Information processing device, information processing method, and information processing program
The information processing device efficiently identifies cause events in networked systems by acquiring and grouping logs, using event correlation information to pinpoint the root cause, thereby reducing troubleshooting time and maintenance costs.
Patent Information
- Application Number
- JP2021037852
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-09
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-03-09
AI Technical Summary
Existing methods struggle to identify the primary cause of abnormalities in networked systems, especially when multiple events occur simultaneously, leading to prolonged troubleshooting times and increased maintenance costs.
An information processing device connected to a network that includes a log acquisition unit, a grouping processing unit, a specification unit, and an output unit. This device acquires logs from multiple devices, groups related events, identifies cause events using event correlation information, and outputs the identified cause events.
Enables efficient identification of cause events among multiple simultaneous events, reducing troubleshooting time and maintenance costs by accurately pinpointing the root cause of abnormalities.
Smart Images

Figure 0007673435000001 
Figure 0007673435000002 
Figure 0007673435000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing apparatus connected to a network to which a plurality of apparatuses are connected, an information processing method for the information processing apparatus, and an information processing program. [Background technology]
[0002] ICT (Information and Communication Technology) is also being used in manufacturing sites, and various devices are increasingly being networked. As a result, the main cause of an abnormality can be identified and the problem can be solved based on the events recorded in the system logs.
[0003] When an abnormality occurs, many secondary events occur as a result, making it difficult to identify the main cause by simply checking the logs as chronological data. As a result, troubleshooting takes a huge amount of time, leading to losses due to equipment shutdowns and increased maintenance costs. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2018-124697 A Summary of the Invention [Problem to be solved by the invention]
[0005] Patent Document 1 discloses a method for identifying the cause from system configuration information when multiple events occur. However, the above-mentioned method is extremely limited in the cases where the cause of multiple events occurring simultaneously can be identified, since the determination is made only from the system configuration information. For example, it is not possible to identify the main cause from events that occur simultaneously in the same device. In addition, it is not possible to identify the cause of an event that occurs in an application that cannot be determined only from the system configuration information.
[0006] Furthermore, in each device that constitutes the system, various events that are different from the cause of the abnormality occur, and these are generally stored in the same memory area. The capacity of the memory area is limited, and since it is overwritten as needed, it is possible that the necessary event logs will be erased, making it impossible to troubleshoot.
[0007] An object of one aspect of the present invention is to identify a cause event from among a plurality of events that have occurred on a network to which a plurality of devices are connected. [Means for solving the problem]
[0008] In order to solve the above problems, an information processing device according to one embodiment of the present invention is an information processing device connected to a network to which multiple devices are connected, and includes a log acquisition unit that acquires a log recording information processing events performed in the device itself and / or other devices connected to the device via the network, a grouping processing unit that groups the multiple events recorded in the log into related event groups based on predetermined criteria, an identification unit that identifies a causal event from the related event group that is a cause of the occurrence of the related event group, and an output unit that outputs the causal event identified by the identification unit, and the identification unit identifies the causal event using event correlation information that indicates information for identifying the causal event for each type of event.
[0009] According to the above configuration, by grouping related events from among multiple events in a log and using event correlation information, it is possible to appropriately identify the event that caused the event. Therefore, even if multiple events occur simultaneously, it is easy to identify the event that caused the event, and troubleshooting can be performed.
[0010] The event correlation information may include, for each type of event, information regarding the cause priority of a device in which the event has occurred, as information for identifying the cause event.
[0011] According to the above configuration, when multiple identical causal events occur during processing by the identification unit, the true causal event can be identified by checking the causal priority level according to the items set in the causal priority level.
[0012] The information on the factor priority may be set by a configuration information priority setting, which is information indicating the order of the factor priority by the position in configuration information indicating the network connection relationship of the device.
[0013] According to the above configuration, it is possible to set factor priorities based on configuration information priority settings, and in accordance with general rules, such as the configuration information of the network, without specifying individual devices.
[0014] The information regarding the factor priority levels may be set by an identification information priority level setting, which is information indicating the order of the factor priorities using information that identifies the device.
[0015] According to the above configuration, by identifying individual devices based on the identification information priority setting, it is possible to set factor priorities in more detail and appropriately.
[0016] The grouping processing unit may perform grouping based on an occurrence time of the event.
[0017] According to the above configuration, since a group of events occurring close to each other is expected to have a causal relationship, by treating these as a group of related events, it is possible to appropriately identify the cause.
[0018] The information processing device may further include a setting unit that reads configuration information indicating a connection relationship of the network and sets the event correlation information.
[0019] According to the above configuration, the event correlation information can be set without the need for a user to input settings, thereby saving the user time and effort.
[0020] The information processing device may be a PLC (Programmable Logic Controller), and the logs may be collected from slave devices connected to the PLC.
[0021] According to the above configuration, a system can be easily constructed that collects logs from a PLC and slaves connected to the PLC, using a program in the PLC.
[0022] The information processing device may be a slave device controlled by a PLC (Programmable Logic Controller), and may collect the logs from lower level devices connected to the slave device.
[0023] According to the above configuration, a system can be easily constructed in which a slave connected to a PLC collects logs from the slave and from lower-level devices on a subordinate network connected to the slave.
[0024] The information processing device may be a personal computer (PC) connected to a programmable logic controller (PLC), and may acquire the log from the PLC.
[0025] According to the above configuration, it is possible to easily build a system in which a PC connected to a PLC collects logs from the PLC and slaves connected to the PLC.
[0026] In order to solve the above problems, an information processing method of an information processing device according to another aspect of the present invention is an information processing method of an information processing device connected to a network to which multiple devices are connected, and includes a log acquisition step of acquiring a log recording information processing events performed in the device itself and / or another device connected to the device itself via the network, a grouping processing step of grouping the multiple events recorded in the log into a related event group based on a predetermined criterion, an identification step of identifying a causal event from the related event group that is the cause of the occurrence of the related event group, and an output step of outputting the causal event identified by the identification unit, wherein the identification unit identifies the causal event using event correlation information indicating information for identifying the causal event for each type of event.
[0027] The information processing device according to each aspect of the present invention may be realized by a computer. In this case, the control program of the information processing device that realizes the information processing device on a computer by causing the computer to operate as each part (software element) of the information processing device, and the computer-readable recording medium on which the control program is recorded, also fall within the scope of the present invention. Effect of the Invention
[0028] According to one aspect of the present invention, it is possible to identify a causative event from among a plurality of events that have occurred simultaneously. [Brief description of the drawings]
[0029] [Figure 1] 1 is a block diagram showing a configuration of a main part of an information processing system according to a first embodiment. [Diagram 2] FIG. 1 is a schematic diagram of a method for determining related events from logs. [Diagram 3] FIG. 13 is a schematic diagram of another method for obtaining a group of related events from a group of logs. [Figure 4] FIG. 4 is a diagram illustrating an example of event correlation information according to the first embodiment. [Diagram 5] FIG. 4 is a diagram showing a process of identifying a causal event according to the first embodiment. [Figure 6] 4 is a flowchart showing the operation of the information processing system according to the first embodiment. [Figure 7] FIG. 11 is a block diagram showing a configuration of a main part of an information processing system according to a second embodiment. [Figure 8] FIG. 11 is a block diagram showing a configuration of a main part of an information processing system according to a third embodiment. [Figure 9] FIG. 13 is a diagram illustrating an example of event correlation information according to the third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0030] [Embodiment 1] Hereinafter, an embodiment according to one aspect of the present invention (hereinafter, also referred to as "the present embodiment") will be described with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference characters and their description will not be repeated.
[0031] § 1. Examples of Application 1 is a block diagram showing a configuration of a main part of an information processing system 100 according to embodiment 1. The information processing system 100 includes a PC (Personal Computer) (information processing device) 1, a PLC (Programmable Logic Controller) (information processing device) 2, a slave (information processing device) A (slave device) 3, a slave B (slave device) 4, a communication unit 5, and a network 6.
[0032] PC 1 collects logs 2a, 3a, and 4a that store events from each device on network 6, such as PLC 2, slave A 3, and slave B 4. The collected logs are divided into several groups based on the time when the events occurred, and predetermined processing is performed on each group based on event correlation information 22 to identify the event that caused the event.
[0033] §2. Example configuration (Configuration of information processing system 100) The information processing system 100 will be described in more detail below. PC1 communicates with PLC2 and operates based on information obtained from PLC2, slave A3, and slave B4. PC1 can take various forms, and may be a notebook computer or a server personal computer.
[0034] The PLC 2 is a control device in the information processing system 100. The PLC 2 is not limited to a PLC, and may be any control device.
[0035] Slave A3 and slave B4 are slaves on network 6 controlled by PLC 2. The number of slaves subordinate to PLC 2 is not limited to two and may be any number. Slaves on network 6 include various devices such as actuator drivers, communication couplers, and image processing units in addition to general-purpose I / O units.
[0036] The communication means 5 is a means for communication between the PC 1 and the PLC 2, and is any communication means such as USB (Universal Serial Bus) (registered trademark), EtherNet (registered trademark), and serial communication.
[0037] The network 6 is a network that allows information to be exchanged between devices, and may be a so-called field network. The network 6 may employ various protocols, such as EtherNet (registered trademark), EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), and CompoNet (registered trademark).
[0038] (Device configuration on network 6) Slave A3 and slave B4 store logs 3a and 4a, respectively, and transmit the logs 3a and 4a to PLC 2 via network 6. PLC 2 stores log 2a, and transmits the logs 2a, 3a, and 4a, along with the received logs 3a and 4a, to PC 1 via communication means 5. PC 1 can therefore obtain the logs of the devices on network 6. The contents of logs 2a, 3a, and 4a will be described later.
[0039] (PC1 configuration) The PC 1 includes a control unit 10 and a storage unit 20. The control unit 10 includes a log acquisition unit 11, a grouping processing unit 12, an identification unit 13, an output unit 14, and a setting unit 15. The storage unit 20 includes event correlation information 22 configured from an identification information priority list (identification information priority setting) 221 and a configuration information priority setting 222, and a network configuration 23.
[0040] The log acquisition unit 11 acquires the log 3a of the slave A 3 and the log 4a of the slave B 4 together in addition to the log 2a of the PLC 2. That is, the log acquisition unit 11 acquires events in the information processing system 100 together as a log group. The log acquisition unit 11 outputs the log group to the grouping processing unit 12.
[0041] (Grouped into related events) The grouping processing unit 12 performs a predetermined process on the log group acquired by the log acquisition unit 11, thereby grouping events included in the log group into a related event group. The grouping is performed using the occurrence time of the event as a key. The grouping processing unit 12 outputs the related event group to the identification unit 13. A related event group is a grouping of multiple events included in the log group into at least one or more related events.
[0042] 2 is a schematic diagram of a method for determining a related event group L2 from a log group L1. Specifically, if the time difference between the occurrence times of an event in the log group L1 and a previously occurring event is within a predetermined time, the event group L2 is determined to be the same related event group L2. For example, if the time difference in the log group 311(L1) is "1 second," the event group L2 is determined to be the same related event group L2 if the time difference is "less than 1 second," and the event grouped as shown by reference numeral 312. Also, if the time difference in the log group 311(L1) is "3 seconds," the event group L2 is determined to be the same related event group L2 if the time difference is "less than 3 seconds," and the event grouped as shown by reference numeral 313.
[0043] 3 is a schematic diagram of another method for obtaining a related event group L2 from a log group L1. Specifically, the log group L1 is divided into groups at regular intervals. For example, in the log group 321(L1), when the period is "1 second", the related event groups L2 are grouped as shown by the reference numeral 322, with one related event group L2 at the occurrence time of "00:00:01", one related event group L2 at "00:00:02", one related event group L2 at "00:00:04", and one related event group L2 at "00:00:07". In addition, when the period is "5 seconds" in the log group 321(L1), the related event groups L2 are grouped as shown by the reference numeral 323, with one related event group L2 at "00:00:01-00:00:05" and one related event group L2 at "00:00:06-00:00:10".
[0044] (About event correlation information) The event correlation information 22 is information that organizes and summarizes factors that cause various events to occur in the information processing system 100. The event correlation information 22 may be in the form of a table.
[0045] Fig. 4 is a diagram showing an example of the event correlation information 22 according to the embodiment 1. As shown in Fig. 4, the event correlation information 22 includes an event name, a cause event, a configuration information priority setting 222, and an identification information priority list 221.
[0046] A causal event is an event that causes an event to occur. In other words, if a causal event and a secondary event that occurs secondary to the causal event occur simultaneously, it is considered that the secondary event occurred because of the causal event. There may be more than one causal event for an event. For example, event A in FIG. 4 may be caused by event B or event C.
[0047] The identification information priority list 221 is the order in which priorities are assigned to multiple causal events. For example, the identification information priority list for "event A" in Fig. 4 is "PLC, slave A, slave B", which means that if event A occurs in slave A3 and event A occurs in slave B4 at the same time, event A occurring in slave A3 becomes the causal event.
[0048] In addition, in the identification information priority list 221, devices on the network 6 can be arbitrarily selected by the user, such as "Slave A, Slave B" in "Event B" in Fig. 4. In this case, the user can set the priority of the device that is the cause regardless of the configuration information of the network 6, so that it becomes possible to set the priority according to the actual system application.
[0049] As shown in Figure 4, in a system connected by a network, if an information processing event such as a communication error occurs in some of the devices on the network, a chain reaction of events may occur. Specifically, event C (e.g., "slave communication error") occurs in the slave, which causes event B (e.g., "communication synchronization error") in the communication coupler, and event A (e.g., "link off error") in the PLC. In this case, event C is the cause event, and event A / event B are secondary events.
[0050] Similarly, not only communication anomalies in a network but also device anomalies may trigger the occurrence of a causal event, resulting in the occurrence of a secondary event (such as an anomaly).In this way, event correlation information is also information that indicates the chain relationship between multiple events.
[0051] (Event correlation information settings) Network configuration 23 is the configuration of network 6. That is, it is a configuration that indicates what is the master and in what order the slaves are connected in network 6. For example, in network 6 in Fig. 1, the master is "PLC" and the slaves are connected in the order of "Slave A" and "Slave B".
[0052] The configuration information priority setting 222 is a parameter for determining the identification information priority list 221. For example, when the configuration information priority setting is "first slave", it is the first device on the network 6, and when it is "last slave", it is the last device on the network 6. Also, it can be arbitrarily set by the user, such as "slave A, slave B", etc.
[0053] The setting unit 15 creates and sets the identification information priority list 221 by referring to the network configuration 23 and the configuration information priority setting 222. Based on the configuration information priority setting 222, it is determined which event correlation information 22 is to be prioritized in the network configuration 23. Therefore, if the configuration information priority setting 222 is "first slave", the identification information priority list 221 is allocated in the order of priority from the top of the network 6, and if the configuration information priority setting 222 is "last slave", the identification information priority list 221 is allocated in the order of priority from the bottom of the network 6.
[0054] (Identifying the causal event) The identification unit 13 identifies a causal event in the related event group L2.
[0055] First, all events are regarded as causal event candidates, which are candidates for causal events, and the causal events of each event are confirmed. If the causal event has some other event and is included in the causal event candidates, the event is considered to be a secondary event and is removed from the causal event list. If the causal event is "none" or is not included in the causal event candidates, the event is considered to be a possible causal event and is left as a causal event candidate. This process is performed for all causal event candidates. Next, if the same event occurs in different devices among the causal event candidates, the events are prioritized according to the order based on the identification information priority list 221 in the event correlation information. As a result, the true causal event is determined.
[0056] Fig. 5 is a diagram showing a process of identifying a causal event according to embodiment 1. Hereinafter, a specific process of identifying a causal event from the related event group L2 in the event correlation information 22 in Fig. 4 will be described with reference to Figs. 4 and 5.
[0057] There is a related event group 331(L2), which includes six events, events 331a to 331f. The related event group 331(L2) includes "event A", "event B", and "event C", and with reference to the event correlation information 22, the causal event of "event A" is "event B", and the causal event of "event B" is "event C". Therefore, in the related event group 331(L2), "event C" is the causal event candidate 332, and events 331c, 331e, and 331f are corresponding events.
[0058] At this time, if there is only one causal event candidate 332, that event is the true causal event 333.
[0059] Since there are multiple causal event candidates 332, the identification information priority list in the event correlation information 22 is used to further narrow down the candidates and identify the true causal event 333. By referring to the event correlation information 22, it is seen that the identification information priority list 221 for "event C" has a first candidate as "slave B4", a second candidate as "slave A", and a third candidate as "PLC". Therefore, from among the causal event candidates 332, event 331c that occurred in "slave B" is identified as the true causal event 333. The identification unit 13 outputs the identified causal event 333 to the output unit 14.
[0060] (Output of cause event) The output unit 14 outputs the identified true cause event 333 to another program or another device. As a form of output, a cause log L3 that summarizes the true cause events 333 may be constructed, a flag indicating that the cause event 333 is a true cause event may be set in an existing log, or the cause event 333 may be displayed on a screen. The true cause event 333 may also be output to another device, or may be displayed on an HMI (Human Machine Interface) such as a touch panel. The operation of the output unit 14 is not limited to these, and may be an operation that outputs any cause event 333.
[0061] §3. Example of operation FIG. 6 is a flowchart showing the operation of the information processing system 100 according to the first embodiment.
[0062] In S11, the log acquisition unit 11 acquires logs from the PLC 2, the slave A3, and the slave B4, respectively, and sets the logs as a log group L1. The targets from which the logs are acquired are not limited to these, and may be any devices sharing the network 6. The log acquisition unit 11 outputs the log group L1 to the grouping processing unit 12.
[0063] In S12, the grouping processing unit 12 groups the log group L1 into a related event group L2. The grouping processing unit 12 outputs the related event group L2 to the identification unit 13.
[0064] In S13, the identification unit 13 identifies a causal event from the related event group L2 based on the event correlation information 22. The identified causal event is output to the output unit .
[0065] In S14, the output unit 14 outputs the cause events identified for each associated event together in a cause log L3.
[0066] § 4. Actions and Effects PC1 acquires logs from devices on network 6, organizes them into log group L1, and groups them into related event group L2, and can identify the causal event for each related event I based on event correlation information 22. Therefore, it is easy to identify the true causal event from among many events, making it easy to take measures.
[0067] Event correlation information 22 can identify a true causal event from among multiple candidates for the same causal event in different devices by checking identification information priority list 221. Also, identification information priority list 221 can be easily set by configuration information priority setting 222 and network configuration 23. In configuration information priority setting 222, when an event that occurs uniquely in a certain device is the cause, the device of the event can also be specified in identification information priority list 221 without taking network configuration 23 into consideration.
[0068] The log group L1 can be grouped into related events I based on the occurrence time of each event. When grouping based on the occurrence time, the grouping process can be performed based on the time difference between the occurrence times or the period between the occurrence times, and it can be used even when multiple events do not occur simultaneously. That is, depending on the priority of the program, a related event (secondary event) may occur with a time difference from the event that is the true cause. Also, an event may propagate from a device that has become a cause on the network 6 to another device on the network 6 via the network 6, in which case a time difference is likely to occur. Even in these cases, grouping can be performed by providing a range for the occurrence time.
[0069] [Embodiment 2] Other embodiments of the present invention will be described below. For ease of explanation, the same reference numerals are given to members having the same functions as those described in the above embodiment, and the description thereof will not be repeated.
[0070] 7 is a block diagram showing the configuration of a main part of an information processing system 100a according to embodiment 2. The information processing system 100a includes a PLC 2, a slave A 3, a slave B 4, and a network 6. The second embodiment differs from the first embodiment in that the device that identifies the cause event is the PLC 2, not the PC 1.
[0071] The PLC 2 includes a control unit 10 and a storage unit 20a. Unlike the storage unit 20, the storage unit 20a further includes a log 2a that stores events that occur in the PLC 2.
[0072] In the second embodiment, unlike the first embodiment, the process of identifying a cause event can be performed only by the PLC, without using the PC 1. Therefore, using the network 6, each time an abnormality occurs on the network 6, a log group L1 can be constructed, and a cause log L3 can be constructed and saved.
[0073] The advantage of this is that when the logs of devices on network 6, such as PLC2, slave A3, and slave B4, are saved in temporary memory, processing can be performed before the temporary memory is overwritten with other data. In other words, when an event occurs, processing can be performed to identify the cause event in real time or at a slightly delayed time interval, making it less likely that a cause event will be overlooked. Therefore, even in a situation where there is no tool on a PC, the cause of multiple events that have occurred can be easily identified, making it easier to take measures.
[0074] [Embodiment 3] Other embodiments of the present invention will be described below. For ease of explanation, the same reference numerals are given to members having the same functions as those described in the above embodiment, and the description thereof will not be repeated.
[0075] 8 is a block diagram showing the configuration of the main parts of an information processing system 100b according to a third embodiment. The information processing system 100b includes a PLC 2, a slave A3, a slave B4, a network 6, a module A7, a module B8, and a lower network 9. The third embodiment differs from the first embodiment in that the device that identifies the cause event is the slave A3, not the PC 1. The slave A3 operates as the master of the lower network 9. In other words, the third embodiment differs from the first embodiment in that the network configuration is nested.
[0076] The lower network 9 may be a field network or a bus communication, etc. An example of a slave serving as a master according to the third embodiment is a communication coupler compatible with the communication standard of the field network.
[0077] The slave A3 includes a control unit 10 and a storage unit 20b. The storage unit 20b differs from the storage unit 20 in that it further includes a log 3a, that the event correlation information 22 becomes event correlation information 22b, and that the network configuration 23 becomes a network configuration 23b. The event correlation information 22b includes an identification information priority list 221b and a configuration information priority setting 222b, which differ from the identification information priority list 221 and the configuration information priority setting 222 in the first embodiment.
[0078] Module A7 and module B8 each have a log 7a and a log 8a that store events that have occurred in the own device. These logs 7a and 8a are communicated to slave A3 via a lower network 9. Module A7 and module B8 are, for example, a slave unit of a field network or a module that complies with a communication coupler standard.
[0079] 9 is a diagram showing an example of event correlation information 22b according to embodiment 3. Unlike embodiment 1, in embodiment 3, the event correlation information 22b includes an attached priority list 223b (identification information priority setting) and an attached priority setting (configuration information priority setting) 224b in addition to an identification information priority list 221b and a configuration information priority setting 222b.
[0080] The auxiliary priority list 223b defines an order for identifying a causal event on the lower network 9. In other words, by identifying a causal event from events occurring in modules constituting the lower network on the lower network 9, it becomes possible to identify a more detailed cause and location of the event.
[0081] The auxiliary priority setting 224b is a user setting that defines the order in which an event occurring in a module is identified as a causal event among a plurality of events occurring in the lower network 9. Specifically, for example, there is a "leading module," which indicates a slave itself (for example, slave A3) equipped with a communication function that becomes the master of the lower network.
[0082] The network configuration 23b includes the configuration of the lower network 9 in addition to the configuration of the network 6. The attached priority list 223b is set by the network configuration 23b and the attached priority setting 224b.
[0083] In the third embodiment, unlike the first embodiment, the information processing system 100b (which may not include the PLC 2) configured only with slaves can also perform the process by itself. Therefore, the lower network 9 can be used to periodically construct the log group L1 and to construct and store the cause log L3.
[0084] The advantage of this is that when logs of devices on the lower network 9, such as slave A3, module A7, and module B8, are saved in the temporary memory, processing can be performed before the temporary memory is overwritten with other data. In other words, when an event occurs, processing can be performed to identify the cause event in real time or at a slightly delayed time interval, making it difficult for cause events to be overlooked. Therefore, even in a situation where there is no tool on a PC, the cause of multiple events that have occurred can be easily identified, making it easy to take measures.
[0085] Furthermore, by identifying the cause log on a slave-by-slave basis on the network 6, the processing in the upper device (eg, PLC2 or PC1) is reduced, improving the processing efficiency for identifying the cause event in the entire information processing system.
[0086] [Software implementation example] The functions of the information processing devices (hereinafter referred to as "devices"), namely PC1, PLC2, and slave A3, can be realized by a program for causing a computer to function as the device, and a program for causing a computer to function as each control block of the device (particularly each part included in the control unit 10).
[0087] In this case, the device includes a computer having at least one control device (e.g., a processor) and at least one storage device (e.g., a memory) as hardware for executing the program. The control device and storage device execute the program to realize each function described in each of the above embodiments.
[0088] The program may be non-transitory and may be recorded in one or more computer-readable recording media. The recording media may or may not be included in the device. In the latter case, the program may be provided to the device via any wired or wireless transmission medium.
[0089] In addition, some or all of the functions of each of the control blocks can be realized by a logic circuit. For example, an integrated circuit in which a logic circuit that functions as each of the control blocks is formed is also included in the scope of the present invention. In addition, the functions of each of the control blocks can be realized by, for example, a quantum computer.
[0090] Furthermore, each process described in each of the above embodiments may be executed by AI (Artificial Intelligence). In this case, the AI may be executed by the control device or another device (for example, an edge computer or a cloud server).
[0091] [Additional Notes] The present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. [Explanation of symbols]
[0092] 1 PC (information processing device) 2 PLC (information processing device) 3 Slave A (slave device) 4 Slave B (slave device) 5. Means of communication 6 Network 7 Module A 8 Module B 9 Subnetwork 10 Control section 11 Log acquisition section 12 Grouping Processing Unit 13 Specific section 14 Output section 15 Setting section 20, 20a, 20b storage section 22, 22b Event correlation information 23, 23b Network Configuration 100, 100a, 100b Information Processing Systems 221, 221b Identification information priority list (identification information priority setting) 222, 222b Configuration information priority setting 223b Attachment Priority List (Identification Information Priority Setting) 224b Attachment Priority Setting (Configuration Information Priority Setting) 2a, 3a, 4a, 7a, 8a Logs L1 Log Group L2 related events L3 Factor Log
Claims
1. An information processing device connected to a network to which a plurality of devices are connected, a log acquisition unit that acquires a log that records events of information processing performed in at least one of the device itself and another device connected to the device via the network; a grouping processing unit that groups the plurality of events recorded in the log into related event groups based on a predetermined criterion; an identification unit that identifies a causal event that is a cause of occurrence of the related event group from the related event group; an output unit that outputs the cause event identified by the identification unit, the identification unit identifies the causal event by using event correlation information indicating information for identifying the causal event for each type of event; The event correlation information includes, as information for identifying the causal event, information regarding a causal priority of a device in which the event occurs for each type of event.
2. The information processing apparatus according to claim 1 , wherein the information regarding the factor priority is set by a configuration information priority setting that indicates the order of the factor priority by a position in configuration information that indicates a network connection relationship of the apparatus.
3. The information processing apparatus according to claim 1 , wherein the information regarding the factor priority levels is set by an identification information priority level setting that indicates an order of the factor priority levels by information for identifying the apparatus.
4. The information processing apparatus according to claim 1 , wherein the grouping processing unit performs grouping based on an occurrence time of the event.
5. The information processing apparatus according to claim 1 , further comprising a setting unit that reads configuration information indicating a connection relationship of the network and sets the event correlation information.
6. The information processing device according to claim 1 , wherein the information processing device is a programmable logic controller (PLC), and collects the logs from slave devices connected to the PLC.
7. The information processing apparatus according to claim 1 , wherein the information processing apparatus is a slave device controlled by a PLC (Programmable Logic Controller), and collects the logs from lower level devices connected to the slave device.
8. The information processing apparatus according to claim 1 , wherein the information processing apparatus is a personal computer (PC) connected to a programmable logic controller (PLC), and acquires the log from the PLC.
9. An information processing method of an information processing device connected to a network to which a plurality of devices are connected, comprising: a log acquisition step of acquiring a log that records an event of information processing performed in at least one of the device itself and another device connected to the device itself via the network; a grouping process step of grouping the plurality of events recorded in the log into related event groups based on a predetermined criterion; a step of identifying a causal event that is a cause of occurrence of the related event group from the related event group; an output step of outputting the cause event identified by the identification step, the identifying step includes identifying the causal event by using event correlation information indicating information for identifying the causal event for each type of event; The information processing method of an information processing device, wherein the event correlation information includes, as information for identifying the causal event, information regarding a causal priority of a device in which the event occurred for each type of event.
10. 2. An information processing program for causing a computer to function as the information processing device according to claim 1, the information processing program causing a computer to function as the log acquisition unit, the grouping processing unit, the identification unit and the output unit.
Citation Information
Patent Citations
Information processing apparatus, information processing program, and information processing method
JP2018124697A
Methods, apparatus and articles of manufacture to perform root cause analysis for network events
US20130185591A1
Management server and management system
WO2010137063A1
Computer program and management computer
WO2013125037A1