Operation Log Processing Device, Operation Log Processing Method, and Operation Log Processing Program
The operation log processing device efficiently separates rollback operations from standard operations in process mining, improving analysis efficiency by identifying and removing rollback logs, thus clarifying standard operation flows.
Patent Information
- Application Number
- JP2023576470
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-01-26
AI Technical Summary
In process mining, distinguishing rollback operations from standard operations is time-consuming due to their mixing and visualization, hindering efficient analysis of standard operation flows.
An operation log processing device that includes a reception unit, detection unit, and display unit to identify and remove rollback operations from the operation log, creating visual information that separates rollback operations from other operations.
Facilitates easier distinction and removal of rollback operations, enhancing the efficiency of process mining by clarifying standard operation flows.
Smart Images

Figure 0007697538000001 
Figure 0007697538000002 
Figure 0007697538000003
Abstract
Description
Technical Field
[0001] The present invention relates to an operation log processing device, an operation log processing method, and an operation log processing program.
Background Art
[0002] Conventionally, in order to improve operations using a PC, there is a process mining technology that acquires operation logs on the PC and analyzes the flow (process) of business operations.
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, if the operation log is directly subjected to process mining, the rollback due to operation errors and the like will also be analyzed as it is. In this process mining, when it is desired to clarify the standard operation flow, for example, the rollback due to operation errors is not an element to be focused on in the analysis and thus needs to be distinguished, but there is a problem that it is time-consuming to proceed with the analysis because the part to be focused on and the rollback operations are mixed and visualized. Therefore, an object of the present invention is to solve the above-described problems and make it easier to distinguish rollback operations from other operations in process mining.
Means for Solving the Problems
[0005] To solve the above problems, the present invention includes a reception unit that receives an input of an operation log indicating a series of operations to a computer, a detection unit that detects an operation log of a rollback operation from the operation log indicating the series of operations, and a display that identifies the operation log of the detected rollback operation from the operation log indicating the series of operations, or an information creation unit that creates information visualizing the process of the series of operations by removing the operation log of the rollback operation.
Effect of the Invention
[0006] According to the present invention, it becomes easier to distinguish a rollback operation from other operations in process mining.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Mode for Carrying Out the Invention
[0008] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. The present invention is not limited to the embodiments described below.
[0009] First, the outline of the operation log processing apparatus according to the present embodiment will be described with reference to FIGS. 1 to 3. The operation log processing apparatus receives, for example, as shown in FIG. 1, an input of an operation log indicating a series of operations on a computer. This operation log is information that describes, for example, the operation date and time, the operation page, the operation position, etc. in a series of operations (see FIG. 2) performed by a user of the computer on a web page.
[0010] The operation log processing apparatus performs process mining on the input operation log and creates a flowchart showing the operation procedure of the computer.
[0011] The flowchart is, for example, as shown in FIG. 1, a visualization of a series of operations indicated by the operation log using a directed graph with nodes and edges. The operation log processing apparatus performs process mining on the input operation log, for example, aggregates nodes of the same operation and also aggregates edges between the same nodes to create the flowchart shown in FIG. 1.
[0012] Here, when the operation log includes an undo operation, the undo operation also becomes an object of process mining and becomes an obstacle when performing process mining. The undo operation is, for example, an operation to the same operation position within the same page among a series of operations on the computer (see FIG. 2).
[0013] The operation log processing device detects a backward operation. For example, after dividing the operation log into pages, it detects duplicate operations (= backward operations) within a page. Then, the operation log processing device makes the detected backward operations explicit or removes them.
[0014] For example, as shown in FIG. 3, after dividing the operation log into pages, the operation log processing device detects duplicate operations (= backward operations) within a page. Then, after making the detected backward operations explicit or removing them from each page, the operation log processing device recombines them and performs process mining analysis or the like.
[0015] As a result, the operation log processing device can obtain an analysis result in which the backward operation is made explicit or removed (for example, the flowchart shown in the upper right of FIG. 3). As a result, the user can efficiently analyze a series of operations on the computer.
[0016] [Configuration Example] Next, a configuration example of the operation log processing device 10 will be described with reference to FIG. 4. The operation log processing device 10 is realized by a general-purpose computer such as a PC, for example. As illustrated in FIG. 4, the operation log processing device 10 includes a communication processing unit 11, an input unit 12, an output unit 13, a control unit 14, and a storage unit 15.
[0017] The communication processing unit 11 is realized by a NIC (Network Interface Card) or the like, and controls communication between the control unit 14 and an external device via a telecommunication line such as a LAN (Local Area Network) or the Internet. For example, the communication processing unit 11 receives an operation log to be processed from an external device.
[0018] The input unit 12 is an input interface for receiving data input from an input device such as a keyboard or a mouse. The output unit 13 is an output interface for outputting data to a display device such as a liquid crystal display.
[0019] The storage unit 15 stores data and programs necessary for various processes by the control unit 14. The storage unit 15 stores, for example, an operation log input via the input unit 12. The storage unit 15 is realized by, for example, a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk.
[0020] Here, with reference to FIG. 5, the original data of the operation log will be described. In the example of FIG. 5, an operation log recording operations on a web browser is shown. The original data of the operation log includes, for example, as shown in FIG. 5, the date and time when the operation was performed, the window handle, URL, window title, tagName, type, id, and name of the window of the operation target, and the input value input by the operation.
[0021] The control unit 14 determines the identity of each operation for the original data of the operation log, and assigns an operation ID for identifying each operation to the operations determined to be the same operation (see FIG. 6). When the control unit 14 visualizes the series of operations shown in the operation log shown in FIG. 6 in a graph, it becomes as shown by reference numeral 601.
[0022] Further, the control unit 14 determines the identity of the operation page for the operation log shown in FIG. 6, for example, and assigns a page ID for identifying the same page (see FIG. 7). Then, the control unit 14 stores the operation log with the operation ID and the page ID assigned in the storage unit 15.
[0023] The control unit 14 has an internal memory for storing programs that define various processing procedures and required data, and executes various processes based on these. For example, the control unit 14 includes a reception unit 14a, a detection unit 14b, an information creation unit 14c, and an output processing unit 14d. Here, the control unit 14 is an electronic circuit such as a CPU (Central Processing Unit) or MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0024] The reception unit 14a receives the input of an operation log indicating a series of operations on the computer. The detection unit 14b detects, from the above operation log, the operation log of the rollback operation, which is the operation log at the same operation position on the same page.
[0025] For example, as shown in FIG. 8, when the detection unit 14b detects an operation log at the same operation position on the same page (= the operation log of the rollback operation) in the operation log indicating a series of operations on the computer, it sets a duplicate flag (true) for that operation log.
[0026] Note that, as shown in FIG. 8, the detection unit 14b may regard the first operation among the duplicate operations as the main operation and set a duplicate flag (true) for the operation logs of the remaining operations, or regard the last operation among the duplicate operations as the main operation and set a duplicate flag (true) for the operation logs of the remaining operations.
[0027] Returning to the description of FIG. 4. The information creation unit 14c explicitly indicates or removes the operation log of the rollback operation detected by the detection unit 14b from the operation logs received by the reception unit 14a, and creates information visualizing the process of a series of operations on the computer.
[0028] For example, among the operation logs received by the reception unit 14a, the information creation unit 14c creates information that visualizes the process of a series of operations after performing a display that discriminates the operation log of the rollback operation detected by the detection unit 14b from other operation logs, or a process of removing the operation log of the rollback operation.
[0029] For example, a case will be described where the information creation unit 14c creates information that visualizes the process of a series of operations shown in the operation log shown in FIG. 9. The rollback operation is an operation with the operation ID "G".
[0030] Here, when the information creation unit 14c makes the operation log of the rollback operation explicit, as shown by reference numeral 901 in FIG. 9, a graph that visualizes a series of operations (A→B→C→D...) is created based on the date and time information of the operation log. At this time, the information creation unit 14c expresses the edge connected to the node of the operation "G" detected as the rollback operation in a manner different from a normal edge (for example, the dashed arrow shown in FIG. 9). Also, the information creation unit 14c connects the edge (H→I) that bypasses the node of the operation "G" with a normal edge.
[0031] By the information creation unit 14c creating a graph that visualizes a series of operations shown in the operation log as described above, it becomes easier for the user to find out which operation among the series of operations is the rollback operation. As a result, it becomes easier for the user to delete the nodes and edges of the rollback operation as needed.
[0032] Also, when the information creation unit 14c deletes the operation log of the rollback operation, the operation log of the rollback operation is deleted from the operation log shown in FIG. 9 (see reference numeral 101 in FIG. 10). Then, the information creation unit 14c creates a graph that visualizes a series of operations (A→B→C→D...) based on the date and time information of the operation log after deleting the operation log of the rollback operation (see reference numeral 102 in FIG. 10).
[0033] In addition, the information creation unit 14c may create a graph that aggregates the processes of a plurality of operations by aggregating the same nodes and aggregating the edges between the same nodes for each graph that visualizes the process of a series of operations.
[0034] First, a case where the information creation unit 14c aggregates the graphs of the processes of a plurality of operations including a backward operation will be described. Here, a case where the information creation unit 14c aggregates the graphs of the processes of three operations including a backward operation (see reference numeral 111 in FIG. 11) will be described as an example.
[0035] The rules for aggregating the graphs of the operation processes are as follows. · When there are a special edge (an edge related to the backward operation) and a normal edge on the path between the same nodes, the information creation unit 14c deletes the special edge. · When only a special edge exists on the path between the same nodes, the information creation unit 14c leaves that special edge. · When there are multiple normal edges on the path between the same nodes, the information creation unit 14c aggregates the multiple normal edges into one normal edge. At this time, the information creation unit 14c may thicken the edge according to the number of aggregated normal edges. In addition to thickening the edge, the information creation unit 14c may use another expression such as changing the color according to the number of aggregated normal edges. · When there are multiple special edges on the path between the same nodes, the information creation unit 14c aggregates the multiple special edges into one special edge. At this time, the information creation unit 14c does not thicken the special edge according to the number of aggregated special edges. However, the special edge may be thickened as necessary. In addition to thickening the edge, the information creation unit 14c may use another expression such as changing the color according to the number of aggregated special edges.
[0036] Based on the above rules, the information creation unit 14c aggregates the nodes of the graph of the processes of the three operations shown by reference numeral 111 in FIG. 11, and creates a graph shown by reference numeral 112. Thereafter, the information creation unit 14c aggregates the edges of the graph shown by reference numeral 112, and creates a graph shown by reference numeral 113.
[0037] In this way, when aggregating the processes of a plurality of operations, if there are a plurality of edges indicating normal operations between the same nodes, the information creation unit 14c changes the display of the edges indicating normal operations between the same nodes according to the number of edges. Here, when there are a plurality of edges indicating a rollback operation between the same nodes, the information creation unit 14c changes the display of the edges according to a rule different from the rule for changing the display of the edges indicating the above normal operations.
[0038] By doing so, the information creation unit 14c can aggregate the graphs of the processes of a plurality of operations after distinguishing the edges related to the rollback operation.
[0039] When the information creation unit 14c aggregates the graphs of the processes of a plurality of operations for which the rollback operation has been deleted (see reference numeral 121 in FIG. 12), node aggregation (see reference numeral 122) and edge aggregation (see reference numeral 123) are performed in the same manner as in the prior art.
[0040] Returning to the description of FIG. 4. The output processing unit 14d outputs the information created by the information creation unit 14c via the output unit 13.
[0041] For example, when the information creation unit 14c creates information (see reference numeral 113 in FIG. 11) that explicitly indicates a rollback operation for a series of operations on a computer, the output processing unit 14d outputs the information. Also, for example, when the information creation unit 14c creates information (see reference numeral 123 in FIG. 11) in which the rollback operation has been deleted for a series of operations on a computer, the output processing unit 14d outputs the information.
[0042] According to such an operation log processing device 10, when creating information that visualizes the process of a series of operations, it is possible to create information in which the rollback operation is explicit or removed (for example, the graph shown by reference numeral 113 in FIG. 11 or the graph shown by reference numeral 123 in FIG. 12). As a result, the user can efficiently perform process mining of a series of operations on the computer.
[0043] [Example of processing procedure] Next, an example of the processing procedure executed by the operation log processing device 10 will be described with reference to FIG. 13. First, the reception unit 14a of the operation log processing device 10 receives an input of an operation log to be processed (S1). After that, the detection unit 14b detects an operation log of a rollback operation, which is an operation log to the same operation position, from the operation log received in S1 (S2).
[0044] Next, the information creation unit 14c creates information that visualizes the process of a series of operations by explicitly or removing the operation log of the rollback operation detected in S2 from the operation log received in S1 (S3). After that, the output processing unit 14d outputs the information created in S3 (S4).
[0045] [Other embodiments] Note that when the operation log processing device 10 deletes an operation log of the same operation position on the same page (log of a rollback operation) from an operation log showing a series of operations on a computer shown in FIG. 8, for example, among the operation logs of duplicate operations, the operation log that is the last in chronological order may be inserted at the position of the first operation log, and the other operation logs may be deleted.
[0046] For example, the operation log processing device 10 inserts the operation log of operation ID "G" in the 9th row of the operation log shown in FIG. 8 at the position of the operation log of operation ID "G" in the 7th row, and deletes the operation log of operation ID "G" that was previously in the 7th row. Then, the operation log processing device 10 creates information that visualizes the process of a series of operations for the operation log after deletion.
[0047] [System configuration, etc.] In addition, each component of each part shown in the figures is functionally conceptual and does not necessarily have to be physically configured as shown in the figures. That is, the specific form of the distribution and integration of each device is not limited to that shown in the figures, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU and a program executed by the CPU, or can be realized as hardware by wired logic.
[0048] Also, among the processes described in the above-described embodiments, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified.
[0049] [Program] The above-described operation log processing device 10 can be implemented by installing a program (operation log processing program) as package software or online software on a desired computer. For example, by causing the information processing device to execute the above program, the information processing device can function as the operation log processing device 10. The information processing device mentioned here includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further includes terminals such as PDAs (Personal Digital Assistants).
[0050] FIG. 14 is a diagram showing an example of a computer that executes an operation log processing program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0051] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0052] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the program that defines each process executed by the operation log processing device 10 described above is implemented as a program module 1093 in which computer-executable code is described. The program module 1093 is stored in the hard disk drive 1090, for example. For example, a program module 1093 for executing the same process as the functional configuration in the operation log processing device 10 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0053] Also, the data used in the processing of the above-described embodiments is stored, as program data 1094, in, for example, the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out and executes the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed.
[0054] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (such as a LAN (Local Area Network) or a WAN (Wide Area Network)). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from the other computer via the network interface 1070.
Explanation of Reference Numerals
[0055] 10 Operation Log Processing Device 11 Communication Processing Unit 12 Input Unit 13 Output Unit 14 Control Unit 14a Reception Unit 14b Detection Unit 14c Information Creation Unit 14d Output Processing Unit 15 Storage Unit
Claims
1. a receiving unit that receives an input of an operation log indicating a series of operations to a computer; a detection unit that detects an operation log of a rollback operation from the operation log indicating the series of operations; an information creation unit that creates a graph representing the process of the series of operations with nodes and edges from the operation log indicating the series of operations, and creates a graph in which the processes of a plurality of operations are aggregated by performing aggregation of the same nodes and aggregation of the edges between the same nodes for each of the created graphs; the information creation unit: when aggregating the edges between the same nodes, if there is only an edge corresponding to the operation log of the rollback operation between the same nodes, the edge is left; if there is an edge corresponding to the operation log of the rollback operation and an edge indicating a normal operation between the same nodes, the edge corresponding to the operation log of the rollback operation is deleted An operation log processing apparatus characterized by the above.
2. the information creation unit: when aggregating the processes of the plurality of operations, if there are a plurality of edges indicating normal operations between the same nodes, the display of the edges indicating normal operations between the same nodes is changed according to the number of the edges; if there are a plurality of edges indicating rollback operations between the same nodes, the edges indicating rollback operations between the same nodes are displayed according to a rule different from the rule for changing the display of the edges indicating normal operations The operation log processing apparatus according to claim 1, characterized by the above.
3. An operation log processing method executed by an operation log processing apparatus, the method including: a step of receiving an input of an operation log indicating a series of operations to a computer; a step of detecting an operation log of a rollback operation from the operation log indicating the series of operations; a step of creating a graph representing the process of the series of operations with nodes and edges from the operation log indicating the series of operations, and creating a graph in which the processes of a plurality of operations are aggregated by performing aggregation of the same nodes and aggregation of the edges between the same nodes for each of the created graphs In the step of creating a graph that aggregates the processes of the plurality of operations, when aggregating the edges between the same nodes, if there is only an edge corresponding to the operation log of the rollback operation between the same nodes, the edge is left; if there is an edge corresponding to the operation log of the rollback operation and an edge indicating a normal operation between the same nodes, the edge corresponding to the operation log of the rollback operation is deleted. An operation log processing method characterized by the above.
4. A step of receiving an input of an operation log indicating a series of operations to a computer; A step of detecting an operation log of a rollback operation from the operation log indicating the series of operations; A step of creating a graph representing the process of the series of operations with nodes and edges from the operation log indicating the series of operations, and creating a graph that aggregates the processes of the plurality of operations by performing aggregation of the same nodes and aggregation of the edges between the same nodes for each of the created graphs. In the step of creating a graph that aggregates the processes of the plurality of operations, when aggregating the edges between the same nodes, if there is only an edge corresponding to the operation log of the rollback operation between the same nodes, the edge is left; if there is an edge corresponding to the operation log of the rollback operation and an edge indicating a normal operation between the same nodes, the edge corresponding to the operation log of the rollback operation is deleted. An operation log processing program for causing a computer to execute the above.
Citation Information
Patent Citations
Work procedure analyzing and assisting system for analyzing project
JP2018147198A