Event analysis system, event analysis method, and event analysis program
The event analysis system accurately identifies hydraulic event chains in water purification plants by using a whitelist to filter out impossible combinations, improving decision-making and knowledge preservation.
Patent Information
- Application Number
- JP2024120308
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-25
- Publication Date
- 2026-02-05
AI Technical Summary
Existing event analysis systems fail to accurately identify hydraulic chains of events in water purification plants, leading to incorrect decision-making and loss of tacit knowledge due to the extraction of hydraulically impossible event combinations.
An event analysis system that utilizes a processor and memory to store a whitelist of hydraulically reachable equipment combinations, chain events with correlated occurrence timing, and initial chain information, identifying and outputting knowledge of valid hydraulic event chains.
Enables accurate identification of hydraulic event chains, enhancing decision-making and preserving operational knowledge by filtering out hydraulically impossible event combinations.
Smart Images

Figure 2026018946000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an event analysis system, an event analysis method, and an event analysis program. [Background technology]
[0002] Japanese Patent Laid-Open Publication No. 2005-216148 (Patent Document 1) is a background art in this technical field. The alarm analysis device described in Patent Document 1 is an alarm analysis device that analyzes plant alarms based on alarms that occur in the plant or events related to operations on instruments in the plant, and includes an alarm information storage unit that stores alarm information that associates the content of alarms in the plant with the time of occurrence, a numeric sequence conversion unit that converts the time of occurrence of each alarm into a numeric sequence, and extracts event pairs consisting of a first event and a second event different from the first event from the alarms whose occurrence times have been converted into numeric sequences, and calculates the order of occurrence of the event pairs (see Abstract). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2005-216148 Summary of the Invention [Problem to be solved by the invention]
[0004] In a plurality of pieces of equipment installed in a facility such as a water purification plant, there is a water flow from an upstream piece of equipment to a downstream piece of equipment. If the technology described in Patent Document 1 is applied as is to the plurality of pieces of equipment, it may be possible to extract a chain of events that cannot occur hydraulically (for example, a chain of events that ignores the direction of the water flow), such as an event that occurs in a downstream piece of equipment (for example, an alarm that occurs in the equipment or an operation performed on the equipment) affecting the occurrence of an event in an upstream piece of equipment.
[0005] Therefore, one aspect of the present invention is to identify possible hydraulic chains of events, thereby enabling more accurate knowledge extraction regarding chains of events. [Means for solving the problem]
[0006] In order to solve the above problem, one aspect of the present invention employs the following configuration: An event analysis system for analyzing events occurring in a plurality of facilities includes a processor and a memory, wherein the memory stores a whitelist indicating a list of reachable combinations of equipment included in the plurality of facilities, each combination being a combination of upstream equipment and downstream equipment where a water flow from the upstream equipment may exist, chain events including the combinations of events that have a high correlation in occurrence timing based on a predetermined condition, and initial chain information indicating the occurrence equipment of each of the events included in the chain events and the occurrence order of the events included in the chain events, wherein the processor identifies, as knowledge, chain events in which an earlier equipment that is the occurrence equipment of an earlier event and a later equipment that is the occurrence equipment of a later event that occur later in the occurrence order match the upstream equipment and the downstream equipment in any of the reachable combinations indicated in the whitelist, generates knowledge information indicating the identified knowledge, and outputs data for generating a screen displaying the knowledge information. [Effects of the Invention]
[0007] According to one aspect of the present invention, it is possible to identify possible hydraulic chains of events, thereby enabling more accurate knowledge extraction regarding chains of events.
[0008] Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram illustrating a configuration example of an event analysis system according to a first embodiment. [Figure 2] FIG. 2 is a diagram showing an example of the data configuration of water system data in the first embodiment. [Figure 3] FIG. 2 is a diagram illustrating an example of a data configuration of a whitelist according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of a data configuration of alarm record data according to the first embodiment. [Figure 5] FIG. 4 is a diagram illustrating an example of a data configuration of operation result data according to the first embodiment. [Figure 6] FIG. 4 is a diagram illustrating an example of a data configuration of event list data according to the first embodiment. [Figure 7] FIG. 10 is a diagram illustrating an example of a data configuration of initial chain data in the first embodiment. [Figure 8] 10 is a flowchart illustrating an example of a whitelist creation process according to the first embodiment. [Figure 9] 2 is an example of a directed graph showing hydraulics in the facilities of the water purification plant in the first embodiment. [Figure 10] FIG. 10 is an explanatory diagram showing an example of a statistical method for creating initial chain data in the first embodiment. [Figure 11] 10 is a flowchart illustrating an example of a chain data creation process according to the first embodiment. [Figure 12] FIG. 10 is a diagram illustrating an example of a screen configuration of a whitelist editing screen according to the first embodiment. [Figure 13] FIG. 10 is a diagram illustrating an example of the data configuration of initial chain data in the second embodiment. [Figure 14] 10 is a flowchart illustrating an example of a chain data creation process according to the second embodiment. [Figure 15] 10 is a flowchart showing an example of a multi-chain dedicated process in the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. In this embodiment, the same components are generally designated by the same reference numerals, and repeated explanations will be omitted. It should be noted that this embodiment is merely an example for realizing the present invention, and does not limit the technical scope of the present invention.
[0011] In this embodiment, an event analysis system for each facility in a water purification plant will be described. Facilities installed in the water purification plant include facilities for coagulating raw water, filtering facilities, and chlorination facilities. The operation and management tasks of the water purification plant performed by the operator include responding to alarms issued by control devices that monitor these facilities.
[0012] These alarms that occur in water purification plants include noise alarms with low urgency, and because multiple alarms may occur simultaneously, it is easy for water purification plant operators to make the wrong decision about which alarm to respond to.In addition, when there are many types and occurrences of alarms, it is difficult to manually separate and remove noise alarms from the data of multiple alarms.
[0013] Furthermore, in many cases, the proper operation of equipment to respond to alarms at water purification plants relies on the tacit knowledge of experienced operators, which means that there is a risk that the know-how of operation and management work will be lost when operators change generations.
[0014] In the following description of the present embodiment, the occurrence of an alarm and the performance of an operation on equipment are collectively referred to as an “event.” When a certain event occurs, there is a tendency for other events to occur in a chain reaction, and such a combination of events is also referred to as a chain event.
[0015] For example, if there is a strong tendency for alarm B to occur in conjunction with alarm A, then there is a high probability that addressing alarm A will also resolve the cause of alarm B, meaning that there is a high probability that addressing alarm A is important. Also, if there is a strong tendency for operation X to be performed in conjunction with alarm A, then there is a high probability that operation X is an appropriate response to alarm A. In this way, knowledge such as important alarms and appropriate operations can be extracted from chain events.
[0016] However, when chain events are extracted using statistical methods, chain events that are hydraulically impossible for water purification plant facilities (such as backflow, system crossing, instantaneous movement, and delayed movement, as will be described in detail later) are also extracted. The event analysis system of this embodiment extracts more accurate knowledge by removing chain events that are hydraulically impossible for water purification plant facilities from the chain events extracted using statistical methods. [Example]
[0017] 1 is a block diagram showing an example of the configuration of an event analysis system 100. The event analysis system 100 is configured by a computer having, for example, a CPU (Central Processing Unit) 101, a memory 102, an auxiliary storage device 103, a communication device 104, an input device 105, and a display device 106.
[0018] The CPU 101 is an example of a processor, and executes programs stored in the memory 102. The memory 102 includes a ROM (Read Only Memory), which is a nonvolatile storage element, and a RAM (Random Access Memory), which is a volatile storage element. The ROM stores unchanging programs (e.g., a BIOS (Basic Input / Output System)). The RAM is a high-speed, volatile storage element such as a DRAM (Dynamic Random Access Memory), and temporarily stores programs executed by the CPU 101 and data used when the programs are executed.
[0019] The auxiliary storage device 103 is a large-capacity, non-volatile storage device such as a magnetic storage device (HDD (Hard Disk Drive)) or a flash memory (SSD (Solid State Drive)), and stores programs to be executed by the CPU 101 and data to be used when the programs are executed. That is, the programs are read from the auxiliary storage device 103, loaded into the memory 102, and executed by the CPU 101.
[0020] The input device 105 is a device that receives input from a user, such as a keyboard or a mouse. The display device 106 is a device that outputs the results of program execution in a format that can be viewed by the user, such as a display device or a printer.
[0021] The communication device 104 is a network interface device that controls communication with other devices in accordance with a predetermined protocol. The communication device 104 may also include a serial interface such as a USB (Universal Serial Bus).
[0022] A part or all of the programs executed by the CPU 101 may be provided to the event analysis system 100 from a removable medium (such as a CD-ROM or flash memory) which is a non-transitory storage medium, or from an external computer equipped with a non-transitory storage device via a network, and may be stored in the non-volatile auxiliary storage device 103 which is a non-transitory storage medium. For this reason, the event analysis system 100 may preferably have an interface for reading data from removable media.
[0023] The event analysis system 100 is a computer system configured on a single physical computer or on multiple logically or physically configured computers, and may operate in separate threads on the same computer, or on a virtual computer constructed on multiple physical computer resources.
[0024] The CPU 101 includes, for example, a whitelist creation unit 111, a chain data creation unit 112, and a screen management unit 113, all of which are functional units. The whitelist creation unit 111 generates a whitelist 122, which will be described later. The whitelist creation unit 111 includes a graph creation unit 114, a reachability determination unit 115, and a reach time calculation unit 116, all of which are functional units.
[0025] The graph creation unit 114 generates a directed graph showing the hydraulics of the facilities of the water purification plant. The reachability determination unit 115 determines whether water can reach from one facility to another in a combination of facilities of the water purification plant based on the directed graph. The arrival time calculation unit 116 calculates the time it takes for water to reach from one facility to another in a combination of facilities that water can reach.
[0026] The chain data creation unit 112 generates chain data 127, which will be described later. The chain data creation unit 112 includes a chain analysis unit 117 and a chain contradiction determination unit 118, both of which are functional units. The chain analysis unit 117 analyzes chain events. The chain contradiction determination unit 118 determines whether the chain events are inconsistent with the whitelist 122.
[0027] The screen management unit 113 manages the screen displayed on the display device 106 (specifically, the whitelist editing screen described later).
[0028] For example, CPU 101 functions as whitelist creation unit 111 by operating in accordance with a whitelist creation program loaded into memory 102, and functions as chained data creation unit 112 by operating in accordance with a chained data creation program loaded into memory 102. The same relationship between programs and chained units applies to other chained units included in CPU 101.
[0029] Note that some or all of the functions of the functional units included in the CPU 101 may be realized by dedicated circuits such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).
[0030] The auxiliary storage device 103 stores, for example, water system data 121, a whitelist 122, alarm record data 123, operation record data 124, event list data 125, initial chain data 126, and chain data 127.
[0031] The water system data 121 holds information about the facilities included in the water purification plant and information about the hydraulics at the water purification plant (i.e., information about the water flow from which facility to which facility installed at the water purification plant). The whitelist 122 holds information about combinations of facilities that can be hydraulically linked.
[0032] Alarm record data 123 holds information indicating the record of alarms (an example of an event) that have occurred in equipment. Operation record data 124 holds information indicating the record of operations (an example of an event) performed on equipment. Event list data 125 holds a list of events and information indicating the equipment in which each event occurs. Initial chain data 126 holds information indicating chain events extracted using statistical methods. Chain data 127 holds information in which chain events that can occur hydraulically have been removed from initial chain data 126. The chain events indicated by chain data 127 are an example of knowledge provided to the operator. Therefore, chain data 127 can also be said to be an example of knowledge information.
[0033] In the example of Figure 1, some or all of the information stored in the auxiliary storage device 103 may be stored in the memory 102 or in an external database connected to the event analysis system 100.
[0034] In this embodiment, the information used by the event analysis system 100 does not depend on the data structure and may be expressed in any data structure. For example, the information may be stored in a data structure appropriately selected from a list, a table, a database, or a queue.
[0035] 2 is a diagram showing an example of the data configuration of the water system data 121. The water system data 121 includes, for example, a facility name column 1211, a flow rate lower limit column 1212, a flow rate upper limit column 1213, a volume column 1214, and a downstream connected facility name column 1215. The facility name column 1211 indicates the name of the facility installed in the water purification plant. It is assumed that each facility can be uniquely identified by the facility name.
[0036] The facilities at the water purification plant include facilities that are subject to event monitoring (which may be facilities where an event may occur) and facilities that are not subject to event monitoring (which may be facilities that cannot be facilities where an event may occur), and information on both of these facilities is stored in the water system data 121. In this embodiment, pipelines are facilities that are not subject to event monitoring, and facilities other than pipelines are facilities that are subject to event monitoring.
[0037] The flow rate lower limit field 1212 indicates the lower limit of the water flow rate within the facility. The flow rate upper limit field 1213 indicates the upper limit of the water flow rate through the facility. Fluctuations in the water flow rate within the facility are expected due to long-term trends such as seasonality and short-term trends such as sudden heavy rain, and since fluctuations in flow rate change the water flow rate within the facility, the upper and lower flow rate limits are defined. The upper and lower flow rate limits are obtained, for example, from actual values of measured values of the water flow rate within the facility over a specified period of time, simulation values, etc. The volume field 1214 indicates the volume of the facility.
[0038] The downstream connected facility name column 1215 indicates the name of the facility connected downstream (i.e., in the direction of the water flow) of the facility indicated in the facility name column 1211. For example, record 1216 of the water system data 121 in FIG. 2 indicates that water flows from "System A Receiving Well" to "Pipeline 1." Note that for facilities that do not have downstream connected facilities (i.e., facilities located at the most downstream position within a water purification plant, where water that flows into the facility is discharged, for example, outside the water purification plant), the value of the downstream connected facility name column 1215 will be, for example, a null value.
[0039] Furthermore, as shown in record 1216 of the water system data 121 in Figure 2, multiple downstream connecting facilities may be defined in the downstream connecting facility name field 1215. As shown in record 1216, the water system branches into "pipeline 1" and "pipeline 2" from the "A-system receiving well." Note that facilities other than pipelines can only be connected via pipelines, meaning that the downstream connecting facility of a facility other than a pipeline is a pipeline. Also, the downstream connecting facility of a pipeline is one facility other than a pipeline.
[0040] According to records 1216 and 1217 of the water system data 121 in Figure 2, the "A-system receiving well" is connected to the "C-system filter basin" via "pipeline 1" in the direction of water flow. Equipment connected to each other via a pipe line is also called adjacent equipment. In this way, the water system data 121 indicates adjacent equipment and the direction of water flow between adjacent equipment.
[0041] 3 is a diagram showing an example of the data configuration of the whitelist 122. The whitelist 122 includes, for example, an upstream equipment name column 1221, a downstream equipment name column 1222, an estimated arrival time lower limit column 1223, and an estimated arrival time upper limit column 1224.
[0042] The upstream equipment name column 1221 and downstream equipment name column 1222 respectively indicate the names of the upstream equipment and downstream equipment on the hydraulic path of water that may occur. In other words, there may be a water flow from the upstream equipment to the downstream equipment. The estimated arrival time lower limit column 1223 indicates the lower limit of the estimated time it takes for water to reach the downstream equipment from the upstream equipment. The estimated arrival time upper limit column 1224 indicates the upper limit of the estimated time it takes for water to reach the downstream equipment from the upstream equipment.
[0043] 4 is a diagram showing an example of the data configuration of the alarm record data 123. The alarm record data 123 includes, for example, a facility name column 1231, a message content column 1232, a start time column 1233, and an end time column 1234.
[0044] The equipment name column 1231 indicates the name of the equipment in which the alarm occurred. The message content column 1232 indicates the message content of the alarm that occurred. Note that the message content of alarms that occur in different equipment will not overlap, meaning that the equipment name can be identified from the message content. The start time column 1233 indicates the start time of the period in which the alarm occurred. The end time column 1234 indicates the end time of the period in which the alarm occurred.
[0045] 5 is a diagram showing an example of the data configuration of the operation record data 124. The operation record data 124 includes, for example, a facility name column 1241, an operation content column 1242, a start time column 1243, and an end time column 1244.
[0046] The equipment name column 1241 indicates the name of the equipment on which the operation was performed. The operation content column 1242 indicates the content of the operation that was performed. Note that the operation content performed on different equipment will not overlap, that is, it is possible to identify the equipment name from the operation content. The start time column 1243 indicates the start time of the period in which the operation content in question was performed. The end time column 1244 indicates the end time of the period in which the operation content in question was performed.
[0047] 6 is a diagram showing an example of the data configuration of the event list data 125. The event list data 125 includes, for example, an event content column 1251 and a facility name column 1252. The event content column 1251 indicates the event content (i.e., the alarm message content or the operation content of the operation). The facility name column 1252 indicates the name of the facility in which the event indicated in the event content column 1251 occurs. Note that the event list data 125 describes, for example, all the event contents that can occur in the facility.
[0048] 7 is a diagram showing an example of the data configuration of the initial chain data 126. The initial chain data 126 includes, for example, a preceding event content column 1261, a subsequent event content column 1262, a time difference column 1263, and a correlation coefficient column 1264.
[0049] The earlier event content column 1261 shows the content of the earlier event, which is the event that occurs first of the two events that make up the chain event. The later event content column 1262 shows the content of the later event, which is the event that occurs later (for example, triggered by the earlier event), of the two events that make up the chain event.
[0050] The time difference column 1263 indicates the time difference between the occurrence time (e.g., start time) of an earlier event and the occurrence time (e.g., start time) of a later event at which the correlation coefficient, described below, reaches a maximum value (however, if multiple maximum values exist, for example, the largest maximum value). The correlation coefficient column 1264 indicates the maximum value (however, if multiple maximum values exist, for example, the largest maximum value) of the correlation coefficient between the occurrence timing of an earlier event and the occurrence timing of a later event, taking the time difference into consideration.
[0051] The chain events stored in the initial chain data 126 are extracted solely by statistical methods. Therefore, the combination of the preceding and succeeding events that make up the chain events stored in the initial chain data 126 can be any combination of events shown in the event list data 125.
[0052] 7 indicates that the content of the earlier event indicated by record 1265 is "Abnormal water level in A-system receiving well" and the content of the later event is "Abnormal water quality in A-system filtration basin," and the content of the earlier event indicated by record 1266 is "Abnormal water quality in A-system filtration basin" and the content of the later event is "Abnormal water level in A-system receiving well." In this way, the initial chain data 126 may include information on chain events in which the combination of event contents that make up the chain event is the same but the order of occurrence of the constituent event contents is different.
[0053] Also, for example, the content of the leading event "A-system water receiving well water level abnormality" and the content of the subsequent event "A-system water receiving well operation X" shown in record 1267 of the initial chain data 126 in Fig. 7 are both events that occur in the "A-system water receiving well" according to the event list data 125 in Fig. 6. In this way, the initial chain data 126 may contain information on chain events that include multiple event contents that occur in the same facility (however, the leading event and subsequent event will never have the same event content).
[0054] Note that, since an example of the data configuration of the chain data 127 is the same as that of the initial chain data 126, an illustration of an example of the data configuration of the chain data 127 is omitted.
[0055] Fig. 8 is a flowchart showing an example of a whitelist creation process. It is assumed that the values of the water system data 121 are set in advance before the process of Fig. 8 starts. Note that, at the start of the process of Fig. 8, the event analysis system 100 may automatically acquire the upper flow rate limit, the lower flow rate limit, and the volume of each facility, and automatically update the values of the water system data 121.
[0056] The whitelist creation unit 111 acquires the water system data 121 from the auxiliary storage device 103 (S801).
[0057] The graph creation unit 114 references the water system data 121 and generates a directed graph in which pipelines are edges and facilities other than pipelines are nodes (S802). Specifically, for example, the graph creation unit 114 determines each facility other than a pipeline indicated in the facility name column 1211 of the water system data 121 as a node. For each node, the graph creation unit 114 generates an edge corresponding to the pipeline indicated in the downstream connected facility name column 1215 corresponding to the node, and determines the node as the start point of the generated edge. The graph creation unit 114 determines the facility indicated in the downstream connected facility name column 1215 of the record having the facility name column 1211 corresponding to the edge as the end point of the edge. As a result, nodes corresponding to facilities connected via pipelines are connected by directed edges indicating the direction of the water flow.
[0058] For example, the graph creation unit 114 generates a node corresponding to the "A-system receiving well" from record 1216 of the water system data 121 in FIG. 2, and generates an edge corresponding to "pipeline 1" and an edge corresponding to "pipeline 2" starting from the node. Since record 1217 indicates that the downstream equipment of "pipeline 1" is the "C-system filtration basin," the end point of the edge corresponding to "pipeline 1" is determined to be the node indicating the "C-system filtration basin." The graph creation unit 114 generates a directed graph corresponding to the water system data 121 by repeating this process. Note that the directed graph generated in step S802 is displayed on a whitelist editing screen, which will be described later, and therefore may be stored in the memory 102 and / or the auxiliary storage device 103.
[0059] The arrival time calculation unit 116 calculates the upper and lower limits of the estimated time for water to arrive (from the upstream facility to the downstream facility) between the facilities indicated by adjacent nodes (i.e., nodes connected by edges) in the directed graph (S803). Specifically, for each facility (including pipelines) indicated in the facility name column 1211 of the water system data 121, the arrival time calculation unit 116 calculates the value obtained by dividing the volume of the facility by the lower limit of the flow velocity of the facility as the upper limit of the water residence time in the facility, and calculates the value obtained by dividing the volume of the facility by the upper limit of the flow velocity of the facility as the lower limit of the water residence time in the facility.
[0060] Furthermore, for each combination of nodes connected by edges in the directed graph, the arrival time calculation unit 116 calculates, for example, the sum of the upper limit of the water residence time for the equipment corresponding to the node that is the start point of the edge (i.e., the upstream equipment) and the upper limit of the water residence time for the pipeline corresponding to the edge, as the upper limit of the estimated time for water to arrive from the upstream equipment to the downstream equipment indicated by the combination.For each combination of nodes connected by edges in the directed graph, the arrival time calculation unit 116 calculates, for example, the sum of the lower limit of the water residence time for the equipment corresponding to the node that is the start point of the edge (i.e., the upstream equipment) and the lower limit of the water residence time for the pipeline corresponding to the edge, as the lower limit of the estimated time for water to arrive from the upstream equipment to the downstream equipment indicated by the combination.
[0061] Since the combination of two adjacent nodes can be identified by an edge, the upper and lower limits of the estimated water arrival time calculated in step S803 can be treated as being assigned to the edge, or as the weight of the edge.
[0062] The reachability determination unit 115 refers to the directed graph and performs an exhaustive search to extract combinations of upstream equipment and downstream equipment that the water can reach (S804). Specifically, the reachability determination unit 115 uses a predetermined search algorithm such as a depth-first search to search for and extract all combinations of two nodes on the directed graph that can be reached by tracing one or more edges from one node to the other node in accordance with the direction of the edges. The reachability determination unit 115 also extracts combinations of the same nodes as combinations of upstream equipment and downstream equipment that the water can reach.
[0063] The arrival time calculation unit 116 calculates the upper and lower limits of the estimated time for the water to arrive from the upstream equipment to the downstream equipment for each combination of upstream equipment and downstream equipment that the water extracted in step S804 can reach (S805).
[0064] Specifically, for example, for each combination of upstream equipment and downstream equipment that water can reach, the arrival time calculation unit 116 calculates the sum of the upper limits of the estimated arrival time of water assigned to each edge that is followed when traveling from the node representing the upstream equipment to the node representing the downstream equipment as the upper limit of the estimated arrival time of water from the upstream equipment to the downstream equipment, and calculates the sum of the lower limits of the estimated arrival time of water assigned to each edge that is followed when traveling from the node representing the upstream equipment to the node representing the downstream equipment as the lower limit of the estimated arrival time of water from the upstream equipment to the downstream equipment.
[0065] For example, when the combination of upstream equipment and downstream equipment to which water can reach consists of the same equipment, the arrival time calculation unit 116 determines the upper and lower limits of the water residence time in that equipment as the upper and lower limits of the estimated arrival time for that combination, respectively.
[0066] The whitelist creation unit 111 associates the combination of upstream equipment and downstream equipment extracted in step S804 with the upper and lower limits of the estimated arrival time calculated in step S805 and stores them in the whitelist 122, and then terminates the whitelist creation process.
[0067] 9 is an example of a directed graph showing the hydraulics of a water purification plant. Each node in the directed graph 900 represents a piece of equipment other than a pipeline, and each edge represents a pipeline connecting the pieces of equipment other than the pipeline. The direction of each edge also indicates the direction in which water flows.
[0068] 9, four systems are defined according to the branching of edges: "System A," "System B," "System C," and "System D." For example, a water receiving well belonging to System A is called an "A-system water receiving well." However, for equipment that only has one, such as an "intake tower," there is no need to distinguish between systems, so it is simply called an "intake tower" without distinguishing between systems.
[0069] In addition, the numbers written above the edges in Figure 9 indicate the upper and lower limits of the estimated time it takes for water to arrive from the equipment indicated by the node that is the starting point of the edge to the equipment indicated by the node that is the end point, as calculated in step S803.
[0070] For example, no matter which edge in directed graph 900 is traced, it is not possible to reach node 902 representing the "sand trap" from node 901 representing the "B-system water receiving well." Because it is not possible to reach node 902 from node 901 without tracing the edges in the reverse direction in directed graph 900, the water flow from the "B-system water receiving well" to the "sand trap" is equivalent to a backflow of water, and the path from the "B-system water receiving well" to the "sand trap" is a water path that cannot occur hydraulically. Therefore, it is assumed that an event that occurs at the "B-system water receiving well" will not trigger an event at the "sand trap."
[0071] Furthermore, for example, no matter which edge included in the directed graph 900 is traced, it is not possible to reach node 903 representing the "System C filtration basin" from node 901 representing the "System B Receiving Well." Because the directed graph 900 does not include an edge for reaching from "System B" to "System C," the water flow from the "System B Receiving Well" to the "System C filtration basin" corresponds to a water system crossing, and the path from the "System B Receiving Well" to the "System C filtration basin" is a water path that cannot occur hydraulically. Therefore, it is assumed that an event that occurs at the "System B Receiving Well" will not trigger an event at the "Settling Basin."
[0072] In step S804, only combinations of nodes (upstream equipment and downstream equipment) that can be reached by tracing the edges in accordance with the direction of the edges are extracted, and therefore, combinations of nodes that correspond to reverse flow as described above and combinations that correspond to system crossings are not included in the whitelist 122. As will be described in detail later, in the chain data creation process, matching with the whitelist 122 is performed, so chain events due to reverse flow or system crossings (combinations of events that cannot be chained) are cut out.
[0073] Furthermore, in the directed graph 900, it is possible to reach the node 901 representing the "B-system water receiving well" by following the edges 904 and 905 from the node 902 representing the "sand trap." Therefore, the path from the "sand trap" to the "B-system water receiving well" is a hydraulically possible water path.
[0074] Here, the lower limit of the expected arrival time assigned to edge 904 is 2 hours, and the lower limit of the expected arrival time assigned to edge 905 is also 2 hours, so the lower limit of the expected arrival time from the "sand trap" to the "B-line water arrival well" is 2 hours + 2 hours = 4 hours. In this case, if water reaches the "B-line water arrival well" from the "sand trap" in less than 4 hours, it is equivalent to water teleportation. Therefore, although an event that occurs in the "sand trap" may trigger an event at the "B-line water arrival well," it is assumed that the event at the "B-line water arrival well" will not be triggered before 4 hours have passed since the event that occurred in the "sand trap".
[0075] Furthermore, the upper limit of the expected arrival time assigned to edge 904 is 6 hours, and the upper limit of the expected arrival time assigned to edge 905 is also 6 hours, so the upper limit of the expected arrival time from the "sand trap" to the "B-line water arrival well" is 6 hours + 6 hours = 12 hours. In this case, if water takes longer than 12 hours to reach the "B-line water arrival well" from the "sand trap" it corresponds to delayed movement of water. Therefore, although an event that occurs in the "sand trap" may trigger an event at the "B-line water arrival well", it is assumed that an event at the "B-line water arrival well" will not be triggered later than 12 hours after the event that occurred in the "sand trap".
[0076] Details will be described later, but when comparing with the whitelist 122 in the chain data creation process, the results of comparing the upper and lower limits of the expected arrival time with the time difference are taken into consideration, so chain events caused by teleportation or time delays (combinations of events that cannot be chained) are cut out.
[0077] 10 is an explanatory diagram showing an example of a statistical method for creating the initial chain data 126. The initial chain data 126 may be created in advance by an external system or the like, but here it is described as being created by the chain analysis unit 117. Before the initial chain data 126 is created, it is assumed that the values of the alarm history data 123, the operation history data 124, and the event list data 125 are set in advance.
[0078] The chain analysis unit 117 selects one arbitrary event content from the event list data 125 and determines it as a first event A1, and selects one arbitrary event content different from the first event from the event list data 125 and determines it as a second event A2.
[0079] The chain analysis unit 117 acquires the occurrence of the earlier event A1 from the alarm history data 123 or the operation history data 124, and generates, for example, a time series S1(t) of binary data indicating whether or not the earlier event A1 occurred at each time (each timing) t every minute. The chain analysis unit 117 acquires the occurrence of the later event A2 from the alarm history data 123 or the operation history data 124, and generates, for example, a time series S2(t) of binary data indicating whether or not the later event A2 occurred at each time (each timing) t every minute.
[0080] The linkage analysis unit 117 calculates the correlation coefficient C between S2(t) and S1(t) shifted back by the time difference m for each time difference m (= 0, 1, 2, . . . , n minutes). In graph 1001, the horizontal axis represents the time difference m, and the vertical axis represents the correlation coefficient C.
[0081] If some correlation is found between the earlier event A1 and the later event A2, the correlation coefficient C will reach a peak value C* at a specific time difference m* in graph 1001. Therefore, for example, if the correlation coefficient reaches a maximum value C* at the time difference m* in graph 1001, which is a local maximum value, and C* is equal to or greater than a predetermined value, the linkage analysis unit 117 stores the combination of the earlier event A1, the later event A2, m*, and C* in the initial linkage data 126. In this way, a combination of events whose occurrence timing correlation is high based on a predetermined condition (i.e., the correlation coefficient between the occurrence timings of the events taking the time difference into consideration is the maximum value and the local maximum value is equal to or greater than a predetermined value) is determined as a chain event in the initial linkage data 126.
[0082] The chain analysis unit 117 can extract combinations of chain events that are considered to be statistically correlated, as well as the time difference and correlation coefficient associated with the chain, by performing the above-mentioned process on any combination of preceding and subsequent events that can be generated from the event list data 125. However, since the hydraulics within the water purification plant are not taken into consideration when creating the initial chain data 126, chain events that are hydraulically impossible to occur may be included in the initial chain data 126.
[0083] 11 is a flowchart showing an example of the chain data creation process. The chain data creation process is executed after the whitelist creation process is completed. Furthermore, it is assumed that values of the event list data 125 and the initial chain data 126 are set in advance before the chain data creation process starts.
[0084] The chain data creation unit 112 acquires the initial chain data 126 from the auxiliary storage device 103 (S1101). The chain analysis unit 117 selects one unselected record from the initial chain data 126 (S1102). The chain analysis unit 117 identifies the names of facilities where the earlier event content and the later event content of the selected record occur from the event list data 125 (S1103). Hereinafter, the name of the facility where the earlier event content occurs will also be referred to as the earlier facility name, and the name of the facility where the later event content occurs will also be referred to as the later facility name. Note that the initial chain data 126 may previously store information indicating the names of facilities where each event included in the chain event occurs (the earlier facility name and the later facility name), in which case the processing of step S1103 is unnecessary.
[0085] The chain contradiction determination unit 118 determines whether there is any record in the whitelist 122 whose upstream equipment name matches the earlier equipment name identified in the most recent step S1103 and whose downstream equipment name matches the later equipment name identified in the most recent step S1103 (S1104).
[0086] If the chain contradiction determination unit 118 determines that the whitelist 122 includes the above-mentioned record (S1104: YES), it determines whether the time difference indicated by the selected record in the initial chain data 126 is included in the range above the lower limit of the expected arrival time and below the upper limit of the expected arrival time indicated by the record in the whitelist 122 (S1105).If the chain contradiction determination unit 118 determines that the whitelist 122 does not include the above-mentioned record (S1104: NO), it transitions to step S1107, which will be described later.
[0087] If the chain contradiction determination unit 118 determines that the time range indicated by the record in the whitelist 122 includes the time difference indicated by the selected record in the initial chain data 126 (S1105: YES), it adds the selected record in the initial chain data 126 to the chain data 127 (S1106).If the chain contradiction determination unit 118 determines that the time range indicated by the record in the whitelist 122 does not include the time difference indicated by the selected record in the initial chain data 126 (S1105: NO), it transitions to step S1107, which will be described later.
[0088] The linkage analysis unit 117 determines whether all records of the initial chain data 126 have been selected (S1107). If the linkage analysis unit 117 determines that there are unselected records of the initial chain data 126 (S1107: NO), the process returns to step S1102. If the linkage analysis unit 117 determines that all records of the initial chain data 126 have been selected (S1107: YES), the linkage data creation process ends.
[0089] The process of step S1104 cuts out chain events related to backflow, system crossing, etc., and the process of step S1105 cuts out chain events related to instantaneous movement, time delay, etc. Therefore, the chain data 127 stores only information indicating chain events that can occur hydraulically, out of the chain events indicated by the initial chain data 126 (i.e., events that are thought to be correlated).
[0090] 12 is a diagram showing an example of the screen configuration of a whitelist editing screen. A whitelist editing screen 1200 is displayed on the display device 106 by the screen manager 113 after the whitelist creation process and the chain data creation process are executed.
[0091] The whitelist editing screen 1200 includes, for example, a chain data display area 1201, a cut chain data display area 1202, a water system data display area 1203, a whitelist display area 1204, and a re-execute button 1207.
[0092] The chain data display area 1201 displays the chain data 127. The cut chain data display area 1202 displays data consisting of records that were included in the initial chain data 126 but were not added to the chain data 127.
[0093] By checking the chain data 127 displayed in the chain data display area 1201, water purification plant operators can check hydraulically linked events that may occur, the order in which those events occur, the time difference, correlation coefficients, etc., and can obtain knowledge about important alarms and important operations.
[0094] Information indicating the reason why each record was cut may also be displayed in the cut chain data display area 1202. Specifically, for example, a record of the initial chain data 126 that is determined not to meet the condition shown in step S1104 indicates a chain event related to reverse flow or system crossing, so information indicating that the chain event indicated by the record is a chain event related to reverse flow or system crossing may also be displayed.
[0095] Furthermore, for example, a record of the initial chain data 126 for which it is determined in step S1105 that the time difference is less than the arrival time lower limit indicates a chain event related to teleportation, and therefore information indicating that the chain event indicated by this record is a chain event related to teleportation may also be displayed. Furthermore, for example, a record of the initial chain data 126 for which it is determined in step S1105 that the time difference is more than the arrival time upper limit indicates a chain event related to a time delay, and therefore information indicating that the chain event indicated by this record is a chain event related to a time delay may also be displayed.
[0096] The graph created in step S802 and the upper and lower limits of the estimated arrival time between adjacent facilities calculated in step S803 are displayed in the river system data display area 1203. When a record in the chain data display area 1201 or a record in the cut chain data display area 1202 is selected, the nodes corresponding to the earlier facility and the later facility (identified from the event list data 125) where the earlier event and the later event indicated by the selected record occur, respectively, are highlighted in the river system data display area 1203.
[0097] The whitelist display area 1204 displays the whitelist 122, an add button 1205, and a delete button 1206. When a record in the whitelist display area 1204 is selected, the nodes corresponding to the upstream facility and downstream facility indicated by the selected record are highlighted in the water system data display area 1203.
[0098] When any record in the whitelist 122 is selected and the delete button 1206 is selected, the selected record is deleted from the whitelist 122.
[0099] When the Add button 1205 is selected, for example, input of a record to be added to the water system data whitelist 122 is accepted from the user via the input device 105. Specifically, for example, when the Add button 1205 is selected, selection of a node corresponding to an upstream facility and a node corresponding to a downstream facility can be accepted from the nodes of the graph displayed in the water system data display area 1203.
[0100] By executing the processing of step S805 for the selected combination of upstream equipment and downstream equipment, the upper and lower limits of the estimated arrival time are calculated, and a new record to be added to the whitelist 122 is generated.
[0101] However, if a combination of upstream and downstream facilities selected from the nodes of the graph displayed in the water system data display area 1203 is not a combination in which water can reach the downstream facility from the upstream facility (for example, if it is determined that the combination is not included in the combinations extracted by the exhaustive search on the directed graph in the above-mentioned step S904), the screen management unit 113 may additionally display, for example, a warning indicating "Does not match hydraulic characteristics" and a selection screen such as "Do you want to ignore and add? Yes / No." When adding a combination in which water cannot reach the downstream facility from the upstream facility, manual input of values in the estimated arrival time lower limit field 1223 and the estimated arrival time upper limit field 1224 is required.
[0102] Furthermore, when a record in the cut chain data display area 1202 is selected, a selection may be accepted to add the earlier equipment and later equipment in which the earlier event and later event indicated by the record occur as upstream equipment and downstream equipment, respectively, to the whitelist 122. In this case as well, the upper and lower limits of the estimated arrival time are calculated, and a new record to be added to the whitelist 122 is generated. Furthermore, the above-mentioned warning and selection screen can be additionally displayed.
[0103] Since records in the whitelist 122 can be added manually or based on records in the cut chain data display area 1202, the whitelist 122 can reflect the rules of thumb of experienced operators and circumstances specific to the target water purification plant.
[0104] When the whitelist 122 is edited on the whitelist editing screen 1200 and then the re-execute button 1207 is selected, the chain data creation process is executed again using the edited whitelist 122. [Example]
[0105] In the first embodiment, the chain event was composed of two events (an earlier event and a later event), but in this embodiment, the chain event may include three or more events. In this embodiment, the chain data creation process will be described when there is a chain event that includes three or more events. In this embodiment, differences from the first embodiment will be mainly described, and explanations of similarities to the first embodiment will be omitted as appropriate.
[0106] 13 is a diagram showing an example of the data configuration of the initial chain data 126. The initial chain data 126 of this embodiment includes a chain event content column 1268 instead of the preceding event content column 1261 and the subsequent event content column 1262. The chain event content column 1268 indicates chain events with a chain number of 2 or more.
[0107] In addition, in this embodiment, the time difference column 1263 indicates the time difference between each event included in the chain event indicated by the chain event content column 1268, and the correlation coefficient column 1264 indicates the correlation coefficient between each event included in the chain event indicated by the chain event content column 1268.
[0108] For example, the chain event content column 1268 of record 1269 of the initial chain data 126 shows a chain event indicating that "A-system filtration pond water quality abnormality" occurs in conjunction with "A-system receiving well water level abnormality", "B-system inflow water quality abnormality" occurs in conjunction with "A-system filtration pond water quality abnormality", "B-system inflow water quality abnormality" occurs in conjunction with "B-system inflow water quality abnormality", and "A-system receiving well operation X" occurs in conjunction with "B-system filtration pond water quality abnormality", and the chain number of the chain event (i.e., the number of events that make up the chain event) is 5.
[0109] Furthermore, for example, the time difference column 1263 of record 1269 of the initial chain data 126 indicates that the time difference between the occurrence times of the "A-system receiving well water level abnormality" and the "A-system filtration pond water quality abnormality" is 4, the time difference between the occurrence times of the "A-system filtration pond water quality abnormality" and the "B-system influent water quality abnormality" is 85, the time difference between the occurrence times of the "B-system influent water quality abnormality" and the "B-system filtration pond water quality abnormality" is 10, and the time difference between the occurrence times of the "B-system filtration pond water quality abnormality" and the "A-system receiving well operation X" is 17.
[0110] Furthermore, for example, the correlation coefficient column 1264 of record 1269 of the initial chain data 126 indicates that the correlation coefficient between "A-system receiving well water level abnormality" and "A-system filtration pond water quality abnormality" is 0.59, the correlation coefficient between "A-system filtration pond water quality abnormality" and "B-system influent water quality abnormality" is 0.20, the correlation coefficient between "B-system influent water quality abnormality" and "B-system filtration pond water quality abnormality" is 0.57, and the correlation coefficient between "B-system filtration pond water quality abnormality" and "A-system receiving well operation X" is 0.48.
[0111] Note that, since the data configuration example of the chain data 127 in this embodiment is similar to that of the initial chain data 126 in FIG. 13, the illustration of the data configuration example of the chain data 127 in this embodiment is omitted.
[0112] 14 is a flowchart showing an example of the chain data creation process. The same processes as those in FIG. 11 will not be described. Following step S1102, the chain analysis unit 117 determines whether the number of chains of the chain events indicated by the selected record in the initial chain data 126 is 3 or more (S1401).
[0113] If the chain analysis unit 117 determines that the chain number of the chain event indicated by the selected record in the initial chain data 126 is not 3 or more, i.e., the chain number is 2 (S1401: NO), it can identify the preceding event and the subsequent event from the chain event, so it transitions to step S1103 and performs processing similar to that in Example 1.
[0114] When the chain analysis unit 117 determines that the number of chains of the chain events indicated by the selected record of the initial chain data 126 is 3 or more (S1401: YES), it executes a multi-chain dedicated process (S1402) and proceeds to step S1107.
[0115] 15 is a flowchart showing an example of the dedicated multi-chain process in step S 1402. The chain analysis unit 117 decomposes the chain event indicated by the selected record of the initial chain data 126 into chain events with a chain number of 2 (S1501).
[0116] Specifically, for example, when record 1269 of the initial chain data 126 of Figure 13 is selected, the chain analysis unit 117 extracts combinations of events directly connected by "→" from the chain event with a chain number of 5 indicated in the chain event content column 1268 of record 1269, "Abnormal water level in the A-system receiving well → Abnormal water quality in the A-system filtration basin → Abnormal in the B-system influent water quality → Abnormal water quality in the B-system filtration basin → A-system receiving well operation X," and decomposes it into chain events with a chain number of 2, "Abnormal water level in the A-system receiving well → Abnormal water quality in the A-system filtration basin," "Abnormal water quality in the A-system filtration basin → Abnormal water quality in the B-system influent water," "Abnormal water quality in the B-system influent water → Abnormal water quality in the B-system filtration basin," and "Abnormal water quality in the B-system filtration basin → Abnormal water quality in the B-system
[0117] Also, by referring to the time difference column 1263 of record 1269, the time difference corresponding to "A system receiving well water level abnormality → A system filtration pond water quality abnormality" is determined to be 4, the time difference corresponding to "A system filtration pond water quality abnormality → B system influent water quality abnormality" is determined to be 85, the time difference corresponding to "B system influent water quality abnormality → B system filtration pond water quality abnormality" is determined to be 10, and the time difference corresponding to "B system filtration pond water quality abnormality → A system receiving well operation X" is determined to be 17.
[0118] Also, by referring to the correlation coefficient column 1264 of record 1269, the correlation coefficient corresponding to "A system receiving well water level abnormality → A system filtration pond water quality abnormality" is determined to be 0.59, the correlation coefficient corresponding to "A system filtration pond water quality abnormality → B system influent water quality abnormality" is determined to be 0.20, the correlation coefficient corresponding to "B system influent water quality abnormality → B system filtration pond water quality abnormality" is determined to be 0.57, and the correlation coefficient corresponding to "B system filtration pond water quality abnormality → A system receiving well operation X" is determined to be 0.48.
[0119] The chain analysis unit 117 selects one unselected chain event from the chain events with a chain number of 2 after decomposition in step S1501 (S1502). All chain events with a chain number of 2 after decomposition are combinations of an earlier event and a later event, and the chain event selected in step S1502 can be treated in the same way as the chain event selected in step S1102 in the first embodiment. Therefore, the processes in steps S1503, S1504, and S1505 are the same as the processes in steps S1103, S1104, and S1105, respectively.
[0120] However, if the chain contradiction determination unit 118 determines that the whitelist 122 does not contain a record whose upstream equipment name matches the earlier equipment name identified in the most recent step S1503 and whose downstream equipment name matches the later equipment name identified in the most recent step S1503 (S1504: NO), it transitions to step S1507 described below.
[0121] Furthermore, if the chain contradiction determination unit 118 determines that the time difference corresponding to the chain event selected in step S1502 is included in the range of the estimated arrival time lower limit and the estimated arrival time upper limit indicated by the record of the whitelist 122 that satisfies the condition indicated by step S1504 (S1505: YES), the process proceeds to step S1506, which will be described later.If the chain contradiction determination unit 118 determines that the time difference corresponding to the chain event selected in step S1502 is not included in the range of the estimated arrival time lower limit and the estimated arrival time upper limit indicated by the record of the whitelist 122 that satisfies the condition indicated by step S1504 (S1505: NO), the process proceeds to step S1507, which will be described later.
[0122] The chain analysis unit 117 temporarily stores the chain event with the chain number of 2 selected in the most recent step S1502 in, for example, the memory 102 as a chain event to be added to the chain data 127 (S1506).
[0123] The chain analysis unit 117 determines whether all of the chain events with a chain number of 2 after decomposition have been selected (S1507). If the chain analysis unit 117 determines that there are unselected chain events with a chain number of 2 after decomposition (S1507: NO), the process returns to step S1502. If the chain analysis unit 117 determines that all of the chain events with a chain number of 2 after decomposition have been selected (S1507: YES), the process proceeds to step S1508, which will be described later.
[0124] The chain data creation unit 112 recombines the chain events with a chain count of 2 that were temporarily stored in step S1506 and that were connected in the chain events before the disassembly, and stores them in the chain data 127 (S1508), and the multi-chain dedicated processing ends.
[0125] Two pairs of chain events with a chain number of 2 that are temporarily stored and in which one subsequent event matches the other's earlier event are linked in the chain events before decomposition. Specifically, for example, if the chain events with a chain number of 2, "Abnormal water level in A-system receiving well → Abnormal water quality in A-system filtration basin," "Abnormal water quality in A-system filtration basin → Abnormal water quality in B-system influent water," and "Abnormal water quality in B-system filtration basin → Operation X of A-system receiving well," are temporarily stored, the chain data creation unit 112 relinks "Abnormal water level in A-system receiving well → Abnormal water quality in A-system filtration basin" and "Abnormal water quality in A-system filtration basin → Abnormal water quality in B-system influent water," to obtain a chain event with a chain number of 3, "Abnormal water level in A-system receiving well → Abnormal water quality in A-system filtration basin → Abnormal water quality in B-system influent water."
[0126] Therefore, in this case, the chain data creation unit 112 stores in the chain data 127 a record indicating the chain event with a chain number of 3, "Abnormal water level in A-system receiving well → Abnormal water quality in A-system filtration pond → Abnormal inflow water quality in B-system", the time difference corresponding to the chain event, "4,85", and the correlation coefficient corresponding to the chain event, "0.59,0.20", as well as a record indicating the chain event with a chain number of 2, "Abnormal water quality in B-system filtration pond → Operation of A-system receiving well X", the time difference corresponding to the chain event, "17", and the correlation coefficient corresponding to the chain event, "0.48".
[0127] The present invention is not limited to the above-described embodiments, but includes various modifications. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.
[0128] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. The above-described configurations, functions, etc. may also be implemented in software, with a processor interpreting and executing a program that implements each function. Information such as the programs, tables, and files that implement each function can be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.
[0129] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]
[0130] 100 Event analysis system, 101 CPU, 102 memory, 105 input device, 106 display device, 111 whitelist creation unit, 112 chain data creation unit, 113 screen management unit, 121 water system data, 122 whitelist, 125 event list data, 126 initial chain data, 127 chain data, 1200 whitelist editing screen
Claims
1. An event analysis system that analyzes events occurring in a plurality of facilities, a processor and a memory, The memory includes: a whitelist indicating a list of reachable combinations of equipment included in the plurality of equipment, which are combinations of upstream equipment and downstream equipment in which a water flow from the upstream equipment may exist; retaining initial chain information indicating a chain event including the combination of events whose occurrence timing correlation is high based on a predetermined condition, the occurrence facilities of each of the events included in the chain event, and the occurrence order of the events included in the chain event; The processor: Identifying, as knowledge, a chain event in which an earlier equipment that is the occurrence equipment of an earlier event that occurs earlier in the order of occurrence and a later equipment that is the occurrence equipment of a later event that occurs later in the order of occurrence, respectively, match the upstream equipment and the downstream equipment in any of the reachable combinations indicated in the whitelist; generating knowledge information indicating the identified knowledge; An event analysis system that outputs data for generating a screen that displays the knowledge information.
2. The event analysis system according to claim 1, There is a water flow from one of the plurality of facilities to the other of adjacent facilities, the memory holds water system data indicating the plurality of facilities, adjacent facilities among the plurality of facilities, and a water flow direction between the adjacent facilities; The processor: Identifying the reachable combinations based on the direction of water flow between the adjacent facilities indicated by the water system data; The event analysis system stores the identified reachable combinations in the whitelist.
3. 3. The event analysis system according to claim 2, The processor: creating a directed graph including nodes representing each of the plurality of facilities and edges connecting nodes representing adjacent facilities and indicating the direction of water flow between the adjacent facilities, with reference to the water system data; extracting combinations of nodes on the directed graph that are reached by tracing one or more edges from one node to another node in accordance with the directions of the one or more edges by applying a predetermined search algorithm to the directed graph; An event analysis system that identifies the reachable combination by defining the equipment corresponding to one of the nodes in the extracted node combination as the upstream equipment and the equipment corresponding to the other node as the downstream equipment.
4. The event analysis system according to claim 1, the whitelist indicates a range of arrival times for water to arrive from the upstream equipment to the downstream equipment for each of the reachable combinations; the initial chain information indicates a time difference between the occurrence timing of the preceding event and the occurrence timing of the subsequent event included in the chain event; The processor: An event analysis system that identifies as the knowledge among the chain events those chain events in which the earlier equipment and the later equipment respectively match the upstream equipment and the downstream equipment in any of the reachable combinations indicated in the whitelist, and the time difference is within the range of the arrival time in the reachable combination.
5. The event analysis system according to claim 4, There is a water flow from one of the plurality of facilities to the other of adjacent facilities, the memory holds water system data indicating the plurality of facilities, adjacent facilities among the plurality of facilities, a water flow direction between the adjacent facilities, a volume of each of the pipelines connecting the adjacent facilities, and an upper limit and a lower limit of the water flow velocity in each of the pipelines; The processor: Identifying the reachable combinations based on the direction of water flow between the adjacent facilities indicated by the water system data; determining a range of the arrival time for the specified reachable combination based on a volume of a pipeline connecting the upstream equipment and the downstream equipment in the specified reachable combination and the upper and lower flow velocity limits in the pipeline; The event analysis system stores the identified reachable combination and the determined range of arrival times in the whitelist.
6. The event analysis system according to claim 1, connected to an input device, The processor: further displaying the whitelist on the screen; An event analysis system that accepts editing of the whitelist on the screen based on input to the input device.
7. The event analysis system according to claim 6, the memory holds a directed graph including a node representing each of the plurality of facilities and an edge connecting the node representing the adjacent facility and indicating a direction of water flow between the adjacent facilities; The processor: extracting combinations of nodes on the directed graph that are reached by tracing one or more edges from one node to another node in accordance with the directions of the one or more edges by applying a predetermined search algorithm to the directed graph; An event analysis system that outputs a warning when a request is made to add a reachable combination in editing the whitelist received based on input to the input device, and the upstream equipment and downstream equipment indicated by the reachable combination do not match the equipment indicated by one node and the equipment indicated by the other node, respectively, of the extracted node combination.
8. The event analysis system according to claim 1, The processor further displays, on the screen, information indicating chain events that are not included in the knowledge information, among the chain events included in the initial chain information.
9. An event analysis method for an event analysis system that analyzes events occurring in a plurality of facilities, comprising: the event analysis system includes a processor and a memory; The memory includes: a whitelist indicating a list of reachable combinations of equipment included in the plurality of equipment, which are combinations of upstream equipment and downstream equipment in which a water flow from the upstream equipment may exist; retaining initial chain information indicating a chain event including the combination of events whose occurrence timing correlation is high based on a predetermined condition, the occurrence facilities of each of the events included in the chain event, and the occurrence order of the events included in the chain event; The event analysis method includes: The processor identifies, as knowledge, a chain event in which an earlier equipment that is the occurrence equipment of an earlier event that occurs earlier in the order of occurrence and a later equipment that is the occurrence equipment of a later event that occurs later in the order of occurrence match the upstream equipment and the downstream equipment in any of the reachable combinations indicated by the whitelist, respectively; the processor generates knowledge information indicating the identified knowledge; The event analysis method further comprises the processor outputting data for generating a screen displaying the knowledge information.
10. An event analysis program that causes an event analysis system to analyze events occurring in a plurality of pieces of equipment, the event analysis system includes a processor and a memory; The memory includes: a whitelist indicating a list of reachable combinations of equipment included in the plurality of equipment, which are combinations of upstream equipment and downstream equipment in which a water flow from the upstream equipment may exist; retaining initial chain information indicating a chain event including the combination of events whose occurrence timing correlation is high based on a predetermined condition, the occurrence facilities of each of the events included in the chain event, and the occurrence order of the events included in the chain event; The event analysis program a process of identifying, as knowledge, a chain event in which an earlier equipment that is the occurrence equipment of an earlier event that occurs first and a later equipment that is the occurrence equipment of a later event that occurs later in the order of occurrence, respectively, match the upstream equipment and the downstream equipment in any of the reachable combinations indicated in the whitelist; a process of generating knowledge information indicating the identified knowledge; and outputting data for generating a screen that displays the knowledge information.
Citation Information
Patent Citations
Alarm analyzer, analyzing method and program
JP2005216148A