Log inquiry device, log inquiry method, and log inquiry program
The log inquiry device provides accurate visualization and correction tools for automatic abnormality determination execution logs, addressing errors and reducing manual checks, thus enhancing efficiency and accuracy in business data processing.
Patent Information
- Application Number
- JP2022212763
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-12-28
AI Technical Summary
Existing systems fail to accurately check the execution logs of automatic abnormality determination for business data, leading to difficulties in identifying errors, missed checks, and increased costs due to manual recalculation and screen transitions.
A log inquiry device and method that visualizes execution logs with detailed data, including execution IDs, dates, and statuses, allowing for accurate checking of abnormality detection processes and enabling direct transition to correction screens.
Enables high-accuracy checking of abnormality determination execution logs, reducing the risk of missed errors and manual recalculations, and facilitating faster problem identification and correction.
Smart Images

Figure 0007791076000001 
Figure 0007791076000002 
Figure 0007791076000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a log inquiry device, a log inquiry method, and a log inquiry program. [Background technology]
[0002] In recent years, there has been an increasing trend of fraudulent acts being committed against business data such as accounting and subsidiary ledgers, and there are systems that automatically detect abnormalities in business data. Because the system processes data automatically, it is important to be able to check whether the processing was normal. For example, Patent Document 1 discloses a conventional log inquiry system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-062243 Summary of the Invention [Problem to be solved by the invention]
[0004] However, Patent Document 1 does not describe anything about checking the execution log of automatic execution of abnormality determination for business data with high accuracy.
[0005] The present invention has been made in consideration of the above, and aims to provide a log inquiry device, a log inquiry method, and a log inquiry program that are capable of checking the execution log of automatic execution of abnormality judgment for business data with high accuracy. [Means for solving the problem]
[0006] In order to solve the above-mentioned problems and achieve the object, the present invention provides a log inquiry device that includes a control unit and queries a log of a processing result of automatic execution of abnormality judgment on business data, wherein the control unit collects abnormality judgment execution log data, which is a log of a processing status related to automatic execution of abnormality judgment 1 processing, and includes an execution ID, an execution date and time, and a status indicating whether abnormality detection has been performed normally; This is a log of the processing status of anomaly judgment and schedule judgment units performed within the automatic execution 1 process of anomaly judgment, and includes the detailed data of the anomaly judgment execution log, including the execution detail ID, execution ID, processing type that is the executed definition, status, schedule definition ID, and anomaly judgment definition ID. This is a log of the detailed processing units associated with each of the anomaly judgment and schedule judgment performed within the automatic execution 1 process of anomaly judgment, and includes details that hold the log ID, status, message indicating the processing content, executed definition ID, and error cause message in the event of an error, and log update information that holds the definition information that was processed when the log was updated. and abnormality determination log data including the original, execution detail ID, and update date and time, and on the log inquiry screen, by referring to the abnormality determination execution log data and the abnormality determination execution log detail data, a list of execution logs is displayed in a log list display area, with one process of automatic abnormality detection execution as one detail, and a detail screen of an execution log selected by an operator is displayed in the log list display area, and on the detail screen, log inquiry means is provided which extracts data from the abnormality determination log data using the execution detail ID linked to the execution ID as a key, and displays the processing details and their status.
[0007] According to another aspect of the present invention, when the log inquiry means displays a list of execution logs in the log list display area, the log inquiry means may display the execution dates and times in descending order of the execution dates and times.
[0008] According to another aspect of the present invention, the log inquiry means may group and display the processes performed in the selected execution log on the detail screen.
[0009] Furthermore, according to one aspect of the present invention, the log inquiry means may launch a setting screen for an abnormal value definition linked to the abnormality determination definition ID of the abnormality determination execution log detail data and the log update source of the abnormality determination log data for a process selected by an operator in the process details on the detail screen.
[0010] Furthermore, in order to solve the above-mentioned problems and achieve the object, the present invention provides a log inquiry method executed by an information processing device having a control unit, wherein the control unit receives abnormality judgment execution log data, which is a log of processing status related to automatic execution 1 anomaly judgment processing and includes an execution ID, execution date and time, and a status indicating whether abnormality detection has been performed normally or not; abnormality judgment execution log detail data, which is a log of processing status of an abnormality judgment / schedule judgment unit performed in automatic execution 1 anomaly judgment processing and includes an execution detail ID, execution ID, processing type which is an executed definition, status, schedule definition ID, and abnormality judgment definition ID; and logs of detailed processing units linked to each of abnormality judgment / schedule judgment performed in automatic execution 1 anomaly judgment processing and includes a log ID, status, and message indicating processing content. and abnormality determination log data including an execution page, details that hold the executed definition ID and the error cause message when an error occurs, the log update source that holds the definition information that was processed when updating the log, an execution detail ID, and the update date and time, and the control unit executes a log inquiry screen that refers to the abnormality determination execution log data and the abnormality determination execution log detail data, displays a list of execution logs in a log list display area, with one process of automatic abnormality detection execution as one detail, and displays a detail screen of an execution log selected by an operator in the log list display area, and on the detail screen, extracts data from the abnormality determination log data using the execution detail ID linked to the execution ID as a key, and displays a breakdown of the processing and its status.
[0011] Furthermore, in order to solve the above-mentioned problems and achieve the object, the present invention provides a log inquiry program to be executed by an information processing device having a control unit, the control unit including: anomaly judgment execution log data, which is a log of processing status related to automatic abnormality judgment execution 1 processing, and includes an execution ID, execution date and time, and a status indicating whether abnormality detection was performed normally; anomaly judgment execution log detail data, which is a log of processing status of anomaly judgment / schedule judgment units performed in automatic abnormality judgment execution 1 processing, and includes an execution detail ID, execution ID, processing type which is an executed definition, status, schedule definition ID, and anomaly judgment definition ID; and a log of detailed processing units linked to each of the abnormality judgment / schedule judgments performed in automatic abnormality judgment execution 1 processing, and includes a log ID, status, and a message indicating processing content. and abnormality determination log data including details that hold the executed definition ID and the error cause message in the event of an error, the log update source that holds the definition information that was processed when updating the log, an execution detail ID, and the update date and time, and the control unit refers to the abnormality determination execution log data and the abnormality determination execution log detail data on the log inquiry screen, displays a list of execution logs in a log list display area, with one process of automatic abnormality detection execution as one detail, displays a detail screen of the execution log selected by the operator in the log list display area, and on the detail screen, extracts data from the abnormality determination log data using the execution detail ID linked to the execution ID as a key, and displays the processing details and its status. [Effects of the Invention]
[0012] The present invention provides an advantage in that it is possible to check the execution log of automatic execution of abnormality determination for business data with high accuracy. [Brief explanation of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram for explaining the problem (1) of the present invention. [Figure 2] FIG. 2 is a diagram for explaining the problem (2) of the present invention. [Figure 3] FIG. 3 is a diagram for explaining the problem (3) of the present invention. [Figure 4] FIG. 4 is a diagram for explaining the problem (4) of the present invention. [Figure 5] FIG. 5 is a block diagram showing an example of the configuration of a log inquiry device according to this embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of the configuration of the abnormality determination definition master. [Figure 7] FIG. 7 is a diagram illustrating an example of the configuration of the data acquisition definition master. [Figure 8] FIG. 8 is a diagram illustrating an example of the configuration of the schedule determination definition master. [Figure 9] FIG. 9 is a diagram illustrating an example of the configuration of the schedule determination definition mapping master. [Figure 10] FIG. 10 is a diagram illustrating an example of the configuration of the abnormality determination execution log data. [Figure 11] FIG. 11 is a diagram showing an example of the structure of the abnormality determination execution log detail data. [Figure 12] FIG. 12 is a diagram illustrating an example of the configuration of the abnormality determination log data. [Figure 13] FIG. 13 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 14A] FIG. 14A is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 14B] FIG. 14B is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 14C] FIG. 14C is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 15] FIG. 15 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 16] FIG. 16 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 17]FIG. 17 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 18] FIG. 18 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 19A] FIG. 19A is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 19B] FIG. 19B is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 19C] FIG. 19C is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 20] FIG. 20 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 21] FIG. 21 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 22] FIG. 22 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 23] FIG. 23 is a diagram for explaining a specific example of the processing of the control unit of the log inquiry device according to this embodiment. [Figure 24A] FIG. 24A is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. [Figure 24B] FIG. 24B is a diagram for explaining a specific example of the process of the control unit of the log inquiry device according to this embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0014] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described in detail with reference to the accompanying drawings. However, the present invention is not limited to this embodiment.
[0015] [1. Overview] The outline of the present invention will be explained in the order of background, issues and measures.
[0016] (1-1. Background) In recent years, there has been an increasing trend of fraudulent activity in business data such as accounting and subsidiary ledgers. To address this, there is a demand for a system that can automatically detect anomalies in business data. Since it is necessary to check for anomalies from a huge amount of data, manual checking is difficult and the system's accuracy is relied upon. Since a system that automatically detects whether something is normal and as expected is required, it is desirable to be able to track execution results in detail. To address this, the present invention is equipped with a function that allows detailed checking of execution logs.
[0017] (1-2. Issues / measures) The problems (1) to (4) of the present invention and the measures taken to address them will be described with reference to Figures 1 to 4. Figures 1 to 4 are diagrams for explaining the problems (1) to (4) of the present invention, the measures taken to address them, and an overview of their functions.
[0018] (1) Issue (1) When anomaly detection is not performed correctly, it takes time to identify the cause of the error. Specifically, if an error occurs during the anomaly detection process, the anomaly detection result is not included in the data, so it cannot be noticed immediately. It is necessary to check where the error occurred, which increases the risk of overlooking the error and takes time. In addition, if internal calculations are required to detect an anomaly, manual recalculation is required, which increases the risk of calculation errors and oversights.
[0019] To address this issue, the present invention visualizes the execution log of abnormality determination. Specifically, it is possible to check whether a process has been completed correctly in small units on a single screen, and also to extract and check only the data of the abnormality determination process in which an error has occurred.
[0020] This allows you to quickly grasp the processing status, such as whether any errors have occurred, and makes it possible to grasp whether errors have occurred in small processing units.
[0021] (2) Issues (2) There is a problem in that it is difficult to confirm whether anomaly detection was performed as planned at the expected time, or whether anomaly detection was performed at an unexpected time. Specifically, if an anomaly detection that should have been performed is not performed, the anomaly detection result is not recorded in the data, so it cannot be noticed immediately, and it is necessary to manually trace the execution log data, which can lead to missed checks and is costly to check. If an anomaly detection that should not have been performed is performed, it requires time-consuming confirmation, such as checking the definition to see if it is set to not be performed in the first place. If the definition has been intentionally changed manually to run on a day when no anomalies occur, the only way to notice is to check the definition, making it difficult to notice.
[0022] To address this issue, the present invention visualizes the execution date of each anomaly detection process. Specifically, by outputting the anomaly detection execution log in descending order of execution date, it is possible to check whether any process has been missed.
[0023] This allows you to notice if a process is not being executed at the date and time it is supposed to be executed, and also if an abnormality judgment is being made at an unexpected timing.
[0024] (3) Issues (3) There is an issue of difficulty in confirming whether anomaly detections are made in the expected order. Specifically, when checking whether detections are made in the predetermined order of anomaly detection, if data processing is inserted during anomaly detection, manual calculations and checks are required to ensure that processing is performed as expected, and manual tracing of execution log data is required, which can lead to missed checks and increases the cost of checking.
[0025] To address this issue, the present invention visualizes the processes performed in a single automatic execution as a group. Specifically, it makes it possible to check all at once whether the expected abnormality detection within a single process is being performed correctly.
[0026] This makes it possible to check whether processing is being performed correctly in the order of the definitions registered in the abnormal value definition master maintenance. Specifically, when multiple abnormality judgments are performed in one process, it is possible to notice if some of the expected definitions have been omitted and if an unexpected definition has been executed.
[0027] (4) Issues (4) If there is a problem with the definition for abnormality judgment, there is a problem in that it is necessary to compare the execution log with the master maintenance setting value to confirm and correct the problematic part. Specifically, the following steps are required: 1. Check the execution log, 2. Start the abnormal value definition master maintenance, 3. Display the abnormality judgment definition in question, 4. Compare with the execution log to confirm and correct the problematic part.
[0028] This requires comparing multiple screens, and since this work is done manually, there is a risk of errors and it takes time.
[0029] To address this issue, the present invention allows users to transition from the screen where the execution log is being checked to the abnormal value definition master maintenance screen, which displays the definition in question. This allows users to immediately transition to a screen where they can correct the definition linked to the problematic log and make the correction.
[0030] This allows for faster problem identification and correction. Although there are screen transitions, processing is generally completed within one screen, so there is less need to switch between viewpoints (preventing confirmation errors).
[0031] The log inquiry device of the present invention is applicable to all business types and industries.
[0032] [2. Configuration] An example of the configuration of the log inquiry device 100 according to this embodiment will be described with reference to Fig. 5. Fig. 5 is a block diagram showing an example of the configuration of the log inquiry device 100.
[0033] The log inquiry device 100 is a commercially available desktop personal computer. Note that the log inquiry device 100 is not limited to a stationary information processing device such as a desktop personal computer, but may also be a portable information processing device such as a commercially available notebook personal computer, a PDA (Personal Digital Assistant), a smartphone, or a tablet personal computer.
[0034] The log inquiry device 100 includes a control unit 102, a communication interface unit 104, a storage unit 106, and an input / output interface unit 108. The units included in the log inquiry device 100 are connected to each other so as to be able to communicate with each other via any communication path.
[0035] The communication interface unit 104 communicatively connects the log inquiry device 100 to a network 300 via a communication device such as a router and a wired or wireless communication line such as a dedicated line. The communication interface unit 104 has a function of communicating data with other devices via the communication line. Here, the network 300 has a function of communicatively connecting the log inquiry device 100, the server 200, and the business system 400, and is, for example, the Internet or a local area network (LAN). The business system 400 is configured to be able to communicate data with the log inquiry device 100 via the network 300. The business system 400 generates various business data such as cost data, manufacturing data, order data, purchase data, sales data, and journal data. The anomaly detection unit 102b of the log inquiry device 100 automatically detects (determines) anomalies in this business data.
[0036] An input device 112 and an output device 114 are connected to the input / output interface unit 108. The output device 114 may be a monitor (including a home television), a speaker, or a printer. The input device 112 may be a keyboard, a mouse, a microphone, or a monitor that cooperates with a mouse to achieve a pointing device function. Note that, hereinafter, the output device 114 may be referred to as the monitor 114, and the input device 112 may be referred to as the keyboard 112 or the mouse 112. Displaying information on the monitor 114 and the user operating the input device 112 may be referred to as a "user operation via a UI."
[0037] Various databases, tables, files, etc. are stored in the storage unit 106. Computer programs that work in conjunction with an OS (Operating System) to issue commands to a CPU (Central Processing Unit) to perform various processes are recorded in the storage unit 106. The storage unit 106 can be, for example, a memory device such as a RAM (Random Access Memory) or a ROM (Read Only Memory), a fixed disk device such as a hard disk, a flexible disk, an optical disk, etc.
[0038] The storage unit 106 stores an abnormality determination definition master 106a, a data acquisition definition master 106b, a schedule determination definition master 106c, a schedule determination definition mapping master 106d, other masters 106e, abnormality determination execution log data, abnormality determination execution log detail data, abnormality determination log data, etc. FIG. 6 is a diagram showing an example of the configuration of the abnormality determination definition master 106a. FIG. 7 is a diagram showing an example of the configuration of the data acquisition definition master 106b. FIG. 8 is a diagram showing an example of the configuration of the schedule determination definition master 106c. FIG. 9 is a diagram showing an example of the configuration of the schedule determination definition mapping master 106d. FIG. 10 is a diagram showing an example of the configuration of the abnormality determination execution log data. FIG. 11 is a diagram showing an example of the configuration of the abnormality determination execution log detail data. FIG. 12 is a diagram showing an example of the configuration of the abnormality determination log data.
[0039] The abnormality determination definition master 106a is a master that sets abnormality determination definitions and is used to manage the definitions of abnormality determination in business data. As shown in Fig. 6, the abnormality determination definition master 106a can be configured from a table or the like that associates and registers abnormality determination definition IDs, abnormality determination definition names, data acquisition definition IDs, preprocessing definition IDs, aggregation condition IDs, change point definition IDs, used algorithm / parameter / extraction condition definition IDs, and abnormality degree rank definition IDs. In the example shown in the figure, the first line contains the abnormality determination definition ID "JD001," the abnormality determination definition name "inventory turnover alert," and the data acquisition definition ID "JDS01."
[0040] The data acquisition definition master 106b is a master that sets data acquisition definitions and is used to manage detailed data on the data acquisition definition IDs of the anomaly determination definition master 106a. It is used to manage definitions for acquiring data used when making anomaly determinations. As shown in Figure 7, the data acquisition definition master 106b can be configured as a table or the like that associates and registers data acquisition definition IDs, data acquisition definition names, and data acquisition stored names. In the example shown in the figure, the first line contains the data acquisition definition ID "JDS01", the data acquisition definition name "Acquire inventory turnover data by product", and the data acquisition stored name "pr_".
[0041] The schedule determination definition master 106c is a master that sets schedule determination definitions and is used to manage the timing of executing the definitions of abnormality determination on business data. As shown in Fig. 8, the schedule determination definition master 106c can be configured as a table or the like that associates and registers schedule definition IDs, schedule definition names, execution timings, etc. In the example shown in the same figure, the first line contains the schedule definition ID "SC001," the schedule definition name "Inventory abnormality determination execution schedule," and the execution timing "5th business day at the beginning of the month."
[0042] The schedule determination definition mapping master 106d is a master for managing the association between anomaly determination definitions and schedule determination definitions. As shown in Fig. 9, the schedule determination definition mapping master 106d can be configured as a table in which schedule definition IDs and anomaly determination definition IDs are registered in association with each other. In the example shown in the same figure, the first row contains the schedule definition ID "SC001" and the anomaly determination definition ID "JD001."
[0043] The other masters 106e include a preprocessing definition master that sets preprocessing definitions, an aggregation definition master that sets aggregation definitions, a change point definition master that sets change point definitions, a usage algorithm, parameter, and extraction condition definition master that sets usage algorithm, parameter, and extraction condition definitions, an abnormality rank definition master that sets abnormality rank definitions, a message definition master that specifies message definitions, and a result table definition master that sets result table definitions.
[0044] The abnormality determination execution log data is data for managing processing status log data related to the automatic execution 1 process of abnormality determination. The abnormality determination execution log data may include an execution ID, execution date and time, and status, as shown in FIG. 10. In the example shown in the same figure, the first line contains the execution ID "EX001", the execution date and time "2022 / 5 / 5 23:00:00", and the status "Abnormality determination execution completed".
[0045] The detailed abnormality judgment execution log data is data for managing the processing status log data for abnormality judgment and schedule judgment units performed within the automatic execution 1 process of abnormality judgment. As shown in Figure 11, the detailed abnormality judgment execution log data may include an execution detail ID, an execution ID, a processing category, a status, a schedule definition ID, and an abnormality judgment definition ID. The "processing category" is the category of the executed definition (executing the definition of abnormal value judgment or executing the definition of schedule judgment). The "schedule definition ID" is a key item of the schedule judgment definition master 106c, and links the log with the data of the schedule judgment definition master 106c. The "abnormality judgment definition ID" is a key item of the abnormality judgment definition master 106a, and links the log with the data of the abnormality judgment definition master 106a. In the example shown in the same figure, the first line contains the execution detail ID "EXD001," the execution ID "EX001," the processing category "schedule judgment," the status "execution completed," and the schedule definition ID "SC001."
[0046] The abnormality determination log data is data for managing the execution log data of the detailed processing unit linked to each abnormality determination and schedule determination performed within the automatic execution 1 process of abnormality determination. As shown in Figure 12, the abnormality determination log data may include the log ID, status, message, details, log update source, execution detail ID, and update date and time. The "log ID" is the identification number of the log. The "details" is used to hold information in the form of messages that contain the details of the processing (holding the executed definition ID and the error cause message in the case of an error). The "log update source" holds the definition information that was being processed when the log was updated, and in the case of an error, holds information about the definition that caused the error.
[0047] The control unit 102 is a CPU or the like that performs overall control of the log inquiry device 100. The control unit 102 has an internal memory for storing control programs such as an OS, programs that define various processing procedures, required data, etc., and executes various information processing operations based on these stored programs.
[0048] The control unit 102 is configured to be able to access the abnormality determination definition master 106a, the data acquisition definition master 106b, the schedule determination definition master 106c, the schedule determination definition mapping master 106d, the other master 106e, the abnormality determination execution log data, the abnormality determination execution log detail data, the abnormality determination log data, and the like, which are stored in the storage unit 106. Note that these masters and data may be provided in other locations (for example, the server 200), as long as they are accessible by the control unit 102.
[0049] The control unit 102 conceptually includes a master maintenance unit 102a, an abnormality detection unit 102b, a log inquiry unit 102c, and a screen display control unit 102d.
[0050] The master maintenance unit 102a sets definitions (data) for the abnormality determination definition master 106a, the data acquisition definition master 106b, the schedule determination definition master 106c, the schedule determination definition mapping master 106d, other masters 106e, etc., in accordance with, for example, an operator's operation on a master maintenance screen (not shown) displayed on the monitor 114.
[0051] The abnormality detection unit 102b performs automatic abnormality detection for various business data generated by the business system 400 in accordance with definitions such as the abnormality determination definition master 106a, the data acquisition definition master 106b, the schedule determination definition master 106c, the schedule determination definition mapping master 106d, and other masters 106e, and registers the processing results in the memory unit 106 as abnormality determination execution log data, abnormality determination execution log detail data, and abnormality determination log data.
[0052] The log inquiry unit 102c refers to the abnormality determination execution log data and the abnormality determination execution log detail data on the log viewer (list) screen (log inquiry screen) displayed on the monitor 114, displays a list of execution logs in the log list display area, with one process of automatic abnormality detection execution being one detail, and displays the log viewer (details) screen (details screen) of the execution log selected by the operator in the log list display area.On the log viewer (details) screen, data is extracted from the abnormality determination log data using the execution detail ID linked to the execution ID as a key, and the processing details and their status are displayed.
[0053] Furthermore, when displaying a list of execution logs in the log list display area, the log inquiry unit 102c may display the execution dates and times in descending order of the execution dates and times.
[0054] Furthermore, the log inquiry unit 102c may group and display the processes performed in the selected execution log on the log viewer (details) screen.
[0055] In addition, the log inquiry unit 102c may launch a setting screen (master maintenance screen) for the abnormal value definition linked to the abnormality determination definition ID of the abnormality determination execution log detail data and the log update source of the abnormality determination log data for the process selected by the operator in the process details on the log viewer (details) screen.
[0056] The screen display control unit 102d controls the display of various screens (for example, a log list screen, a log detail screen, etc.) displayed on the monitor 114 and the inputs thereto.
[0057] [3. Specific Examples] 13 to 24B, a specific example of the processing performed by the control unit 102 of the log inquiry device 100 in this embodiment will be described. Figures 13 to 24B are diagrams for explaining a specific example of the processing performed by the control unit 102 of the log inquiry device 100 in this embodiment.
[0058] (3-1. Automatic Anomaly Detection) The automatic abnormality detection executed by the abnormality detection unit 102b will be described with reference to FIGS.
[0059] FIG. 13 is a diagram showing a list of definitions used by the anomaly detection unit 102b. The schedule definition defines when and under what conditions an anomaly determination is to be made. The data acquisition definition defines the method of acquiring target data for anomaly determination. The preprocessing definition defines data processing that must be performed before anomaly determination (e.g., filling numeric items with no data with fixed 0). The aggregation definition defines data aggregation that must be performed before anomaly determination (e.g., aggregating sales amounts by business location as subtotals). The change point definition defines the method of checking changes on the time series axis of target data for anomaly determination.
[0060] The algorithm, parameters, and extraction condition definitions define the method for determining anomalies and the threshold for determining anomalies separately for data after an anomaly determination has been made (for example, only sales of 1,000 yen or more that are abnormally high compared to past sales are targeted). The anomaly rank definition defines the degree of anomaly (impact on the company) for data after an anomaly determination has been made. The message definition defines the message text to be used to explain the data after an anomaly determination has been made. The result table definition defines the table that will store the data after an anomaly determination has been made.
[0061] 14A to 14C are diagrams showing the processing flow of automatic abnormality determination executed by the abnormality detection unit 102b, and also show the definitions used, the abnormality determination execution log data, the abnormality determination execution log detail data, and the transition of the abnormality determination log data.
[0062] 14A to 14C, first, in step S1, when the abnormality determination process is started, a definition of the abnormality determination to be executed is obtained, and in step S2, data to be used for the determination is obtained based on the data acquisition definition.
[0063] In step S3, preprocessing such as missing data interpolation and standardization and data aggregation are performed based on the preprocessing definition and aggregation conditions. In step S4, change points in the time series data are detected based on the change point definition.
[0064] In step S5, anomaly detection is performed based on the definition of the algorithm, parameters, extraction conditions, and anomaly rank definition, using statistically calculated thresholds or arbitrarily specified thresholds. At this time, ranking according to the degree of anomaly is also performed.
[0065] In step S6, the judgment result is updated based on the message definition and the result table definition, and additional information is also updated. Then, in step S7, the process ends.
[0066] Next, assumed patterns in which errors occur in the processing flow will be described with reference to Figures 15 and 16. Various patterns are possible, but one assumed pattern will be described below. Examples of assumed patterns include (1) the structure of the table (master) assumed for use has been changed in an unintended way, and (2) the data acquisition conditions assumed for use have been changed in an unintended way.
[0067] (1) Referring to Figure 15, we will explain a pattern in which the format of the table used in the anomaly judgment definition and schedule definition has changed between when the definition was set and when the judgment was executed. For example, if the table structure is changed by an external batch process for some reason, an error will occur if the definition and the actual table do not match.
[0068] (2) Referring to Figure 16, we will explain a pattern in which the arguments and return values for data acquisition used when executing anomaly judgment are changed between when the definition is set and when the judgment is executed. For example, if for some reason the structure is changed by manipulating the arguments and return values in an external batch process, an error will occur if the definition and the actual arguments and return values are not consistent.
[0069] (3-2. Log inquiry) 17 to 24B, the log inquiry executed by the log inquiry unit 102 will be described in detail. A log viewer (list) screen (initial log screen) will be described with reference to Fig. 17. The log viewer (list) screen displays a list of execution logs, with one process in the automatic execution of abnormality determination by the abnormality detection unit 102b being one detail.
[0070] 17 is a diagram showing a display example of the log viewer (list) screen 50. The diagram shows which columns of the abnormality determination execution log data, the abnormality determination execution log detail data, the abnormality determination definition master 106a, and the schedule determination definition master 106c are referenced to extract data.
[0071] The log viewer (list) screen 50 includes an extraction condition specification area 51 and a log list display area 52. The extraction condition specification area 51 includes extraction condition input fields for the execution date, abnormality determination definition name, and abnormality determination schedule definition name, and a display button.
[0072] When extraction conditions are specified and the display button is pressed, the execution logs that meet the extraction conditions are extracted as abnormality determination execution log data and abnormality determination execution log detail data, and displayed in the log list display area 52. The execution logs are displayed in the log list display area 52 with one process in the automatic abnormality determination execution (each execution ID unit of the abnormality determination execution log data) as one detail. If no extraction conditions are specified, all execution logs are displayed. The example shown in Figure 17 shows a case where no extraction conditions are specified.
[0073] If "Execution date" is specified, records corresponding to the execution date and time of the abnormality judgment execution log data are extracted. If "Abnormality judgment definition name" is specified, the abnormality judgment definition ID of the abnormality judgment definition name specified from the abnormality judgment definition master 106a is obtained, and records with the abnormality judgment definition ID obtained from the abnormality judgment execution log detailed data are extracted. If "Abnormality judgment schedule definition name" is specified, the schedule definition ID of the schedule definition name specified from the schedule judgment definition master 106c is obtained, and records with the schedule definition ID obtained from the abnormality judgment execution log detailed data are extracted.
[0074] The display in the log list display area 52 can be switched using a switch button (display all, display errors, display normal). In the log list display area 52, for each detail, a normal icon indicating normal completion or an error icon indicating that an error has occurred is displayed on the left side, the status and execution time of the abnormality determination execution log data are displayed on the first line, and the abnormality determination definition name or schedule definition name (executed definition) of the abnormality determination definition master 106a or schedule determination definition master 106c linked to the abnormality determination definition ID or schedule definition ID of the abnormality determination execution log detail data is displayed on the second line.
[0075] The execution log details are sorted in descending order based on the execution date and time of the anomaly determination execution log data and output. When outputting the execution log details to the screen, the execution detail IDs of the anomaly determination execution log detail data are sorted in ascending order using the execution ID as a key, and the anomaly determination definition name or schedule definition name (executed definition) of that anomaly determination definition ID or schedule definition ID is obtained from the anomaly determination definition master 106a or schedule determination definition master 106c, connected with an "→" between them, and output as one line of information.
[0076] FIG. 18 is a diagram for explaining the icons displayed for each execution log on the screen. An icon is output according to the status setting value of the abnormality determination execution log data. FIG. 18(A) is an example of abnormality determination execution log data, and FIG. 18(B) is a diagram for explaining the types of icons. In FIG. 18(B), if the status is normal, a normal icon is used. If the status is an error, an error icon is used.
[0077] In addition, if the status is that the judgment process is in progress, the running icon is used. This running icon is used until the process has finished successfully or with an error. Also, if the status is just before the judgment process is executed, the not executed icon is used. This not executed icon is used when creating a log before starting specific processing.
[0078] The log viewer (details) screen will be described with reference to Figures 19A and 19B. In Figures 19A and 19B, (A) shows the log viewer (list) screen, and (B) shows the log viewer (details) screen. The figures also show which columns of the abnormality determination execution log data, abnormality determination execution log detail data, and abnormality determination log data are referenced (as keys) to extract data.
[0079] When the details of the execution log in the log list display area 52 of the log viewer (list) screen 50 shown in (A) is clicked, the corresponding log viewer (details) screen 60 is displayed as shown in (B). The log viewer (details) screen has a header item that displays information about the executed definition, a details area 61 that displays a processing breakdown (details items) that displays detailed information about each process of the executed definition, and a log details area 62 that displays details of the processing breakdown log.
[0080] When the details of the execution log in the log list display area 52 are clicked, the execution ID of the corresponding abnormality determination execution log data is used as a key to obtain the execution detail ID of the abnormality determination execution log detailed data. Using the acquired execution detail ID as a key, the status, message, and details of the abnormality determination log data are acquired and displayed in the details area 61. The header item displays the executed definition and the definition ID of the acquired details. The processing details display an icon corresponding to the acquired status and the acquired message (processing content). Details will be described later, but by clicking on the processing details log, the details of that log are displayed in the log details area 62.
[0081] FIG. 20 is a diagram for explaining the display items of the details area 61. The details area displays a header item that displays information about the executed definition, and a breakdown item (processing breakdown) that displays detailed information about each process of the executed definition. By clicking the header item, it is possible to display only the header item on the screen. By clicking the header item again, it is possible to display the breakdown items.
[0082] FIG. 21 is a diagram for explaining the icons displayed for each execution definition log on the screen. An icon is displayed for each definition of the execution log in the header field of the details area 61. Two types of icons are displayed in the header field. If the processing category of the abnormality determination execution log detail data is "schedule determination," the (1) schedule definition icon for the schedule definition is displayed, and if the processing category of the abnormality determination execution log detail data is "abnormal value determination," the (2) abnormality determination definition icon for the definition that performs abnormality determination is displayed.
[0083] 22 is a diagram illustrating the icons displayed in the details area 61. In the details area 61, an icon is displayed that indicates the status of the processing, whether the definition being displayed completed processing normally. (1) If the processing ended normally, a normal icon is displayed, and (2) if the processing ended in an error, an error icon is displayed (similar to the icon used in the log list display area 52 of the log viewer (list) screen).
[0084] Depending on the status of the abnormality determination execution log detail data, a normal or error icon is displayed in the upper right corner of the header item definition icon. Also, depending on the status of the abnormality determination log data, a normal or error icon is displayed for each processing (message) of a detailed item.
[0085] 23 is a diagram illustrating items displayed in the log details area 62. By clicking on a log in the processing breakdown in the details area 61, details of that log are displayed in the log details area 62. The log details area 62 displays items such as the log ID, log date and time, log message, detailed log information, and log update source. Specifically, using the process (message) of the clicked log as a key, a record of the abnormality determination log data is extracted, and the log ID, log date and time, log message, detailed log information, and log update source data are displayed in the log details area 62.
[0086] 24A and 24B, the function of referencing the abnormality determination definition linked to each process (message) in the abnormality determination log data will be described. Log details are created for each process definition within the abnormality determination definition. By clicking on the icon in the process breakdown of the log in the details area 61, the abnormal value definition master maintenance is launched, and the setting screen (master maintenance screen) for the process definition linked to the log is launched. The definition can be modified on this setting screen for the process definition.
[0087] 24A and 24B, (A) is a display example of the details area 61 of the log viewer (details) screen 60, (B) is a display example of the data acquisition definition setting screen for abnormal value definition master maintenance, (C) is a diagram showing the contents of the data acquisition stored (pr_UriageNebikiKingaku_select), and (D) is a diagram showing a display example of the log details area 62 of the log viewer (details) screen 60. The figures also show which column of the abnormality determination execution log detail data and the abnormality determination log data is referenced (as a key) to launch the setting screen for the processing definition linked to the log.
[0088] In (A), in the processing breakdown of the details area 61, if an error occurs in the log details linked to the processing definition set in the abnormal value definition master maintenance, a master maintenance transition icon is displayed on the right side.
[0089] When the master maintenance transition icon for the target process is clicked, the screen transitions to the setting screen for the target definition of abnormal value definition master maintenance, as shown in (B), using the corresponding abnormality determination definition ID of the abnormality determination execution log detail data and the corresponding log update source of the abnormality determination log data as keys. The example shown in the same figure shows the case where data acquisition is clicked in the processing details, and the setting screen for the data acquisition definition of abnormal value definition master maintenance is displayed. In the example shown in the same figure, the data acquisition definition ID and data acquisition definition name are displayed. By modifying the data on this data acquisition definition setting screen, the data acquisition definition (data acquisition definition master 106b) can be modified.
[0090] Also, in the example shown in the figure, as shown in (D), the details in the log details area 62 display "Referenced table does not exist." Therefore, as shown in (C), you can check the contents of the data acquisition stored procedure from the stored procedure name linked to the data acquisition definition ID to see if a non-existent table has been set. In this case, the error is likely caused by a change to the table contents. Note that, for example, if "Preprocessing" is clicked in the processing details, the preprocessing definition settings screen is displayed, allowing you to modify the preprocessing definition (preprocessing definition master), and if "Aggregation" is clicked, the aggregation definition settings screen is displayed, allowing you to modify the aggregation definition (aggregation definition master). The same applies to other procedures.
[0091] As described above, according to this embodiment, the log inquiry screen refers to the abnormality determination execution log data and the abnormality determination execution log detail data, and displays a list of execution logs in the log list display area, with one process of automatic abnormality detection execution being one detail, and displays a detail screen of the execution log selected by the operator in the log list display area. The detail screen is equipped with log inquiry unit 102c which extracts data from the abnormality determination log data using the execution detail ID linked to the execution ID as a key, and displays the processing details and their status, making it possible to check the execution log of automatic abnormality detection execution for business data with high accuracy.
[0092] [4. Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This embodiment can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to the achievement of SDGs Goals 8 and 9.
[0093] Furthermore, this embodiment can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to the achievement of SDGs Goals 12, 13, and 15.
[0094] Furthermore, this embodiment can contribute to strengthening control and governance, which can contribute to Goal 16 of the SDGs.
[0095] 5. Other Embodiments The present invention may be implemented in various different embodiments other than those described above within the scope of the technical concept set forth in the claims.
[0096] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using known methods.
[0097] Furthermore, the processing procedures, control procedures, specific names, information including parameters such as registered data and search conditions for each process, screen examples, and database configurations shown in this specification and drawings can be changed as desired unless otherwise specified.
[0098] Furthermore, with regard to the log inquiry device 100, the components shown in the figures are functional concepts, and do not necessarily have to be physically configured as shown in the figures.
[0099] For example, all or any part of the processing functions of the log inquiry device 100, particularly the processing functions performed by the control unit, may be implemented by a CPU and a program interpreted and executed by the CPU, or may be implemented as hardware using wired logic. The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the information processing device to execute the processes described in this embodiment, and is mechanically read by the log inquiry device 100 as needed. That is, a computer program for providing instructions to the CPU in cooperation with the OS and performing various processes is recorded in a storage unit such as a ROM or HDD (Hard Disk Drive). This computer program is executed by being loaded into RAM, and cooperates with the CPU to form the control unit.
[0100] This computer program may also be stored in an application program server connected to the log inquiry device 100 via any network, and all or part of it may be downloaded as needed.
[0101] Furthermore, the program for executing the processes described in this embodiment may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product. Here, the term "recording medium" includes any "portable physical medium" such as a memory card, a Universal Serial Bus (USB) memory, a Secure Digital (SD) card, a flexible disk, a magneto-optical disk, a ROM, an Erasable Programmable Read Only Memory (EPROM), an Electrically Erasable and Programmable Read Only Memory (EEPROM (registered trademark)), a Compact Disk Read Only Memory (CD-ROM), a Magneto-Optical disk (MO), a Digital Versatile Disk (DVD), and a Blu-ray (registered trademark) disc.
[0102] Furthermore, a "program" is a data processing method written in any language or description method, regardless of the format, such as source code or binary code. Note that a "program" is not necessarily limited to a single program, but also includes programs that are distributed as multiple modules or libraries, or programs that achieve their functions by working together with other programs, such as an OS. Note that the specific configurations and reading procedures for reading a recording medium in each device shown in the embodiments, as well as the installation procedures after reading, can use well-known configurations and procedures.
[0103] The various databases stored in the memory unit are storage means such as memory devices such as RAM and ROM, fixed disk devices such as hard disks, flexible disks, and optical disks, and store various programs, tables, databases, and web page files used for various processes and providing websites.
[0104] The log inquiry device 100 may be configured as an information processing device such as a known personal computer or workstation, or may be configured as the information processing device to which any peripheral device is connected. The log inquiry device 100 may be realized by installing software (including programs, data, etc.) that causes the device to perform the processing described in this embodiment.
[0105] Furthermore, the specific form of distribution and integration of the devices is not limited to that shown in the drawings, and all or part of them can be configured by functionally or physically distributing and integrating them in any unit according to various additions or functional loads. In other words, the above-described embodiments can be implemented in any combination, or embodiments can be implemented selectively. [Explanation of symbols]
[0106] 100 Log inquiry device 102 Control section 102a Master Maintenance Department 102b Abnormality detection unit 102c Log query section 102d Screen display control unit 104 Communication interface unit 106 Storage section 106a Abnormality judgment definition master 106b Data Acquisition Definition Master 106c Schedule Judgment Definition Master 106d Schedule Judgment Definition Mapping Master 106e Other Masters 108 Input / Output Interface Section 112 Input Device 114 Output Device 200 servers 300 Network 400 Business Systems
Claims
1. A log inquiry device including a control unit that queries a log of a processing result of automatic execution of anomaly determination on business data, The control unit Anomaly determination execution log data is a log of the processing status of the automatic anomaly determination execution 1 process, and includes an execution ID, an execution date and time, and a status indicating whether anomaly detection was performed normally or not; Anomaly determination execution log detail data is a log of the processing status of anomaly determination / schedule determination units performed within one automatic execution process of anomaly determination, and includes an execution detail ID, an execution ID, a processing category that is an executed definition, a status, a schedule definition ID, and anomaly determination definition ID; Abnormality determination log data is a log of detailed processing units linked to each of abnormality determination and schedule determination performed within one automatic execution process of abnormality determination, and includes a log ID, status, a message indicating the processing content, details holding the executed definition ID and an error cause message in the event of an error, a log update source holding the definition information processed when updating the log, an execution detail ID, and an update date and time; It is configured to be accessible to a log inquiry device that is provided with a log inquiry means that, on a log inquiry screen, refers to the abnormality determination execution log data and the abnormality determination execution log detail data, displays a list of execution logs in a log list display area, with one process of automatic abnormality detection execution being one detail, and displays a detail screen of an execution log selected by an operator in the log list display area, and on the detail screen, extracts data from the abnormality determination log data using an execution detail ID linked to the execution ID as a key, and displays a processing breakdown and its status.
2. 2. The log inquiry device according to claim 1, wherein the log inquiry means displays the execution date and time in descending order of the execution date and time when displaying the list of execution logs in the log list display area.
3. 2. The log inquiry device according to claim 1, wherein the log inquiry means displays, on the detail screen, the processes performed in the selected execution log in a grouped manner.
4. The log inquiry device described in any one of claims 1 to 3, characterized in that the log inquiry means launches a setting screen for an abnormal value definition linked to the abnormality judgment definition ID of the abnormality judgment execution log detail data and the log update source of the abnormality judgment log data for the process selected by the operator in the processing details of the detail screen.
5. A log inquiry method executed by an information processing device having a control unit, The control unit Anomaly determination execution log data is a log of the processing status of the automatic anomaly determination execution 1 process, and includes an execution ID, an execution date and time, and a status indicating whether anomaly detection was performed normally or not; Anomaly determination execution log detail data is a log of the processing status of anomaly determination / schedule determination units performed within one automatic execution process of anomaly determination, and includes an execution detail ID, an execution ID, a processing category that is an executed definition, a status, a schedule definition ID, and anomaly determination definition ID; Abnormality determination log data is a log of detailed processing units linked to each of the abnormality determination and schedule determination performed within one automatic execution process of abnormality determination, and includes a log ID, status, a message indicating the processing content, details holding the executed definition ID and an error cause message in the event of an error, a log update source holding the definition information processed when updating the log, an execution detail ID, and an update date and time; It is configured to be accessible to Executed in the control unit: a log inquiry step of: on a log inquiry screen, referring to the abnormality determination execution log data and the abnormality determination execution log detail data, displaying a list of execution logs in a log list display area, with one process of automatic abnormality detection execution as one detail, and displaying a detail screen of an execution log selected by an operator in the log list display area; and on the detail screen, extracting data from the abnormality determination log data using an execution detail ID linked to the execution ID as a key, and displaying a processing breakdown and its status.
6. A log inquiry program to be executed by an information processing device having a control unit, The control unit Anomaly determination execution log data is a log of the processing status of the automatic anomaly determination execution 1 process, and includes an execution ID, an execution date and time, and a status indicating whether anomaly detection was performed normally or not; Anomaly determination execution log detail data is a log of the processing status of anomaly determination / schedule determination units performed within one automatic execution process of anomaly determination, and includes an execution detail ID, an execution ID, a processing category that is an executed definition, a status, a schedule definition ID, and anomaly determination definition ID; Abnormality determination log data is a log of detailed processing units linked to each of abnormality determination and schedule determination performed within one automatic execution process of abnormality determination, and includes a log ID, status, a message indicating the processing content, details holding the executed definition ID and an error cause message in the event of an error, a log update source holding the definition information processed when updating the log, an execution detail ID, and an update date and time; It is configured to be accessible to In the control unit, A log inquiry program for executing a log inquiry process in which, on a log inquiry screen, the abnormality determination execution log data and the abnormality determination execution log detail data are referenced, a list of execution logs is displayed in a log list display area, with one process of automatic abnormality detection execution being one detail, and a detail screen of an execution log selected by an operator is displayed in the log list display area, and on the detail screen, data is extracted from the abnormality determination log data using an execution detail ID linked to the execution ID as a key, and a processing breakdown and its status are displayed.
Citation Information
Patent Citations
Object managing method
JP1999143737A
Commodity sales system
JP2004021689A
Log provision system, log provision method and computer program
JP2007265296A
Information processing apparatus and information processing system
JP2016062243A
Control apparatus, information processing system, and control program
JP2017054415A