Fault response support system and fault response support method

The failure response support system addresses the challenge of diverse log formats by utilizing a storage and computing system to match input logs with past judgment results, ensuring efficient and tailored fault responses.

JP7811888B2Active Publication Date: 2026-02-06HITACHI INFORMATION & TELECOMM ENG LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022110347
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-08
Publication Date
2026-02-06
Estimated Expiration
2042-07-08

AI Technical Summary

Technical Problem

Existing technologies are inadequate in handling logs from faulty devices with varying formats, limiting effective fault response support.

Method used

A failure response support system that includes a storage device for past failure responses and log judgment results, and a computing device to judge and output appropriate responses based on input logs, capable of handling logs in various formats.

Benefits of technology

Enables effective fault response support by accurately matching input logs with past judgment results, facilitating quick and tailored responses to device failures across different log formats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007811888000001
    Figure 0007811888000001
  • Figure 0007811888000002
    Figure 0007811888000002
  • Figure 0007811888000003
    Figure 0007811888000003
Patent Text Reader

Abstract

To provide a failure response support technology capable of responding to logs of various descriptive methods.SOLUTION: A failure response support system supports response to a failure generated in a device. The failure response support system stores response information for responding to each of a plurality of past failures in one or more device configurations, and a plurality of past log determination results indicating the result of a determination made on a device state according to a predetermined rule for a plurality of past logs concerning the plurality of past failures. The failure response support system determines an input log according to the predetermined rule, generates an input log determination result, selects at least one past log determination result that is the same as or similar to the input log determination result from the plurality of past log determination results, and outputs information on responses to the past failure that is associated with the selected past log determination result.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technology for supporting failure response. [Background technology]

[0002] One way to respond when a device fails is to acquire and examine the device's logs and take action based on them. If logs acquired when a failure occurred in the past have been saved, when a new failure occurs, it is possible to search for the same or similar log among the saved logs and use that log as a reference for how to respond to the device.

[0003] Here, as background art of the present invention, for example, Patent Document 1 discloses "an information processing device comprising: a log accumulation means for accumulating logs represented by event data in a predetermined format; a similarity acquisition means for comparing the logs accumulated in the log accumulation means for each event and obtaining a similarity between the logs based on the comparison result; a log appearance frequency calculation means for calculating an appearance frequency of each log based on the similarity between the logs obtained from all the logs by the similarity acquisition means; and an output log selection means for selecting a log to be output in accordance with the appearance frequency of each log calculated by the log appearance frequency calculation means." It further states that "in the information processing device, the similarity acquisition means determines the similarity taking into account the data format and data content."

[0004] Patent Document 1 describes a method for obtaining similarity for a line in which "Serial Number," "Date Time," "Error Code," "Error Message," and "User" are written in a predetermined order within a single line.

[0005] Patent Document 1 describes that "Serial Number" and "Date Time" are unsuitable for use in similarity analysis, that "Error Code" is determined to be an exact match in similarity analysis, that "Error Message" is expressed as a character string, so similarity is analyzed based on the content of the character string and the evaluation is expressed as the degree of similarity, and that the decision on whether to use "User" in similarity analysis is made based on whether it is necessary for the intended use of the analysis results.

[0006] Regarding the analysis method for "Error Messages," it is described that factors such as the language used in the log string and the length of the string are taken into consideration to select the method that will provide the best accuracy. For example, it is described that the words contained in the string are examined, and the value is determined as the ratio of the number of matching words to the total number of words. [Prior art documents] [Patent documents]

[0007] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-155064 Summary of the Invention [Problem to be solved by the invention]

[0008] There are various log description formats. However, Patent Document 1 does not disclose a method for processing logs of faulty devices written in formats other than those described above. The present invention has been made in consideration of the above-mentioned problems, and aims to provide a fault response support technology that can handle logs written in various formats. [Means for solving the problem]

[0009] To solve the above-mentioned problems, a representative example of the invention disclosed in this application is as follows. That is, a failure response support system that supports responses to failures that occur in equipment includes a storage device and a computing device. The storage device stores response information for responding to each of multiple past failures in one or more equipment configurations, and multiple past log judgment results that indicate the results of judgments made on the equipment status for multiple past logs related to the multiple past failures in accordance with predetermined rules. The computing device makes a judgment on an input log in accordance with the predetermined rules, generates an input log judgment result, selects at least one past log judgment result that is the same as or similar to the input log judgment result from the multiple past log judgment results, and outputs information related to the response to the past failure associated with the selected past log judgment result. [Effects of the Invention]

[0010] According to the present invention, it is possible to provide a fault response support technology that can handle logs written in various ways. Problems, configurations, and effects other than those described above will become clear from the following description of the embodiment. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a block diagram illustrating an example of a functional configuration of a failure response support system according to a first embodiment. [Figure 2] FIG. 2 is a schematic diagram of a log handled by the failure response support system of the first embodiment. [Figure 3] 6 is a flowchart illustrating an operation of a log determination unit according to the first embodiment. [Figure 4] 10 is a table showing the relationship between pattern numbers and determination results according to the first embodiment. [Figure 5] 10 is a relationship table between pattern numbers and management numbers according to the first embodiment. [Figure 6] 10 is a relationship table between pattern numbers and pattern numbers with high similarity according to the first embodiment. [Figure 7] 10 is a table showing the relationship between pattern numbers and determination events according to the first embodiment. [Figure 8]10 is a table showing the relationship between pattern numbers and failure handling methods according to the first embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a screen showing a result output by the failure response support system of the first embodiment. [Figure 10] FIG. 2 illustrates an example of a hardware configuration of the failure response support system according to the first embodiment. [Figure 11] FIG. 10 is a block diagram illustrating an example of a functional configuration of a failure response support system according to a second embodiment. [Figure 12] 10 is a flowchart illustrating an operation of a log analysis unit according to the second embodiment. [Figure 13] 10 is a table illustrating an example of an analysis result presented to a user according to the second embodiment. [Figure 14] 10 is a table showing the relationship between pattern numbers and determination results according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. For convenience, the following embodiments will be divided into multiple sections or embodiments. However, unless otherwise specified, these are not unrelated and one is related to the other in terms of partial or complete modifications, details, supplementary explanations, etc. Each embodiment may be implemented individually or in combination.

[0013] Furthermore, in the following embodiments, when referring to the number of elements (including numbers, numerical values, quantities, ranges, etc.), unless otherwise specified or when it is clearly limited to a specific number in principle, it is not limited to that specific number and may be more or less than the specific number.

[0014] Furthermore, it goes without saying that in the following embodiments, the components (including element steps, etc.) are not necessarily essential unless otherwise specified or considered to be clearly essential in principle.

[0015] Similarly, in the following embodiments, when referring to the shapes, positional relationships, etc. of components, etc., unless otherwise specified or clearly considered otherwise in principle, it is intended to include those that are substantially similar or approximate to those shapes, etc. The same applies to numerical values ​​and ranges.

[0016] In the following description, expressions such as "xxx table" may be used, but the information may be data of any structure. In the following description, the structure of each table is an example, and one table may be divided into two or more tables, or two or more tables may all or partly be one table. In the following description, functions may be described using the expression "xxx part," but the functions may be realized by executing one or more computer programs.

[0017] An embodiment of the present specification relates to a technology for supporting troubleshooting of equipment. For example, when a failure occurs in a device used for communication, information on how to handle the failure is output using the device's log information. The following describes a troubleshooting support system that can extract logs that are the same as or similar to the device status described in the log of the failed device, and can also extract similar logs even if the description method has changed due to, for example, a change in the device model number or operating system. First Embodiment

[0018] The first embodiment will be described with reference to Figures 1 to 10. Figure 1 is a block diagram showing an example of the functional configuration of a failure response support system 100. The failure response support system 100 includes a response information storage unit 101, a log information storage unit 102, a log determination unit 103, a database creation and storage unit 104, an interface 106, an input information processing unit 107, and an output information creation unit 105.

[0019] The response information storage unit 101 is a functional block that assigns a management number (hereinafter referred to as a management number) to each failure that occurs in a device and stores information for investigating and dealing with the cause of the failure along with the management number information. The information for investigating and dealing with the cause of the failure includes, for example, what information was acquired, what cause was assumed from that information, what response was taken for the assumed cause, and whether the response was effective. This response information can be configured so that it can be stored in the failure response support system 100 by the user of the failure response support system 100 via the interface 106.

[0020] The log information storage unit 102 is a functional block that stores logs (past logs) acquired at the time of or after the occurrence of a failure in a device where a failure has occurred, in association with a management number. If there are multiple logs for a management number, this can be handled by adding a subnumber to the end of the management number, for example.

[0021] These logs may be stored in the failure response support system 100 by a user of the failure response support system 100 through the interface 106, or, although not shown in Figure 1, the failure response support system 100 may be configured to obtain and store the logs from the equipment through the interface 106.

[0022] The log determination unit 103 is a functional block that holds preset rules for determining the state of the device, determines the logs according to the rules, and performs processing to classify the logs or to output logs that have the same determination result. Details of the processing by the log determination unit 103 will be described later.

[0023] The database creation and maintenance unit 104 is a functional block that creates and maintains a relationship table between logs and determination results from the results of determination by the log determination unit 103. Details of the processing by the database creation and maintenance unit 104 will be described later.

[0024] The interface 106 is an interface through which the failure response support system 100 inputs and outputs information.

[0025] Input information processing unit 107 is a functional block that converts information input from interface 106 into a format suitable for processing within failure response support system 100 as necessary, and transmits the information to a functional block corresponding to the processing. Output information creation unit 105 is a functional block that creates information for presenting the results processed by failure response support system 100 to the user, and transmits the information to interface 106.

[0026] Next, the operation of the log determination unit 103 will be described with reference to Figures 2 to 4. The failure response support system 100 of the first embodiment has two processing modes. The first processing mode is a classification mode in which logs stored in the log information storage unit 102 are classified according to rules. The second processing mode is a presentation mode in which the management numbers of logs that belong to the same or similar classification as the input log are presented.

[0027] The processing mode may be set so that the user specifies one of two modes when starting up the failure response support system 100. Alternatively, the failure response support system 100 may be configured to automatically operate in the classification mode when it detects that no new logs have been input to the failure response support system 100 for a certain period of time and that the system is in a standby state, and to pause the classification mode and switch to the presentation mode in response to the input of a new log. This reduces the impact of the classification mode on the presentation mode.

[0028] 2 is a schematic diagram of a log 200 handled by the fault response support system 100 of the first embodiment. It is possible to acquire only the information in the device log, such as information about the time setting or information about the CPU usage rate, by inputting a dedicated command for that information. On the other hand, there are also commands that acquire multiple pieces of predetermined information together, and by inputting such commands, it is possible to acquire a log containing a variety of information, as shown in FIG. 2.

[0029] 2, the parts marked as "parts to be judged" or "parts not to be judged" indicate the range of information that can be acquired by the respective dedicated commands. The fault response support system 100 assumes a log 200 containing various information as shown in FIG.

[0030] The log determination unit 103 holds rules for determining whether the contents of the log indicate that the device is normal, or that the settings and state are as expected by the user, or whether the device is abnormal, or that the settings and state are not as expected. In the following explanation, the expected settings and state will be referred to as "normal," and the settings and state that are not as expected will be referred to as "abnormal."

[0031] The way information is recorded in device logs may change if the device configuration, for example, the device model number or the version of the device's operating system (hereafter referred to as OS), changes. Therefore, it is desirable to prepare rules for determining whether something is normal or abnormal for each device model number and OS version. Of course, if the same rules can be used to determine whether something is normal or abnormal even if the OS version changes, then those rules should be used.

[0032] Furthermore, if, for example, analysis based on the logs of two devices connected by a cable is required to determine whether a device is operating normally or abnormally, then it is sufficient to input two logs for the determination, check the status of each of the two devices, and implement a rule that determines whether the device is operating normally or abnormally based on the results.

[0033] In the first embodiment, for the sake of simplicity, an example is shown in which a log determination unit implements rules for determining whether information written in a determination target portion A201, a determination target portion B202, and a determination target portion C203 in a log 200 indicates a normal state or an abnormal state of the device, and the log is determined based on the rules. No determination is performed on a non-determination target portion a204 and a determination target portion b205 in FIG. 2.

[0034] Fig. 3 is a flowchart showing an example of processing by the log determination unit 103. As shown in Fig. 3, when the processing mode, the log, and the control number linked to the log are input, the log determination unit 103 reads this information (S301), sequentially determines whether the determination target locations A to C are normal or abnormal (S302 to S304), and acquires the control number and the pattern number of the determination result as a result (S305).

[0035] As mentioned above, the rules for determining whether something is normal or abnormal may vary depending on the device model number and OS version, so although not shown in Figure 3, the system can be configured to read the model number and OS version from the log and determine whether the device is normal or abnormal using rules appropriate for them. Alternatively, the system may be configured so that the user can input the model number and OS version.

[0036] Here, the pattern numbers of the judgment results will be explained using Fig. 4. Fig. 4 is a table showing the relationship between pattern numbers 401 and judgment results 402, and is stored in the database creation and storage unit 104. As mentioned above, the way information is recorded in a device log may change if the device model number or the device OS version changes, so Fig. 4 also lists the device model number 403 and OS version 404 that correspond to the pattern number.

[0037] In the first embodiment, normal / abnormal judgment is performed for three locations in the log, so the patterns of the judgment results are combinations of normal or abnormal for judgment target location A, normal or abnormal for judgment target location B, and normal or abnormal for judgment target location C, resulting in a total of eight patterns, as shown in Figure 4. Pattern numbers P1 to P8 (401) are assigned to each pattern, and the judgment results are represented by the pattern numbers.

[0038] When the log determination unit 103 has finished determining the determination target portion C (S304), it accesses the database creation and maintenance unit 104 to obtain the pattern number for the input log (S305). Then, depending on whether the current operating mode is the classification mode (S306), if it is the classification mode (YES in S306), it outputs the pattern number and management number to the database creation and maintenance unit (S307).

[0039] If the classification mode is not selected (NO in S306), that is, if the presentation mode is selected, the control number belonging to the same or similar pattern number is obtained from the database creation and maintenance unit 104 (S308), and the control number and pattern number of the input log, as well as the control number belonging to the same or similar pattern number obtained from the database creation and maintenance unit, are output to the user interface (S309). The similar pattern number may be predefined.

[0040] During the operation, control numbers belonging to the same or similar pattern numbers are obtained from the database creation and storage unit (S308), and the control numbers belonging to the same or similar pattern numbers are output from the database creation and storage unit to the user interface (S309). The user may be able to select whether the information to be output is the control numbers belonging to the same pattern number, the control numbers belonging to similar pattern numbers, or both. Basically, the same pattern number may be output preferentially, and if the same pattern number does not exist, a similar pattern number may be output. Similar pattern numbers will be described later.

[0041] Next, the information created and stored by the database creation and maintenance unit 104 will be described with reference to Figures 4 to 8. As mentioned above, the database creation and maintenance unit 104 stores the table shown in Figure 4. This table can be created by assigning a number to each pattern, since the number of patterns is automatically determined once the location in the log to be judged is determined.

[0042] Fig. 5 is a relationship table between pattern numbers 401 and management numbers 501 in the first embodiment. The fault response support system 100 operates in classification mode and creates the table in Fig. 5 by receiving the results of judging the past logs held by the log information holding unit 102. Through this operation, the logs in the log information holding unit 102 are classified according to the status of the device described in the log.

[0043] The relationship table between pattern numbers and management numbers in Figure 5 is created according to the judgment rules used to classify logs. As with Figure 4, Figure 5 also lists the model number 403 and OS version 404 of the device to which the pattern number corresponds. In Figure 5, even when the model number and OS version are different, they are summarized in one table, but separate tables can also be created for each rule used.

[0044] 6 is a table showing the device states indicated by each pattern number 401 and the pattern numbers 601 with high similarity to the states. This table may be provided to the fault response support system 100 by the user, or the fault response support system 100 may be configured to automatically create the table based on conditions provided by the user. For example, if the same model number has different determination rules depending on the OS version, and different pattern numbers are assigned even if the pattern of the determination result is the same, logs with similar OS versions that are classified as the same determination result are considered to have high similarity. Logs that are considered to have high similarity can be defined as similar logs.

[0045] Therefore, when different pattern numbers are assigned to a device with an OS version branch number, for example, branch number 11.22.33 and a device with OS version 11.22.22, if the patterns of the judgment results are the same, it is considered that the device states have a high degree of similarity. Therefore, although not shown in Figure 1, such an algorithm may be implemented in the fault response support system 100, and a configuration may be adopted in which a relationship table of pattern numbers with high similarity shown in Figure 6 is automatically created.

[0046] If the judgment results are expressed by the same pattern number even if the devices have the same model number but different OS versions, then logs classified with pattern numbers that produce the same judgment results for devices with the same functions, or for devices with successor model numbers, or for devices with model numbers equivalent to the previous model of that model number, are considered to be logs with a high degree of similarity in device status.This concept can be implemented as an algorithm so that logs with a high degree of similarity can be presented as similar logs.

[0047] Furthermore, in cases where the way the log is written changes depending on the OS version, instead of making a judgment based on the judgment target location as described in FIG. 2, as shown in FIG. 7, events that represent the status of the device to be judged may be used as items, and a judgment may be made as normal or abnormal for, for example, the power status, CPU usage status, memory usage status, and network connection status, and a pattern number 401 may be assigned to the normal or abnormal pattern for the judgment event 701.

[0048] The log determination unit 103 searches the log according to pre-specified rules and determines whether each item indicated by the determination event 701 is normal or abnormal. By standardizing the determination event 701 across different OS versions in this way, there is no need to separate it for each OS version. However, in this case, it becomes difficult to respond to cases where a failure occurs only in a specific OS version, so it is recommended to add OS version information along with the management number to the management number 501 in Figure 5. This makes it possible to indicate the OS version along with the management number for failure response.

[0049] 8 is a relationship table between the pattern number 401 and the fault handling method 801, in which the management number 501 in FIG. 5 is replaced with the fault handling method 801. In FIG. 8, the user determines the handling method based on the handling method for the management number 501 and registers it in the fault handling support system 100.

[0050] When a log of a device that requires new troubleshooting is input while the troubleshooting support system 100 is operating in the presentation mode, the system may be configured to present a troubleshooting method instead of the management number that belongs to the same pattern number as the log. The troubleshooting support system 100 may present one or more of the management number, information for examining the cause of the fault, the assumed cause of the fault, the troubleshooting method, and information regarding the effectiveness of the troubleshooting method.

[0051] If the equipment failure is transient, it may be the case that no abnormality is found in the equipment even after judging the log. For this reason, it may be difficult to consolidate the failure response methods for logs that are not judged to be abnormal into a single response. Therefore, in such cases, instead of consolidating the response methods into one, it is possible to consolidate the response methods for each event reported as an equipment failure and enter the results in a table, as shown in Figure 8. Also, it is possible to configure the system so that, in addition to the equipment log, the failure event that occurred in the equipment in that log is also input as input information. As a result, even if it is judged that there is no abnormality in the log, it is possible to output a response method that suits the failure event.

[0052] Next, the output results of the fault response support system 100 will be described using FIG. 9. FIG. 9 is a diagram showing an example of a screen 900 of results output by the fault response support system 100 operating in presentation mode, and is displayed on a display device 901. The screen 900 has a selection button 905 for information to be output as the judgment result for the input log, and an input field 906 for the maximum number of outputs. When these are selected and input, and an execute button 907 is pressed, the input results include the input log file name, the judgment rule used, the pattern number obtained by the judgment, the result for the selected information, and the description of the log used for the judgment. It is also possible to select whether or not to save the results. FIG. 9 is an example, and the screen may be configured to output other information required by the user.

[0053] FIG. 10 is a block diagram 1000 showing an example of the hardware configuration of the failure response support system 100 according to the first embodiment.

[0054] As shown in Figure 10, the fault response support system 100 is a system equipped with a computing device 1001, a memory 1002, an auxiliary storage device 1003, a communication interface 1004, an input interface 1005, and an output interface 1006, and various functions of the fault response support system 100 are realized by the computing device 1001 executing various programs.

[0055] The arithmetic device 1001 is an arithmetic device that executes a program stored in a memory 1002. The program executed by the arithmetic device 1001 is provided to the failure response support system 100 via removable media or a network 1007, and is stored in a non-volatile auxiliary storage device 1003, which is a non-transitory storage medium. For this reason, the failure response support system 100 may have an interface that reads data from removable media.

[0056] The memory 1002 includes a ROM (Read Only Memory), which is a nonvolatile storage element, and a RAM (Random Access Memory), which is a volatile storage element. The ROM stores unchanging programs (e.g., BIOS). The RAM is a high-speed, volatile storage element such as a DRAM (Dynamic Random Access Memory), and temporarily stores processes executed by the arithmetic device 1001 and data used when executing the processes.

[0057] The auxiliary storage device 1003 is, for example, a large-capacity, non-volatile storage device such as a magnetic storage device (HDD (Hard Disk Drive)) or a flash memory (SSD (Solid State Drive)). The auxiliary storage device 1003 also stores data used by the arithmetic device 1001 when executing a program, and the program executed by the arithmetic device 1001. That is, the program is read from the auxiliary storage device 1003, loaded into the memory 1002, and executed by the arithmetic device 1001, thereby realizing each function of the failure response support system 100.

[0058] The communication interface 1004 controls communication with other devices in accordance with a predetermined protocol. For example, as shown in Fig. 10, the failure response support system 100 may use the communication interface 1004 to communicate with other devices 1008 via a network 1007. Furthermore, with such a configuration, device logs may be periodically acquired from one or more other devices to determine the status of the devices.

[0059] The input interface 1005 is an interface to which input devices such as a keyboard 1009 and a mouse 1010 are connected. When a user operates the input device, the input interface 1005 receives input from the user via the input device.

[0060] The output interface 1006 is an interface to which an output device such as the display device 901 or a printer (not shown) is connected. The output interface 1006 outputs, for example, the results shown in Fig. 9 to the output device in a format that can be viewed by the user.

[0061] The failure response support system 100 may also be constructed on an on-premise or cloud server connected via a network to a terminal operated by a user. Furthermore, the system is not limited to being constructed on a single physical computer as shown in Fig. 10, but may be, for example, a system constructed on multiple logically or physically configured computers, or may operate on a virtual computer constructed on physical computer resources.

[0062] Furthermore, the failure response support system 100 may be configured to automatically read a failure event from a document containing a request for failure response as input information in addition to the log and input the information to the log determination unit.

[0063] By configuring the failure response support system 100 in the above-described embodiment, when a new failure occurs, the user can determine from the log the management number or response method used when dealing with a failure of the same or similar status, enabling the user to quickly respond to the failed device. Also, by classifying the logs according to the determined events as shown in Figure 7, the logs can be classified using the same criteria even if the OS versions are different and the log entries are different. <Second embodiment>

[0064] The second embodiment will be described with reference to Figures 11 to 14. The following mainly describes the functions that differ from the first embodiment.

[0065] 11 is a block diagram showing an example of the functional configuration of a failure response support system 1100. The failure response support system 1100 differs from the functional blocks of the failure response support system 100 in the first embodiment in that a log analysis unit 1101 is added. The log analysis unit analyzes whether content indicating the state of the device is included in locations that have not been subject to judgment until now, such as non-judgment target location a204 in FIG. 2, and further checks the ratio of words indicating normal states to words indicating abnormal states in the past logs it has stored. For example, words indicating normal states include OK, Green, Normal, and Success, and words indicating abnormal states include NG, Red, Abnormal, and Fail.

[0066] 12 is a flowchart showing the operation of the log analysis unit 1101 of the second embodiment. The log analysis unit selects one unanalyzed log from the log information storage unit 102 (S1201), and extracts the device model number and OS version (S1202). It selects one non-target section from the selected log (S1203), counts the number of words indicating a normal state or an abnormal state used in that section (S1204), and adds the number currently counted to the number previously counted for logs with the same model number and OS version (S1205).

[0067] It is checked whether all non-target locations have been investigated (S1206), and if not (NO in S1206), one of the remaining non-target locations is selected and the same process is repeated. If all non-target locations have been investigated (YES in S1206), it is then checked whether a predetermined number of logs have been analyzed (S1207), and if they have been investigated (YES in S1207), the analysis results are presented to the user (S1208).

[0068] If the predetermined number of logs has not been analyzed (NO in S1207), one unanalyzed log is selected and the process is repeated. The predetermined number does not have to be one, and multiple values ​​can be set, for example, when 20 logs have been analyzed, when 50 logs have been analyzed, when 100 logs have been analyzed, etc., and the results can be presented to the user when the number of analyzed logs reaches 20, when further logs have been analyzed and the number reaches 50, and when the number reaches 100.

[0069] 13 is a table showing an example of the analysis results presented to the user when the number of analyzed logs reaches a number set by the user. For each model number 403 and OS version 404, the number of words indicating a normal state 1302 and the number of words indicating an abnormal state 1303 are summarized for each non-target part 1301.

[0070] From the analysis results table shown in Figure 13, the user can see that, from the logs examined so far, there are no words indicating an abnormal state in the non-judgment target area a, there are no words indicating either a normal or abnormal state in the non-judgment target area b, and there are both words indicating a normal and an abnormal state in the non-judgment target area c.

[0071] From these results, for example, it can be considered that there is little need for the user to create rules for determining whether the equipment status is normal or abnormal for non-judgment target point a and to implement them in failure response support system 100. It can also be considered that rules are unnecessary for non-judgment target point b. On the other hand, it can be considered that the equipment can be in either a normal or abnormal state from non-judgment target point c.

[0072] Therefore, if it is possible to create a rule for determining whether something is normal or abnormal by checking the contents of the non-judgment target part c, the rule can be created and implemented in the fault response support system 100, and from next time onwards, the judgment target part c can also be added and the log judgment unit 103 can make a judgment.

[0073] Accordingly, the database creation and maintenance unit 104 creates a relationship table between the pattern numbers and the determination results with the determination target portion c added, as shown in Fig. 14. Also, when a relationship table is maintained for the determination events rather than the determination target portions as shown in Fig. 7, a relationship table between the pattern numbers and the determination events with the determination event for the determination target portion c added is created.

[0074] Then, the log determination unit 103 performs a new determination on the determination target portion c for the log that was previously determined, and updates the tables shown in FIGS. 5, 6, and 8 in the first embodiment.

[0075] By configuring the failure response support system 100 in the second embodiment, it is possible to extract logs that can be used to determine the status of equipment from logs that were previously not subject to judgment, and by implementing these judgment rules to classify past logs, it is possible to improve the accuracy of classifying the status of equipment compared to the past.

[0076] As a result, it becomes possible to present information related to troubleshooting that is more suited to the state of the device, even for logs of devices where a new failure has occurred.

[0077] The present invention is not limited to the above-described embodiments and includes various modifications. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and are not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.

[0078] Furthermore, the above-mentioned components, functions, processing units, etc. may be realized in part or in whole by hardware, for example, by designing them as integrated circuits. Furthermore, the above-mentioned components, functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function. Information such as the programs, tables, and files that realize each function can be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card or SD card.

[0079] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]

[0080] 100, 1100 Disaster Response Support System 101 Correspondence information storage unit 102 Log information storage unit 103 Log determination unit 104 Database Creation and Maintenance Department 105 Output Information Creation Department 106 Interface 107 Input information processing unit 200 Log 901 Display device 1001 Arithmetic equipment 1002 memory 1003 Auxiliary storage device 1004 Communication Interface 1005 Input Interface 1006 Output Interface 1007 Network 1008 Other equipment 1009 Keyboard 1010 Mouse 1101 Log Analysis Unit

Claims

1. A failure response support system that supports responses to failures that occur in equipment, A storage device; a computing device; The storage device includes: Response information for responding to each of a plurality of past failures in one or more device configurations; and storing a plurality of past log determination results indicating the results of determinations made on the device status according to a predetermined rule for a plurality of past logs relating to the plurality of past failures; The computing device A judgment is made on the input log in accordance with the predetermined rule, and an input log judgment result is generated; Selecting at least one past log determination result that is the same as or similar to the input log determination result from the plurality of past log determination results; A failure response support system that outputs information about responses to past failures associated with the selected past log determination result.

2. 2. The fault response support system according to claim 1, the plurality of past logs and the input log each include one or more determination target portions, The computing device makes a judgment on the one or more judgment target locations in accordance with the predetermined rule.

3. 3. The fault response support system according to claim 2, the plurality of past logs and the input log include a plurality of determination target portions, A fault response support system, wherein the plurality of past log judgment results and the input log judgment result indicate a pattern of a combination of normal or abnormal states of the plurality of judgment target locations.

4. 2. The fault response support system according to claim 1, the correspondence information includes a management number for managing the plurality of past failures, A failure response support system in which the information regarding responses to past failures that is output is one or more of the management number, information for examining the cause of the failure, the assumed cause of the failure, the response method, and information regarding the effectiveness of the response method.

5. 2. The fault response support system according to claim 1, the storage device stores the plurality of past logs; The computing device performs a judgment on the plurality of past logs in accordance with the predetermined rule to generate the plurality of past log judgment results, and stores the plurality of past log judgment results in the storage device.

6. 6. The fault response support system according to claim 5, The computing device In a first operation mode, outputting information relating to a response to the past failure for the input log; In the second operation mode, a determination is made on the past log in accordance with the preset rule to generate a past log determination result, and the past log determination result is stored in the storage device; When it is detected that no log is input for a predetermined time, the device operates in the second operation mode; A failure response support system that changes from the second operation mode to the first operation mode in response to detection of a log input.

7. 2. The fault response support system according to claim 1, The computing device outputs a method of dealing with a failure event when the failure event is input together with the log.

8. 2. The fault response support system according to claim 1, The computing device determines the similarity between the input log judgment result and the multiple past log judgment results based on information regarding the device configuration of the input log and the multiple past logs.

9. 3. The fault response support system according to claim 2, the storage device stores the plurality of past logs; The computing device Analyzing whether or not content that indicates the state of the device is included in non-target locations other than the target locations in the plurality of past logs; A fault response support system that outputs the results of the analysis.

10. 10. The failure response support system according to claim 9, The computing device makes a judgment on the judgment target points added to the multiple past logs based on the results of the analysis, and updates the multiple past log judgment results.

11. A method for supporting a system in responding to a failure that occurs in a device, comprising: The system comprises: Response information for responding to each of a plurality of past failures in one or more device configurations; and storing a plurality of past log determination results indicating the results of determinations made on the device status according to a predetermined rule for a plurality of past logs relating to the plurality of past failures; The method further comprises the steps of: A judgment is made on the input log in accordance with the predetermined rule, and an input log judgment result is generated; Selecting at least one past log determination result that is the same as or similar to the input log determination result from the plurality of past log determination results; A method for outputting information relating to responses to past failures associated with the selected past log determination result.

Citation Information

Patent Citations

  • Diagnostic device of defect cause of electronic device based on event

    JP1995044526A

  • Fault countermeasure supporting method

    JP1996314751A

  • Fault management device and fault management method

    JP2006099249A

  • Information processor and program used therefor

    JP2006155064A

  • Monitoring system and monitoring program

    JP2022044844A