Monitoring device, monitoring method, and program
By distinguishing between main and back system events and performing classification only on main system events, the monitoring device reduces processing load and maintains efficient operation in dual-active configurations.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2022-03-07
- Publication Date
- 2026-04-28
AI Technical Summary
In monitoring systems with dual-active configurations, the increased load on one monitoring device can affect the monitoring process of the other device, leading to potential disruptions and inefficiencies.
The monitoring device determines whether an event is from a main system or a back system, storing back system events for classification later and performing classification only for main system events, thereby reducing load on the monitoring device.
This approach reduces the load on the monitoring device by classifying only main system events during normal operation, minimizing processing requirements and ensuring efficient load distribution across dual-active configurations.
Smart Images

Figure 0007852303000001 
Figure 0007852303000002 
Figure 0007852303000003
Abstract
Description
Technical Field
[0001] The technical field relates to a monitoring device, a monitoring method, and a program used in a monitoring system with a dual-active configuration.
Background Art
[0002] In a monitoring system with a dual-active configuration, a monitoring device is provided for each of a plurality of sites, and each monitoring device performs a different monitoring process. However, when the load on one monitoring device increases, it may affect the monitoring process of the other monitoring device.
[0003] As a related technique, Patent Document 1 discloses a system in which a monitoring manager device has a dual-active configuration and when a monitoring agent generates an event, the event is issued to all the monitoring manager devices. According to Patent Document 1, even when one monitoring manager device stops, monitoring control is continued by the other monitoring manager device that has received the event issued from the monitoring agent.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in Patent Document 1, it is necessary to cause the monitoring agent to perform classification processing with a large processing load. For example, when a rush of monitoring events occurs in a business server in which a monitoring agent is introduced, if the load on the monitoring agent increases, it may affect the business.
[0006] One objective is to provide a monitoring device, a monitoring method, and a program that suppress the load of a monitoring device used in a monitoring system with a dual-active configuration. [Means for solving the problem]
[0007] To achieve the above objective, the monitoring device on one side is: A determination unit determines whether a main system monitoring event is notified by a main system monitoring agent or a back system monitoring event is notified by a back system monitoring agent, and if it is determined to be a back system monitoring event, stores back system monitoring event identification information for identifying the back system monitoring event in a back system classification waiting storage unit. A classification unit classifies the aforementioned main system monitoring events using pre-configured main system classification rule information, and stores main system classification result information in a main system classification result storage unit, which associates the classified classification results with main system monitoring event identification information for identifying the aforementioned main system monitoring events. It is characterized by having the following features.
[0008] Furthermore, in order to achieve the above objective, one aspect of the method is: Computers The system determines whether the event is a main system monitoring event notified by the main system monitoring agent or a back system monitoring event notified by the back system monitoring agent. If it is determined to be a back system monitoring event, the system stores back system monitoring event identification information for identifying the back system monitoring event in the back system classification waiting storage unit. The aforementioned main system monitoring events are classified using pre-configured main system classification rule information, and the main system classification result information, which associates the classified classification result with main system monitoring event identification information for identifying the main system monitoring event, is stored in the main system classification result storage unit. It is characterized by the following:
[0009] Furthermore, in order to achieve the above objectives, one aspect of the program is: On the computer, The system determines whether the event is a main system monitoring event notified by the main system monitoring agent or a back system monitoring event notified by the back system monitoring agent. If it is determined to be a back system monitoring event, the system stores back system monitoring event identification information for identifying the back system monitoring event in the back system classification waiting storage unit. The main system monitoring events are classified using pre-configured main system classification rule information, and the main system classification result information, which associates the classified classification result with main system monitoring event identification information for identifying the main system monitoring event, is stored in the main system classification result storage unit. It is characterized by the following: [Effects of the Invention]
[0010] One aspect of this is that it can reduce the load on the monitoring equipment used in the monitoring system with both active configurations. [Brief explanation of the drawing]
[0011] [Figure 1] Figure 1 is a diagram illustrating an example of the system configuration. [Figure 2] Figure 2 is a diagram illustrating monitoring agent management information, main system monitoring event information, back-end system monitoring event information, and back-end system classification pending information. [Figure 3] Figure 3 is a diagram illustrating the main system classification rule information, main system classification result information, back system classification rule information, and back system classification result information. [Figure 4] Figure 4 is a diagram illustrating monitoring agent management information, main system monitoring event information, back-end system monitoring event information, and back-end system classification pending information. [Figure 5] Figure 5 is a diagram illustrating the main system classification rule information, main system classification result information, back system classification rule information, and back system classification result information. [Figure 6] Figure 6 is a diagram illustrating the operation of the monitoring device during normal operation. [Figure 7]FIG. 7 is a diagram for explaining the operation of the monitoring device when shifting to the degraded operation. [Figure 8] FIG. 8 is a diagram for explaining the operation of the monitoring device when the monitoring device recovers from an abnormal state and returns to the normal operation. [Figure 9] FIG. 9 is a block diagram showing an example of a computer that realizes the monitoring device in Embodiments 1 to 3.
MODE FOR CARRYING OUT THE INVENTION
[0012] Hereinafter, embodiments will be described with reference to the drawings. In the drawings described below, elements having the same function or corresponding functions are denoted by the same reference numerals, and repeated descriptions thereof may be omitted.
[0013] (Embodiment 1) The configuration of the monitoring system in Embodiment 1 will be described with reference to FIG. 1. FIG. 1 is a diagram for explaining an example of the system configuration.
[0014] [System Configuration] The system 1 in FIG. 1 includes a site 10 (first site) and a site 20 (second site). The sites 10 and 20 have an Active-Active type cluster configuration. The sites 10 and 20 have one or more resources to be monitored. Also, the sites 10 and 20 are connected by a network or the like. Furthermore, the system 1 has a monitoring management system.
[0015] The resources are, for example, devices such as servers and databases. In the example of FIG. 1, two sites 10 and 20 are shown, but the system 1 may have three or more sites.
[0016] A network is a general network built using communication lines such as the internet, LAN (Local Area Network), dedicated lines, telephone lines, corporate networks, mobile communication networks, Bluetooth®, and WiFi (Wireless Fidelity).
[0017] This section explains the monitoring and management system. The monitoring management system includes a monitoring system 100 (first monitoring system) that monitors site 10, and a monitoring system 200 (second monitoring system) that monitors site 20.
[0018] The monitoring systems 100 and 200 are configured as dual active systems (load balancing configuration). Note that while Figure 1 shows two sites 10 and 20, if three or more sites are to be monitored, a separate monitoring system should be provided for each site.
[0019] The monitoring system 100 includes a monitoring device 101 (first monitoring device) and a monitoring terminal 102 (first monitoring terminal). The monitoring system 200 includes a monitoring device 201 (second monitoring device) and a monitoring terminal 202 (second monitoring terminal).
[0020] In normal operation, monitoring systems 100 and 200 perform monitoring tasks for site 10, while monitoring system 200 performs monitoring tasks for site 20.
[0021] In normal operation, monitoring processing is distributed across monitoring systems 100 and 200. Therefore, even in the event of a large volume of access or high-load calculations, monitoring systems 100 and 200 can prevent the monitoring processing from stopping due to excessive load.
[0022] Furthermore, if a failure occurs in monitoring system 100 or monitoring system 200, the monitoring process that the failed monitoring system was performing will be taken over to the monitoring system that is not experiencing the failure, thus ensuring that monitoring of sites 10 and 20 continues. Therefore, the monitoring management system can be considered a highly available system.
[0023] The monitoring device 101 includes a receiving unit 111 (first receiving unit), a determination unit 112 (first determination unit), a classification unit 113 (first classification unit), a synchronization unit 114 (first synchronization unit), a control unit 115 (first control unit), and a storage unit 116 (first storage unit).
[0024] The monitoring device 201 (other monitoring device) includes a receiving unit 211 (second receiving unit), a determination unit 212 (second determination unit), a classification unit 213 (second classification unit), a synchronization unit 214 (second synchronization unit), a control unit 215 (second control unit), and a storage unit 216 (second storage unit).
[0025] The monitoring devices 101 and 201 are, for example, information processing devices such as a CPU (Central Processing Unit), a programmable device such as an FPGA (Field-Programmable Gate Array), a GPU (Graphics Processing Unit), or a circuit or server computer equipped with one or more of these.
[0026] The monitoring terminal 102 is used to instruct the monitoring device 201 to start degraded operation if an abnormality occurs in the monitoring device 201. Specifically, the user uses the monitoring terminal 102 to instruct the monitoring device 101 to continue the monitoring process that the monitoring device 201 was performing.
[0027] Furthermore, once the monitoring device 101 recovers from an abnormal state to a normal state, the user can use the monitoring terminal 102 to instruct the monitoring device 101 to return to normal operation.
[0028] The monitoring terminal 202 is used to instruct the monitoring device 201 to start degraded operation if an abnormality occurs in the monitoring device 101. Specifically, the user uses the monitoring terminal 202 to instruct the monitoring device 201 to continue the monitoring process that the monitoring device 101 was performing.
[0029] Furthermore, once the monitoring device 201 recovers from an abnormal state to a normal state, the user can use the monitoring terminal 202 to instruct the monitoring device 201 to return to normal operation.
[0030] The monitoring terminals 102 and 202 are, for example, information processing devices such as a CPU, a programmable device such as an FPGA, a GPU, or a circuit equipped with one or more of these, a server computer, a personal computer, or a mobile terminal.
[0031] Monitoring agent 103 and monitoring agent 203 are programs that notify monitoring devices 101 and 201 of monitoring events, respectively. From the perspective of monitoring device 101, monitoring agent 103 located at the same site is the main monitoring agent, and monitoring agent 203 located at a different site is the backup monitoring agent. Similarly, from the perspective of monitoring device 201, monitoring agent 203 located at the same site is the main monitoring agent, and monitoring agent 103 located at a different site is the backup monitoring agent.
[0032] Furthermore, from the perspective of monitoring device 101, events notified by monitoring agent 103 are main system monitoring events, and events notified by monitoring agent 203 are background system monitoring events. Similarly, from the perspective of monitoring device 201, events notified by monitoring agent 203 are main system monitoring events, and events notified by monitoring agent 103 are background system monitoring events.
[0033] Monitoring agent 103 is installed on the monitored resources at site 10 and collects monitoring information from those resources. Monitoring agent 203 is installed on the monitored resources at site 20 and collects monitoring information from those resources.
[0034] Monitoring information includes, for example, CPU usage, memory usage, process status, and response performance. Monitoring events are generated when the collected monitoring information meets pre-configured conditions for generating monitoring events.
[0035] The monitoring device 101 will be described in detail. The receiving unit 111 receives monitoring events notified by monitoring agent 103 and monitoring agent 203. The receiving unit 111 outputs the received monitoring events to the determination unit 112.
[0036] The determination unit 112 determines whether the monitoring agent that notified the monitoring event is monitoring agent 103 whose main system is monitoring device 101, or monitoring agent 203 whose main system is monitoring device 201 (backup system relative to monitoring device 101).
[0037] Specifically, first, the determination unit 112 uses the monitoring agent identification information, which identifies the monitoring agent associated with the acquired monitoring event, to refer to the monitoring agent management information 121 and determine whether the monitoring agent that notified the acquired monitoring event is the main system or the backup system for the monitoring device 101.
[0038] Figure 2 is a diagram illustrating monitoring agent management information, main system monitoring event information, back-end system monitoring event information, and back-end system classification pending information.
[0039] The monitoring agent management information 121 is information that associates monitoring agent identification information for identifying each monitoring agent with main system / backup system information indicating whether the monitoring agent is a main system or a backup system for the monitoring device. The monitoring agent management information 121 is pre-stored in the monitoring agent management information storage unit of the storage unit 116.
[0040] In the example in Figure 2, in the monitoring agent management information 121, the monitoring agent identification information (Ag1 (main system), Ag2 (backup system), etc.) corresponding to the monitoring agent 103 is associated with main system / backup system information (1: main system, 0: backup system) that represents the main system.
[0041] Next, if the determination unit 112 determines that the acquired monitoring event is from the main system, it stores the monitoring event as main system monitoring event information 122 in the main system monitoring event storage unit of the storage unit 116.
[0042] Furthermore, if the acquired monitoring event is a background system event, the determination unit 112 stores the monitoring event as background system monitoring event information 123 in the background system monitoring event storage unit of the storage unit 116.
[0043] The main system monitoring event information 122 includes monitoring event identification information (Ev1, Ev2...) for identifying monitoring events, monitoring device internal numbers (1, 2...) indicating the order in which monitoring devices acquired monitoring events, reception date and time information (YMDT1, YMDT2...) indicating the date and time the monitoring event was received (e.g., year, month, day and time), monitoring agent information (Ag1, Ag1...) for identifying the monitoring agent that notified the monitoring event, and information contained in the monitoring event (e.g., message text (MT1, MT2...)). Furthermore, importance information (LV1, LV2...) indicating the importance of the monitoring event may be associated with the main system monitoring event information.
[0044] The background monitoring event information 123 includes monitoring event identification information (Ev3, Ev4...) for identifying monitoring events, monitoring device internal number (1, 2...) indicating the order in which the monitoring device acquired the monitoring events, reception date and time information (YMDT3, YMDT4...) indicating the date and time the monitoring event was received (e.g., year, month, day and time), monitoring agent information (Ag2, Ag2...) for identifying the monitoring agent that notified the monitoring event, and information contained in the monitoring event (e.g., message text (MT3, MT4...)). Furthermore, importance information (LV2, LV1...) indicating the importance of the monitoring event may be associated with the background monitoring event information.
[0045] Furthermore, if the acquired monitoring event is a back-end system event, the determination unit 112 stores the acquired back-end system monitoring event identification information (Ev3, Ev4...) as back-end system classification waiting information 124 in the back-end system classification waiting storage unit of the storage unit 116. The back-end system classification waiting storage unit is, for example, a queue.
[0046] The classification unit 113, when the source of the monitoring event notification is the monitoring agent 103 (which is the main monitoring agent for the monitoring device 101), performs classification processing using regular expressions or the like for the monitoring event.
[0047] Specifically, first, if the source of the monitoring event notification is the monitoring agent 103, the classification unit 113 uses the message text of the monitoring event to refer to the main system classification rule information 125 and classifies the monitoring event.
[0048] Figure 3 is a diagram illustrating the main system classification rule information, main system classification result information, back system classification rule information, and back system classification result information.
[0049] The main system classification rule information 125 includes rule identification information (R1, R2, etc.) for identifying rules and classification rule information (rule1, rule2, etc.) representing rules for classifying monitored events. The main system classification rule information 125 is stored in the main system classification rule storage unit of the storage unit 116.
[0050] Classification rule information consists of rules used to classify monitoring events based on the cause of the monitoring event. Examples include upper and lower threshold rules for numerical information such as CPU usage, and regular expression rules for text information such as process presence or absence and logs.
[0051] Next, the classification unit 113 associates the monitoring event identification information (Ev1, Ev2...) of the monitoring event with the classification result information (Sv1, Sv2...) representing the classification result, and stores it in the main system classification result storage unit as main system classification result information 126.
[0052] Classification result information identifies the cause of each monitoring event. For example, classification result information is information (category identification information) used to identify categories such as CPU failure, memory failure, process abnormality, degraded response performance, and application abnormality.
[0053] Furthermore, in normal operation, if the source of a monitoring event notification is the monitoring agent 203 (which is a background monitoring agent for the monitoring device 101), the classification unit 113 does not perform classification processing using regular expressions or the like for that monitoring event. Therefore, the load on the monitoring device 101 due to classification processing can be reduced.
[0054] The synchronization unit 114 synchronizes the main system monitoring event information 122 of the monitoring device 101 with the background system monitoring event information 223 of the monitoring device 201. The synchronization unit 114 also synchronizes the main system classification result information 126 of the monitoring device 101 with the background system classification result information 228 of the monitoring device 201.
[0055] Specifically, after the new main system classification result is added to the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, the synchronization unit 114 makes the contents of the background system monitoring event information 223 in the background system monitoring event storage unit of the monitoring device 201 the same as the contents of the main system monitoring event information 122 in the main system monitoring event storage unit of the monitoring device 101.
[0056] Furthermore, after the new main system classification result is added to the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, the synchronization unit 114 makes the contents of the background system classification result information 228 in the background system classification result storage unit of the monitoring device 201 the same as the contents of the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101.
[0057] Furthermore, the synchronization unit 114 makes the contents of the background system classification result information 228 in the background system classification result storage unit of the monitoring device 201 the same as the contents of the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, and then deletes the background system monitoring event identification information corresponding to the classification results that were added when making them the same from the background system classification waiting information 124.
[0058] Synchronization processing may be performed at pre-set intervals or when it is determined that the processing load on the backend system is light.
[0059] If an abnormality occurs in the monitoring device 201, the control unit 115 receives an instruction from the monitoring terminal 102 to start degraded operation of the monitoring device 101 and controls the monitoring device 101 to continue the monitoring process that it was performing.
[0060] Furthermore, when the monitoring device 201 recovers from an abnormal state to a normal state, the control unit 115 receives an instruction from the monitoring terminal 102 to return the monitoring device 201 to normal operation and controls the monitoring device 101 to return it to normal operation.
[0061] The memory unit 116 stores at least monitoring agent management information 121, main system monitoring event information 122, back system monitoring event information 123, back system classification waiting information 124, main system classification rule information 125, main system classification result information 126, back system classification rule information 127, and back system classification result information 128.
[0062] The storage unit 116 is a storage device such as a server computer or a database. In the example in Figure 1, it is located inside the monitoring device 101, but it may also be located outside the monitoring device 101. Figure 1 shows an example in which the above information is stored in one storage unit 116, but the above information may also be divided and stored in multiple storage units.
[0063] The monitoring device 201 will be described in detail. The receiving unit 211 receives monitoring events notified by monitoring agent 203 and monitoring agent 103. The receiving unit 211 outputs the received monitoring events to the determination unit 212.
[0064] The determination unit 212 determines whether the monitoring agent that notified the monitoring event is monitoring agent 203 whose main system is monitoring device 201, or monitoring agent 103 whose main system is monitoring device 101 (backup system for monitoring device 201).
[0065] Specifically, first, the determination unit 212 uses the monitoring agent identification information, which identifies the monitoring agent associated with the acquired monitoring event, to refer to the monitoring agent management information 221 and determine whether the monitoring agent that notified the acquired monitoring event is the main system or the backup system for the monitoring device 201.
[0066] Figure 4 is a diagram illustrating monitoring agent management information, main system monitoring event information, back-end system monitoring event information, and back-end system classification pending information.
[0067] The monitoring agent management information 221 is information that associates monitoring agent identification information for identifying each monitoring agent with main system / backup system information indicating whether the monitoring agent is a main system or a backup system for the monitoring device. The monitoring agent management information 221 is pre-stored in the monitoring agent management information storage unit of the storage unit 216.
[0068] In the example in Figure 4, the monitoring agent management information 221 associates the monitoring agent identification information (Ag1 (backup system), Ag2 (main system), etc.) corresponding to the monitoring agent 103 with main system / backup system information (1: main system, 0: backup system) that represents the main system.
[0069] Next, if the determination unit 212 determines that the acquired monitoring event is from the main system, it stores the monitoring event as main system monitoring event information 222 in the main system monitoring event storage unit of the storage unit 216.
[0070] Furthermore, if the acquired monitoring event is a background system event, the determination unit 212 stores the monitoring event as background system monitoring event information 223 in the background system monitoring event storage unit of the storage unit 216.
[0071] The main system monitoring event information 222 includes monitoring event identification information (Ev3, Ev4...) for identifying monitoring events, an internal monitoring device number indicating the order in which monitoring devices acquired monitoring events, reception date and time information (YMDT3, YMDT4...) indicating the date and time the monitoring event was received (e.g., year, month, day, and time), monitoring agent information (Ag2, Ag2...) for identifying the monitoring agent that notified the monitoring event, and information contained in the monitoring event (e.g., message text (MT3, MT4...)). Furthermore, importance information (LV2, LV1...) indicating the importance of the monitoring event may be associated with the main system monitoring event information.
[0072] The background monitoring event information 223 includes monitoring event identification information (Ev1, Ev2...) for identifying monitoring events, monitoring device internal numbers (1, 2...) indicating the order in which monitoring devices acquired monitoring events, reception date and time information (YMDT1, YMDT2...) indicating the date and time the monitoring event was received (e.g., year, month, day and time), monitoring agent information (Ag1, Ag1...) for identifying the monitoring agent that notified the monitoring event, and information contained in the monitoring event (e.g., message text (MT1, MT2...)). Furthermore, importance information (LV1, LV2...) indicating the importance of the monitoring event may be associated with the background monitoring event information.
[0073] Furthermore, if the acquired monitoring event is a background system event, the determination unit 212 stores the monitoring agent identification information (Ev1, Ev2, etc.) of the acquired background system monitoring event as background system classification waiting information 224 in the background system classification waiting storage unit of the storage unit 216. The background system classification waiting storage unit is, for example, a queue.
[0074] The classification unit 213, when the source of the monitoring event notification is the monitoring agent 203 (which is the main monitoring agent for the monitoring device 201), performs classification processing using regular expressions or the like for the monitoring event.
[0075] Specifically, first, if the source of the monitoring event notification is the monitoring agent 203, the classification unit 213 uses the message text of the monitoring event to refer to the main system classification rule information 225 and classifies the monitoring event.
[0076] Figure 5 is a diagram illustrating the main system classification rule information, main system classification result information, back system classification rule information, and back system classification result information.
[0077] The main system classification rule information 225 includes rule identification information (R3, R4...) for identifying rules and classification rule information (rule3, rule4...) representing rules for classifying monitored events. The main system classification rule information 125 is stored in the main system classification rule storage unit of the storage unit 216.
[0078] Next, the classification unit 213 associates the monitoring event identification information (Ev3, Ev4...) of the monitoring event with the classification result information (Sv3, Sv4...) representing the classification result, and stores it in the main system classification result storage unit as main system classification result information 226.
[0079] Furthermore, in normal operation, if the source of a monitoring event notification is the monitoring agent 103 (which is a background monitoring agent for the monitoring device 201), the classification unit 213 does not perform classification processing using regular expressions or the like for that monitoring event. Therefore, the load on the monitoring device 201 due to classification processing can be reduced.
[0080] The synchronization unit 214 synchronizes the main system monitoring event information 222 with the background system monitoring event information 123 of the monitoring device 101. The synchronization unit 214 also synchronizes the main system classification result information 226 with the background system classification result information 128 of the monitoring device 101.
[0081] Specifically, after the new main system classification result is added to the main system classification result information 226 in the main system classification result storage unit of the monitoring device 201, the synchronization unit 214 makes the contents of the background system monitoring event information 123 in the background system monitoring event storage unit of the monitoring device 101 the same as the contents of the main system monitoring event information 222 in the main system monitoring event storage unit of the monitoring device 201.
[0082] Furthermore, after the new main system classification result is added to the main system classification result information 226 in the main system classification result storage unit of the monitoring device 201, the synchronization unit 214 makes the contents of the background system classification result information 128 in the background system classification result storage unit of the monitoring device 101 the same as the contents of the main system classification result information 226 in the main system classification result storage unit of the monitoring device 201.
[0083] Furthermore, the synchronization unit 214 makes the contents of the background system classification result information 128 in the background system classification result storage unit of the monitoring device 101 the same as the contents of the main system classification result information 226 in the main system classification result storage unit of the monitoring device 201, and then deletes the background system monitoring event identification information corresponding to the classification results added during the matching process from the background system classification waiting information 224.
[0084] Synchronization processing may be performed at pre-set intervals or when it is determined that the processing load on the backend system is light.
[0085] If an abnormality occurs in the monitoring device 101, the control unit 215 receives an instruction from the monitoring terminal 202 to start degraded operation of the monitoring device 201 and controls the monitoring device 201 to continue the monitoring process that it was performing.
[0086] Furthermore, when the monitoring device 101 recovers from an abnormal state to a normal state, the control unit 215 receives an instruction from the monitoring terminal 202 to return the monitoring device 101 to normal operation and controls the monitoring device 201 to return it to normal operation.
[0087] The memory unit 216 stores at least monitoring agent management information 221, main system monitoring event information 222, back system monitoring event information 223, back system classification waiting information 224, main system classification rule information 225, main system classification result information 226, back system classification rule information 227, and back system classification result information 228.
[0088] The storage unit 216 is a storage device such as a server computer or a database. In the example in Figure 1, it is located inside the monitoring device 201, but it may also be located outside the monitoring device 201. Figure 1 shows an example where the above information is stored in a single storage unit 216, but the above information may also be divided and stored in multiple storage units.
[0089] [Device operation] The operation of the monitoring device in Embodiment 1 will be explained using Figure 6. Figure 6 is a diagram illustrating the operation of the monitoring device during normal operation. In the following explanation, refer to the figure as appropriate. In Embodiment 1, the monitoring method is performed by operating the monitoring device. Therefore, the explanation of the monitoring method in Embodiment 1 will be replaced by the following explanation of the operation of the monitoring device.
[0090] Figure 6 illustrates the operation of monitoring device 101 during normal operation, where monitoring device 101 in Figure 1 is the main system and monitoring device 201 is the backup system.
[0091] The receiving unit 111 receives a monitoring event (step A1). The determination unit 112 determines whether the received monitoring event was notified by monitoring agent 103 (main system) or by monitoring agent 203 (backup system) (step A2).
[0092] Specifically, in step A2, the determination unit 112 uses the monitoring event acquired from the receiving unit 111 to refer to the monitoring agent management information 121 and determines whether the monitoring agent that notified the monitoring event is the main system or the backup system for the monitoring device 101.
[0093] Next, in step A2, if the determination unit 112 determines that the acquired monitoring event is from the main system, it stores the monitoring event as main system monitoring event information 122 in the main system monitoring event storage unit of the storage unit 116.
[0094] Furthermore, in step A2, if the acquired monitoring event is a background system event, the determination unit 112 stores the monitoring event as background system monitoring event information 123 in the background system monitoring event storage unit of the storage unit 116.
[0095] Next, in step A2, if the acquired monitoring event is a background system event, the determination unit 112 stores the monitoring agent identification information of the acquired monitoring event as background system classification waiting information 124 in the background system classification waiting storage unit of the storage unit 116.
[0096] The classification unit 113, if the source of the monitoring event notification is the monitoring agent 103, performs classification processing using regular expressions or the like only for that monitoring event (step A3).
[0097] Specifically, in step A3, if the source of the monitoring event notification is the monitoring agent 103, the classification unit 113 uses the monitoring event to refer to the main system classification rule information 125 and classifies the monitoring event.
[0098] Next, in step A3, the classification unit 113 associates the monitoring event identification information of the monitoring event with the classification result information representing the classification result and stores it as the main system classification result information 126.
[0099] In step A3, the classification unit 113 does not perform classification if the source of the monitoring event notification is the monitoring agent 203.
[0100] The synchronization unit 114 synchronizes the main system monitoring event information 122 of the monitoring device 101 with the background system monitoring event information 223 of the monitoring device 201 (step A4). In step A4, the synchronization unit 114 also synchronizes the main system classification result information 126 of the monitoring device 101 with the background system classification result information 228 of the monitoring device 201.
[0101] Specifically, in step A4, after the new main system classification result is added to the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, the synchronization unit 114 makes the contents of the background system monitoring event information 223 in the background system monitoring event storage unit of the monitoring device 201 the same as the contents of the main system monitoring event information 122 in the main system monitoring event storage unit of the monitoring device 101.
[0102] Furthermore, in step A4, after the new main system classification result is added to the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, the synchronization unit 114 makes the contents of the back system classification result information 228 in the back system classification result storage unit of the monitoring device 201 the same as the contents of the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101.
[0103] Furthermore, in step A4, after the new main system classification result is added to the main system classification result information 126 in the main system classification result storage unit of the monitoring device 101, the synchronization unit 114 deletes the monitoring event identification information corresponding to the added classification result from the back system classification waiting information 124.
[0104] Thus, in normal operation, the monitoring device 101 repeatedly executes the processes from steps A1 to A4 described above.
[0105] Furthermore, synchronization may be performed at pre-set intervals or when it is determined that the processing load on the backend system is low. This determination can be made, for example, by checking whether the CPU usage of the backend monitoring system exceeds a certain threshold.
[0106] Using Figure 6, we have explained the operation of monitoring device 101 in normal operation, with monitoring device 101 in Figure 1 as the main system and monitoring device 201 as the backup system. Therefore, we will omit the explanation of the operation of monitoring device 201 in normal operation, with monitoring device 201 in Figure 1 as the main system.
[0107] [Effects of Embodiment 1] As described above, according to Embodiment 1, in the monitoring device used in the monitoring system of both active configurations, the classification processing of the backend system is not performed during normal operation, so the load on the monitoring device can be suppressed.
[0108] By synchronizing the main system classification results of one monitoring device with the background system classification results of other monitoring devices, pre-processing for synchronization (such as pre-extracting data) becomes unnecessary. Therefore, the load on the monitoring device during normal operation can be reduced.
[0109] [program] The program in Embodiment 1 can be any program that causes a computer to execute steps A1 to A4 shown in Figure 6. By installing and running this program on a computer, the monitoring device and monitoring method in Embodiment 1 can be realized.
[0110] In the case of monitoring device 101, the computer processor functions as a receiving unit 111, a determination unit 112, a classification unit 113, a synchronization unit 114, and a control unit 115, and performs processing. Similarly, in the case of monitoring device 201, the computer processor functions as a receiving unit 211, a determination unit 212, a classification unit 213, a synchronization unit 214, and a control unit 215, and performs processing.
[0111] Furthermore, the program in Embodiment 1 may be executed by a computer system constructed by multiple computers. In the case of the monitoring device 101, for example, each computer may function as one of the following: receiving unit 111, determination unit 112, classification unit 113, synchronization unit 114, or control unit 115. Similarly, in the case of the monitoring device 201, for example, each computer may function as one of the following: receiving unit 211, determination unit 212, classification unit 213, synchronization unit 214, or control unit 215.
[0112] (Embodiment 2) This section explains a scenario where one of the monitoring devices malfunctions due to a disaster or other reason, and the system begins operating in a reduced state using the other monitoring device.
[0113] The operation of the monitoring device in Embodiment 2 will be explained using Figure 7. Figure 7 is a diagram illustrating the operation of the monitoring device when transitioning to degraded operation. In the following explanation, refer to the figure as appropriate. In Embodiment 2, the monitoring method is performed by operating the monitoring device. Therefore, the explanation of the monitoring method in Embodiment 2 will be replaced by the following explanation of the operation of the monitoring device.
[0114] Let's explain the scenario where monitoring device 201 enters an abnormal state. First, if the monitoring device 201 becomes abnormal due to a disaster or other reason, the user uses the monitoring terminal 102 to send an instruction to the monitoring device 101 to start degraded operation using the monitoring device 101.
[0115] Next, when the control unit 115 receives an instruction from the monitoring terminal 102 to start degraded operation (step B1), the classification unit 113 refers to the monitoring event identification information stored in the back-end classification waiting information 124 and acquires the unclassified monitoring event corresponding to the monitoring event identification information (step B2).
[0116] Next, the classification unit 113 performs classification processing using regular expressions on unclassified monitoring events (step B3).
[0117] Specifically, in step B3, if the source of the monitoring event notification is the monitoring agent 103, the classification unit 113 uses the monitoring event to refer to the background classification rule information 227 and classifies the monitoring event.
[0118] The background classification rule information 127 shown in Figure 3 includes rule identification information (R3, R4...) for identifying background rules and classification rule information (rule3, rule4...) representing rules for classifying monitoring events.
[0119] Next, in step B3, the classification unit 113 associates the monitoring event identification information (Ev3, Ev4...) of the monitoring event with the classification result information (Sv3, Sv4...) representing the classification result, and stores it as background classification result information 128 in the background classification result storage unit of the storage unit 116.
[0120] Next, after the processes described in steps B1 to B3 above are executed and degraded operation is started, newly occurring monitoring events of the back system notified by monitoring agent 203 are processed by monitoring device 101 in the same way as monitoring events of the main system notified by monitoring agent 103.
[0121] Next, we will explain the scenario where the monitoring device 101 enters an abnormal state. First, if the monitoring device 101 becomes abnormal due to a disaster or other reason, the user uses the monitoring terminal 202 to send an instruction to the monitoring device 201 to start degraded operation using the monitoring device 201.
[0122] Next, when the control unit 215 receives an instruction from the monitoring terminal 202 to start degraded operation (step B1), the classification unit 213 refers to the monitoring event identification information stored in the back-end classification waiting information 224 and acquires the unclassified monitoring event corresponding to the monitoring event identification information (step B2).
[0123] Next, the classification unit 213 performs classification processing using regular expressions on unclassified monitoring events (step B3).
[0124] Specifically, in step B3, if the source of the monitoring event notification is the monitoring agent 203, the classification unit 213 uses the monitoring event to refer to the background classification rule information 227 and classifies the monitoring event.
[0125] The background classification rule information 227 shown in Figure 5 includes rule identification information (R1, R2...) for identifying background rules and classification rule information (rule1, rule2...) representing rules for classifying monitoring events.
[0126] Next, in step B3, the classification unit 213 associates the monitoring event identification information (Ev1, Ev2...) of the monitoring event with the classification result information (Sv1, Sv2...) representing the classification result, and stores it as background classification result information 228 in the background classification result storage unit of the storage unit 216.
[0127] Next, after the processes described in steps B1 to B3 above are executed and degraded operation is started, newly occurring monitoring events of the back system notified by monitoring agent 103 are processed by monitoring device 201 in the same way as monitoring events of the main system notified by monitoring agent 203.
[0128] [Effects of Embodiment 2] As described above, according to Embodiment 2, in the monitoring systems used in both active configurations, even if one of the monitoring devices enters an abnormal state, the system can transition to degraded operation using the other monitoring device.
[0129] (Embodiment 3) This section explains how a monitoring device recovers from an abnormal state and returns to normal operation.
[0130] The operation of the monitoring device in Embodiment 3 will be explained using Figure 8. Figure 8 is a diagram illustrating the operation of the monitoring device when it recovers from an abnormal state and returns to normal operation. In the following explanation, refer to the figure as appropriate. In Embodiment 3, the monitoring method is performed by operating the monitoring device. Therefore, the explanation of the monitoring method in Embodiment 3 will be replaced by the following explanation of the operation of the monitoring device.
[0131] From this point forward, the explanation will assume that the monitoring device 101, which has become abnormal due to a disaster or other reason, has been restored.
[0132] First, once the monitoring device 101, which has become abnormal due to a disaster or other reason, is restored, the user uses the monitoring terminal 102 to send instructions to the monitoring device 101 to return it to normal operation.
[0133] When the control unit 115 receives an instruction to return the monitoring device 101 to normal operation (step C1), the synchronization unit 114 synchronizes the contents of the main system monitoring event information 122 of the monitoring device 101 with the contents of the background system monitoring event information 223 of the monitoring device 201 (step C2). In other words, the contents of the main system monitoring event information 122 are made the same as the contents of the background system monitoring event information 223.
[0134] Next, the synchronization unit 114 updates the internal monitoring device code number of the main system monitoring event information 122 (step C3). For example, if the internal monitoring device code number of the last event processed by the main system is 100, the synchronization unit updates the codes for events added by the synchronization process with incremented numbers such as 101, 102, and 103 in order.
[0135] Next, the synchronization unit 114 synchronizes the contents of the background monitoring event information 123 of the monitoring device 101 with the contents of the main system monitoring event information 222 of the monitoring device 201 (step C4). In other words, it makes the contents of the background monitoring event information 123 the same as the contents of the main system monitoring event information 222.
[0136] Next, the synchronization unit 114 updates the internal monitoring device code number of the background system monitoring event information 123 (step C5). For example, if the internal monitoring device code number of the last event processed by the background system is 150, the synchronization unit updates the codes for events added by the synchronization process with incremented numbers such as 151, 152, and 153 in order.
[0137] Next, the synchronization unit 114 synchronizes the contents of the main system classification result information 126 of the monitoring device 101 with the contents of the background system classification result information 228 of the monitoring device 201 (step C6). In other words, it makes the contents of the main system classification result information 126 the same as the contents of the background system classification result information 228.
[0138] Furthermore, the synchronization unit 114 synchronizes the contents of the background system classification result information 128 of the monitoring device 101 with the contents of the main system classification result information 226 of the monitoring device 201 (step C7). In other words, it makes the contents of the background system classification result information 128 the same as the contents of the main system classification result information 226.
[0139] Next, once synchronization is complete, monitoring device 101 sends an instruction to monitoring device 201 to start normal operation (step C8). After executing the processes from steps C1 to C8 described above, monitoring devices 101 and 201 transition to normal operation.
[0140] As the operation of monitoring device 101 when it recovers from an abnormal state has been described above, the explanation of the operation of monitoring device 201 when it recovers from an abnormal state will be omitted. [Effects of Embodiment 3] As described above, according to Embodiment 3, when the monitoring device recovers from an abnormal state, it can be returned to normal operation.
[0141] [Physical configuration] Here, a computer that implements a monitoring device by executing the programs in Embodiments 1 to 3 will be described using Figure 9. Figure 9 is a block diagram showing an example of a computer that implements a monitoring device in Embodiments 1 to 3.
[0142] As shown in Figure 9, the computer 910 comprises a CPU 911, main memory 912, storage device 913, input interface 914, display controller 915, data reader / writer 916, and communication interface 917. Each of these components is connected to each other via a bus 921 to enable data communication. In addition to the CPU 911, or in place of the CPU 911, the computer 910 may also include a GPU or FPGA.
[0143] The CPU 911 loads the program (code) in the embodiment, stored in the storage device 913, into the main memory 912 and performs various calculations by executing them in a predetermined order. The main memory 912 is typically a volatile storage device such as DRAM (Dynamic Random Access Memory). The program in the embodiment is provided stored in a computer-readable recording medium 920. The program in the embodiment may be distributed over the internet connected via the communication interface 917. The recording medium 920 is a non-volatile recording medium.
[0144] Specific examples of the storage device 913 include hard disk drives and semiconductor storage devices such as flash memory. The input interface 914 mediates data transmission between the CPU 911 and input devices 918 such as a keyboard and mouse. The display controller 915 is connected to the display device 919 and controls the display on the display device 919.
[0145] The data reader / writer 916 mediates data transmission between the CPU 911 and the recording medium 920, reads programs from the recording medium 920, and writes processing results from the computer 910 to the recording medium 920. The communication interface 917 mediates data transmission between the CPU 911 and other computers.
[0146] Furthermore, specific examples of the recording medium 920 include general-purpose semiconductor memory devices such as CF (Compact Flash®) and SD (Secure Digital), magnetic recording media such as Flexible Disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).
[0147] Furthermore, the monitoring devices in embodiments 1 to 3 can also be implemented using hardware corresponding to each part, rather than a computer on which the program is installed. In addition, the monitoring device may be partially implemented by program and the remaining part by hardware.
[0148] Although the invention has been described above with reference to embodiments, the invention is not limited to the embodiments described above. Various modifications to the structure and details of the invention can be made that will be understood by those skilled in the art within the scope of the invention. [Industrial applicability]
[0149] As described above, under normal operation, the load on monitoring devices used in monitoring systems with both active configurations can be reduced. Furthermore, it is useful in fields where monitoring systems with both active configurations are required. [Explanation of Symbols]
[0150] 1 System 10, 20 sites 100, 200 monitoring systems 101, 201 Monitoring equipment 102, 202 monitoring terminals 103, 203 Surveillance Agents 111, 211 Receiving Unit 112, 212 Judgment section 113, 213 Classification section 114, 214 Classmates 115, 215 Control Unit 116, 216 Storage section 121, 221 Monitoring Agent Management Information 122, 222 Main System Monitoring Event Information 123, 223 Back-related monitoring event information 124, 224 Back-related classification pending information 125, 225 Main Classification Rule Information 126, 226 Main System Classification Results Information 127, 227 Back-type classification rule information 128, 228 Back-type classification results information 910 Computer 911 CPU 912 Main Memory 913 Storage device 914 Input Interface 915 Display Controller 916 Data Reader / Writer 917 Communication Interface 918 Input devices 919 Display device 920 recording media 921 Bus
Claims
1. A determination means that determines whether a main system monitoring event is notified by a main system monitoring agent or a back system monitoring event is notified by a back system monitoring agent, and if it is determined to be a back system monitoring event, stores back system monitoring event identification information for identifying the back system monitoring event in a back system classification waiting storage unit. A classification means that classifies the aforementioned main system monitoring events using pre-configured main system classification rule information, and stores main system classification result information in a main system classification result storage unit, which associates the classified classification result with main system monitoring event identification information for identifying the aforementioned main system monitoring event. A monitoring device having the following features.
2. A synchronization means that associates the classification result obtained by classifying the main system monitoring event notified by the main system monitoring agent to another monitoring device different from the monitoring device using the main system classification rule information with monitoring event identification information that identifies the main system monitoring event, and makes the content of the back system classification result information of the other monitoring device stored in the back system classification result storage unit of the other monitoring device the same as the content of the main system classification result information of the main system classification result storage unit of the monitoring device, A monitoring device according to claim 1, having the following features.
3. The synchronization means further makes the contents of the background classification result information of the other monitoring device the same as the contents of the main system classification result information of the main system classification result storage unit of the monitoring device, and then deletes the background monitoring event identification information corresponding to the classification result added during the matching process from the background system classification waiting storage unit. The monitoring device according to claim 2.
4. When an abnormality occurs in the monitoring device, the classification means classifies the background monitoring events related to the background monitoring event identification information stored in the background classification waiting storage unit using pre-configured background classification rule information, in order to allow the other monitoring device to continue the monitoring process that the monitoring device was performing. The classification means then stores background classification result information, which associates the classified classification result with the background monitoring event identification information that identifies the background monitoring event, in the background classification result storage unit of the monitoring device. The monitoring device according to claim 3.
5. When the monitoring device is restored, the synchronization means makes the content of the main system monitoring event information in the main system monitoring event storage unit of the monitoring device, which stores the main system monitoring events, the same as the content of the background system monitoring event information in the background system monitoring event storage unit of the other monitoring device, which stores the main system monitoring events. The content of the background system monitoring event information in the background system monitoring event storage unit of the monitoring device for storing the background system monitoring events is made the same as the content of the main system monitoring event information in the main system monitoring event storage unit of the other monitoring device for storing the main system monitoring events. The content of the main system classification result information in the main system classification result storage unit of the monitoring device is made the same as the content of the back system classification result information stored in the back system classification result storage unit of the other monitoring device. The contents of the back-system classification result information in the back-system classification result storage unit of the monitoring device are made to be the same as the contents of the main-system classification result information stored in the main-system classification result storage unit of the other monitoring device. The monitoring device according to claim 4.
6. Computers The system determines whether the event is a main system monitoring event notified by the main system monitoring agent or a back system monitoring event notified by the back system monitoring agent. If it is determined to be a back system monitoring event, the system stores back system monitoring event identification information for identifying the back system monitoring event in the back system classification waiting storage unit. The aforementioned main system monitoring events are classified using pre-configured main system classification rule information, and the main system classification result information, which associates the classified classification result with the main system monitoring event identification information for identifying the main system monitoring event, is stored in the main system classification result storage unit. Monitoring method.
7. On the computer, The system determines whether the event is a main system monitoring event notified by the main system monitoring agent or a back system monitoring event notified by the back system monitoring agent. If it is determined to be a back system monitoring event, the system stores back system monitoring event identification information for identifying the back system monitoring event in the back system classification waiting storage unit. The aforementioned main system monitoring events are classified using pre-configured main system classification rule information, and the main system classification result information, which associates the classified classification result with main system monitoring event identification information for identifying the main system monitoring event, is stored in the main system classification result storage unit. program.
Citation Information
Patent Citations
Digital control system
JP1995271626A
Computer system, method of shifting to backup system, program of shifting to backup system, monitoring device, terminal, and backup system
JP2008092144A
Monitored device, agent program, and monitoring system
WO2014147692A1