Monitoring device, management device, communication system, and recovery method

The monitoring device's adaptive recovery process determination addresses inefficiencies in existing systems by allowing selective self-determined or operator-commanded recovery, ensuring timely and appropriate equipment recovery without disrupting system operations.

JP7775176B2Active Publication Date: 2025-11-25HITACHI IND EQUIP SYST CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022169337
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2025-11-25
Estimated Expiration
2042-10-21

AI Technical Summary

Technical Problem

Existing systems for remotely monitoring and controlling equipment face inefficiencies in recovery processing, as automatic restarts can cause unexpected system disruptions, while operator-commanded recovery may be too slow for urgent abnormalities.

Method used

A monitoring device that determines the type of recovery process based on predefined conditions, allowing either self-determined or instruction-received recovery, and a management device that communicates with the monitoring device to selectively execute recovery processing.

Benefits of technology

Enables early recovery for urgent abnormalities while avoiding system disruptions by allowing selective execution of recovery processing, ensuring timely and appropriate responses to equipment abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007775176000001
    Figure 0007775176000001
  • Figure 0007775176000002
    Figure 0007775176000002
  • Figure 0007775176000003
    Figure 0007775176000003
Patent Text Reader

Abstract

To change an entity which determines content of restoration processing according to a type of an abnormality generated in a device.SOLUTION: A monitoring device comprises: an abnormality detection unit which monitors one or more devices to be monitoring objects to detect abnormalities generated in the devices; an abnormality notification unit which outputs the detected abnormalities to the outside as abnormality notification; a restoration processing determination unit which determines a restoration type which is the type of restoration to either of self-determination restoration in which the monitoring device determines the content of restoration processing for the devices or instruction reception restoration in which the outside of the monitoring device determines the content of restoration processing for the devices according to abnormality types which are the types of the abnormalities; and a restoration processing execution unit which executes the restoration processing of the devices on the basis of determination of the restoration types by the restoration processing determination unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a monitoring device, a management device, a communication system, and a recovery method. [Background technology]

[0002] In recent years, systems have been developed that remotely monitor and control equipment in factories and other locations by collecting data about the equipment via communication devices and consolidating it in a remote management device. Stable operation of these systems requires the detection of abnormalities in the equipment and rapid recovery. However, an operation model in which an abnormality is confirmed each time by the management device and then a remote command to perform recovery processing is issued by an operator, resulting in a problem of time-consuming recovery. One known solution to this problem is to operate a communication device connected to the equipment as a monitoring device, monitor the equipment for abnormalities, and automatically perform recovery processing, such as restarting the equipment, when an abnormality is detected. This method enables rapid recovery from abnormalities and is particularly effective for highly urgent abnormalities.

[0003] On the other hand, automatic execution of recovery processing by a monitoring device may result in unexpected restarts of equipment, causing inconveniences in system operation. In consideration of such cases, it is desirable to selectively use a form in which the monitoring device automatically executes recovery processing and a form in which recovery processing is executed based on commands from a management device operated by an operator, etc. Patent Document 1 discloses a remote power control system for network devices, including a power supply control device that monitors the status of network devices in real time and, when an abnormality signal is generated due to a failure, automatically resets the network devices based on recovery standard data to restore power, and a management server that generates the recovery standard data and monitors the power supply control device in real time. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2021-72076 Summary of the Invention [Problem to be solved by the invention]

[0005] In the invention described in Patent Document 1, there is room for further consideration regarding the determination of the recovery process. [Means for solving the problem]

[0006] A monitoring device according to a first aspect of the present invention is a monitoring device that monitors one or more devices to be monitored, and includes an abnormality detection unit that detects an abnormality occurring in the device, an abnormality notification unit that outputs the detected abnormality to an external device as an abnormality notification, a recovery process determination unit that determines a recovery type that is a type of recovery depending on an abnormality type that is a type of the abnormality, to either a self-determined recovery that is determined by the monitoring device as a content of a recovery process for the device, or an instruction-received recovery that is determined by an external device of the monitoring device, a recovery process execution unit that executes recovery process for the device based on the recovery type determination by the recovery process determination unit, and a storage device that stores an abnormality definition that is a definition of the abnormality type, whether or not self-determined recovery is possible for each abnormality type, whether the self-determined recovery is possible for each abnormality type, or whether the instruction-received recovery is possible, and a recovery process content that is a content of the recovery process for each abnormality type that is the self-determined recovery. Preparation picture The storage device further stores a first change condition for changing the self-determined recovery in the self-determined recovery possibility to the instruction reception recovery for each of the abnormality types, and when the first change condition is met, the recovery processing determination unit changes the self-determined recovery possibility to the instruction reception recovery. . According to the second aspect of the present invention the recovery process determination unit determines a recovery type depending on the abnormality type to be either a self-determined recovery determined by the monitoring device or an instruction-received recovery determined by a device external to the monitoring device, as a recovery process for the device; a recovery process execution unit executes recovery processing for the device based on the recovery type determined by the recovery process determination unit; and a storage device that stores an abnormality definition that defines the abnormality type, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction-received recovery for each abnormality type, and a recovery process content that is the content of the recovery process for each abnormality type that is the self-determined recovery, wherein a second change condition is further stored in the storage device for changing the instruction-received recovery in the self-determined recovery possibility to the self-determined recovery for each abnormality type, and when the second change condition is met, the recovery process determination unit changes the self-determined recovery possibility to the self-determined recovery. The present invention 3 The communication system according to the aspect is a communication system including a monitoring device that monitors one or more devices to be monitored, and a management device that can communicate with the monitoring device, wherein the monitoring device includes an abnormality detection unit that detects an abnormality occurring in the device, an abnormality notification unit that outputs the detected abnormality to the outside as an abnormality notification; a recovery process determination unit that determines a recovery type that is a type of recovery to either a self-determined recovery that is determined by the monitoring device or an instruction-received recovery that is determined by an external device of the monitoring device according to an abnormality type that is a type of the abnormality; and a recovery process execution unit that executes recovery process of the device based on the determination of the recovery type by the recovery process determination unit, wherein the management device comprises an abnormality notification management unit that receives the abnormality notification output by the monitoring device, and a recovery process command unit that outputs the content of the recovery process determined based on the abnormality notification to the monitoring device. The device further includes a storage device that stores an abnormality definition that is a definition of the abnormality type, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each abnormality type, and a recovery process content that is a content of the recovery process for each abnormality type that is the self-determined recovery, wherein the storage device further stores a first change condition that changes the self-determined recovery in the self-determined recovery possibility to the instruction reception recovery for each abnormality type, and when the first change condition is met, the recovery process determination unit changes the self-determined recovery possibility to the instruction reception recovery. . A communication system according to a fourth aspect of the present invention is a communication system including a monitoring device that monitors one or more devices to be monitored, and a management device that can communicate with the monitoring device, wherein the monitoring device comprises an abnormality detection unit that detects an abnormality that occurs in the device, an abnormality notification unit that outputs the detected abnormality to the outside as an abnormality notification, a recovery process determination unit that determines a recovery type that is a type of recovery depending on the abnormality type that is a type of the abnormality, to be either a self-determined recovery that is determined by the monitoring device or an instruction-received recovery that is determined by an outside of the monitoring device, as the content of the recovery process for the device, and a recovery process execution unit that executes recovery process for the device based on the recovery type determined by the recovery process determination unit, and the management device comprises and a recovery process command unit that outputs the content of the recovery process determined based on the abnormality notification to the monitoring device, and further includes a storage device that stores an abnormality definition that is a definition of the abnormality type, a self-determined recovery possibility that indicates whether the self-determined recovery is the self-determined recovery or the instruction-received recovery for each abnormality type, and a recovery process content that is the content of the recovery process for each abnormality type that is the self-determined recovery, wherein the storage device further stores a second change condition that changes the instruction-received recovery in the self-determined recovery possibility to the self-determined recovery for each abnormality type, and the recovery process determination unit changes the self-determined recovery possibility to the self-determined recovery when the second change condition is met. The present invention 5 The recovery method according to the aspect is a recovery method executed by a monitoring device that monitors one or more devices to be monitored, and includes an abnormality detection step of detecting an abnormality occurring in the device, an abnormality notification step of outputting the detected abnormality as an abnormality notification to the outside, a recovery process determination step of determining a recovery type, which is a type of recovery, to either a self-determined recovery in which the monitoring device determines the content of a recovery process for the device, or an instruction-received recovery in which an external device determines the content of a recovery process for the device, depending on the abnormality type, and a recovery process execution step of executing a recovery process for the device based on the recovery type determined by the recovery process determination step. fruit , The monitoring device further includes a storage device that stores an abnormality definition that is a definition of each of the abnormality types, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each of the abnormality types, and a recovery processing content that is a content of the recovery processing for each of the abnormality types that is the self-determined recovery, and the storage device further stores a first change condition that changes the self-determined recovery in the self-determined recovery possibility to the instruction reception recovery for each of the abnormality types, and in the recovery processing determination step, if the first change condition is met, the self-determined recovery possibility is reinterpreted as the instruction reception recovery. . A recovery method according to a sixth aspect of the present invention is a recovery method executed by a monitoring device that monitors one or more devices to be monitored, and includes: an abnormality detection step of detecting an abnormality occurring in the device; an abnormality notification step of outputting the detected abnormality as an abnormality notification to the outside; a recovery process determination step of determining a recovery type, which is a type of recovery, to either a self-determined recovery in which the monitoring device determines the content of a recovery process for the device, or an instruction-received recovery in which an external device determines the content of a recovery process for the device, depending on the abnormality type; and a recovery process execution step of executing a recovery process for the device based on the recovery type determined in the recovery process determination step. The monitoring device further includes a storage device that stores an abnormality definition, which is a definition of the abnormality type, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction-received recovery for each abnormality type, and a recovery processing content, which is the content of the recovery processing for each abnormality type that is the self-determined recovery, and the storage device further stores a second change condition that changes the instruction-received recovery in the self-determined recovery possibility to the self-determined recovery for each abnormality type, and in the recovery processing determination step, if the second change condition is met, the self-determined recovery possibility is reinterpreted as the self-determined recovery. [Effects of the Invention]

[0007] According to the present invention, the entity that determines the content of the recovery process can be changed depending on the type of abnormality that occurs in the device. [Brief explanation of the drawings]

[0008] [Figure 1] Overall configuration of the communication system [Figure 2] FIG. 10 is a diagram showing an example of an abnormality definition table in the first embodiment. [Figure 3] FIG. 10 is a diagram showing an example of a recovery process table according to the first embodiment; [Figure 4] Figure 4 shows the time chart when self-determined recovery is allowed. [Figure 5] Figure 5 shows the time chart when self-determined recovery is prohibited. [Figure 6] 10 is a flowchart showing the process of the recovery process determination unit in the first embodiment. [Figure 7] FIG. 10 is a diagram showing an example of a screen display for registering an abnormality definition table and a recovery process table. [Figure 8] Figure 10 shows an example of a screen display that outputs an abnormality notification and an example of a screen display that accepts a recovery processing command. [Figure 9] FIG. 10 is a diagram showing an example of an abnormality definition table in the second embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of a recovery process table according to the second embodiment. [Figure 11] 10 is a flowchart showing the process of the recovery process determination unit in the second embodiment. [Figure 12] FIG. 13 is a diagram showing an example of an abnormality definition table according to the third embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a recovery process table according to the third embodiment. [Figure 14] 10 is a flowchart showing the process of the recovery process determination unit in the third embodiment. [Figure 15] FIG. 20 is a diagram showing an example of a recovery process table according to the fourth embodiment; [Figure 16]10 is a flowchart showing the process of the recovery process determination unit in the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] (Summary of the Invention) A monitoring device connected to a monitored device stores, as tables, a list of abnormality detection conditions for each type of abnormality in the device, a list of message contents to be sent to the management device when an abnormality is detected, a list of recovery actions to be taken for each type of abnormality, and a list of whether the recovery action can be automatically executed at the device's discretion. Based on the tables, the monitoring device uses its abnormality detection unit to monitor and detect abnormalities in the device, and when an abnormality is detected, its abnormality notification unit sends an abnormality notification containing the message to the management device. The monitoring device's recovery action determination unit then determines the recovery action to be taken for the abnormality and whether the recovery action can be automatically executed at the device's discretion (hereinafter referred to as "self-determined recovery"). If self-determined recovery is permitted, the monitoring device executes the recovery action at its recovery action execution unit, achieving early recovery. On the other hand, if self-determined recovery is not permitted for the detected abnormality type, the monitoring device waits for a recovery action command from the management device.

[0010] When the management device receives the abnormality notification sent by the monitoring device, it outputs the abnormality notification on a screen and presents it to the worker. When the worker confirms this output and issues a recovery processing command to the monitoring device, the recovery processing command unit transmits the recovery processing command to the monitoring device. Upon receiving this recovery processing command, the monitoring device executes the specified recovery processing on the equipment, thereby realizing recovery from the equipment abnormality.

[0011] In this way, by selectively executing recovery processing either automatically by the monitoring device or based on an instruction from the management device depending on the type of abnormality, it is possible to achieve both early recovery and recovery at an appropriate timing that does not interfere with system operation. For example, for a highly urgent abnormality that requires early recovery, the recovery processing management unit of the monitoring device can permit self-determined recovery, giving priority to early recovery. On the other hand, for a less urgent abnormality, self-determined recovery can be prohibited, and recovery processing can be performed only when an instruction from the management device is received, and recovery processing can be performed only when instructed by an operator. This ultimately makes it possible to perform recovery processing at an appropriate timing that does not interfere with system operation.

[0012] Each embodiment will be described below with reference to the drawings. Note that each embodiment described below does not limit the invention according to the claims, and not all of the elements and combinations described in the embodiments are necessarily essential to the solution of the invention. In the following description, information may be described using the expression [AAA table], but the information may be expressed in any data structure. In other words, to indicate that the information is independent of the data structure, [AAA table] can be expressed as [AAA information].

[0013] -First embodiment- A first embodiment of a communication system will be described below with reference to Figures 1 to 8. First, the overall configuration of the communication system and the configurations of the devices, monitoring device, and management device that make up the communication system will be described with reference to Figure 1. Next, tables stored in the monitoring device will be described with reference to Figures 2 and 3. After that, the flow of recovery processing performed by the monitoring device and management device will be described with reference to Figures 4 to 6, and examples of screen displays related to table input in the monitoring device, and abnormality notification output and recovery processing command input in the management device will be described with reference to Figures 7 and 8.

[0014] 1 is a diagram showing the overall configuration of a communication system. The communication system is configured to include one or more devices 101 (101-a to 101-b) to be managed, monitoring devices 102 (102-a to 102-b), and a management device 103. In the following description, when devices 101-a to 101-b and monitoring devices 102-a to 102-b are not individually specified, the reference numerals "101" and "102" are used, with the parts after "-" omitted.

[0015] The device 101 and the monitoring device 102, and the monitoring device 102 and the management device 103 are connected via either wired communication or wireless communication, or both, and the device 101 transmits log information and the like that records its own operation information to the monitoring device 102. The monitoring device 102 then transmits the log information and the like to the management device 103, which allows the management device 103 to provide a remote monitoring service for the device 101. Similarly, when remotely controlling the device 101 from the management device 103, the remote control is realized by transmitting a control command from the management device 103 to the device 101 via the monitoring device 102.

[0016] Furthermore, the monitoring device 102 not only relays communications between the device 101 and the management device 103, but also monitors and detects abnormalities that occur in the device 101. When an abnormality is detected, the monitoring device 102 sends an abnormality notification to the management device 103, and executes recovery processing for the detected abnormality, either automatically at the discretion of the monitoring device 102 or based on a command received from the management device 103. An operator at the management device 103 views the abnormality notification sent by the monitoring device 102 and makes a judgment, and the management device 103 appropriately sends a recovery processing command to the monitoring device 102 to achieve recovery from the abnormality.

[0017] The management device 103 may be installed in the same room or on the same premises as the devices 101 and monitoring device 102, or may be installed at a different location such as on the cloud. Also, while Fig. 1 illustrates a configuration in which one device 101 is connected to one monitoring device 102, multiple devices 101 may be connected to one monitoring device 102, or one device 101 may be connected to multiple monitoring devices 102.

[0018] The hardware configuration of the device 101 will be described. The device 101 is a hardware device that operates on-site, such as a factory, and has a communication function with the monitoring device 102. The device 101 stores data acquired from the site, such as video data and temperature data, as well as its own log information, in packets and transmits them to the monitoring device 102. The device 101 has various configurations depending on the data it acquires and its role. For example, the device 101 may be a surveillance camera that monitors on-site video, or an air compressor that compresses gas on-site. The device 101 may be an independent device or a relatively small device that is incorporated into another device. Furthermore, as described above, the device 101 has various configurations depending on the type of on-site data it acquires, and may also include, for example, a camera module, a temperature sensor, or an acceleration sensor.

[0019] The device 101 includes a communication I / F 111, which is a communication interface (hereinafter referred to as "I / F"), a CPU 112, an input unit 113, an output unit 114, and a storage device 115. When transmitting and receiving packets to and from the monitoring device 102 via wireless communication, for example, the communication I / F 111 includes a transmitter that converts digital signals to wireless signals and vice versa, converts the generated digital data into wireless signals, and transmits them, and a receiver that extracts digital data from received wireless signals. The communication I / F 111 can use any communication method, such as wireless communication such as 4G or 5G, IEEE802.3, wireless LAN, or optical fiber line. The device 101 may also be equipped with multiple communication I / Fs 111 depending on the application. For example, the device 101 may have multiple communication I / Fs 111 in preparation for communication disconnection. The CPU 112 executes various computer programs stored in the storage device 115, thereby realizing various functions of the device 101.

[0020] The input unit 113 includes, for example, a keyboard, a mouse, or a touch sensor. The input unit 113 is used by an operator to input various operations and settings. The output unit 114 includes, for example, a liquid crystal display. The output unit 114 is used to display and present setting screens and the results of various processes to the operator. However, when the device 101 receives input information from an external device or provides output information to an external device via the communication I / F 111, such as when remotely logging in to the device 101 from another external device, the device 101 does not need to include the input unit 113 and the output unit 114. Alternatively, the input unit 113 and the output unit 114 may be integrated into one device. The storage device 115 includes, for example, a read-only semiconductor memory or a rewritable semiconductor memory element. The storage device 115 stores computer programs that implement various processes, acquired data, and the like.

[0021] The application program 116 issues instructions to acquire data and determines the timing of transmission. The application program 116 instructs the CPU 112 connected via an internal bus to acquire data, and instructs the communication processing unit 117 to transmit the acquired data at a predetermined timing. For example, the application program 116 manages the acquisition method of log information to be transmitted to the monitoring device 102 and the transmission schedule of the log information. The application program 116 can also function as a log information management unit that collects log information and transmits the log information to the monitoring device 102 at a predetermined timing. The communication processing unit 117 realizes the transmission and reception processing with the monitoring device 102. Specifically, the communication processing unit 117 performs packet assembly processing when transmitting, and packet analysis processing, including determining whether a packet is addressed to the device itself when receiving.

[0022] The hardware configuration of the monitoring device 102 will be described. The monitoring device 102 transmits data and log information acquired from the connected device 101 to the management device 103. The monitoring device 102 also monitors whether there is an abnormality in the device 101, and executes recovery processing based on its own judgment or in response to an instruction from the management device 103. The monitoring device 102 has a communication function with the device 101 and the management device 103. The monitoring device 102 may be an independent device, or may be a relatively small device incorporated into another device. When acquiring on-site data, the monitoring device 102 may also be configured to include a camera module, temperature sensor, acceleration sensor, etc.

[0023] The monitoring device 102 includes a communication I / F 121, a CPU 122, an input unit 123, an output unit 124, a storage device 125, and a communication processing unit 127, and each component has the same configuration and function as the component with the same name in the device 101. When receiving input information from an external device or providing output information to an external device via the communication I / F 121, the monitoring device 102 does not need to include the input unit 123 or the output unit 124.

[0024] The application program 126 processes data collected from the device 101 and adjusts the transmission timing. The application program 126 instructs the CPU 122 connected via an internal bus to process the data, and instructs the communication processing unit 127 to transmit the data. Note that in cases where the data and log information received from the device 101 are immediately transferred to the management device 103 without processing, the monitoring device 102 does not need to have the application program 126.

[0025] The abnormality detection unit 128 diagnoses the device 101 and detects an abnormality. The abnormality detection unit 128 detects an abnormality by a method preset in the abnormality definition table 132, such as sending a live / dead confirmation packet to the device 101 or judging an input signal from the device 101. The abnormality notification unit 129 notifies the management device 103 of the abnormality detected by the abnormality detection unit 128 as an abnormality notification. Specifically, the abnormality notification unit 129 outputs the notification content to the communication processing unit 127 and executes a transmission process.

[0026] The recovery process determining unit 130 determines whether recovery process for an abnormality detected by the abnormality detection unit 128 can be automatically executed at the discretion of the device itself, i.e., whether self-determined recovery is possible. Specifically, the recovery process determining unit 130 determines whether recovery should be performed at the discretion of the device itself, i.e., the monitoring device 102, without waiting for an instruction from the management device 103, or whether recovery should be performed based on an instruction from the management device 103. However, the possibility of self-determined recovery does not refer to the difficulty of self-determined recovery due to physical constraints or technical problems, but rather to a determination of whether self-determined recovery is permitted under a pre-determined situation setting. Details of this determination will be described later with reference to FIG. 6.

[0027] In this embodiment, the recovery that executes recovery processing instructed by the management device 103, which is the counterpart concept of self-determined recovery, is called "command-received recovery." In this embodiment, when an abnormality occurs in the device 101, the monitoring device 102 performs either self-determined recovery or command-received recovery. The monitoring device 102 performs self-determined recovery when self-determined recovery is permitted, and performs command-received recovery when self-determined recovery is not permitted, in other words, when self-determined recovery is prohibited.

[0028] If the recovery processing determination unit 130 determines that self-determined recovery is permitted, it refers to the recovery processing table 133 to identify a specific recovery method and outputs the recovery method to the recovery processing execution unit 131. If the recovery processing determination unit 130 determines that self-determined recovery is not permitted, it outputs an instruction to the recovery processing execution unit 131 to perform recovery using a method instructed by the management device 103. The recovery processing execution unit 131 executes recovery processing based on an instruction from the recovery processing determination unit 130 or a recovery processing instruction received from the management device 103. By executing the recovery processing, the device 101 in which the abnormality occurred is restored.

[0029] The abnormality definition table 132 stores abnormality detection conditions for each abnormality type and the contents of the message to be sent to the management device when an abnormality is detected. The recovery process table 133 stores recovery processes for each abnormality type and whether the recovery processes can be automatically executed, as determined by the monitoring device 102. Specific examples of the abnormality definition table 132 and the recovery process table 133 will be described later with reference to Figures 2 and 3. The storage device management unit 134 creates or updates the abnormality definition table 132 and the recovery process table 133 based on input from the input unit 123 by an operator.

[0030] The following describes the hardware configuration of the management device 103. The management device 103 aggregates data and log information collected from the devices 101 via the monitoring device 102. The management device 103 transmits a recovery processing command to the monitoring device 102 based on an abnormality notification transmitted from the monitoring device 102. The management device 103 has a function for communicating with the monitoring device 102.

[0031] The management device 103 includes a communication I / F 141, a CPU 142, an input unit 143, an output unit 144, a storage device 145, and a communication processing unit 147. Each component has the same configuration and function as the component with the same name in the device 101 or the monitoring device 102. The management device 103 does not need to include the input unit 143 and the output unit 144 when receiving input information from an external device or providing output information to an external device via the communication I / F 141.

[0032] The application program 146 provides the user with services that utilize data and log information collected from the devices 101 via the monitoring device 102. For example, the application program 146 is a program that provides an average value per unit time of on-site data (temperature, etc.) received from the devices 101, and performs data analysis processing, such as calculating the average value from the values ​​of the collected data. The application program 146 may also be a program that remotely sets a transmission schedule for data and log information in the devices 101 and the monitoring device 102.

[0033] The abnormality notification management unit 148 records the abnormality notification received from the monitoring device 102, and outputs the notification information via the output unit 144 to present it to the worker. Specifically, based on a notification from the communication processing unit 147 that has confirmed the reception of the abnormality notification, a screen display example described later in FIG. 8 is output via the output unit 144. The recovery process command unit 149 transmits a command to execute recovery process to the monitoring device 102 based on an operation by the worker. Specifically, in a screen display example described later in FIG. 8, a recovery process command from the worker is received via the input unit 143, and the recovery process command unit 149 outputs the content of the command to the communication processing unit 147.

[0034] The functions of the management device 103 may be shared and realized by multiple hardware devices. That is, the provision of services utilizing received data and the management of abnormality notifications and the issuing of recovery processing commands may be realized separately by different hardware devices. Therefore, it is not essential that a single management device 103 includes all of the components shown in FIG. 1.

[0035] FIG. 2 is a diagram showing an example of anomaly definition table 132. Anomaly definition table 132 includes multiple records, and each record has fields for an event ID 201, anomaly detection condition 202, and a notification message 203. Event ID 201 is an identifier that distinguishes the type of anomaly. In the example of FIG. 2, event ID 201 is given a notation that prioritizes readability, such as "LAN-Disconn," but consecutive numbers such as "event01, event02, ..." may also be used.

[0036] The anomaly detection condition 202 is a condition for determining that a particular anomaly has occurred. When the anomaly detection condition 202 is satisfied, the anomaly detection unit 128 determines that an anomaly has occurred for the event ID 201. The format of the anomaly detection condition 202 is arbitrary. For convenience of explanation, the example in FIG. 2 uses a sentence such as "No response three times consecutively in LAN communication with the monitored device." However, the anomaly detection condition 202 may be defined by separating items such as "monitoring information," "comparison condition," and "threshold" into multiple items, such as "monitoring information: number of consecutive missed responses in LAN communication with the monitored device," "comparison condition: ≧," and "threshold: 3." Also, FIG. 2 illustrates an example in which anomaly detection is performed based on the presence or absence of a response to a transmitted packet or an input signal value from the device 101. However, as described above, any method for detecting an anomaly may be used. For example, if the device 101 itself has a function for diagnosing anomalies in its own device and notifying of anomalies such as an increase in CPU usage, the receipt of such a notification may be specified as an anomaly detection condition, as illustrated in FIG. 2.

[0037] The notification message 203 is the content of a message sent to the management device 103 when an abnormality specified in the event ID 201 is detected. The abnormality notification containing this message content is intended to notify the occurrence of an abnormality in the device 101 and to enable the management device 103 to identify the content of the abnormality that has occurred. The format of the message content is arbitrary as long as this purpose is achieved. In the example of FIG. 2, the prefix "[Self Recovery]" is added to the message content for abnormality types for which automatic execution of recovery processing by the monitoring device 102 is permitted in the recovery processing table 133 described later in FIG. 3.

[0038] When an abnormality notification with this prefix is ​​received, the management device 103 and the operator can determine that the recovery process will be automatically executed by the monitoring device 102 and that issuing a recovery process command is unnecessary, thereby avoiding the issuance of redundant recovery process commands. In this way, in addition to notifying the abnormality type, any additional information may be added to the notification message 203. On the other hand, if there is an abnormality that does not require notification to the management device 103, the notification message 203 for that abnormality type may be set to blank. Note that any field may be added to the abnormality definition table 132 in addition to the fields exemplified in FIG. 2. For example, if multiple devices 101 are connected to the monitoring device 102, a "device ID" field may be added to enable the identifier of the device 101 that is the target of the abnormality detection condition 202 to be defined.

[0039] Fig. 3 is a diagram showing an example of the recovery process table 133. The recovery process table 133 has multiple records, and each record has fields for an event ID 301, a first recovery process content 302, a first timer 303, a second recovery process content 304, a second timer 305, and self-determined recovery feasibility 306. In Fig. 3, "-" means that no data exists.

[0040] Event ID 301 is an identifier for distinguishing anomaly types and is the same as event ID 201 in the anomaly definition table 132. First recovery action content 302 and second recovery action content 304 are recovery action content to be implemented when the anomaly described in event ID 301 is detected. The format of the recovery action content is arbitrary. In the example of FIG. 3, for convenience of explanation, a sentence such as "restart the communication I / F of the monitored device" is used. However, for example, a command to implement the recovery action may be written, or a script file that provides the recovery action may be prepared in advance and the name of the script file may be written. Furthermore, while FIG. 3 illustrates examples of recovery action content, such as restarting the device 101 and changing settings, the recovery action content is not limited to a specific process. Furthermore, if multiple communication methods exist between the device 101 and the monitoring device 102, a field may be added that explicitly specifies which method to use to implement the recovery action.

[0041] The first timer 303 and the second timer 305 are the wait times until the recovery process specified in the first recovery process content 302 and the second recovery process content 304 is executed. For example, if immediately executing a recovery process after detecting an abnormality would cause a problem, setting the appropriate timer value can avoid the problem. Note that in the example of Figure 3, the timer is specified in seconds, but the unit of specification is arbitrary. Also, instead of specifying a timer value, it is possible to specify a time period during which recovery process execution is permitted or prohibited. In the example of Figure 3, up to two combinations of recovery process content and timer value can be registered. For example, in response to a "CPU-HighUsage (CPU usage abnormality)" abnormality, after making a setting change to reduce CPU usage, it is possible to perform a reboot process to reflect the setting change. However, supporting the registration of multiple recovery process content and timer values ​​is not required, and the number of registrations can be changed as desired.

[0042] Self-determined recovery possibility 306 indicates whether or not recovery processing based on the above-mentioned recovery processing content and timer value may be automatically executed at the discretion of the monitoring device 102 when an abnormality described in event ID 301 is detected, without waiting for a recovery processing command to be received from the management device 103. In the example of FIG. 3, "OK" indicates that self-determined recovery is permitted, and "NG" indicates that self-determined recovery is prohibited. The format is arbitrary, and may be expressed, for example, as "True / False." It can also be said that "OK" in self-determined recovery possibility 306 indicates self-determined recovery, and "NG" indicates instruction-received recovery.

[0043] For an abnormality for which self-determined recovery is permitted, the processes described in first recovery process content 302 and second recovery process content 304 are executed after the times specified by first timer 303 and second timer 305 have elapsed. On the other hand, for an abnormality for which self-determined recovery is not permitted, recovery process is not executed regardless of the recovery process content or timer value described above, and the device waits for a recovery process command from management device 103.

[0044] 3, for example, for a highly urgent abnormality such as a disconnection of communication with the device 101 (e.g., "LAN-Disconn" in FIG. 3), early recovery can be achieved by allowing the monitoring device 102 to automatically execute a recovery process. On the other hand, for a less urgent abnormality that does not require immediate recovery, such as a case where an input signal value different from the expected begins to be observed from the device 101 (e.g., "DI-3timesLow" in FIG. 3), or for a precursory phenomenon where the occurrence of an abnormality cannot be immediately determined, self-determined recovery can be prohibited and the decision to execute a recovery process can be left to the management device 103 and an operator, allowing recovery processes to be implemented at an appropriate time.

[0045] When an input signal value different from the expected value continues to be observed, such as the event ID "DI-5timesLow" in FIG. 3, it is possible to set the monitoring device 102 to automatically execute a recovery process when it is determined to be an obvious abnormality. In the example of FIG. 3, recovery process details and timer values ​​are set even for event IDs for which execution of recovery processes at the discretion of the monitoring device 102 is prohibited (e.g., "DI-3timesLow" in FIG. 3), but values ​​do not need to be set. Furthermore, the field for self-determined recovery availability 306 may be omitted, and only event IDs for which self-determined recovery is permitted may be entered in the recovery process table 133. In this case, it is determined that automatic execution of recovery processes at the discretion of the monitoring device 102 is prohibited for abnormalities with event IDs not listed in the recovery process table 133. In addition to the fields illustrated in FIG. 3, any other fields may be added to the recovery process table 133. For example, if multiple devices 101 are connected to the monitoring device 102, a "device ID" field may be added to enable definition of the identifier of the device 101 that is the target of the recovery process.

[0046] Figures 4 and 5 are time charts showing the recovery process. Figure 4 is a time chart when self-determined recovery is permitted, and Figure 5 is a time chart when self-determined recovery is prohibited. In Figures 4 and 5, time passes from the top to the bottom of the illustration. The final stages of the process differ between Figures 4 and 5, but the processes up to the middle are the same.

[0047] In steps S401a and S401b of FIG. 4, the anomaly detection unit 128 of the monitoring device 102 diagnoses whether or not there is an abnormality in the device 101. The anomaly detection unit 128 refers to the anomaly definition table 132 and diagnoses whether or not there is an abnormality based on the detection conditions described in the anomaly detection conditions 202 in the table. For example, in the diagnosis process for "LAN-Disconn" illustrated in FIG. 2, a live / dead check packet is transmitted to the device 101 via LAN communication, and the presence or absence of a response is determined. Note that the timing of the execution of the anomaly diagnosis process by the anomaly detection unit 128 in steps S401a and S401b is managed by the anomaly detection unit 128, and is executed at time intervals of a predetermined anomaly diagnosis cycle Δt, as illustrated in FIG. 4, for example. In addition to this, the anomaly diagnosis process may be executed at any arbitrary timing, such as at a specified time every day.

[0048] If one or more of the abnormality detection conditions defined in the abnormality definition table 132 are met in the abnormality diagnosis process, the process proceeds to step S402. On the other hand, if all of the abnormality detection conditions are not met, the process waits until the timing for executing the next abnormality diagnosis process. In step S402, the abnormality detection unit 128 of the monitoring device 102 detects the occurrence of an abnormality in the device 101. In other words, in step S402, the type of abnormality is identified. The abnormality detection unit 128 refers to the abnormality definition table 132, obtains the event ID 201 corresponding to the abnormality detection condition 202 that was met in the abnormality diagnosis process described above, and detects the occurrence of an abnormality for that event ID. Then, the abnormality detection unit 128 notifies the abnormality notification unit 129 of the event ID.

[0049] In step S403, the abnormality notification unit 129 of the monitoring device 102 transmits an abnormality notification to the management device 103 to notify the management device 103 of the occurrence of an abnormality. The abnormality notification unit 129 references the abnormality definition table 132 and acquires the notification message 203 corresponding to the event ID notified by the abnormality detection unit 128 in step S402. The abnormality notification unit 129 then notifies the communication processing unit 127 of the content of the message, and transmits an abnormality notification packet storing the content of the message to the management device 103. For example, if the "LAN-Disconn" abnormality illustrated in FIG. 2 is detected, the abnormality notification packet storing the message "[Self Recovery]LAN-Disconn" is transmitted to the management device 103. When the transmission is complete, the monitoring device 102 proceeds to step S404.

[0050] On the other hand, when the management device 103 receives the abnormality notification, the communication processing unit 147 analyzes the packet, and if it confirms that the content of the packet is an abnormality notification, it notifies the abnormality notification management unit 148. Thereafter, the management device 103 proceeds to step S405. The processing of step S405 will be described later.

[0051] Step S404 is a process in which the recovery process determination unit 130 of the monitoring device 102 determines whether to automatically execute recovery process for the abnormality that occurred in the device 101 at its own discretion, or whether to wait for a recovery process command from the management device 103 before executing recovery process. Specifically, the recovery process determination unit 130 references the recovery process table 133 and determines whether self-determined recovery is possible based on the setting value of self-determined recovery possibility 306 for the event ID detected in step S402. Details of this recovery process determination will be described later with reference to FIG. 6. In FIG. 4, it is determined that self-determined recovery is possible, and the process proceeds to step S406. In FIG. 5, which will be described later, a case in which it is determined that self-determined recovery is impossible will be described.

[0052] In step S405, the management device 103, which received the abnormality notification transmitted in step S403, records the abnormality notification in the abnormality notification management unit 148 and outputs the notification information via the output unit 144. The abnormality notification management unit 148 may display the content of the received abnormality notification as is, or may determine whether the abnormality notification is a self-determined recovery or an instruction-received recovery and change the screen display based on the determination result. An example of the screen display to be output will be described later with reference to FIG. 8. Upon completion of the output process, the management device 103 waits for receipt of a recovery processing command by an operator via the input unit 143. Note that, as described above, by including a character string indicating that self-determined recovery, such as [Self Recovery], in the abnormality notification, it is possible to prevent the operator from issuing redundant recovery processing commands.

[0053] In step S406, the recovery process execution unit 131 executes recovery process at the discretion of the monitoring device 102. Specifically, the recovery process table 133 is referenced, and recovery process is executed based on the first recovery process content 302 and second recovery process content 304 for the event ID detected in step S402 and the set values ​​of the first timer 303 and second timer 305. For example, when an abnormality of "LAN-Disconn" in FIG. 3 is detected and recovery process for this abnormality is executed, "restart communication I / F of monitored device" is executed without waiting time. In this way, the monitoring device 102 detects an abnormality that has occurred in the device 101 and automatically executes recovery process at the discretion of the monitoring device 102, thereby achieving early recovery.

[0054] A time chart for when self-determined recovery is not permitted will be described with reference to FIG. 5. In FIG. 5, steps S401a, S401b, S402, S403, S404, and S405 are the same as those in FIG. 4, and therefore will not be described again. In step S501, the management device 103 accepts, via the input unit 143, the issuance of a recovery processing command to the monitoring device 102 based on an operation by an operator. If the operator determines that a recovery processing command is necessary in response to the abnormality notification output in step S405, the operator issues the recovery processing command to the monitoring device 102 via the input unit 143. In step S501, the management device 103 accepts the issuance. When the operator issues a recovery processing command, the contents of the command are transmitted from the input unit 143 to the recovery processing command unit 149, and the management device 103 proceeds to the processing of step S502. An example of a screen display for the operator to input and issue a recovery processing command will be described later with reference to FIG. 8.

[0055] In step S502, the recovery process command unit 149 of the management device 103 transmits a recovery process command to the monitoring device 102. Specifically, the contents of the recovery process command received in step S501 are notified to the communication processing unit 147, and a recovery process command packet storing the command contents is transmitted to the monitoring device 102. Note that the recovery process command packet transmitted to the monitoring device 102 stores, for example, the recovery process content and timer value to be executed by the monitoring device 102, that is, information equivalent to the recovery process content and timer value stored in the recovery process table 133 of FIG. 3.

[0056] However, storing this information is not essential. For example, as shown in Fig. 3, if the recovery process content and timer value are defined even for an event for which the execution of recovery process is prohibited at the discretion of the monitoring device 102 (e.g., "DI-3timesLow" in Fig. 3), it is possible to omit specifying this information and instead notify only the event ID, indicating which abnormality (event ID) the recovery process is to be commanded for. Furthermore, information other than the recovery process content and timer value may be stored in the recovery process command packet as necessary.

[0057] On the other hand, when the monitoring device 102 receives the recovery processing command, the communication processing unit 127 analyzes the packet, and if it confirms that the contents of the packet are a recovery processing command, it notifies the recovery processing execution unit 131. Thereafter, the monitoring device 102 proceeds to step S503. In step S503, the monitoring device 102, which has received the recovery processing command of step S502, executes recovery processing in the recovery processing execution unit 131 based on the command from the management device 103. Specifically, the recovery processing is executed based on the recovery processing content and timer value specified by the management device 103. If an event ID is stored in the recovery processing command packet and notified as in the example described above, the recovery processing table 133 in FIG. 3 is referenced, and the recovery processing corresponding to the event ID is executed.

[0058] In this way, recovery processing is not executed based on the judgment of the monitoring device 102, but is executed based on a recovery processing command from the management device 103, so that only recovery processing that the operator judges necessary can be executed. In particular, if there is a time period in which the execution of recovery processing will have an adverse effect on the operation of the system, the operator can wait until an appropriate time to issue a recovery processing command, thereby enabling efficient recovery processing without interfering with the operation of the system.

[0059] Fig. 6 is a flowchart showing the processing of the recovery processing determination unit 130. Specifically, the processing shown in Fig. 6 corresponds to the processing executed in step S404 in Fig. 4 and Fig. 5. In this processing, the monitoring device 102 determines whether or not self-determined recovery is possible for an abnormality detected by the abnormality detection unit 128.

[0060] First, in step S601, the recovery processing determination unit 130 identifies a corresponding record in the recovery processing table 133. Specifically, the recovery processing determination unit 130 identifies a record in the recovery processing table 133 that includes the abnormality type (event ID) detected by the abnormality detection unit 128 in step S402 of FIG. 4 or FIG. 5. In the following step S602, the recovery processing determination unit 130 determines whether self-determined recovery is possible. Specifically, if the field value of the self-determined recovery possibility 306 of the record identified in step S601 is "OK", that is, if self-determined recovery is permitted, the recovery processing determination unit 130 proceeds to step S603. On the other hand, if the field value of the self-determined recovery possibility 306 is "NG", that is, if self-determined recovery is prohibited, the recovery processing determination unit 130 proceeds to step S604.

[0061] In step S603, the recovery processing determination unit 130 reads the recovery processing content for the detected abnormality from the recovery processing table 133, and has the recovery processing content executed by the recovery processing execution unit 131, thereby completing the processing shown in Fig. 6. Specifically, the recovery processing determination unit 130 reads the first recovery processing content 302, the first timer 303, the second recovery processing content 304, and the second timer 305 of the record in the recovery processing table 133 that includes the abnormality type (event ID) detected by the abnormality detection unit 128, and has the recovery processing execution unit 131 execute them.

[0062] In step S604, the recovery process determination unit 130 instructs the recovery process execution unit 131 to execute the command from the management device 103, and ends the process shown in Fig. 6. In this case, the management device 103 transmits a recovery process command in step S502 in Fig. 5, and when the monitoring device 102 receives the command, it executes recovery process in step S503 in Fig. 5. Note that when waiting to receive a recovery process command from the management device 103, a timeout value may be explicitly set. If a recovery process command is received outside the timeout period, the command may be discarded, i.e., invalidated.

[0063] By having the recovery process determination unit 130 perform the process shown in Figure 6, the monitoring device 102 can flexibly choose between automatically executing recovery processes based on its own judgment and executing recovery processes based on commands from the management device 103, depending on the type of abnormality, based on the entries in the recovery process table 133.

[0064] Fig. 7 is a diagram showing an example of a screen display for registering the abnormality definition table 132 and the recovery process table 133. The storage device management unit 134 creates or updates the abnormality definition table 132 and the recovery process table 133, for example, based on input by an operator to the screen shown in Fig. 7. The display screen 700 shown in Fig. 7 may be displayed on the output unit 124 of the monitoring device 102, or may be displayed on an external device via the communication I / F 121. The display screen 700 has a first display area 701 for setting the abnormality definition table 132 and a second display area 702 for setting the recovery process table 133.

[0065] In the first display area 701, when the worker inputs various pieces of information such as the abnormality detection conditions and the notification message contents for each abnormality type (event ID) from the input unit 123, the input values ​​are set in the abnormality definition table 132. It is possible that event IDs will be added as needed during the operation of the system. Therefore, in the example of FIG. 7, a first addition button 703 is provided for adding an input field (row) for the event ID. When the worker presses the first addition button 703, a new input field with each value left blank is added.

[0066] In the second display area 702, when the worker inputs various information such as the recovery process content, timer value, and whether or not self-determined recovery is possible for each abnormality type (event ID) from the input unit 123, the input values ​​are set in the recovery process table 133. A second addition button 704 is arranged in the second display area 702, and when the worker presses the second addition button 704, new input fields with blank spaces for the respective values ​​are added.

[0067] Furthermore, various table information may be managed not only on the display screen 700 of FIG. 7 but also in other external files using import and export functions. Therefore, the example screen display of FIG. 7 also has a file input button 706 and a file output button 705. When the worker presses the file input button 706 via the input unit 123, various table values ​​stored in other external files are read onto the display screen 700 of FIG. 7. Furthermore, when the worker presses the file output button 705, the table values ​​input on the display screen 700 of FIG. 7 are output to the external file. This makes it possible to easily achieve linkage with external files in which table values ​​are stored. However, the inclusion of this function is optional.

[0068] By displaying a setting screen for various table information as shown in Figure 7, the operator can easily register various table values ​​or make changes during the process. Note that the example screen display in Figure 7 shows examples of how to directly input table values ​​and how to select or set values ​​using a pull-down menu, but the display format for accepting settings is arbitrary.

[0069] FIG. 8 shows an example of a screen display in which the management device 103 outputs an abnormality notification in step S405 in FIGS. 4 and 5 , and an example of a screen display in which the management device 103 receives a recovery processing command from an operator in step S501 in FIG. 5 . The display screen 800 is displayed on the output unit 144. The display screen 800 has a third display area 801 for outputting an abnormality notification received from the monitoring device 102 and a fourth display area 802 for receiving a recovery processing command. The abnormality notification management unit 148 may cause the output unit 144 to display the fourth display area 802 only when it determines that an instruction has been received and recovery has occurred based on the content of the received abnormality notification. For example, if the received message does not contain [Self Recovery], the abnormality notification management unit 148 determines that an instruction has been received and recovery has occurred and causes the output unit 144 to display the fourth display area 802. In this case, if a recovery instruction is not required, the fourth display area 802 is not displayed, so the operator does not need to determine whether an instruction is required.

[0070] The third display area 801 displays the sender of the abnormality notification (monitoring device ID), the notification message, and the last notification time (i.e., the last time the abnormality notification was received) for the abnormality notification received from the monitoring device 102. This display allows the operator to easily know which monitoring device 102 detected what kind of abnormality, when, and what kind of abnormality. Furthermore, as described above, by adding a prefix such as "[Self Recovery]" to the message content stored in the abnormality notification to indicate that recovery processing will be automatically performed by the monitoring device 102, the operator can also determine whether or not a recovery processing command needs to be issued.

[0071] Note that other arbitrary information may be output in the third display area 801 as needed. For example, not only the sender of the abnormality notification (monitoring device ID), but also the identifier of the device 101 connected to the monitoring device 102 may be output. Also, instead of the table format shown in FIG. 8, a screen display that outputs in text format, for example, may be used, and the display format is not limited to a specific method. Note that in the example of FIG. 8, the monitoring device IDs of the monitoring devices 102-a and 102-b are expressed as "monitoring device a, monitoring device b," but the monitoring device IDs may be substituted with arbitrary host names, IP addresses, etc.

[0072] The operator inputs a recovery processing command to be issued to the monitoring device 102 in the fourth display area 802. Specifically, the operator inputs the destination (monitoring device ID) of the recovery processing command, the recovery processing content to be commanded, and the timer value until the recovery processing is executed. Then, when the operator presses (or clicks) the command issue button 803 from the input unit 143, this input information is accepted by the management device 103 in step S501 of Fig. 5, and the recovery processing command is then sent in the subsequent step S502.

[0073] As mentioned above, if recovery process details and timer values ​​are set in the recovery process table 133 of the monitoring device 102 even for an abnormality for which automatic execution of recovery process at the device's own discretion is prohibited, such as "DI-3timesLow" in Fig. 3, the following change may be made: That is, instead of inputting the recovery process details and timer value in the fourth display area 802, the operator may input an event ID indicating which abnormality (event ID) recovery process is to be ordered for.

[0074] 8, the operator can view the abnormalities detected by the monitoring device 102 and issue a recovery processing command for the abnormality at any timing. The recovery processing command is issued when the operator presses the command issue button 803, so the operator can flexibly control the timing of the recovery processing, for example, by waiting until a time when the system operation will not be disturbed when issuing the command.

[0075] According to the first embodiment described above, the following advantageous effects can be obtained. (1) The monitoring device 102 monitors one or more devices 101 as monitoring targets. The monitoring device 102 includes an abnormality detection unit 128 that detects an abnormality occurring in the device 101, an abnormality notification unit 129 that outputs the detected abnormality as an abnormality notification to the outside, a recovery process determination unit 130 that determines a recovery type depending on the abnormality type, either a self-determined recovery in which the monitoring device determines the content of the recovery process for the device 101, or an instruction-received recovery in which the monitoring device determines the content of the recovery process for the device 101, and a recovery process execution unit 131 that executes the recovery process for the device 101 based on the recovery type determined by the recovery process determination unit 130. Therefore, the entity that determines the content of the recovery process can be changed depending on the type of abnormality occurring in the device 101. Specifically, depending on the type of abnormality occurring in the device 101, it is possible to flexibly switch between automatic execution of the recovery process by the monitoring device 102 and execution of the recovery process based on an instruction from the management device 103.

[0076] (2) The monitoring device 102 includes a storage device 125 that stores anomaly definitions, which are definitions of each anomaly type; self-determined recovery possibility 306, which indicates whether each anomaly type is self-determined recovery or instruction-received recovery; and first recovery processing content 302 and second recovery processing content 304, which are the contents of the recovery processing for each anomaly type that is self-determined recovery.

[0077] (3) The storage device 125 stores a notification message 203 which is the content of the abnormality notification for each abnormality type, and a timer which is the time allowance until the recovery process is executed for each abnormality type, that is, a first timer 303 and a second timer 305.

[0078] (4) The monitoring device 102 includes a storage device management unit 134 that records at least one of the following in the storage device 125 based on external input: anomaly definition, self-determined recovery possibility, recovery process details, content of anomaly notification for each anomaly type, and a timer. Therefore, the data stored in the storage device 125 can be updated after the fact.

[0079] (5) When the recovery process determination unit 130 determines to perform recovery upon receiving an instruction, the recovery process execution unit 131 of the monitoring device 102 waits until it receives an external instruction on the details of the recovery process for the device 101, and immediately executes the details of the recovery process for the device 101 when it receives the instruction from the outside. Therefore, the management device 103, which is an external device, can freely set the timing of the recovery process for the device 101. For example, an operator of the management device 103 can efficiently execute the recovery process by immediately instructing the details of the recovery process for a highly urgent abnormality to achieve early recovery, and by waiting until a timing that will not interfere with system operation for a less urgent abnormality.

[0080] (6) The management device 103 includes an abnormality notification management unit 148 that receives abnormality notifications output by the monitoring device 102, and a recovery processing command unit 149 that outputs the contents of recovery processing determined based on the abnormality notification to the monitoring device 102.

[0081] (7) The management device 103 includes an output unit 144 that presents information to the user. The abnormality notification management unit 148 outputs the abnormality notification received from the monitoring device 102 to the output unit 144. The management device 103 includes an input unit 143 that accepts the contents of the recovery process for the monitoring device 102 from the user. The recovery process command unit 149 outputs the contents of the recovery process input to the input unit 143 to the monitoring device 102 via the communication processing unit 147.

[0082] (Variation 1) Although the first embodiment described above is premised on an operation by an operator, a configuration in which an operator is not required may also be adopted. That is, in this embodiment, an abnormality notification is output to the operator as shown in Fig. 8, and a recovery processing command is received from the operator via the input unit 143 in step S501 of Fig. 5. However, the management device 103 may automatically send a recovery processing command without requiring an operation by an operator.

[0083] For example, this can be achieved by previously defining in the abnormality notification management unit 148 of the management device 103 an abnormality notification that permits automatic return of a recovery processing command, and a recovery processing command (the recovery processing content and timer value) in response to the abnormality notification. In this case, the content of the recovery processing command may be linked from the abnormality notification management unit 148 to the recovery processing command unit 149 at the timing when the abnormality notification is received, and the recovery processing command may be automatically sent without waiting for an operator's operation. According to this modification, while realizing early recovery at the same level as self-determined recovery by the monitoring device 102, the management device 103 can also store the recovery processing command history, in other words, the content and execution time of the recovery processing, as management information.

[0084] (Variation 2) The fault definition table 132 and the recovery process table 133 stored in the storage device 125 of the monitoring device 102 may be configured as an integrated unit. Also, there may be only one recovery process content, and a timer need not be set. Furthermore, the fault notification sent by the monitoring device 102 to the management device 103 may be, for example, the event ID itself, and the notification message 203 may not be included in the fault definition table 132. According to this modification, the storage capacity required for managing the fault definition table 132 and the recovery process table 133 can be reduced.

[0085] --Second embodiment-- A second embodiment of a communication system will be described with reference to Figures 9 to 11. In the following description, the same components as those in the first embodiment are assigned the same reference numerals, and differences will be mainly described. Points that are not particularly described are the same as those in the first embodiment. This embodiment differs from the first embodiment mainly in that the execution of recovery processing for an abnormality that has occurred can be dynamically switched from automatic execution based on the judgment of the monitoring device 102 to execution based on an instruction from the management device 103.

[0086] In the first embodiment described above, an example was given in which the monitoring device 102 statically switches between automatic execution of recovery processing and execution of recovery processing based on an instruction from the management device 103 depending on the type of abnormality. However, if the recovery processing executed by the monitoring device 102 in self-determined recovery for the abnormality that has occurred is inappropriate, the device 101 may not be able to recover from the abnormality, and the monitoring device 102 may repeatedly detect the abnormality and automatically execute the recovery processing. For example, if the monitoring device 102 detects a communication disconnection with the device 101 (e.g., "LAN-Disconn" in FIG. 3) and executes a recovery processing of "restarting the communication I / F of the monitored device," but the communication disconnection with the device 101 is not resolved and the same abnormality continues to be detected, even if the monitoring device 102 executes the same recovery processing again, it is unlikely that recovery will be achieved. In such a case, it is desirable to stop the automatic execution of the recovery processing by the monitoring device 102 and dynamically switch to execute another recovery processing based on an instruction from the management device 103, i.e., the operator's judgment.

[0087] The configurations and functions of the management device 103 and the device 101 in the second embodiment are the same as those in the first embodiment. The hardware configuration of the monitoring device 102 is the same as that in the first embodiment. The monitoring device 102 differs from the first embodiment in the configurations of the abnormality definition table 132 and the recovery process table 133. The processing of the recovery process determination unit 130 also differs from that in the first embodiment. The operations of the application program 126, the communication processing unit 127, the abnormality detection unit 128, the abnormality notification unit 129, the recovery process execution unit 131, and the storage device management unit 134 are the same as those in the first embodiment.

[0088] 9 is a diagram showing an example of anomaly definition table 132 in the second embodiment. Event ID 901, anomaly detection condition 902, and first notification message 903 in FIG. 9 are the same as event ID 201, anomaly detection condition 202, and notification message 203 in anomaly definition table 132 in FIG. 2 in the first embodiment, and therefore a description thereof will be omitted. Second notification message 904 is a message sent to management device 103 when an anomaly specified by event ID 901 is detected and meets the conditions set forth in message switching condition 905, which will be described later. Hereinafter, second notification message 904 will also be referred to as "changed notification content."

[0089] The message switching condition 905 is a condition for switching the message content notified to the management device 103 when an abnormality is detected from the first notification message 903 to the second notification message 904. While this condition is met, when an abnormality specified by the event ID 901 is detected, the message content described in the second notification message 904 is notified to the management device 103. Hereinafter, the message switching condition 905 is also referred to as the "fourth change condition."

[0090] 9, if a communication disconnection with the device 101 ("LAN-Disconn" in FIG. 9) is detected three or more times within one hour, the abnormality notification unit 129 of the monitoring device 102 changes the content of the message to be notified to the management device 103 from "[Self Recovery] LAN-Disconn" to "LAN-Disconn." In the example of the recovery process table 133 in FIG. 10 (to be described later), if a communication disconnection with the device 101 is detected three or more times within one hour, the monitoring device 102 disables (prohibits) the automatic execution of recovery process at its own discretion, and changes its operation so that recovery process is executed based on a command from the management server.

[0091] At this time, as shown in Fig. 9, for example, by changing the content of the message sent to the management device 103 to delete the prefix "[Self Recovery]", the worker can determine by viewing the screen in Fig. 8 that the automatic execution of recovery processing by the monitoring device 102 has been disabled and that a new recovery processing command needs to be issued. Note that if there is no need to switch the content of the message sent, the second notification message 904 may contain the same content as the first notification message 903, or may be left blank.

[0092] Fig. 10 is a diagram showing an example of the recovery process table 133 in the second embodiment. The event ID 906, first recovery process content 907, first timer 908, second recovery process content 909, second timer 910, and self-determined recovery feasibility 911 in Fig. 10 are the same as the event ID 301, first recovery process content 302, first timer 303, second recovery process content 304, second timer 305, and self-determined recovery feasibility 306 in the recovery process table 133 in Fig. 3 in the first embodiment, and therefore description thereof will be omitted.

[0093] The invalidation condition 912 is a condition that invalidates (prohibits) the automatic execution of recovery processing determined by the monitoring device 102. While this condition is met, the automatic execution of recovery processing is disabled even if the self-determined recovery feasibility 911 field indicates that automatic execution is permitted. In the example shown in FIG. 10, if a communication disconnection with the device 101 ("LAN-Disconn" in FIG. 10) is detected three or more times within one hour, the recovery processing determination unit 130 of the monitoring device 102 disables the automatic execution of recovery processing in response to the communication disconnection and determines to wait for a command from the management device 103 before executing recovery processing. Details of this process will be described later with reference to FIG. 11. Hereinafter, the invalidation condition 912 is also referred to as a "first change condition." When the first change condition of a certain record is met, the recovery processing determination unit 130 changes the value of "OK" in the self-determined recovery feasibility 911 of that record to "NG."

[0094] 9 and 10, for the sake of convenience, the message switching condition 905 and the invalidation condition 912 are written in sentences such as "the same event is detected three times within one hour," but this format is arbitrary. These conditions can be specified not only by detection frequency, but also by detection time or detection time period, and the condition content can be defined arbitrarily. Furthermore, after the message switching condition 905 and the invalidation condition 912 are met, the timing for returning the notification message content to the original first notification message 903 and the timing for canceling the invalidation of the execution of recovery processing determined by the device itself can be set arbitrarily. For example, the invalidation can be canceled after a certain time has passed since the condition was met.

[0095] 11 is a flowchart showing the processing of the recovery processing determination unit 130 in the second embodiment. Steps S601, S602, S603, and S604 in FIG. 11 are the same as those in FIG. 6, and therefore their explanation will be omitted. In steps S601 to S602, the recovery processing table 133 in FIG. 10 is referenced, and if "OK" is entered in the field of self-determined recovery feasibility 911 corresponding to the detected abnormality, the process proceeds to step S1001. In step S1001, the recovery processing determination unit 130 references the invalidation conditions 912 in the recovery processing table 133 and acquires the invalidation conditions for executing recovery processing at the discretion of the device itself.

[0096] In the following step S1002, the recovery process determining unit 130 determines whether the invalidation conditions acquired in step S1001 are met. In the example of FIG. 10, when a communication disconnection with the device 101 ("LAN-Disconn" in FIG. 10) is detected, the number of times the same event was detected within one hour is used to determine whether the condition is met. If the invalidation conditions for the detected abnormality are not registered (blank) or the invalidation conditions are not met (YES), the process proceeds to step S603, where it is determined that the monitoring device 102 will automatically execute recovery processing. On the other hand, if the invalidation conditions are met (NO), the value of "OK" in the self-determined recovery feasibility 911 is changed to "NG," and it is determined that the execution of recovery processing based on the determination of the monitoring device 102 is invalidated. The process proceeds to step S604, where it instructs the recovery process execution unit 131 to execute recovery processing based on a command from the management device 103.

[0097] According to the second embodiment described above, the following advantageous effects can be obtained. (8) The storage device 125 stores a first change condition for changing the self-determined recovery status for each anomaly type from self-determined recovery to instruction-received recovery. When the first change condition is met, the recovery process determination unit 130 changes the self-determined recovery status to instruction-received recovery. Therefore, the entity that determines the content of the recovery process can be dynamically changed from the monitoring device 102 to the management device 103.

[0098] (9) The first change condition is the detection frequency of the same anomaly or the time of anomaly detection. Therefore, if the same anomaly is detected frequently or if an anomaly is detected during a specific time period, changing the self-determined recovery to the instruction-received recovery is expected to enable the operator to instruct a more appropriate recovery process.

[0099] (10) The storage device 125 stores a fourth change condition, which is a message switching condition 905 that is a condition for changing the content of the abnormality notification for each abnormality type, and a second notification message 904 (changed notification content) that is the content of the abnormality notification when the fourth change condition is met. When the fourth change condition is met, the abnormality notification unit 129 outputs the second notification message 904 instead of the first notification message 903. Therefore, an operator who sees the output of the output unit 144 of the management device 103 can know that the self-determined recovery has been changed to the instruction-received recovery.

[0100] -Third embodiment- A third embodiment of a communication system will be described with reference to Figures 12 to 14. In the following description, the same components as those in the first embodiment are denoted by the same reference numerals, and differences will be mainly described. Points that are not particularly described are the same as those in the first embodiment. This embodiment differs from the first embodiment mainly in that the execution of recovery processing can be dynamically switched from execution based on a command from the management device 103 to automatic execution based on the judgment of the monitoring device 102.

[0101] In the second embodiment described above, the execution of recovery processing for an abnormality is dynamically switched from automatic execution based on the judgment of the monitoring device 102 to execution based on an instruction from the management device 103. On the other hand, there are also cases where efficiency can be improved by switching from execution of recovery processing based on an instruction from the management device 103 to automatic execution based on the judgment of the monitoring device 102. For example, when an unexpected input signal is detected from the device 101 (e.g., "DI-3timesLow" in FIG. 3), an abnormality notification is sent to the management device 103, and recovery processing is executed based on the instruction from the management device 103, i.e., by seeking the judgment of an operator. In this case, if a recovery processing instruction is received with a high probability after the abnormality notification is sent, it is considered that there is little point in seeking the judgment of an operator every time. In such cases, dynamically switching to self-determined recovery can shorten the time required for recovery.

[0102] The configurations and functions of the management device 103 and the device 101 in the third embodiment are the same as those in the first embodiment. The hardware configuration of the monitoring device 102 is the same as that in the first embodiment. The monitoring device 102 differs from the first embodiment in the configurations of the abnormality definition table 132 and the recovery process table 133. The processing of the recovery process determination unit 130 also differs from that in the first embodiment. The operations of the application program 126, the communication processing unit 127, the abnormality detection unit 128, the abnormality notification unit 129, the recovery process execution unit 131, and the storage device management unit 134 are the same as those in the first embodiment.

[0103] FIG. 12 is a diagram showing an example of the abnormality definition table 132 in the third embodiment. The configuration of this table is similar to that of the abnormality definition table 132 shown in FIG. 9 in the second embodiment, and therefore a detailed description thereof will be omitted. In the example shown in FIG. 12, after observing a "Low" digital input signal three consecutive times from the device 101 ("DI-3timesLow" in FIG. 12), if a recovery processing command for the same event is received three or more times from the management device 103 within one day, the abnormality notification unit 129 of the monitoring device 102 changes the content of the message notified to the management device 103 from "DI-3timesLow" to "[Self Recovery]DI-3timesLow." In the example of the recovery processing table 133 in FIG. 13 (described later), if the same condition is met, the monitoring device 102 enables (permits) self-determined recovery and changes its operation so that recovery processing is performed for the abnormality in question without waiting for a command from the management server.

[0104] When self-determined recovery is enabled, the content of the message sent to the management device 103 is also changed to include the prefix "[Self Recovery]" as shown in Fig. 12. This change allows the operator to determine by viewing the screen shown in Fig. 8 that automatic execution of recovery processing by the monitoring device 102 has been enabled and that issuing a recovery processing command is no longer necessary. This in turn makes it possible to prevent redundant recovery processing commands from being issued.

[0105] Fig. 13 is a diagram showing an example of the recovery processing table 133 in the third embodiment. In Fig. 13, an event ID 1101, a first recovery processing content 1102, a first timer 1103, a second recovery processing content 1104, a second timer 1105, and a self-determined recovery feasibility 1106 are the same as the event ID 906, the first recovery processing content 907, the first timer 908, the second recovery processing content 909, the second timer 910, and a self-determined recovery feasibility 911 in the recovery processing table 133 shown in Fig. 10 in the second embodiment, and therefore a description thereof will be omitted.

[0106] The enablement condition 1107 is a condition for enabling (allowing) self-determined recovery. While this condition is met, self-determined recovery is enabled even if self-determined recovery is prohibited in the self-determined recovery enable / disable field 1106. In the example of FIG. 13, the enablement condition 1107 is met if a recovery processing command is received three or more times from the management device 103 within one day after sending an abnormality notification related to "DI-3timesLow" in FIG. 12. Therefore, the recovery processing determination unit 130 of the monitoring device 102 enables self-determined recovery for the abnormality and executes recovery processing without waiting for a command from the management device 103. Details of this processing will be described later with reference to FIG. 14. Hereinafter, the enablement condition 1107 will also be referred to as a "second change condition."

[0107] In the example of FIG. 13, for the sake of convenience, the activation condition 1107 is written in a sentence such as "recovery processing commands for the same event are received three times within one day," but the format is arbitrary. These conditions may be specified by the frequency of receiving recovery processing commands, or the content of the conditions may be defined arbitrarily, such as by the time an abnormality is detected. Furthermore, the timing for canceling the activation of the recovery processing determined by the device itself after the activation condition 1107 is met may be set arbitrarily. For example, the activation may be canceled when a certain time has passed after the condition is met.

[0108] Fig. 14 is a flowchart showing the processing of the recovery processing determination unit 130 in the third embodiment. Steps S601, S602, S603, and S604 in Fig. 11 are the same as those in Fig. 6, and therefore their explanation will be omitted. In steps S601 and S602, the recovery processing table 133 is referenced, and if "NG" is entered in the field of self-determined recovery feasibility 911 corresponding to the detected abnormality, the process proceeds to step S1201.

[0109] In step S1201, the recovery process determination unit 130 of the monitoring device 102 references the activation conditions 1107 and acquires the activation conditions for self-determined recovery. In the following step S1202, the recovery process determination unit 130 of the monitoring device 102 determines whether the activation conditions acquired in step S1201 are met. In the example of FIG. 13, if a "Low" digital input signal is observed three consecutive times from the device 101 ("DI-3timesLow" in FIG. 13), the unit 130 determines whether the activation conditions are met using the number of times a recovery process command was received within the past day after an abnormality notification was sent for the abnormality. If the activation condition for the detected abnormality is not registered (blank) or does not match the activation condition (YES), the process proceeds to step S604, where it is determined whether recovery process is to be executed based on a command from the management device 103. On the other hand, if the activation conditions are met (NO), the monitoring device 102 determines to activate the execution of recovery processing, proceeds to step S603, and determines to automatically execute recovery processing at the discretion of the monitoring device 102 without waiting for an instruction from the management device 103.

[0110] According to the above-described third embodiment, the following advantageous effects can be obtained. (11) The storage device 125 stores a second change condition for changing the instruction-received recovery to the self-determined recovery for each anomaly type. When the second change condition is met, the recovery process determination unit 130 changes the interpretation of the instruction-received recovery to the self-determined recovery. Therefore, the execution of the recovery process for the occurred anomaly can be dynamically switched from execution based on a command from the management device 103 to automatic execution based on the judgment of the monitoring device 102.

[0111] (12) The second change condition is the frequency of receiving an external command to execute a recovery process for the same abnormality or the time when the abnormality was detected. Therefore, if the rate at which recovery process commands are issued for the same abnormality is high or if an abnormality is detected during a specific time period, the time required for recovery from the abnormality can be shortened by switching to automatic execution of the recovery process at the discretion of the monitoring device 102.

[0112] --Fourth embodiment-- A fourth embodiment of a communication system will be described with reference to Figures 15 and 16. In the following description, the same components as those in the first embodiment are denoted by the same reference numerals, and differences will be mainly described. Points that are not particularly described are the same as those in the first embodiment. This embodiment differs from the first embodiment mainly in that the content of the recovery process executed in self-determined recovery is dynamically switched.

[0113] Assume that, even though the monitoring device 102 detects a communication disconnection with the device 101 and executes a recovery process of "restarting the communication I / F of the monitored device," the communication disconnection with the device 101 remains, and the same abnormality continues to be detected. In this case, it is possible that the problem lies not with the communication I / F 111 of the device 101, but with the communication I / F 121 of the monitoring device 102. Therefore, recovery from the communication disconnection can be expected by changing the recovery process executed by the monitoring device 102 in its self-determined recovery from "restarting the communication I / F of the monitored device" to "restarting the communication I / F of its own device." For this reason, in this embodiment, it is possible to dynamically switch the content of the recovery process that the monitoring device 102 automatically executes in response to an abnormality that has occurred.

[0114] The configurations and functions of the management device 103 and the device 101 in the fourth embodiment are the same as those in the first embodiment. The hardware configuration of the monitoring device 102 is the same as that in the first embodiment. The monitoring device 102 differs from the first embodiment in the configuration of the recovery process table 133. The processing of the recovery process determination unit 130 also differs from that in the first embodiment. The operations of the application program 126, communication processing unit 127, abnormality detection unit 128, abnormality notification unit 129, recovery process execution unit 131, and storage device management unit 134 are the same as those in the first embodiment. The configuration of the abnormality definition table 132 is also the same as that in the first embodiment.

[0115] 15 is a diagram showing an example of the recovery process table 133 in the fourth embodiment. The event ID 1301, first recovery process content 1302, first timer 1303, second recovery process content 1304, second timer 1305, self-determined recovery feasibility 1306, and invalidation condition 1307 in FIG. 15 are the same as the event ID 906, first recovery process content 907, first timer 908, second recovery process content 909, second timer 910, self-determined recovery feasibility 911, and invalidation condition 912 in the recovery process table 133 shown in FIG. 10 in the second embodiment, and therefore their description will be omitted. The recovery process table 133 in FIG. 15 has a field for activation condition 1308, and this item is the same as the activation condition 1107 shown in the recovery process table 133 in FIG. 13 in the third embodiment, and therefore its description will be omitted.

[0116] In the example shown in FIG. 15, if a communication disconnection with the device 101 ("LAN-Disconn" in FIG. 15) is detected three or more times within one hour, the recovery process determination unit 130 of the monitoring device 102 disables the automatic execution of "restarting the communication I / F of the monitored device" determined by the monitoring device 102. Instead, the automatic execution of "restarting the communication I / F of the device itself" is enabled, and the recovery process content to be taken in response to the communication disconnection is switched. In other words, if the number of times that a communication disconnection with the device 101 has been detected within the past hour is less than three, recovery is attempted by restarting the communication I / F 111 of the device 101, and if the number of detections reaches three or more, the target for restart is switched to the communication I / F 121 of the device itself. Details of this process will be described later with reference to FIG. 16.

[0117] As shown in this embodiment, when the same value is set in the invalidation condition 1307 and the activation condition 1308, the content of the recovery process to be executed when that condition is met is changed. Therefore, the same value of the invalidation condition 1307 and the activation condition 1308 in this case are specially called a "third change condition." The third change condition is a condition for changing the content of the recovery process.

[0118] Fig. 16 is a flowchart showing the processing of the recovery processing determination unit 130 in the fourth embodiment. Steps S601, S602, S603, and S604 in Fig. 16 are the same as those in Fig. 6 in the first embodiment, and steps S1001 and S1002 are the same as those in Fig. 11 in the second embodiment. Furthermore, steps S1201 and S1202 in Fig. 16 are the same as those in Fig. 14 in the third embodiment. Therefore, a description of these steps will be omitted.

[0119] For example, when the abnormality detection unit 128 of the monitoring device 102 detects a communication disconnection with the device 101 ("LAN-Disconn" in FIG. 15), the recovery process determination unit 130 of the monitoring device 102 refers to the recovery process table 133 of FIG. 15 in the processing of steps S601 to S602, and proceeds to step S1001 because the record for "Restarting the communication I / F of the monitored device" has self-determined recovery feasibility 1306 set to "OK." At this time, if a communication disconnection with the device 101 has been detected three or more times within one hour in step S1002, the invalidation condition 1307 of FIG. 15 is met (NO), and the process proceeds to step S1401.

[0120] In step S1401, the recovery process determining unit 130 of the monitoring device 102 refers to the recovery process table 133 and determines whether there is an undetermined recovery process for the detected abnormality. If there is an undetermined recovery process (YES), the recovery process determining unit 130 returns to step S601. If there is no undetermined recovery process (NO), the recovery process determining unit 130 proceeds to step S604 and instructs the recovery process executing unit 131 to execute a command from the management device 103. In the example shown in FIG. 15, there is an undetermined recovery process ("restart communication I / F of own device") for the communication disconnection with the device 101 (LAN-Disconn), so the recovery process determining unit 130 returns to step S601.

[0121] Thereafter, in the processing of steps S601 to S602, the recovery processing determination unit 130 of the monitoring device 102 again refers to the recovery processing table 133 of Fig. 15, and since automatic execution of "restarting the communication I / F of the own device" is prohibited (NO), the processing proceeds to step S1201. Furthermore, in the determination processing of step S1202, it determines that the automatic execution of "restarting the communication I / F of the own device" satisfies the enablement condition 1308 of Fig. 15 (NO), and the processing proceeds to step S603. As a result, automatic execution of "restarting the communication I / F of the own device" is determined by the judgment of the monitoring device 102, and dynamic switching of the recovery processing content is realized.

[0122] According to the above-described fourth embodiment, the following advantageous effects can be obtained. (13) The storage device 125 further stores third change conditions, which are conditions for changing the recovery process content for each anomaly type, and changed recovery process content, which is the recovery process content when the third change condition is met. The recovery process execution unit 131 executes the changed recovery process content when the third change condition is met. Therefore, the recovery process content automatically executed by the monitoring device 102 in response to the occurred anomaly can be dynamically switched. In particular, when the recovery process automatically executed by the monitoring device 102 is inappropriate and does not result in recovery, dynamically switching the recovery process content can achieve recovery from the anomaly.

[0123] The above-described configurations, functions, etc. may be realized in part or in whole by hardware, for example, by designing them as integrated circuits. Furthermore, the above-described configurations, functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function. Information such as the program, table, and file that realizes each function may be pre-recorded on a recording device such as a memory, a hard disk, or an SSD (Solid State Drive), or on a recording medium such as an IC card, SD card, or DVD, and then loaded into each device.

[0124] In each of the above-described embodiments and modifications, the functional block configurations are merely examples. Some functional configurations shown as separate functional blocks may be configured as an integrated unit, or a configuration shown in a single functional block diagram may be divided into two or more functions. Furthermore, some of the functions of each functional block may be provided by other functional blocks.

[0125] The above-described embodiments and modifications may be combined with each other. Although various embodiments and modifications have been described above, the present invention is not limited to these. Other embodiments conceivable within the scope of the technical concept of the present invention are also included within the scope of the present invention. [Explanation of symbols]

[0126] 101:Equipment 102: Monitoring device 103: Management device 123: Input section 124: Output section 125: Storage device 127: Communication processing unit 128: Abnormality detection unit 129: Abnormality notification section 130: Recovery process determination unit 131: Recovery processing execution unit 132: Anomaly definition table 133: Recovery process table

Claims

1. A monitoring device that monitors one or more devices to be monitored, an abnormality detection unit that detects an abnormality occurring in the device; an abnormality notification unit that outputs the detected abnormality to an external device as an abnormality notification; a recovery process determination unit that determines a recovery type, which is a type of recovery, according to an abnormality type, to be either a self-determined recovery in which the content of a recovery process for the device is determined by the monitoring device, or an instruction-received recovery in which the content of a recovery process for the device is determined by an external device of the monitoring device; a recovery process execution unit that executes a recovery process for the device based on the determination of the recovery type by the recovery process determination unit; a storage device that stores anomaly definitions that are definitions of the anomaly types, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each anomaly type, and a recovery process content that is a content of the recovery process for each anomaly type that is the self-determined recovery, The storage device further stores a first change condition for changing the self-determined recovery to the instruction reception recovery in the self-determined recovery possibility for each of the abnormality types, The recovery process determination unit is a monitoring device that, when the first change condition is met, changes the self-determined recovery possibility to the instruction reception recovery.

2. The monitoring device according to claim 1, The first change condition includes at least one of a detection frequency for the same abnormality, a time when the abnormality is to be detected, and a time period when the abnormality is to be detected.

3. A monitoring device that monitors one or more devices to be monitored, an abnormality detection unit that detects an abnormality occurring in the device; an abnormality notification unit that outputs the detected abnormality to an external device as an abnormality notification; a recovery process determination unit that determines a recovery type, which is a type of recovery, according to an abnormality type, to be either a self-determined recovery in which the content of a recovery process for the device is determined by the monitoring device, or an instruction-received recovery in which the content of a recovery process for the device is determined by an external device of the monitoring device; a recovery process execution unit that executes a recovery process for the device based on the determination of the recovery type by the recovery process determination unit; a storage device that stores anomaly definitions that are definitions of the anomaly types, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each anomaly type, and a recovery process content that is a content of the recovery process for each anomaly type that is the self-determined recovery, The storage device further stores a second change condition for changing the instruction reception recovery to the self-determined recovery in the self-determined recovery possibility for each of the abnormality types, The recovery process determination unit changes the self-determined recovery possibility to the self-determined recovery when the second change condition is met.

4. The monitoring device according to claim 3, The second change condition includes at least one of a frequency of receiving an execution command for the recovery process from outside for the same abnormality, and a time when the abnormality was detected.

5. The monitoring device according to claim 1 or 3, The monitoring device further stores in the storage device a timer indicating a grace period until the recovery process is executed for each of the abnormality types.

6. The monitoring device according to claim 5, The monitoring device further includes a storage device management unit that records at least one of the abnormality definition, the self-determined recovery possibility, the recovery processing content, the content of the abnormality notification for each abnormality type, and the timer in the storage device based on an external input.

7. The monitoring device according to claim 1 or 3, The storage device further stores a third change condition, which is a condition for changing the recovery process content for each of the abnormality types, and a changed recovery process content, which is a content of the recovery process when the third change condition is met, The recovery process execution unit executes the changed recovery process content when the third change condition is met.

8. The monitoring device according to claim 1 or 3, the storage device further stores a fourth change condition, which is a condition for changing the content of the abnormality notification for each abnormality type, and a changed notification content, which is the content of the abnormality notification when the fourth change condition is met; The abnormality notification unit outputs the changed notification content when the fourth change condition is met.

9. The monitoring device according to claim 1 or 3, When the recovery process determination unit determines that the instruction reception recovery should be performed, the recovery process execution unit waits until the content of the recovery process for the equipment is instructed from outside, and immediately executes the content of the recovery process for the equipment when it is instructed from outside.

10. A management device capable of communicating with the monitoring device according to claim 1 or 3, an abnormality notification management unit that receives the abnormality notification output by the monitoring device; a recovery process command unit that outputs the content of the recovery process determined based on the abnormality notification to the monitoring device.

11. The management device according to claim 10, further comprising an output unit that presents information to a user; The abnormality notification management unit determines whether the abnormality notification received from the monitoring device is the self-determined recovery or the instruction-received recovery, and changes the output to the output unit based on the determination.

12. A communication system including a monitoring device that monitors one or more devices to be monitored, and a management device that can communicate with the monitoring device, The monitoring device an abnormality detection unit that detects an abnormality occurring in the device; an abnormality notification unit that outputs the detected abnormality to an external device as an abnormality notification; a recovery process determination unit that determines a recovery type, which is a type of recovery, according to an abnormality type, to be either a self-determined recovery in which the content of a recovery process for the device is determined by the monitoring device or an instruction-received recovery in which the content of a recovery process for the device is determined by an external device of the monitoring device; a recovery process execution unit that executes recovery process of the device based on the determination of the recovery type by the recovery process determination unit, The management device an abnormality notification management unit that receives the abnormality notification output by the monitoring device; a recovery process command unit that outputs the content of the recovery process determined based on the abnormality notification to the monitoring device, a storage device for storing anomaly definitions that are definitions of the anomaly types, whether self-determined recovery is possible for each anomaly type, which indicates whether the self-determined recovery is possible or whether the instruction reception recovery is possible, and recovery process content that is the content of the recovery process for each anomaly type that is the self-determined recovery, The storage device further stores a first change condition for changing the self-determined recovery to the instruction reception recovery in the self-determined recovery possibility for each of the abnormality types, The recovery process determination unit changes the self-determined recovery possibility to the instruction reception recovery when the first change condition is met.

13. A communication system including a monitoring device that monitors one or more devices to be monitored, and a management device that can communicate with the monitoring device, The monitoring device an abnormality detection unit that detects an abnormality occurring in the device; an abnormality notification unit that outputs the detected abnormality to an external device as an abnormality notification; a recovery process determination unit that determines a recovery type, which is a type of recovery, according to an abnormality type, to be either a self-determined recovery in which the content of a recovery process for the device is determined by the monitoring device or an instruction-received recovery in which the content of a recovery process for the device is determined by an external device of the monitoring device; a recovery process execution unit that executes recovery process of the device based on the determination of the recovery type by the recovery process determination unit, The management device an abnormality notification management unit that receives the abnormality notification output by the monitoring device; a recovery process command unit that outputs the content of the recovery process determined based on the abnormality notification to the monitoring device, a storage device for storing anomaly definitions that are definitions of the anomaly types, whether self-determined recovery is possible for each anomaly type, which indicates whether the self-determined recovery is possible or whether the instruction reception recovery is possible, and recovery process content that is the content of the recovery process for each anomaly type that is the self-determined recovery, The storage device further stores a second change condition for changing the instruction reception recovery to the self-determined recovery in the self-determined recovery possibility for each of the abnormality types, When the second change condition is met, the recovery process determination unit changes the self-determined recovery possibility to the self-determined recovery.

14. A recovery method executed by a monitoring device that monitors one or more devices to be monitored, comprising: an abnormality detection step of detecting an abnormality occurring in the device; an abnormality notification step of outputting the detected abnormality as an abnormality notification to the outside; a recovery process determination step of determining a recovery type, which is a type of recovery, to either a self-determined recovery in which the monitoring device determines the content of the recovery process for the device, or an instruction-received recovery in which the content of the recovery process for the device is determined by an external device of the monitoring device, according to the abnormality type, which is a type of the abnormality; a recovery processing execution step of executing a recovery processing of the device based on the determination of the recovery type by the recovery processing determination step, the monitoring device further includes a storage device that stores an abnormality definition that is a definition of each of the abnormality types, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each of the abnormality types, and a recovery process content that is a content of the recovery process for each of the abnormality types that is the self-determined recovery, The storage device further stores a first change condition for changing the self-determined recovery to the instruction reception recovery in the self-determined recovery possibility for each of the abnormality types, In the recovery method, when the first change condition is met, the recovery process determination step changes the self-determined recovery possibility to the instruction reception recovery.

15. A recovery method executed by a monitoring device that monitors one or more devices to be monitored, comprising: an abnormality detection step of detecting an abnormality occurring in the device; an abnormality notification step of outputting the detected abnormality as an abnormality notification to the outside; a recovery process determination step of determining a recovery type, which is a type of recovery, to either a self-determined recovery in which the monitoring device determines the content of the recovery process for the device, or an instruction-received recovery in which the content of the recovery process for the device is determined by an external device of the monitoring device, according to the abnormality type, which is a type of the abnormality; a recovery processing execution step of executing a recovery processing of the device based on the determination of the recovery type by the recovery processing determination step, the monitoring device further includes a storage device that stores an abnormality definition that is a definition of each of the abnormality types, a self-determined recovery possibility indicating whether the self-determined recovery is the self-determined recovery or the instruction reception recovery for each of the abnormality types, and a recovery process content that is a content of the recovery process for each of the abnormality types that is the self-determined recovery, The storage device further stores a second change condition for changing the instruction reception recovery to the self-determined recovery in the self-determined recovery possibility for each of the abnormality types, In the recovery method, when the second change condition is met, the recovery process determination step changes the self-determined recovery possibility to the self-determined recovery.

Citation Information

Patent Citations

  • System monitoring device

    JP1996179969A

  • Center monitoring system for distributed system

    JP1999096043A

  • Monitoring system

    JP2005339015A

  • Information processor and failure recovery method

    JP2012079212A

  • Power supply control system of network device and method thereof

    JP2021072076A