Information processing device, information processing method and information processing program
The information processing apparatus enhances anomaly detection in log analysis systems by comparing log information identifiers and calculating a normal processing ratio, thereby improving accuracy and enabling comprehensive, pattern-independent monitoring.
Patent Information
- Application Number
- JP2023208770
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-11
- Publication Date
- 2025-06-23
- Estimated Expiration
- 2043-12-11
AI Technical Summary
Existing log analysis systems face challenges in accurately detecting anomalies based on log information, particularly in determining whether log information is output as expected and in calculating the percentage of logs output normally.
An information processing apparatus that compares log information identifiers within a specified monitoring time period with pre-stored identifiers from normal operation times, calculates a normal processing ratio, and uses this ratio to detect state information and output event log information for monitoring.
The apparatus improves the accuracy of anomaly detection by assessing the overall matching rate of log information, enabling per-site operation status monitoring and comprehensive log monitoring that is not pattern-dependent.
Smart Images

Figure 2025093185000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and an information processing program.
Background Art
[0002] Today, various services such as Web (World Wide Web) services or application services are provided. In such services, an abnormal state is monitored constantly or at predetermined time intervals, and an abnormality in the system is determined based on specific log information output.
[0003] For example, Patent Document 1 (Japanese Patent Application Laid-Open No. 2016-024786) discloses a log analysis apparatus that analyzes logs of a plurality of applications to detect abnormal events. This log analysis apparatus collects logs of a plurality of applications. Further, as an error log indicating a direct abnormal event, the similarity between a log pattern registered in advance and the log pattern of the collected log is calculated, where the log pattern is a combination of the error log and a warning log continuously output immediately before it. Then, based on the calculated similarity, the content of the abnormal event to be notified is determined.
[0004] Thereby, an abnormal event can be detected based on the analysis results of the logs of a plurality of applications.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] Here, there is a demand for the development of an apparatus that improves the accuracy of abnormality detection based on log information such as events.
[0007] The present invention has been made in view of the above problems, and an object thereof is to provide an information processing apparatus, an information processing method, and an information processing program capable of improving the accuracy of anomaly detection based on log information such as events.
Means for Solving the Problems
[0008] In order to solve the above problems and achieve the object, an information processing apparatus according to the present invention compares, for each identifier of log information for a monitoring time period, which is the time from the time at a predetermined timing to the time that is a specified time back in time, among the log information of a monitoring target stored with time information added in a storage unit, with the identifier of log information recorded during normal times, which is stored in the storage unit in advance, and outputs, for each identifier, a determination result indicating whether there is log information having the identifier of log information recorded during normal times among the log information for the monitoring time period; a normal processing ratio calculation unit that calculates a normal processing ratio, which is the ratio of the number of log information determined by the determination unit to be log information having the identifier of log information recorded during normal times among the log information for the monitoring time period, to the total number of determinations as to whether there is log information having the identifier of log information recorded during normal times among the log information for the monitoring time period; a state information detection unit that refers to the storage unit based on a comparison result of comparing the value of the calculated normal processing ratio with a determination threshold value of the normal processing ratio stored in the storage unit, and detects state information indicating the state of the monitoring target associated with the determination threshold value and stored in the storage unit; an event log information detection unit that detects, among the event log information indicating the state of the monitoring target stored in the storage unit, event log information corresponding to the state information detected by the state information detection unit; and an event log information output unit that supplies the detected event log information to a monitoring unit that monitors the normal operation of the monitoring target.
[0009] Also, in order to solve the above problems and achieve the object, an information processing method according to the present invention includes a determination unit that, among the log information of a monitoring target stored in a storage unit with time information added thereto, from the time at a predetermined timing to the time retroactively specified time, compares the identifier of each log information for the monitoring time, which is the time up to the time, with the identifier of the log information recorded during normal times pre-stored in the storage unit, and outputs, for each identifier, a determination result indicating whether there is log information having the identifier of the log information recorded during normal times among the log information for the monitoring time; a normal processing ratio calculation unit that calculates a normal processing ratio, which is the ratio of the number of log information determined to be log information having the identifier of the log information recorded during normal times in the determination step among the log information for the monitoring time, to the total number of determinations as to whether there is log information having the identifier of the log information recorded during normal times among the log information for the monitoring time; a state information detection unit that refers to the storage unit based on a comparison result of comparing the calculated value of the normal processing ratio with a determination threshold value of the normal processing ratio stored in the storage unit, and detects state information indicating the state of the monitoring target associated with the determination threshold value and stored in the storage unit; an event log information detection unit that detects event log information corresponding to the state information detected in the state information detection step among the event log information indicating the state of the monitoring target stored in the storage unit; and an event log information output unit that supplies the detected event log information to a monitoring unit that monitors the normal operation of the monitoring target.
[0010] Also, in order to solve the above-described problems and achieve the object, an information processing program according to the present invention causes a computer to compare, among log information of a monitoring target stored in a storage unit with time information added thereto, identifiers of each piece of log information for a monitoring time, which is the time from the time at a predetermined timing to the time retrogressed by a specified time, with identifiers of log information recorded during normal times, which are stored in the storage unit in advance, and output, for each identifier, a determination result indicating whether or not there is log information including an identifier of log information recorded during normal times in each piece of log information for the monitoring time; a normal processing ratio calculation unit that calculates a normal processing ratio, which is a ratio of the number of pieces of log information determined to be log information including an identifier of log information recorded during normal times by the determination unit to the total number of determinations as to whether or not there is log information including an identifier of log information recorded during normal times in each piece of log information for the monitoring time; a state information detection unit that refers to the storage unit based on a comparison result of comparing the calculated value of the normal processing ratio with a determination threshold value of the normal processing ratio stored in the storage unit, and detects state information indicating a state of a monitoring target associated with the determination threshold value and stored in the storage unit; an event log information detection unit that detects, among event log information indicating a state of a monitoring target stored in the storage unit, event log information corresponding to the state information detected by the state information detection unit; and causes an event log information output unit to function to supply the detected event log information to a monitoring unit that monitors normal operation of the monitoring target.
Effect of the Invention
[0011] The present invention can improve the accuracy of detecting abnormalities based on log information such as events.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Figure 27
Figure 28
Figure 29
Figure 30
Figure 31
DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, an information processing apparatus according to an embodiment to which the present invention is applied will be described in detail with reference to the drawings. Note that the present invention is not limited to the following embodiments.
[0014] [Summary] Today, among the various services provided such as web services or application services, timely and accurate monitoring of failures and abnormal states is required to prevent major risks that may occur later. Also, grasping the operation status across multiple services or the operation status of services on a per-site basis is required as a basis for judging the actions necessary in subsequent processes.
[0015] Here, when specific log information is output, it is easy to determine that it is abnormal. However, it has been difficult to perform anomaly detection according to multiple types of log information such as "whether the log that should be output at a specific timing is output" or "what percentage of the logs to be monitored are output normally".
[0016] Also, generally, there are cases where judgments are made based on a unique output of log information or multiple log information of server devices, other devices, etc. taking the cloud as an example. On the other hand, when considering dependencies on the CPU (Central Processing Unit) or writing to and reading from disks, such as in performance investigations, various cases are assumed and it has been difficult to extract. For this reason, the development of an exhaustive log monitoring function that is not affected by patterns is desired.
[0017] The information processing apparatus according to the embodiment detects the degree of abnormality based on the overall matching rate of the output log information, rather than determining whether it exactly matches the output log in the normal state.
[0018] Also, the information processing apparatus according to the embodiment enables the operation status and the detection of the degree of abnormality on a per-site basis for the monitoring target.
[0019] Note that the information processing apparatus according to the embodiment can be generally applied as long as a case where specific log information (regardless of the type of log information) can be assumed. Further, the above-described case can be set across a plurality of service application infrastructures.
[0020] [Hardware Configuration] As shown in FIG. 1, the information processing apparatus 1 according to the embodiment has the same configuration as a normal personal computer apparatus, and includes a storage unit 2, a control unit 3, a communication interface unit 4, and an input / output interface unit 5. An input device 6 and an output device 7 are connected to the input / output interface unit 5. As the output device 7, a display unit such as a monitor device (including a home television), a printing device, or a speaker device can be used. As the input device 6, in addition to a keyboard device, a mouse device, and a microphone device, a monitor device that cooperates with the mouse device to realize a pointing device function can be used. The communication interface unit 4 is connected to a network such as a wide area network such as the Internet or a private network such as a LAN (Local Area Network).
[0021] As the storage unit 2, for example, a storage device such as a ROM (Read Only Memory), a RAM (Random Access Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive) can be used. A general-purpose operation system and a monitoring program are stored in the storage unit 2.
[0022] As general-purpose operating systems, for example, widely used operating systems such as Windows (registered trademark), MacOS (registered trademark), Chrome OS (registered trademark), UNIX (registered trademark), Linux (registered trademark), Android (registered trademark), iOS (registered trademark) can be used. In the information processing apparatus 1 of the embodiment, the control unit 3 functions as an event log generation unit 21 based on this general-purpose operating system. Further, the control unit 3 functions as a monitoring unit 27 based on the general-purpose operating system, and monitors (detects) system anomalies based on the event log information generated by the determination units 23 to the event log information output unit 26.
[0023] The monitoring program is an example of an information processing program. Although details will be described later, the control unit 3 functions as an acquisition unit 22 to an event log information output unit 26 based on this monitoring program, and detects the generation rate (matching rate) of the log information to be generated based on the log information for the specified monitoring time. Then, the control unit 3 generates event log information indicating the operation state (normal, error, warning, etc.: see FIG. 7) of the monitoring target corresponding to the matching rate, and supplies this event log information to the monitoring unit 27.
[0024] In addition, the storage unit 2 is provided with a monitoring code master 11, a status master 12, a log type master 13, a monitoring detail master 14, a status determination threshold master 15, an event log setting master 16, a log information storage unit 17, a monitoring result table 18, and a determination result work table 19, which are respectively storage areas.
[0025] Further, the storage unit 2 is provided with an event log information storage unit 20 in which event log information of various events generated by the event log generation unit 21, business application log information, and operation log information are stored.
[0026] In the monitoring code master 11, as shown in FIG. 2, for each process (monitoring name) to be monitored, a monitoring code (monitoring CD) and a monitoring time are set. The "monitoring time" is the time from the time of a predetermined timing at which the monitoring of the process starts to the time that is the specified number of minutes back in time. In other words, the "monitoring time" is the time of the log information acquired when monitoring the process.
[0027] For example, in the example of FIG. 2, the monitoring time for the session host abnormality check process is set to "90 minutes". In this case, the acquisition unit 22 acquires the log information having the time information from the time when the monitoring of the session host abnormality check process starts to the time that is 90 minutes back in time among the log information stored in the storage unit 2. Similarly, for example, in the example of FIG. 2, the monitoring time for the restart process is set to "60 minutes". In this case, the acquisition unit 22 acquires the log information having the time information from the time when the monitoring of the restart process starts to the time that is 60 minutes back in time among the log information stored in the storage unit 2. In this way, the monitoring code master 11 stores the monitoring time for each monitoring target.
[0028] In the status master 12, as shown in FIG. 3, status codes assigned to each status of the monitoring target are stored. This example of FIG. 3 shows that when the monitoring target is in the "before monitoring" status, a status code of "0" is assigned, and when the monitoring target is in the "normal" status, a status code of "1" is assigned. Also, this example of FIG. 3 shows that when the monitoring target is in the "failed" status, a status code of "2" is assigned, and when the monitoring target is in the "partially failed" status, a status code of "3" is assigned. Also, this example of FIG. 3 shows that when the monthly closing process is not recommended, a status code of "4" is assigned.
[0029] For such a status master 12, it is possible to set status codes for the number of assumed statuses.
[0030] In the log type master 13, as shown in FIG. 4, the source of log information for each log type is set. The example in FIG. 4 shows that for the log information of the log type "Event Log", the "event log information" is acquired from the event log information storage unit 20. Similarly, the example in FIG. 4 shows that for the log information of the log type "Application Log", the "application log information" is acquired from the event log information storage unit 20. Similarly, the example in FIG. 4 shows that for the log information of the log type "Operational Log", the "operational log information" is acquired from the event log information storage unit 20.
[0031] Note that the source of each log information may be set to be acquired from a plurality of services, a plurality of applications, and / or a plurality of infrastructures respectively.
[0032] In the monitoring details master 14, individual processing for each monitoring target is set. Specifically, in the monitoring details master 14, as shown in FIG. 5, the monitoring code, line number, log type code, identifier, and processing content are stored in association with each other. The example in FIG. 5 shows that when monitoring "session host abnormality check" with a monitoring code of "1", the presence or absence of log information with an event identification number (event ID) of "1238" is detected from the event log information (Event Log) as the individual processing for line number "1", and the presence or absence of log information with an event ID of "1231" is detected from the event log information (Event Log) as the individual processing for line number "2".
[0033] Also, the example in FIG. 5 shows that when monitoring "payment closing process" with a monitoring code of "3", the presence or absence of each identifier from "Batch.Sime_1001" to "Batch.Sime_1020" is detected from the application log information (Application Log) as the individual processing for line numbers "1" to "20".
[0034] The identifier corresponds to the identification information (ID) of various log information of the general-purpose operating system described above. For example, when Windows (registered trademark) is provided as the general-purpose operating system, the identifier is set corresponding to the identification information (ID) of various log information of this Windows (registered trademark).
[0035] Also, identifiers such as "Batch.Sime_1001" are examples of job IDs of business application log information.
[0036] In the state determination threshold master 15, as shown in FIG. 6, a "status code" and a "determination threshold (%)" are associated and stored for each monitoring code described with reference to FIG. 2. The "determination threshold (%)" is the ratio (matching rate) of the number of log information determined by the determination unit 23 to be log information having the identifier of the log information recorded during normal operation (the identifier stored in the monitoring detail master 14 in FIG. 5) among the log information for the monitoring time period, with respect to the total number of determinations as to whether there is log information having the identifier of the log information recorded during normal operation.
[0037] Also, the "status code" corresponds to the status code assigned for each state (level) of the monitoring target in the event log setting master 16 described with reference to FIG. 7.
[0038] That is, in the state determination threshold master 15 shown in FIG. 6, a status code indicating the state (level) of the monitoring target is assigned for each determination threshold. In the example of FIG. 6, for example, for the monitoring code of "1", a determination threshold of "70%" and a determination threshold of "0%" are set. In the case of the determination threshold of "70%", it indicates that the monitoring target is in the state indicated by the status code of "1", and in the case of the determination threshold of "0%", it indicates that the monitoring target is in the state indicated by the status code of "2".
[0039] Similarly, in the example of FIG. 6, for the monitoring code of, for example, "3", determination thresholds of "80%", "0%", and "50%" are set. And in the case of the determination threshold of "80%", it indicates that the monitoring target is in the state indicated by the state code of "1". In the case of the determination threshold of "0%", it indicates that the monitoring target is in the state indicated by the state code of "2". In the case of the determination threshold of "50%", it indicates that the monitoring target is in the state indicated by the state code of "3".
[0040] Therefore, based on the monitoring code and the state code, by referring to the event log setting master 16 shown in FIG. 7, it is possible to detect the "state corresponding to the determination threshold" of the monitoring target. That is, in the event log setting master 16 shown in FIG. 7, a log name, a source name, an event ID, a classification, a level, and a message are associated and stored for the monitoring code and the state code.
[0041] For example, the level where the monitoring code is "1" and the state code is "1" is the "normal" level indicating that the monitoring target is operating normally. In this case, the message is "The processing of the monitoring target is normal." Also, the level where the monitoring code is "2" and the state code is "2" is the "error" level indicating that the monitoring target is not operating normally. In this case, the message is "The restart process is not being executed." Also, the level where the monitoring code is "3" and the state code is "3" is the "warning" level indicating that the monitoring target is not operating normally and a warning is required. In this case, the message is "Some bases where the input process is not completed remain. Please check separately."
[0042] As will be described later, the event log information output unit 26 generates event log information including such levels and messages and supplies it to the monitoring unit 27.
[0043] [Functional Configuration of Information Processing Apparatus] Next, the control unit 3 functions as an acquisition unit 22, a determination unit 23, a normal processing ratio calculation unit 24, a state information detection unit 25, and an event log information output unit 26 shown in FIG. 1 by executing the monitoring program stored in the storage unit 2. Further, the control unit 3 functions as an event log generation unit 21 and a monitoring unit 27 shown in FIG. 1 by executing the general-purpose operating system stored in the storage unit 2.
[0044] Note that the event log generation unit 21 to the monitoring unit 27 are described as being realized by software by a monitoring program or a general-purpose operating system. However, part or all of the event log generation unit 21 to the monitoring unit 27 may be realized by hardware. Even in this case, the same effects as those described later can be obtained.
[0045] The event log generation unit 21 generates event log information, business application log information, and operation log information of various events, and stores them in the event log information storage unit 20.
[0046] The acquisition unit 22 acquires the monitoring time corresponding to the monitoring process from the monitoring code master 11 shown in FIG. 2.
[0047] As shown in FIGS. 8 and 9, the determination unit 23 compares the identifier of each log information for the monitoring time, which is the time from the time at a predetermined timing to the time retroactively specified time, among the log information of the monitoring target stored with time information added in the storage unit 2 (log information storage unit 17), with the identifier of the log information recorded during normal times, which is stored in the storage unit 2 in advance. Then, the determination unit 23 outputs, for each identifier, a determination result indicating whether or not there is log information having the identifier of the log information recorded during normal times in each log information for the monitoring time.
[0048] As shown in FIGS. 8 and 9, the normal processing ratio calculation unit 24 calculates the normal processing ratio (matching ratio), which is the ratio of the number of log information determined by the determination unit 23 to be log information having an identifier of log information recorded during normal operation among each log information for the monitoring time, to the total number of determinations as to whether or not there is log information having an identifier of log information recorded during normal operation in each log information for the monitoring time.
[0049] As shown in FIGS. 8 and 9, the state information detection unit 25 refers to the storage unit (event log setting master 16 in FIG. 7) based on the comparison result of comparing the calculated value of the normal processing ratio with the determination threshold of the normal processing ratio stored in the storage unit (state determination threshold master 15 in FIG. 6). Then, the state information detection unit 25 detects state information (state code) indicating the state of the monitoring target stored in the storage unit (state determination threshold master 15 in FIG. 6) associated with the determination threshold.
[0050] As shown in FIG. 9, the event log information detection unit (event log information output unit 26) detects event log information corresponding to the state information (state code) detected by the state information detection unit 25 from the event log information (records including the levels and messages of each column in FIG. 7) indicating the state of the monitoring target stored in the storage unit (event log setting master 16 in FIG. 7).
[0051] As shown in FIG. 9, the event log information output unit 26 supplies the detected event log information to the monitoring unit 27 that monitors the normal operation of the monitoring target.
[0052] Further, when a plurality of determination thresholds are stored in the storage unit (state determination threshold master 15 in FIG. 6) (for example, for the monitoring code of "1", the determination thresholds of the state codes of "1" and "2" are respectively stored), the state information detection unit 25 compares the calculated value of the normal processing ratio with each determination threshold, and detects the state information (state code) associated with the determination threshold having the minimum difference value from the calculated value of the normal processing ratio.
[0053] In addition, the event log information output unit 26 outputs event log information in an information format that can be processed by a general-purpose operating system. The monitoring unit 27 operates based on the general-purpose operating system and outputs a monitoring result corresponding to the event log information to an external device (output device 7: for example, a display unit, a printing device, an external storage unit, etc.).
[0054] [Monitoring Operation] FIGS. 10 and 11 are flowcharts showing the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment. Among them, FIG. 10 is a flowchart showing the first half of the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment, and FIG. 11 is a flowchart showing the second half of the flow of the monitoring operation of the information processing apparatus 1 according to the embodiment.
[0055] The control unit 3 of the information processing apparatus 1 according to the embodiment functions as an acquisition unit 22, a determination unit 23, a normal processing ratio calculation unit 24, a state information detection unit 25, and an event log information output unit 26 based on the monitoring program shown in FIG. 1. In addition, the control unit 3 of the information processing apparatus 1 according to the embodiment functions as an event log generation unit 21 and a monitoring unit 27 based on a general-purpose operating system.
[0056] Note that the event log generation unit 21 to the monitoring unit 27 will be described as being realized by software by a monitoring program or a general-purpose operating system, but a part or all of the event log generation unit 21 to the monitoring unit 27 may be realized by hardware. Also in this case, the same effects as those described later can be obtained.
[0057] First, in the flowchart of FIG. 10, when the information processing apparatus 1 according to the embodiment is powered on, the information processing apparatus 1 enters the startup state, and the monitoring process starts from step S1. In this example, when an event or the like is executed, the event log generation unit 21 generates event log information shown in FIG. 12, business application log information shown in FIG. 13, and operation log information shown in FIG. 14, which are sequentially stored in the log information storage unit 17.
[0058] As shown in FIGS. 12 to 14, various log information includes an event ID or a job ID (JobID) along with time information (time information) indicating the date and time. Although it is an example, the job ID is identification information assigned to accounting operations such as closing processing (Batch.Sime), prepayment input processing (Sitabarai), deposit processing (Nyuukin), and order input processing (Juchuu).
[0059] Returning to the description of the flowchart in FIG. 10, in step S1, the control unit 3 starts the monitoring process at a predetermined timing or interval, and records the date, time, monitoring code, processing content, and status code when the monitoring process is started in the monitoring result table 18 of the storage unit 2. Note that the monitoring process is executed as a batch process.
[0060] [First Monitoring Example] For example, an example of executing the "session host abnormality check process" with the monitoring code "1" in the monitoring code master 11 shown in FIG. 2 at 7:00 am every Wednesday will be described. In this case, when the execution time arrives, as shown in FIG. 15, the control unit 3 stores in the monitoring result table 18 the date, time, such as 7:00 am on August 30, 2023, and the processing content of "monitoring process execution start" indicating that this time is the start time of the process. Also, the control unit 3 refers to the monitoring code master 11 shown in FIG. 2 and stores the monitoring code "1" in the monitoring result table 18 as shown in FIG. 15.
[0061] Furthermore, the control unit 3 refers to the status master 12 shown in FIG. 3 and stores the status code indicating the current status in the monitoring result table 18 as shown in FIG. 15. At this point, since the current status is "before monitoring", the control unit 3 stores the status code "0" in the monitoring result table 18 as shown in FIG. 15.
[0062] Next, in step S2, the control unit 3 functions as the acquisition unit 22, refers to the monitoring code master 11 shown in FIG. 2, and acquires the monitoring time set for the "session host abnormality check process" of the current monitoring process. In the case of this example, the monitoring time set for the "session host abnormality check process" is "90 minutes" as shown in FIG. 16.
[0063] Also, in step S2, the acquisition unit 22 refers to the monitoring detail master 14 shown in FIG. 5 based on the monitoring code of "1", and acquires the individual monitoring processes stored in association with the monitoring code of "1". In the case of this example, an individual monitoring process for detecting the presence or absence of the output of the event ID of "1238" (identifier: 1238, log type code: EventLog) and an individual monitoring process for detecting the presence or absence of the output of the event ID of "1231" (identifier: 1231, log type code: EventLog) are respectively associated with the monitoring code of "1". As shown in FIG. 17, the acquisition unit 22 acquires these individual monitoring processes from the monitoring detail master 14.
[0064] Also, in step S2, the acquisition unit 22 refers to the log type master 13 shown in FIG. 4 based on the log type code of the individual monitoring process, and acquires the source of the log information corresponding to the log type code. In the case of this example, since the log type code is "EventLog", as shown in FIG. 18, the source of the log information is "event log information".
[0065] Also, in step S2, the acquisition unit 22 refers to the state determination threshold master 15 shown in FIG. 6 based on the monitoring code of "1", and acquires the state code and the determination threshold corresponding to the monitoring code of "1" as shown in FIG. 19. The example of FIG. 19 is an example in which, based on the monitoring code of "1", the determination threshold of "70%" for the state code of "1" and the determination threshold of "0%" for the state code of "2" are acquired.
[0066] Next, in step S3 and step S4, the determination unit 23 sequentially compares the identifier of each log information for the monitoring time, which is the time from the monitoring start time (7:00 am on August 30, 2023) to the time 90 minutes (see Figure 2) back, among the event log information stored in the log information storage unit 17, with the identifier of each individual monitoring process obtained from the monitoring detail master 14 (the identifier of the log information recorded during normal times: 1238 or 1231).
[0067] Then, the determination unit 23 determines for each log information for the monitoring time whether there is log information with the identifier of each individual monitoring process (step S4), and stores the determination result in the determination result work table 19 (step S5). The determination unit 23 executes the processes of step S3 to step S5 for each individual monitoring process until it is determined in step S6 that the determination for each individual monitoring process is completed.
[0068] Specifically, Figure 20 is a schematic diagram showing how the determination result is output in the first monitoring example. In the case of the example in Figure 20, within the monitoring time from 7:00 am on August 30, 2023, which is the monitoring start time, to the time 90 minutes back, log information with the identifier of "1238" (in this case, the event ID) is first output (5:48:55 am on August 30, 2023). Therefore, the determination unit 23 makes a determination of "true" for the log information with the identifier of "1238". Then, as shown in Figure 21, the determination unit 23 stores in the determination result work table 19 the monitoring code of "1", the row number of "1", and the determination result of "true".
[0069] When the determination of the presence or absence of the identifier "1238" is completed, the determination of the presence or absence of the identifier "1231" remains (step S6: Yes). Therefore, the process returns to step S3, and the determination unit 23 determines the presence or absence of log information having the identifier "1231". In the case of the example in FIG. 20, log information having the identifier "1238" is output at 5:48:55 am on August 30, 2023, and next, log information having the identifier "1231" is output at 5:55:00 am on August 30, 2023.
[0070] Therefore, the determination unit 23 makes a determination of "true" for the log information having the identifier "1231". Then, as shown in FIG. 21, the determination unit 23 stores a monitoring code of "1", a line number of "2", and a determination result of "true" in the determination result work table 19.
[0071] When the determination for each individual monitoring process is completed in this way (step S6: No), the process proceeds to step S7 in the flowchart of FIG. 11. In step S7, the normal processing ratio calculation unit 24 calculates the normal processing ratio (matching rate) as described below based on the determination results of the line number "1" and the line number "2" of the monitoring code "1" stored in the determination result work table 19 shown in FIG. 21.
[0072] That is, the normal processing ratio calculation unit 24 performs an operation of "normal processing ratio = "(the number of individual processes determined to be normal) / (the total number of individual processes)" × 100" based on the determination results stored in the determination result work table 19.
[0073] Thereby, the normal processing ratio (matching rate), which is the ratio of the number of log information determined to be (true), that is, log information having the identifier of the log information recorded during normal times by the determination unit 23, to the total number of determinations made as to whether there is log information having the identifier of the log information recorded during normal times in each log information for the monitoring time period, is calculated.
[0074] In the case of the example in FIG. 21, the total number of determinations made as to whether there is log information having an identifier of log information recorded during normal operation is "2 (pieces)". Also, the number of pieces of log information determined to be (true), i.e., log information having an identifier of log information recorded during normal operation, is "2 (pieces)". In this case, the normal processing ratio calculation unit 24 calculates a normal processing ratio of "100%" by performing an operation of "(total number of true 2 pieces / total number 2 pieces) × 100".
[0075] Also, the normal processing ratio calculation unit 24 compares the calculated normal processing ratio with the determination threshold value of the "1" monitoring code detected from the state determination threshold value master 15 as shown in FIG. 19. Then, the normal processing ratio calculation unit 24 detects, from the state determination threshold value master 15, the state code associated with the determination threshold value such that the value of the normal processing ratio is greater than or equal to the determination threshold value and the difference value between the determination threshold value and the normal processing ratio is the smallest value.
[0076] Specifically, this example is an example in which the determination threshold values of "70%" and "0%" are detected from the state determination threshold value master 15. For this reason, the normal processing ratio calculation unit 24 compares the determination threshold value of "70%" with the normal processing ratio of "100%" and calculates a difference value of "30%". Also, the normal processing ratio calculation unit 24 compares the determination threshold value of "0%" with the normal processing ratio of "100%" and calculates a difference value of "100%". Then, the normal processing ratio calculation unit 24 compares the difference value of "30%" with the difference value of "100%" and detects the difference value of "30%", which is the smallest difference value in this case. Then, the normal processing ratio calculation unit 24 refers to the state determination threshold value master 15 shown in FIG. 19 and detects the state code of "1" associated with the determination threshold value of "70%" corresponding to the difference value of "30%".
[0077] Note that this example was one where a plurality of determination thresholds corresponding to a predetermined monitoring code were set in the state determination threshold master 15. On the other hand, when only one determination threshold corresponding to a predetermined monitoring code is set in the state determination threshold master 15, the normal processing ratio calculation unit 24 determines whether the value of the normal processing ratio described above is greater than or equal to this only set determination threshold. When the value of the normal processing ratio is greater than or equal to this only set determination threshold, the difference value between the normal processing ratio and the only set determination threshold will indicate the minimum value. For this reason, the normal processing ratio calculation unit 24 detects the state code associated with the only set determination threshold from the state determination threshold master 15.
[0078] When the state code is detected in this way, in step S8, as shown in FIG. 22, the control unit 3 stores the monitoring process end date and time, such as 7:03:00 on August 30, 2023, in the monitoring result table 18. At the same time, the control unit 3 stores the monitoring code of "1", the processing content of "monitoring process end", and the state code of "1 (normal): refer to FIG. 3" detected from the state determination threshold master 15 shown in FIG. 19 in the monitoring result table 18.
[0079] Next, in step S9, the state information detection unit 25 refers to the event log setting master 16 shown in FIG. 7 based on the combination where the monitoring code is "1" and the state code is "1", and detects the event log information corresponding to the combination where the monitoring code is "1" and the state code is "1". In the case of the example in FIG. 7, as shown in FIG. 23, the event log information including various information such as the log name being "Application", the source name being "LogMonitoringProcess", the event ID being "1", the classification being "none", the level being "normal", and the message being "The process to be monitored is normal." is detected by the state information detection unit 25 for the combination where the monitoring code is "1" and the state code is "1".
[0080] Also, in step S9, the event log information output unit 26 deletes the detection results with a monitoring code of "1" and a status code of "1" from the event log information detected from the event log setting master 16, and generates event log information exemplified in FIG. 24 in an information form processable by the general-purpose operation system. Then, the event log information output unit 26 supplies the generated event log information to the monitoring unit 27 that operates based on the general-purpose operation system.
[0081] Thereby, in step S10, the monitoring unit 27 monitors the normal operation of the event corresponding to the event log information. The monitoring unit 27 outputs this monitoring result via the output device 7 (such as a monitor device or a printing device).
[0082] [Second Monitoring Example] Next, a second monitoring example will be described. For example, an example of executing the "payment closing process" with the monitoring code "3" of the monitoring code master 11 shown in FIG. 2 at 15:00 on every Tuesday will be described. In this case, when the execution time arrives, as shown in FIG. 25, the control unit 3 stores in the monitoring result table 18 the processing details of the date, time such as 15:00 on August 29, 2023, and "monitoring process execution start" indicating that this time is the start time of the process. Also, the control unit 3 refers to the monitoring code master 11 shown in FIG. 2 and stores the monitoring code "3" in the monitoring result table 18 as shown in FIG. 25.
[0083] Furthermore, the control unit 3 refers to the status master 12 shown in FIG. 3 and stores the status code indicating the current status in the monitoring result table 18 as shown in FIG. 25. At this point, since the current status is "before monitoring", the control unit 3 stores the status code "0" in the monitoring result table 18 as shown in FIG. 25.
[0084] Next, the control unit 3 functions as the acquisition unit 22, refers to the monitoring code master 11 shown in FIG. 2, and acquires the monitoring time set for the "payment closing process" of this monitoring process. In the case of this example, the monitoring time set for the "payment closing process" is "45 minutes" as shown in FIG. 2.
[0085] Further, the acquisition unit 22 refers to the monitoring detail master 14 shown in FIG. 5 based on the monitoring code of "3", and acquires the individual monitoring processes stored in association with the monitoring code of "3". In the case of this example, individual monitoring processes (log type code: ApplicationLog) for detecting the presence or absence of output of job IDs from "Batch.Sime_1001" to "Batch.Sime_1020" are respectively associated with the monitoring code of "3". The acquisition unit 22 acquires these individual monitoring processes from the monitoring detail master 14.
[0086] Also, the acquisition unit 22 refers to the log type master 13 shown in FIG. 4 based on the log type code of the individual monitoring process, and acquires the source of the log information corresponding to the log type code. In the case of this example, since the log type code is "ApplicationLog", as shown in FIG. 4, the source of the log information is "business application log information".
[0087] Also, the acquisition unit 22 refers to the state determination threshold master 15 shown in FIG. 6 based on the monitoring code of "3", and acquires the state code and determination threshold corresponding to the monitoring code of "3" as shown in FIG. 26. The example of FIG. 26 is an example in which, based on the monitoring code of "3", the determination threshold of "80%" for the state code of "1", the determination threshold of "0%" for the state code of "2", and the determination threshold of "50%" for the state code of "3" are acquired.
[0088] Next, the determination unit 23 sequentially compares the identifier of each log information for the monitoring time period, which is the time from the monitoring start time (15:00 on August 29, 2023) to the time "45 minutes (see FIG. 2)" back, among the event log information stored in the log information storage unit 17, with the identifier of each individual monitoring process acquired from the monitoring detail master 14 (identifiers of log information recorded during normal times: Batch.Sime_1001 to Batch.Sime_1020).
[0089] Then, the determination unit 23 determines, for each piece of log information for the monitoring time, whether there is log information having an identifier for each individual monitoring process, for each identifier, and stores the determination result in the determination result work table 19.
[0090] Specifically, FIG. 27 is a schematic diagram showing a state in which a determination result is output in the second monitoring example. In the case of the example of FIG. 27, within the monitoring time from the monitoring start time of 15:00 on August 29, 2023 to the time 45 minutes back, log information having an identifier of "Batch.Sime_1020" (in this case, the job ID) is output first (at 14:19:25 on August 29, 2023). Therefore, the determination unit 23 makes a determination of "true" for the log information having the identifier of "Batch.Sime_1020". Then, as shown in FIG. 28, the determination unit 23 stores in the determination result work table 19 a monitoring code of "3", a line number of "20", and a determination result of "true" which is the determination result.
[0091] Next, at 14:19:24 on August 29, 2023 shown in FIG. 27, log information having an identifier of "Batch.Sime_1019" (job ID) is output. Therefore, the determination unit 23 makes a determination of "true" for the log information having the identifier of "Batch.Sime_1019". Then, as shown in FIG. 28, the determination unit 23 stores in the determination result work table 19 a monitoring code of "3", a line number of "19", and a determination result of "true" which is the determination result.
[0092] Next, at 14:19:23 on August 29, 2023 shown in FIG. 27, log information having an identifier of "Batch.Sime_1018" (job ID) is output. Therefore, the determination unit 23 makes a determination of "true" for the log information having the identifier of "Batch.Sime_1018". Then, as shown in FIG. 28, the determination unit 23 stores in the determination result work table 19 a monitoring code of "3", a line number of "18", and a determination result of "true" which is the determination result.
[0093] On the other hand, assume that log information with the identifier (job ID) of "Batch.Sime_1017" is not output (refer to 14:19:22 on August 29, 2023 in Fig. 27). In this case, the determination unit 23 makes a determination of "false" for the log information with the identifier of "Batch.Sime_1017". Then, as shown in Fig. 28, the determination unit 23 stores in the determination result work table 19 a monitoring code of "3", a line number of "17", and a determination result of "false" which is the determination result.
[0094] Similarly, assume that log information with the identifier (job ID) of "Batch.Sime_1016" is not output (refer to 14:19:21 on August 29, 2023 in Fig. 27). Also in this case, the determination unit 23 makes a determination of "false" for the log information with the identifier of "Batch.Sime_1016". Then, as shown in Fig. 28, the determination unit 23 stores in the determination result work table 19 a monitoring code of "3", a line number of "16", and a determination result of "false" which is the determination result.
[0095] In this way, the determination unit 23 determines the presence or absence of output of log information with each identifier from "Batch.Sime_1001" to "Batch.Sime_1020", and stores this determination result (true or false) in the determination result work table 19.
[0096] Next, when the determination for each individual monitoring process is completed, the normal processing ratio calculation unit 24 calculates the normal processing ratio (matching rate) as described above based on the determination results of the line numbers "1" to "20" of the monitoring code of "3" stored in the determination result work table 19 shown in Fig. 28.
[0097] That is, in the case of the example in FIG. 28, the total number of determinations made as to whether there is log information having an identifier of log information recorded during normal operation is "20 (pieces)". Also, the number of pieces of log information determined to be (true), that is, log information having an identifier of log information recorded during normal operation, is "15 (pieces)". In this case, the normal processing ratio calculation unit 24 calculates a normal processing ratio of "75%" by performing an operation of "(total number of true cases 15 pieces / total number 20 pieces) × 100".
[0098] Also, the normal processing ratio calculation unit 24 compares the calculated normal processing ratio with each determination threshold of the "3" monitoring code detected from the state determination threshold master 15 as shown in FIG. 26 as described above. Specifically, in this example, the determination thresholds of "80%", "0%", and "50%" are detected from the state determination threshold master 15. For this reason, the normal processing ratio calculation unit 24 compares the "80%" determination threshold with the "75%" normal processing ratio and calculates a difference value of "5%". Also, the normal processing ratio calculation unit 24 compares the "0%" determination threshold with the "75%" normal processing ratio and calculates a difference value of "75%". Further, the normal processing ratio calculation unit 24 compares the "50%" determination threshold with the "75%" normal processing ratio and calculates a difference value of "25%".
[0099] Among the calculated difference values, the difference values that satisfy the condition of "determination threshold < normal processing ratio" are the "75%" difference value of "0% determination threshold < 75% normal processing ratio" and the "25%" difference value of "50% determination threshold < 75% normal processing ratio". For this reason, the normal processing ratio calculation unit 24 compares the "75%" difference value with the "25%" difference value and detects the "25%" difference value, which is the smallest difference value in this case. Then, the normal processing ratio calculation unit 24 refers to the state determination threshold master 15 shown in FIG. 26 and detects the "3" state code associated with the "50%" determination threshold corresponding to the "25%" difference value.
[0100] When the status code is detected in this way, as shown in FIG. 29, the control unit 3 stores the monitoring end date and time, such as 15:02:00 on August 29, 2023, in the monitoring result table 18. At the same time, the control unit 3 stores the monitoring code of "3", the processing content of "monitoring process end", and the status code of "3 (partial failure): refer to FIG. 3" detected from the status determination threshold value master 15 shown in FIG. 19 in the monitoring result table 18.
[0101] Next, based on the combination where the monitoring code is "3" and the status code is "3", the status information detection unit 25 refers to the event log setting master 16 shown in FIG. 7 and detects the event log information corresponding to the combination where the monitoring code is "3" and the status code is "3". In the case of the example in FIG. 7, as shown in FIG. 30, the event log information including various information such as the log name being "Application", the source name being "LogMonitoringProcess", the event ID being "23", the classification being "none", the level being "warning", and the message being "There are some bases where the input process is not completed. Please check separately." is detected by the status information detection unit 25 for the combination where the monitoring code is "3" and the status code is "3".
[0102] The event log information output unit 26 deletes the detection results where the monitoring code is "3" and the status code is "3" from the event log information detected from the event log setting master 16, and generates the event log information illustrated in FIG. 31 in an information form processable by the general-purpose operation system. Then, the event log information output unit 26 supplies the generated event log information to the monitoring unit 27 that operates based on the general-purpose operation system.
[0103] Thereby, the monitoring of the normal operation of the event according to the event log information is performed by the monitoring unit 27. The monitoring unit 27 outputs this monitoring result via the output device 7 (such as a monitor device or a printing device).
[0104] [Effects of the Embodiment] As is clear from the above description, the information processing apparatus 1 according to the embodiment can detect the degree of abnormality of the monitoring target based on the matching rate between various log information to be recorded during normal times and the actually recorded log information.
[0105] Therefore, on the one hand, it is possible to perform abnormality detection corresponding to a plurality of types of logs, such as "whether the log that should be originally output at a specific timing is output" or "what percentage of the logs to be monitored are output normally".
[0106] In addition, when considering CPU dependence or writing to and reading from a disk, such as in a performance investigation, it is possible to perform extraction assuming various cases. Therefore, a comprehensive log monitoring function that is not affected by patterns can be realized.
[0107] In addition, when extracting log information to be monitored, it is possible to select the monitoring time and acquisition target and control so as not to acquire unnecessary log information. Therefore, accurate monitoring of log information can be enabled.
[0108] In addition, by assigning mandatory and optional settings to a plurality of monitoring targets (such as DB sessions and various application operations), strict abnormality detection can be performed with any combination of a mandatory monitoring target that requires a 100% matching rate and an optional monitoring target (multiple settings possible) that matches the determination of the state determination threshold master 15.
[0109] [Contribution to the Sustainable Development Goals (SDGs) led by the United Nations] According to the present invention, since it can contribute to improving business efficiency and promoting appropriate management decisions of enterprises, it can contribute to the goals "8" and "9" of the SDGs.
[0110] In addition, according to the present invention, since it can contribute to reducing waste loss and promoting paperless and digitalization, it can contribute to the goals "12", "13" and "15" of the SDGs.
[0111] In addition, according to the present invention, since it can contribute to control and enhanced governance, it can contribute to the "16" goal of the SDGs.
[0112] [Other Embodiments] The present invention can be implemented in various different forms within the scope of the technical idea described in the claims even in addition to the above-described embodiments.
[0113] For example, among the respective processes described in the embodiments, all or part of the processes described as being automatically performed may be performed manually. Or, all or part of the processes described as being performed manually may be automatically performed by a known method or the like.
[0114] In addition, regarding the processing procedures, control procedures, specific names, information including registered data of each process, parameters such as search conditions, screen examples, and database configurations shown in the specification or drawings, they can be arbitrarily changed unless otherwise specified.
[0115] Regarding the information processing apparatus 1, each illustrated component is a functional concept and does not necessarily have the physical configuration shown in the figure. For example, regarding the processing functions provided in the information processing apparatus 1, particularly each processing function performed by the control unit 3, all or any part of them may be realized by a program interpreted and executed by the control unit 3 (CPU: Central Processing Unit), or may be realized by hardware using wired logic.
[0116] The program is recorded on a non-transitory computer-readable recording medium including programmed instructions for causing the information processing apparatus to execute the processes described in the embodiments, and is mechanically read by the information processing apparatus 1 as necessary. That is, in the storage unit 2 such as a ROM or HDD, a computer program for giving commands to the control unit 3 (CPU) in cooperation with the OS (Operating System) and performing various processes is recorded. This computer program is loaded into the RAM and expanded, and is appropriately executed by the control unit 3.
[0117] Also, the business support program of the information processing apparatus 1 may be stored in another server device connected to the information processing apparatus 1 via an arbitrary network, and all or part of it may be downloaded and executed as necessary.
[0118] Also, the business support program for executing the processes described in the embodiments may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product.
[0119] Here, as the "recording medium", any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical Disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc can be used.
[0120] Also, the "program" is a data processing method described in an arbitrary language or description method, and is not limited to a form such as source code or binary code.
[0121] Note that the "program" is not necessarily limited to being configured singly, and includes those that are distributed as a plurality of modules or libraries and those that achieve their functions in cooperation with a separate program typified by an OS.
[0122] In addition, regarding the specific configuration, reading procedure, and installation procedure after reading for the recording medium in the information processing apparatus 1 of the embodiment, well-known configurations or procedures can be used.
[0123] The storage unit 2 is a storage means such as a memory device such as a RAM or a ROM, a fixed disk device such as a hard disk, a flexible disk, and an optical disk, and stores various programs, tables, databases, and web page files used for various processes or website provision.
[0124] Also, the information processing apparatus 1 may be configured by an information processing apparatus such as a known personal computer device or a workstation, or may be configured by an information processing apparatus to which an arbitrary peripheral device is connected. Further, the information processing apparatus may be realized by implementing software (including programs or data, etc.) that realizes the processing described in the embodiment.
[0125] Furthermore, the specific forms of distribution and integration of the devices are not limited to those illustrated, and all or part of them can be functionally or physically distributed or integrated in arbitrary units according to various additions or functional loads. That is, by arbitrarily combining the above-described embodiments, the above-described embodiments may be selectively implemented.
Industrial Applicability
[0126] The present invention is applicable to any system as long as it is a system that performs anomaly detection based on log information such as events.
Explanation of Signs
[0127] 1 Information processing apparatus 2 Storage unit 3 Control unit 4 Communication interface unit 5 Input / output interface unit 6 Input device 7 Output device 11 Monitoring code master 12 Status Master 13 Log Type Master 14 Monitoring Details Master 15 Status Judgment Threshold Master 16 Event Log Setting Master 17 Log Information Storage Unit 18 Monitoring Performance Table 19 Judgment Result Work Table 20 Event Log Information Storage Unit 21 Event Log Generation Unit 22 Acquisition Unit 23 Judgment Unit 24 Normal Processing Ratio Calculation Unit 25 Status Information Detection Unit 26 Event Log Information Output Unit 27 Monitoring Unit
Claims
1. Among the log information of the monitoring target that is stored in the memory unit with time information added, for each piece of log information for the monitoring time, which is the time from the time at a predetermined timing to the time that is the specified time back, compare the identifier of the log information with the identifier of the log information that is recorded during normal times and is pre-stored in the memory unit, and for each of the identifiers, output a determination result indicating whether there is log information including the identifier of the log information that is recorded during normal times among each piece of the log information for the monitoring time; a determination unit; A normal processing ratio calculation unit that calculates a normal processing ratio, which is the ratio of the number of pieces of the log information determined by the determination unit to be log information including the identifier of the log information that is recorded during normal times among each piece of the log information for the monitoring time, to the total number of determinations as to whether there is log information including the identifier of the log information that is recorded during normal times among each piece of the log information for the monitoring time; Refer to the memory unit based on a comparison result of comparing the calculated value of the normal processing ratio with the determination threshold value of the normal processing ratio stored in the memory unit, and detect state information indicating the state of the monitoring target that is stored in the memory unit and is associated with the determination threshold value; a state information detection unit; An event log information detection unit that detects, among the event log information indicating the state of the monitoring target stored in the memory unit, the event log information corresponding to the state information detected by the state information detection unit; An event log information output unit that supplies the detected event log information to a monitoring unit that monitors the normal operation of the monitoring target; An information processing apparatus having the above.
2. When a plurality of the determination threshold values are stored in the memory unit, the state information detection unit compares the calculated value of the normal processing ratio with each of the determination threshold values, and detects the state information associated with the determination threshold value for which the difference value from the value of the normal processing ratio is the smallest. The information processing apparatus according to claim 1, characterized by the above.
3. The event log information output unit outputs the event log information in an information format that can be processed by a general-purpose operation system. The monitoring unit operates based on the general-purpose operation system, and outputs a monitoring result corresponding to the event log information to an external device. The information processing apparatus according to claim 1 or claim 2, characterized in that.
4. A determination step in which a determination unit compares an identifier of each log information for a monitoring time, which is a time from a time at a predetermined timing to a time retroactively specified for a specified time among log information of a monitoring target stored with time information added thereto in a storage unit, with an identifier of log information recorded during normal times, which is stored in advance in the storage unit, and outputs, for each identifier, a determination result indicating whether or not there is log information including the identifier of the log information recorded during normal times in each of the log information for the monitoring time; A normal processing ratio calculation step in which a normal processing ratio calculation unit calculates a normal processing ratio, which is a ratio of the number of the log information determined to be log information including the identifier of the log information recorded during normal times in each of the log information for the monitoring time to the total number of determinations as to whether or not there is log information including the identifier of the log information recorded during normal times in each of the log information for the monitoring time; A state information detection step in which a state information detection unit refers to the storage unit based on a comparison result of comparing the calculated value of the normal processing ratio with a determination threshold value of the normal processing ratio stored in the storage unit, and detects state information indicating a state of the monitoring target associated with the determination threshold value and stored in the storage unit; An event log information detection step in which an event log information detection unit detects event log information corresponding to the state information detected in the state information detection step among event log information indicating a state of the monitoring target stored in the storage unit; An event log information output step in which an event log information output unit supplies the detected event log information to a monitoring unit that monitors normal operation of the monitoring target; An information processing method having the above steps.
5. A computer, among the log information of the monitoring target that is stored in the storage unit with time information added thereto, for each identifier of the log information for the monitoring time that is the time from the time at a predetermined timing to the time that is a specified time back, compare with the identifier of the log information recorded during normal times that is stored in advance in the storage unit, and output for each identifier a determination result indicating whether there is log information having the identifier of the log information recorded during normal times in each of the log information for the monitoring time; a determination unit; a normal processing ratio calculation unit that calculates a normal processing ratio, which is the ratio of the number of the log information determined by the determination unit to be the log information having the identifier of the log information recorded during normal times among each of the log information for the monitoring time, to the total number of determinations as to whether there is log information having the identifier of the log information recorded during normal times in each of the log information for the monitoring time; refer to the storage unit based on a comparison result of comparing the value of the calculated normal processing ratio with the determination threshold value of the normal processing ratio stored in the storage unit, and detect state information indicating the state of the monitoring target that is stored in the storage unit and associated with the determination threshold value; a state information detection unit; an event log information detection unit that detects, among the event log information indicating the state of the monitoring target stored in the storage unit, the event log information corresponding to the state information detected by the state information detection unit; causing the detected event log information to function as an event log information output unit that supplies the event log information to a monitoring unit that monitors the normal operation of the monitoring target; An information processing program, characterized by the above.
Citation Information
Patent Citations
Device and program for notifying log determination information
JP2004038483A
Device fault analysis apparatus, device fault analysis method and device fault analysis program
JP2012094046A
Log analysis system, log analysis method, log analysis program, and storage medium
WO2019064370A1
Log analysis device
JP2016024786A