the source name of "LogMonitoringProcess", the event ID of "1", the classification of "none", the level of "normal", and the message of "The monitored process is normal." Also, in this example, when the monitoring code is "1" and the status code is "2", the event log setting master 18 is configured to output event log information including the log name of "Application", the source name of "LogMonitoringProcess", the event ID of "2", the classification of "none", the level of "error", and the message of "A problem has occurred in the monitored process."

[0051] Also, in this example, when the monitoring code is "3" and the status code is "1", the event log setting master 18 is configured to output event log information including the log name of "Application", the source name of "LogMonitoringProcess", the event ID of "1", the classification of "none", the level of "normal", and the message of "The monitored process is normal." Also, in this example, when the monitoring code is "3" and the status code is "2", the event log setting master 18 is configured to output event log information including the log name of "Application", the source name of "LogMonitoringProcess", the event ID of "4", the classification of "none", the level of "error", and the message of "The cost calculation process has failed."

[0052] Furthermore, in this example, when the monitoring code is "3" and the status code is "3", the event log setting master 18 is configured to output event log information including the log name of "Application", the source name of "LogMonitoringProcess", the event ID of "10", the classification of "none", the level of "error", and the message of "The process has not been partially executed."

[0053] [Functional Configuration of Information Processing Apparatus] Next, the control unit 3 functions as an acquisition unit 21, a determination unit 22, a state detection unit 25, and an event log information output unit 26 shown in FIG. 1 by executing the monitoring program stored in the storage unit 2. Further, the control unit 3 functions as a monitoring unit 23 and an event log generation unit 24 shown in FIG. 1 by executing the general-purpose operating system stored in the storage unit 2.

[0054] The event log generation unit 24 generates event log information, business application log information, and operation log information of various events, and stores them in the storage unit 2.

[0055] The acquisition unit 21 acquires the monitoring time corresponding to the monitoring process from the monitoring code master 11 shown in FIG. 2, acquires individual monitoring processes from the monitoring detail master 14 shown in FIG. 5, and acquires the processing order of each individual monitoring process from the processing order master 15 shown in FIG. 6.

[0056] As shown in FIGS. 10 and 11, the determination unit 22 compares the identifier of each log information for the monitoring time, which is the time from the time at a predetermined timing to the time retrogressed by the specified time, among the log information (event log information, business application log information, operation log information, etc.) of the monitoring target stored in the storage unit 2 with the time information added and stored, with the identifier of the log information recorded during normal times, which is stored in advance in the storage unit (monitoring detail master 14 in FIG. 5), and outputs, for each identifier, a determination result indicating whether or not there is log information having the identifier of the log information recorded during normal times in each log information for the monitoring time.

[0057] As shown in FIGS. 10 and 11, the state detection unit 25 refers to the basic pattern in which the determination results for each identifier, set for each state of the monitoring target, stored in the storage unit (state determination master 16 in FIG. 7) are combined, and detects the basic pattern that matches the occurrence pattern of the determination result in which the determination results for each identifier are combined, thereby detecting the state of the monitoring target corresponding to the occurrence pattern of the determination result.

[0058] Then, as shown in FIG. 11, the event log information output unit 26 detects the event log information corresponding to the detected state among the event log information indicating each state stored in the storage unit (event log setting master 18 in FIG. 9), and supplies it to the monitoring unit 23 that monitors the normal operation of the monitoring target.

[0059] In addition, the storage unit (processing order master 15 in FIG. 6) stores processing order information indicating the processing order in which the log information of each identifier occurs, together with the log information and identifiers recorded during normal operation. In this case, the determination unit 22 outputs a determination result for each identifier based on whether the log information of the identifier for the acquired monitoring time is obtained in the processing order of the log information of the identifier recorded during normal operation.

[0060] In addition, the storage unit (state determination breakdown master 17 in FIG. 8) stores other patterns combined with the determination results, together with the basic patterns. In this case, the state detection unit 25 refers to the basic patterns and other patterns, and detects a basic pattern or other pattern that matches the occurrence pattern of the determination results.

[0061] In addition, the event log information output unit 26 outputs the event log information in an information format that can be processed by a general-purpose operation system. The monitoring unit 23 operates based on the general-purpose operation system, and outputs a monitoring result corresponding to the event log information to an external device (output device 7: monitor device or printing device, etc.).

[0062] [Monitoring Operation] FIGS. 12 and 13 are flowcharts showing the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment. Among them, FIG. 12 is a flowchart showing the first half of the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment, and FIG. 13 is a flowchart showing the second half of the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment.

[0063] Based on the monitoring program shown in FIG. 1, the control unit 3 of the information processing apparatus 1 according to the embodiment functions as an acquisition unit 21, a determination unit 22, a state detection unit 25, and an event log information output unit 26. Further, based on a general-purpose operation system, the control unit 3 of the information processing apparatus 1 according to the embodiment functions as a monitoring unit 23 and an event log generation unit 24.

[0064] Note that, although the acquisition unit 21 to the event log information output unit 26 will be described as being realized by software by a monitoring program or a general-purpose operation system, part or all of the acquisition unit 21 to the event log information output unit 26 may be realized by hardware. Even in this case, the same effects as those described later can be obtained.

[0065] First, in the flowchart of FIG. 12, when the information processing apparatus 1 according to the embodiment is powered on, the information processing apparatus 1 enters the startup state, and the monitoring process starts from step S1. In this example, when an event or the like is executed, the event log generation unit 24 generates event log information shown in FIG. 14, business application log information shown in FIG. 15, and operation log information shown in FIG. 16, which are sequentially stored in the storage unit 2.

[0066] As shown in FIGS. 14 to 16, the various log information includes an event ID or a job ID (JobID) together with time information (time information) indicating the date and time. Although it is an example, the job ID is identification information assigned to accounting operations such as a billing input process (Seikyuu), a prepayment input process (Sitabarai), a cost calculation process (GenkaCalc), an order input process (Juchuu), and an estimate input process (Mitumori).

[0067] Returning to the description of the flowchart of FIG. 12, in step S1, the control unit 3 starts the monitoring process at a predetermined timing or interval, and records the date, time, monitoring code, processing content, and status code when the monitoring process starts in the monitoring result table 19 of the storage unit 2. Note that the monitoring process is executed as a batch process.

[0068] [First monitoring example] For example, an example of executing the "session host abnormality check process" of the monitoring code "1" in the monitoring code master 11 shown in FIG. 2 at 7:00 am every Wednesday will be described. In this case, when the execution time arrives, as shown in FIG. 17, the control unit 3 stores the date and time such as 7:00 am on August 30, 2023 in the monitoring result table 19. At the same time, the control unit 3 refers to the monitoring code master 11 shown in FIG. 2 and stores the processing content of the "session host abnormality check process" and the monitoring code "1" in the monitoring result table 19 as shown in FIG. 17.

[0069] Furthermore, the control unit 3 refers to the state master 12 shown in FIG. 3 and stores the state code indicating the current state in the monitoring result table 19 as shown in FIG. 17. At this point, since the current state is "0 (before monitoring)", the control unit 3 stores the state code "0" in the monitoring result table 19 as shown in FIG. 17.

[0070] Next, the control unit 3 functions as the acquisition unit 21 in step S2, refers to the monitoring code master 11 shown in FIG. 2, and acquires the monitoring time set for the "session host abnormality check process" of the current monitoring process. In the case of this example, the monitoring time set for the "session host abnormality check process" is "90 minutes" as shown in FIG. 18.

[0071] Also, in step S2, the acquisition unit 21 refers to the monitoring detail master 14 shown in FIG. 5 based on the monitoring code "1" to acquire the individual monitoring processes associated with the monitoring code "1". In the case of this example, the individual monitoring processes for detecting the presence or absence of the output of the event ID "1238" (identifier: 1238, log type code: EventLog) and the individual monitoring process for detecting the presence or absence of the output of the event ID "1231" (identifier: 1231, log type code: EventLog) are respectively associated with the monitoring code "1". The acquisition unit 21 acquires these individual monitoring processes from the monitoring detail master 14 as shown in FIG. 19.

[0072] Also, in step S2, the acquisition unit 21 refers to the log type master 13 shown in FIG. 4 based on the log type code of the individual monitoring process, and acquires the source of the log information corresponding to the log type code. In the case of this example, since the log type code is "EventLog", as shown in FIG. 20, the source of the log information is "event log information".

[0073] Also, in step S2, the acquisition unit 21 refers to the process order master 15 shown in FIG. 6 based on the monitoring code and line number of the individual monitoring process shown in FIG. 19, and acquires the process order corresponding to the monitoring code and line number. In the case of this example, the monitoring code is "1", and there are individual monitoring processes with line numbers "1" and "2" respectively. Therefore, as shown in FIG. 21, the acquisition unit 21 acquires the process order "1" as the process order of line number "1" with the monitoring code "1" and the process order "2" as the process order of line number "2".

[0074] Next, in steps S3 and S4, the determination unit 22 compares, in order, the identifier of each log information within the monitoring time period, which is the time from the monitoring start time (7:00 am on August 30, 2023) back by "90 minutes (see FIG. 2)", with the identifier of each individual monitoring process acquired from the monitoring detail master 14 (the identifier of the log information recorded during normal times: 1238 or 1231) among the event log information stored in the storage unit 2.

[0075] Then, the determination unit 22 determines for each identifier whether there is log information including the identifier of each individual monitoring process in each log information within the monitoring time period (step S4), and stores the determination result in the determination result work table 20 (step S5). The determination unit 22 executes the processes of steps S3 to S5 for each individual monitoring process until it is determined in step S6 that the determination for each individual monitoring process is completed.

[0076] Specifically, FIG. 22 is a schematic diagram showing how the determination result is output in the first monitoring example. In the case of the example in FIG. 22, within the monitoring time from 7:00 am on August 30, 2023, which is the start time of monitoring, back to the time 90 minutes earlier, log information with the identifier "1238" (in this case, the event ID) was first output (at 5:48:55 am on August 30, 2023).

[0077] This means that within the monitoring time, the individual monitoring process with the processing order of "1" was executed first. Therefore, the determination unit 22 makes a "true" determination for the log information with the identifier "1238". Then, as shown in FIG. 23, the determination unit 22 stores in the determination result work table 20 the monitoring code of "1", the line number of "1", the processing order of the individual monitoring process of "1", and the determination result of "true" which is the determination result.

[0078] At this point, the determination of the individual monitoring process with the processing order of "2" remains (step S6: Yes). Therefore, the process returns to step S3, and the determination unit 22 determines the presence or absence of log information with the identifier "1231". In the case of the example in FIG. 22, the log information with the identifier "1238" was output at 5:48:55 am on August 30, 2023, and then, the log information with the identifier "1231" was output at 5:55:00 am on August 30, 2023.

[0079] This means that within the monitoring time, following the individual monitoring process with the processing order of "1", the individual monitoring process with the processing order of "2" was executed. Therefore, the determination unit 22 makes a "true" determination for the log information with the identifier "1231". Then, as shown in FIG. 23, the determination unit 22 stores in the determination result work table 20 the monitoring code of "1", the line number of "2", the processing order of the individual monitoring process of "2", and the determination result of "true" which is the determination result.

[0080] When the determination for each individual monitoring process is completed in this way (step S6: No), the process proceeds to step S7 of the flowchart in FIG. 13. In step S7, the state detection unit 25 refers to the basic pattern of the state determination master 16 shown in FIG. 7 based on the monitoring code, the determination result of row number "1", and the determination result of row number "2" in the determination result work table 20 shown in FIG. 23.

[0081] In the case of the example in FIG. 23, the pattern of the determination result combining the determination results of row number "1" and row number "2" is the pattern of "true, true". In the case of the example of the state determination master 16 shown in FIG. 7, when the monitoring code is "1" and the pattern is "true, true", the state code is "1". In this case, as shown in FIG. 24, the state determination master 16 detects the state code of "1" as the state code with the monitoring code of "1" and the pattern of "true, true".

[0082] When the state code is detected in this way, in step S8, the control unit 3 stores, as shown in FIG. 25, the monitoring process end date and time, such as 7:03:00 on August 30, 2023, in the monitoring result table 19. At the same time, the control unit 3 stores the monitoring code of "1", the processing content of "monitoring process end", and the state code of "1" corresponding to the determination result (true, true) of each individual monitoring process in the monitoring result table 19.

[0083] Next, in step S9, the event log information output unit 26 refers to the event log setting master 18 shown in FIG. 9 based on the monitoring code of "1" and the state code of "1", and detects the event log information corresponding to the combination of the monitoring code of "1" and the state code of "1". In the case of the example in FIG. 9, the event log information corresponding to the combination of the monitoring code of "1" and the state code of "1" is, as shown in FIG. 26, event log information including various information such as the log name being "Application", the source name being "LogMonitoringProcess", the event ID being "1", the classification being "none", the level being "normal", and the message being "The monitored process is normal."

[0084] Therefore, the event log information output unit 26 deletes the monitoring code "1" and the status code "1" from this event log information, and generates the event log information shown in FIG. 27 in an information form that can be processed by a general-purpose operation system. Then, the event log information output unit 26 supplies the generated event log information to the monitoring unit 23 that operates based on the general-purpose operation system.

[0085] Thereby, in step S10, the monitoring unit 23 monitors the normal operation of the event according to the event log information. The monitoring unit 23 outputs this monitoring result via the output device 7 (such as a monitor device or a printing device).

[0086] [Second Monitoring Example] Next, a second monitoring example will be described. For example, an example of executing the "session host abnormality check process" of the monitoring code "1" of the monitoring code master 11 shown in FIG. 2 at 7:20 am on Wednesday every week will be described. In this case, when the execution time arrives, the control unit 3 stores the date and time, such as 7:20 am on August 30, 2023, in the monitoring result table 19 as shown in FIG. 28. At the same time, the control unit 3 refers to the monitoring code master 11 shown in FIG. 2 and stores the processing content of the "session host abnormality check process" and the monitoring code "1" in the monitoring result table 19 as shown in FIG. 17.

[0087] Furthermore, the control unit 3 refers to the status master 12 shown in FIG. 3 and stores the status code indicating the current status in the monitoring result table 19 as shown in FIG. 17. At this point, since the current status is "0 (before monitoring)", the control unit 3 stores the status code "0" in the monitoring result table 19 as shown in FIG. 28.

[0088] Next, the control unit 3 functions as the acquisition unit 21, refers to the monitoring code master 11 shown in FIG. 2, and acquires the monitoring time set for the "session host abnormality check process" of the current monitoring process. In the case of this example, the monitoring time set for the "session host abnormality check process" is "90 minutes" as shown in FIG. 2.

[0089] Also, the acquisition unit 21 refers to the monitoring detail master 14 shown in FIG. 5 based on the monitoring code of "1", and acquires the individual monitoring processes stored in association with the monitoring code of "1". In the case of this example, an individual monitoring process for detecting the presence or absence of the output of the event ID of "1238" (identifier: 1238, log type code: EventLog) and an individual monitoring process for detecting the presence or absence of the output of the event ID of "1231" (identifier: 1231, log type code: EventLog) are respectively associated with the monitoring code of "1".

[0090] Also, the acquisition unit 21 refers to the log type master 13 shown in FIG. 4 based on the log type code of the individual monitoring process, and acquires the acquisition source of the log information corresponding to the log type code. In the case of this example, since the log type code is "EventLog", as shown in FIG. 4, the acquisition source of the log information is "event log information".

[0091] Also, the acquisition unit 21 refers to the processing order master 15 shown in FIG. 6 based on the monitoring code and line number of the individual monitoring process shown in FIG. 5, and acquires the processing order corresponding to the monitoring code and line number. In the case of this example, the monitoring code is "1", and there are individual monitoring processes with line numbers "1" and "2" respectively. Therefore, as shown in FIG. 6, the acquisition unit 21 acquires the processing order of "1" as the processing order of line number "1" with the monitoring code of "1", and the processing order of "2" as the processing order of line number "2".

[0092] Next, the determination unit 22 sequentially compares the identifiers of each log information for the monitoring time, which is the time from the monitoring start time (7:00 am on August 30, 2023) to the time 90 minutes back (see Figure 2), with the identifiers of each individual monitoring process obtained from the monitoring detail master 14 (the identifiers of the log information recorded during normal times: 1238 or 1231).

[0093] Then, the determination unit 22 determines for each log information for the monitoring time whether there is log information with the identifier of each individual monitoring process, and stores the determination result in the determination result work table 20 for each identifier.

[0094] Specifically, Figure 29 is a schematic diagram showing how the determination result is output in the second monitoring example. In the case of the example in this Figure 29, the monitoring time is from 5:50 am, which is 90 minutes back from the monitoring start time of 7:20 am on August 30, 2023. Before this monitoring time, log information with the identifier of "1238" (in this case, the event ID) was output (at 5:48:55 am on August 30, 2023).

[0095] This indicates that the individual monitoring process with the processing order of "1" was executed before the monitoring time. Therefore, the determination unit 22 makes a "false" determination for the log information with the identifier of "1238". Then, as shown in Figure 30, the determination unit 22 stores in the determination result work table 20 the monitoring code of "1", the line number of "1", the processing order of the individual monitoring process of "1", and the determination result of "false".

[0096] Subsequently, the determination unit 22 determines the presence or absence of log information with the identifier of "1231". In the case of the example in Figure 29, the log information with the identifier of "1231", for which the processing order should be "2", was output first within the monitoring time (at 5:55:00 am on August 30, 2023).

[0097] This means that during the monitoring time, the individual monitoring process with the processing order of "2" was executed before the individual monitoring process with the processing order of "1". Therefore, the determination unit 22 makes a "false" determination for the log information with the identifier of "1231". Then, as shown in FIG. 30, the determination unit 22 stores the monitoring code of "1", the line number of "2", the processing order of the individual monitoring process of "2", and the determination result of "false" in the determination result work table 20.

[0098] When the determination for each individual monitoring process is completed in this way, the state detection unit 25 refers to the basic pattern of the state determination master 16 shown in FIG. 7 based on the monitoring code, the determination result of the line number "1", and the determination result of the line number "2" in the determination result work table 20 shown in FIG. 30.

[0099] In the case of the example in FIG. 30, the pattern of the determination result combining the determination results of the line number "1" and the line number "2" is the pattern of "false, false". In the case of the example of the state determination master 16 shown in FIG. 7, when the monitoring code is "1" and the pattern is "false, false", the state code is "2". In this case, as shown in FIG. 31, the state determination master 16 detects the state code of "2" as the state code with the monitoring code of "1" and the pattern of "false, false".

[0100] When the state code is detected in this way, the control unit 3 stores, as shown in FIG. 32, the monitoring process end date and time such as 7:23:00 on August 30, 2023 in the monitoring result table 19. At the same time, the control unit 3 stores the monitoring code of "1", the processing content of "monitoring process end", and the state code of "2" corresponding to the determination results (false, false) of each individual monitoring process in the monitoring result table 19.

[0101] Next, in step S9, the event log information output unit 26 refers to the event log setting master 18 shown in FIG. 9 based on the monitoring code "1" and the status code "2", and detects event log information corresponding to the combination of the monitoring code "1" and the status code "2". In the case of the example in FIG. 9, the event log information corresponding to the combination of the monitoring code "1" and the status code "2" is event log information including various information such as the log name being "Application", the source name being "LogMonitoringProcess", the event ID being "2", the classification being "none", the level being "error", and the message being "A problem has occurred in the process to be monitored." as shown in FIG. 33.

[0102] Therefore, the event log information output unit 26 deletes the monitoring code "1" and the status code "2" from this event log information, and generates the event log information shown in FIG. 34 in an information form processable by a general-purpose operation system. Then, the event log information output unit 26 supplies the generated event log information to the monitoring unit 23 that operates based on the general-purpose operation system.

[0103] Thereby, in step S10, the monitoring unit 23 monitors the normal operation of the event according to the event log information. The monitoring unit 23 outputs this monitoring result via the output device 7 (such as a monitor device or a printing device).

[0104] [Third Monitoring Example] For example, an example of executing the "cost calculation process" of the monitoring code "3" in the monitoring code master 11 shown in FIG. 2 at 15:00 on Tuesday every week will be described. In this case, when the execution time arrives, the control unit 3 stores the date and time such as 15:00 on August 29, 2023 in the monitoring result table 19 as shown in FIG. 35. At the same time, the control unit 3 refers to the monitoring code master 11 shown in FIG. 2 and stores the processing content of the "cost calculation process" and the monitoring code "3" in the monitoring result table 19 as shown in FIG. 35.

[0105] Furthermore, the control unit 3 refers to the status master 12 shown in FIG. 3, and stores the status code indicating the current status in the monitoring result table 19 as shown in FIG. 35. At this point, since the current status is "0 (before monitoring)", the control unit 3 stores the status code "0" in the monitoring result table 19 as shown in FIG. 35.

[0106] Next, the control unit 3 functions as the acquisition unit 21, refers to the monitoring code master 11 shown in FIG. 2, and acquires the monitoring time set for the "cost calculation process" of the current monitoring process. In the case of this example, the monitoring time set for the "cost calculation process" is "40 minutes" as shown in FIG. 36.

[0107] Also, the acquisition unit 21 refers to the monitoring detail master 14 shown in FIG. 5 based on the monitoring code "3", and acquires the individual monitoring processes stored in association with the monitoring code "3". In the case of this example, a total of three individual monitoring processes from line number "1" to line number "3" are set in association with the monitoring code "3".

[0108] The individual monitoring process of line number "1" is a monitoring process for the execution of prepayment input, and the log type code is "AplicationLog" and the identifier is "Sitabarai".

[0109] The individual monitoring process of line number "2" is a monitoring process for the execution of cost calculation process, and the log type code is "AplicationLog" and the identifier is "GenkaCalc".

[0110] The individual monitoring process of line number "3" is a monitoring process for the output of the event ID "1000", and the log type code is "EventLog" and the identifier is "1000".

[0111] Further, the acquisition unit 21 refers to the log type master 13 shown in FIG. 4 based on the log type code of individual monitoring processes, and acquires the source of the log information corresponding to the log type code. In the case of this example, since the log type codes of the identifiers of "Sitabarai" and "GenkaCalc" are "AplicationLog", as shown in FIG. 38, the source of the log information is "business application log information".

[0112] Also, in the case of this example, since the log type code of the identifier of "EventLog" is "1000", as shown in FIG. 38, the source of the log information is "event log information".

[0113] Further, the acquisition unit 21 refers to the processing order master 15 shown in FIG. 6 based on the monitoring code "3" and line numbers "1" to "3" of each individual monitoring process shown in FIG. 37, and acquires the processing order corresponding to the monitoring code "3" and each line number. In the processing order master 15, the processing orders of "1", "2", and "0" are set for each individual monitoring process of line numbers "1" to "3" of the monitoring code "3". As shown in FIG. 39, the acquisition unit 21 acquires the processing order corresponding to the monitoring code "3" and line numbers "1" to "3".

[0114] Next, the determination unit 22 compares, in order, the identifiers of each log information for the monitoring time period, which is the time from the monitoring start time (15:00 on August 29, 2023) to the time "40 minutes (see FIG. 2)" back, among the event log information and business application log information stored in the storage unit 2, with the identifiers of each individual monitoring process acquired from the monitoring detail master 14 (the identifiers of the log information recorded during normal times: Sitabarai, GenkaCalc, 1000).

[0115] Specifically, FIG. 40 is an example of determining the presence or absence of the identifier "1000" set to the processing order "0" regardless of the order, based on the event log information for the monitoring time. The example in FIG. 40 is an example where the event log information of the identifier "1000" was detected at 14:42:14 on August 29, 2023. Therefore, the determination result of the determination unit 22 is "true".

[0116] Also, FIG. 41 is an example of determining the presence or absence of each identifier of "Sitabarai" and "GenkaCalc" based on the business application log information for the monitoring time. The example in FIG. 41 is an example where the business application log information of the identifier of "GenkaCalc" was detected at 14:41:56 on August 29, 2023, and the business application log information of the identifier of "Sitabarai" was detected at 14:42:57 on August 29, 2023, which is a later time.

[0117] For each identifier of "Sitabarai" and "GenkaCalc", from the processing order, the identifier of "GenkaCalc" should occur at a time after the time when the identifier of "Sitabarai" occurs. However, in the case of the example in FIG. 41, the identifier of "GenkaCalc" occurred first, and then the identifier of "Sitabarai" occurred at a later time. In this case, the determination unit 22 sets the determination result of the identifier of "GenkaCalc" that occurred in the wrong processing order to "false". Also, since the identifier of "Sitabarai" that occurred after "GenkaCalc" can be regarded as the occurrence of the identifier of the processing order "1", the determination unit 22 sets the determination result to "true".

[0118] Then, as shown in FIG. 42, the determination unit 22 stores in the determination result work table 20 the determination results of "true", "false", and "true" as the determination results of the monitoring code "3", line numbers "1" to "3", and processing orders "1", "2", and "0".

[0119] When the determination for each individual monitoring process is completed in this way, the state detection unit 25 refers to the basic pattern of the state determination master 16 shown in FIGS. 7 and 43 based on the monitoring code "3" of the determination result work table 20 shown in FIG. 42 and the determination results of line numbers "1" to "line number 3".

[0120] In the case of the example in FIG. 42, the pattern of the determination result combining the determination results of line numbers "1" to "line number 3" is the pattern of "true, false, true". In the case of the example of the state determination master 16 shown in FIGS. 7 and 43, there is no pattern of "true, false, true" with the monitoring code being "3".

[0121] In this case, the state detection unit 25 refers to the state determination breakdown master 17 shown in FIGS. 8 and 44. When referring to this state determination breakdown master 17, there is a pattern of "true, false, true" (other patterns) with the monitoring code being "3". And the state code of the pattern of "true, false, true" with the monitoring code being "3" is "3". Thereby, the state determination master 16 detects the state code of "3" as the state code of the pattern of "true, false, true" with the monitoring code being "3".

[0122] When the state code is detected in this way, as shown in FIG. 45, the control unit 3 stores the monitoring process end date and time, such as 15:02:00 on August 29, 2023, in the monitoring result table 19. At the same time, the control unit 3 stores the monitoring code of "3", the processing content of "monitoring process end", and the state code of "3" corresponding to the determination results (true, false, true) of each individual monitoring process in the monitoring result table 19.

[0123] Next, based on the monitoring code "3" and the status code "3", the event log information output unit 26 refers to the event log setting master 18 shown in FIG. 9 and detects event log information corresponding to the combination of the monitoring code "3" and the status code "3". In the case of the example in FIG. 9, the event log information corresponding to the combination of the monitoring code "3" and the status code "3" is event log information including various information such as the log name being "Application", the source name being "LogMonitoringProcess", the event ID being "10", the classification being "none", the level being "error", and the message being "The process has not been partially executed." as shown in FIG. 46.

[0124] Therefore, the event log information output unit 26 deletes the monitoring code "3" and the status code "3" from this event log information and generates the event log information shown in FIG. 47 in an information form that can be processed by a general-purpose operation system. Then, the event log information output unit 26 supplies the generated event log information to the monitoring unit 23 that operates based on the general-purpose operation system.

[0125] Thereby, in step S10, the monitoring unit 23 monitors the normal operation of the event according to the event log information. The monitoring unit 23 outputs this monitoring result via the output device 7 (such as a monitor device or a printing device).

[0126] [Effects of the Embodiment] As is clear from the above description, the information processing apparatus according to the embodiment detects an abnormality in the monitoring target and determines its state by comparing the log pattern (basic pattern) to be recorded during normal times with the actually recorded log pattern.

[0127] Thereby, when monitoring the abnormality of the system, it is possible to detect an internal abnormality that is difficult to judge from the appearance, such as an interrupted state.

[0128] In addition, various anomaly detections can be enabled, such as whether there are any omissions in the procedures of the service restart sequence after maintenance or the application procedures (e.g., prepayment → payment closing process).

[0129] Therefore, it is possible to improve the anomaly detection accuracy based on log information such as events.

[0130] [Contribution to the Sustainable Development Goals (SDGs) Led by the United Nations] According to this embodiment, since it can contribute to improving business efficiency and promoting appropriate business judgment of enterprises, it is possible to contribute to Goals 8 and 9 of the SDGs.

[0131] In addition, according to this embodiment, since it can contribute to reducing waste loss and promoting paperless and digitalization, it is possible to contribute to Goals 12, 13, and 15 of the SDGs.

[0132] In addition, according to this embodiment, since it can contribute to strengthening control and governance, it is possible to contribute to Goal 16 of the SDGs.

[0133] [Other Embodiments] In addition to the above-described embodiments, the present invention may be implemented in various different embodiments within the scope of the technical idea described in the claims.

[0134] For example, among the respective processes described in the embodiment, all or part of the processes described as being automatically performed can also be performed manually, or all or part of the processes described as being performed manually can be automatically performed by a known method.

[0135] In addition, regarding the processing procedures, control procedures, specific names, information including parameters such as registered data and search conditions for each process, screen examples, and database configurations shown in this specification and the drawings, they can be arbitrarily changed unless otherwise specified.

[0136] Regarding the information processing apparatus 1, each of the illustrated components is conceptually functional and does not necessarily have to be physically configured as shown in the drawings.

[0137] For example, regarding the processing functions provided by the information processing apparatus 1, particularly the various processing functions performed by the control unit 3 and the control unit 3, all or any part of them may be realized by a CPU (Central Processing Unit) and a program interpreted and executed by the CPU, or may be realized as hardware by wired logic. The program is recorded on a non-transitory computer-readable recording medium including programmed instructions for causing the information processing apparatus to execute the processing described in this embodiment, and is mechanically read by the information processing apparatus 1 as necessary. That is, in a storage unit such as a ROM or an HDD, a computer program for giving instructions to the CPU in cooperation with the OS to perform various processes is recorded. This computer program is executed by being loaded into the RAM and constitutes the control unit 3 in cooperation with the CPU.

[0138] Also, the information processing program (monitoring program) of this information processing apparatus 1 may be stored in another server apparatus connected to the information processing apparatus 1 via an arbitrary network, and all or part of it can be downloaded as necessary.

[0139] Also, an information processing program (monitoring program) for executing the processes described in this embodiment may be stored in a non-temporary computer-readable recording medium, or may be configured as a program product. Here, this "recording medium" includes any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical Disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc.

[0140] Also, the "program" is a data processing method described in any language or description method, and is not limited to a specific form such as source code or binary code. Note that the "program" is not necessarily limited to a single configuration, and also includes those that are distributed as a plurality of modules or libraries, or those that achieve their functions in cooperation with other separate programs represented by an OS. Also, for the specific configuration, reading procedure, and installation procedure after reading for reading the recording medium in the information processing apparatus 1 shown in the embodiment, well-known configurations and procedures can be used.

[0141] The storage unit 2 is a storage means such as a memory device such as a RAM or a ROM, a fixed disk device such as a hard disk, a flexible disk, and an optical disk, and stores various programs, tables, databases, and web page files used for various processes and website provision.

[0142] Further, the information processing apparatus 1 may be configured by an information processing apparatus such as a known personal computer apparatus or a workstation, or may be configured by an information processing apparatus to which an arbitrary peripheral device is connected. Further, the information processing apparatus may be realized by implementing software (including programs or data, etc.) for realizing the processing described in the present embodiment.

[0143] Furthermore, the specific form of the dispersion and integration of the devices is not limited to that shown in the drawings, and all or part of them can be functionally or physically dispersed and integrated in arbitrary units according to various additions or according to the functional load. That is, the above-described embodiments may be arbitrarily combined and implemented, or the embodiments may be selectively implemented.

Industrial Applicability

[0144] The present invention is applicable to any system as long as it is a system for performing anomaly detection based on log information such as events.

Explanation of Signs

[0145] 1 Information processing apparatus 2 Storage unit 3 Control unit 4 Communication interface unit 5 Input / output interface unit 6 Input device 7 Output device 11 Monitoring code master 12 Status master 13 Log type master 14 Monitoring details master 15 Processing order master 16 Status determination master 17 Status determination breakdown master 18 Event log setting master 19 Monitoring result table 20 Judgment result work table 21 Acquisition unit 22 Judgment unit 23 Monitoring unit 24 Event log generation unit 25 State detection unit 26 Event log information output unit

Claims

1. Among the log information of the monitoring target that is stored in the memory unit with time information added, for each piece of log information for the monitoring time, which is the time from the time at a predetermined timing to the time that is the specified time back, the identifier of each piece of log information is compared with the identifier of the log information that is recorded during normal times and is stored in the memory unit in advance, and a determination unit that outputs, for each identifier, a determination result indicating whether there is log information having the identifier of the log information recorded during normal times among each piece of the log information for the monitoring time; A state detection unit that, by referring to a basic pattern in which the determination results for each identifier, which is set for each state of the monitoring target and stored in the memory unit, are combined, detects the basic pattern that matches the occurrence pattern of the determination results, and thereby detects the state of the monitoring target corresponding to the occurrence pattern of the determination results; An event log information output unit that, among the event log information indicating each of the states and stored in the memory unit, detects the event log information corresponding to the detected state and supplies it to a monitoring unit that monitors the normal operation of the monitoring target; An information processing apparatus having the above.

2. In the memory unit, together with the log information and the identifier that are recorded during normal times, processing order information indicating the processing order, which is the order of occurrence of the log information for each identifier, is stored; The determination unit outputs the determination result for each identifier based on whether the log information of the identifier for the acquired monitoring time is obtained in the processing order of the log information of the identifier that is recorded during normal times. The information processing apparatus according to claim 1, characterized by the above.

3. In the memory unit, together with the basic pattern, other patterns in which the determination results are combined are stored; The state detection unit refers to the basic pattern and the other patterns and detects the basic pattern or the other pattern that matches the occurrence pattern of the determination results. The information processing apparatus according to claim 2, characterized by the above.

4. The event log information output unit outputs the event log information in an information form that can be processed by a general-purpose operation system; The monitoring unit operates based on the general-purpose operation system and outputs a monitoring result corresponding to the event log information to an external device. The information processing apparatus according to any one of claims 1 to 3, characterized by the above.

5. The acquisition unit compares the identifier of each piece of log information for the monitoring time, which is the time from the time of a predetermined timing to the time that is the specified number of minutes back from the time of the predetermined timing, among the log information of the monitoring target stored in the storage unit with the time information added and stored, with the identifier of the log information recorded during normal times that is stored in advance in the storage unit, and outputs, for each identifier, a determination result indicating whether or not there is log information having the identifier of the log information recorded during normal times in each piece of the log information for the monitoring time. The state detection unit refers to the basic pattern in which the determination results for each identifier, which is set for each state of the monitoring target and stored in the storage unit, are combined, and detects the basic pattern that matches the occurrence pattern of the determination results in which the determination results for each identifier are combined, thereby detecting the state of the monitoring target corresponding to the occurrence pattern of the determination results. The event log information output unit detects the event log information corresponding to the detected state among the event log information indicating each of the states stored in the storage unit, and supplies it to the monitoring unit that monitors the normal operation of the monitoring target. An information processing method having the above.

6. A computer, a determination unit that compares the identifier of each piece of log information for the monitoring time, which is the time from the time of a predetermined timing to the time that is the specified number of minutes back from the time of the predetermined timing, among the log information of the monitoring target stored in the storage unit with the time information added and stored, with the identifier of the log information recorded during normal times that is stored in advance in the storage unit, and outputs, for each identifier, a determination result indicating whether or not there is log information having the identifier of the log information recorded during normal times in each piece of the log information for the monitoring time; a state detection unit that refers to the basic pattern in which the determination results for each identifier, which is set for each state of the monitoring target and stored in the storage unit, are combined, and detects the basic pattern that matches the occurrence pattern of the determination results in which the determination results for each identifier are combined, thereby detecting the state of the monitoring target corresponding to the occurrence pattern of the determination results; causing it to function as an event log information output unit that detects the event log information corresponding to the detected state among the event log information indicating each of the states stored in the storage unit, and supplies it to the monitoring unit that monitors the normal operation of the monitoring target. An information processing program characterized by the above.

Citation Information

Patent Citations

  • Log analysis device

    JP2016024786A

  • Failure symptom detection system and failure symptom detection method

    JP2017107372A

  • Log analysis system, log analysis method, and program recording medium

    WO2016132717A1