Method and system for monitoring and addressing anomalies detected during a field operation
An Al-powered framework with a generative Al agent autonomously detects and resolves anomalies in drilling operations, addressing cybersecurity and network isolation challenges, thereby enhancing operational efficiency and safety in edge computing environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SCHLUMBERGER TECH CORP
- Filing Date
- 2025-10-29
- Publication Date
- 2026-05-07
AI Technical Summary
The challenge in drilling operations is the need for a comprehensive automation system that enhances operational resilience, reduces tool runs, and adds measurable value to the bottom line, while addressing cybersecurity risks and network isolation challenges in edge computing environments, particularly in remote and offshore settings.
An Al-powered framework with a generative Al agent integrates with a fleet management system to autonomously detect and resolve anomalies by analyzing real-time logs, providing direct insights to remotely based SRE teams without manual intervention, using embedding models for real-time anomaly detection and LLM-powered agents for autonomous resolution.
This approach enables proactive issue detection and self-management, enhancing operational efficiency, safety, and security, minimizing downtime and improving operational resilience across geographically distributed drilling sites.
Smart Images

Figure US2025053145_07052026_PF_FP_ABST
Abstract
Description
PATENT Attorney Docket No.: IS24.0625-WOMETHOD AND SYSTEM FOR MONITORING AND ADDRESSING ANOMALIESDETECTED DURING A FIELD OPERATIONCross-Reference to Related ApplicationsThis patent application claims priority to U.S. Provisional Patent Application No. 63 / 714235, filed on October 31, 2024, which is incorporated by reference herein in its entirety.Background
[0001] The ongoing adoption of digitization in the oil and gas sector, especially within drilling operations, has significantly accelerated the deployment of digital technologies in the field. With this rapid growth, there is a pressing need for an effective framework to proactively monitor field deployments and enhance operational resilience. Previously, an advanced monitoring system featuring Elastic Fleet Management was introduced to address this need, combining real-time performance tracking with incident alerting capabilities integrated with tools such as Software as a Service (SaaS) incident management platforms. This approach established new benchmarks for reducing Non-Productive Time (NPT) and improving service delivery by providing Site Reliability Engineering (SRE) teams with critical tools to maintain high standards amid continuous expansion.
[0002] In the evolving landscape of drilling technologies, automation has emerged as a key driver for improving efficiency, safety, and operational performance. For nearly a decade, the oil and gas industry has focused on deploying advanced tools such as rig mechanization, robotics, and Al-driven automation to optimize drilling operations. However, the full potential of these systems is still being realized, as delivering consistent financial savings and efficiency gains remains a challenge. The complexities of drilling operations, especially in remote and offshore environments, require a comprehensive approach to automation that goes beyond traditional methods. It is not just about deploying the right tools but about creating a system that enhances overall performance, reduces tool runs, and adds measurable value to the bottom line.
[0003] To achieve these goals, integrating edge computing has become essential. By bringing Al-powered analytics and advanced processing closer to the operational environment, edge computing addresses the unique challenges of drilling automation. However, this also introduces cybersecurity risks, particularly when solutions are deployed on Operational Technology (OT) networks with restrictive access. Ensuring the security of these deployments is crucial, as itPATENT Attorney Docket No.: IS24.0625-WO involves managing who accesses devices, detecting any unusual activities, and responding swiftly to incidents like reboots or suspicious network connections.
[0004] Observability, while a well-established concept in cloud computing, poses a different set of challenges when applied to edge environments. The complexity of rig networks, combined with bandwidth limitations, makes it difficult for centralized support teams to maintain a clear picture of what is happening at the edge. With support teams often located remotely and not at the rig site, it becomes imperative to provide real-time visibility into the status of devices and operations. To address these challenges, a flexible fleet management system has been implemented that enables proactive monitoring of edge deployments. This approach may ensure that support teams can detect anomalies, track access and activity, and manage the performance of devices from a central location, setting the stage for a quick and effective response. However, even with the fleet management system providing proactive monitoring, network isolation still poses significant challenges, as it limits the ability of SRE support teams to connect directly to edge devices.
[0005] Energy exploration digital platforms tackle drilling challenges by connecting the rig to town and automating operations through Al-driven solutions. Real-time connectivity and data- driven insights enable collaboration and performance. With global commercial deployments, its innovative platform sets the standard in drilling efficiency and sustainability. The energy exploration platform leverages cutting-edge technology and an experimental mindset to revolutionize drilling operations. For example, cloud-edge integration enables seamless connectivity and real-time collaboration between the wellsite and the office across the MWD (Measurement While Drilling), DD (Directional Drilling), surface logging, fluids, procedural adherence, and drilling domains. Additionally, Al-driven drilling automation brings enhanced safety, performance, and consistency to the drilling operation while data-driven insights, empower operators to overcome the limitations of traditional drilling practices, unlocking new levels of efficiency, safety, and sustainability. Furthermore, the energy exploration platform provides a modular design, thereby enabling scaling and distributed development of the system using plugins.
[0006] The energy exploration platform solution adopts a goal-based automation methodology, using powerful data analysis and learning systems to assist and optimize every task, from setting rate of penetration to drilling a stand. Users may choose from a preset menu of automatable drilling tasks, and using data analysis and models, share a plan to achieve the specified goal, taking anyPATENT Attorney Docket No.: IS24.0625-WO measurements required to calibrate itself. Operators have the flexibility to modify and replan activities dynamically, based on a live appraisal of equipment, personnel, and supplies.
[0007] Automation enables reduced staffing levels on mechanized rigs and delivers unparalleled consistency of repetitive tasks, helping users reach the technical limit on every well. Alert and escalate procedures are built directly into the energy exploration platform solution — making it easier to resolve any potential conflicts and administer corrective action. Everything that happens is automatically documented within the digital well file to streamline reporting and drive continuous improvement.
[0008] The energy exploration platform solution may be used to monitor and capture a broad range of operational data to support operators during drilling with real-time advice and coaching to improve decision-making and reduce risk. Intelligent advisory systems guide crews to stay within operating windows and safety thresholds. Predictive analytics continuously identify drilling dysfunctions, alerting personnel before pre-defined limits are due to be exceeded to reduce nonproductive time (NPT).
[0009] Progress may be continually compared with targets defined in the drilling plan across a range of criteria, including operating costs and other key performance indicators, to deliver a live picture of performance. Any deviations from the plan are recorded in the digital well file, alongside all the relevant operational data. By capturing the full operational context across multiple domains, the energy exploration platform solution may increase the value of reporting and post-job analysis to improve every subsequent well.
[0010] The energy exploration platform solution may execute the digital drilling plan and ensure plan adherence. It may further improve collaboration and coordination by directing the relevant information to the right people, at the right time, and always in the right context. Since workflows are curated centrally by the system, step-by-step activity plans are automatically generated for individual operations teams to keep all teams aligned. With all well construction activities from tripping to cementing continually monitored and dynamically updated with the latest operational activity, the operations team is always up to date.
[0011] The integration of all data into one system by utilizing relevant downhole tool data and surface measurements combine to make the best use of the information available. Step-by-step simplified workflows, reduction of human dependencies, and transformation of how directional and data services are delivered, enable a consistent approach.PATENT Attorney Docket No.: IS24.0625-WO
[0012] What is needed is an intelligent agent which enhances the automation of edge operations by analyzing real-time logs from the system, autonomously applying pre-defined procedures to resolve potential issues. Additionally, it should provide direct insights to the remotely based SRE team, enabling them to make informed decisions quickly, even without direct network access to the devices. By empowering the system to act on detected anomalies and guiding SRE teams with actionable information, the standard of operational resilience should be elevated while the downtime in drilling operations should be minimized. The system should also include an Al-driven solution which address these challenges by integrating a generative Al agent with the fleet management system to autonomously detect and resolve issues, thereby enhancing the operational efficiency and security of energy exploration software deployments.Summary
[0013] According to certain embodiments, an Al-powered framework is provided that goes beyond traditional observability. Leveraging autonomous capabilities, the system may intelligently analyze a wide range of logs — including software, system, and firewall activities — enabling proactive issue detection and self-management. Generative Al (GenAI) enhancements may be deployed, the generative Al capable of not only of identifying anomalies but also autonomously resolving detected issues without manual user intervention. This approach marks a shift towards fully self-managing operations, setting the stage for a transformative leap in operational efficiency, safety, and service quality across geographically distributed drilling sites. The current system may use a fleet management system to monitor system metrics such as CPU usage, memory usage, disk space, and network traffic in real-time. However, the need for manual remote connections to field devices or wellsite equipment for troubleshooting has resulted in slower ticket resolution times and operational inefficiencies.
[0014] According to certain embodiments, a method is provided for monitoring and autonomously addressing anomalies related to a site. In certain embodiments, the method includes receiving data from a plurality of sources. In certain embodiments, the data may be received from equipment disposed within a wellsite and include performance metrics of the equipment, firewall logs and alerts from intrusion detection systems (IDS), network connectivity data, and database data related to the equipment within the wellsite. In certain embodiments, the received data may include data related to a wellsite action. The data may be received by a fleet management system,PATENT Attorney Docket No.: IS24.0625-WO according to an embodiment. The method may also include identifying an anomaly within the received data. In certain embodiments, identifying the anomaly includes analyzing performance metrics to determine a high latency and load related to the equipment within the wellsite, analyzing firewall logs and IDS alerts to confirm if there has been suspicious network activity related to the wellsite, identifying repeated connection errors and latency spikes from the network connectivity data, or identifying a rapid increase in data volume within the database data related to the wellsite equipment. According to certain embodiments, the method includes generating an insight that is based on the identified anomaly. In certain embodiments, generating an insight includes generating the insight autonomously. Generating the insight may include submitting a query via a graphical interface that is communicated to the fleet management system and the wellsite equipment and then displaying the generated insight on the graphical interface. According to certain embodiments, the method also includes transmitting a command based on the generated insight to the wellsite equipment. In certain embodiments, transmitting the command includes transmitting the command through a hub that is communicated to the wellsite equipment. According to certain embodiments, the method also includes performing a wellsite action based on the transmitted command. Performing the wellsite action may include restarting services in order to reduce the load and latency related to the wellsite equipment, adjusting resource allocations to balance the load related to the wellsite equipment, blocking a determined malicious IP address and tightening firewall rules to prevent unauthorized network activity related to the wellsite, performing a network scan to identify any vulnerabilities or threats related to the use of the wellsite equipment, testing network and secure socket layer (SSL) connections to determine a root cause of any network connectivity instability, adjusting network settings or opening necessary firewall rules to stabilize network connectivity, performing a cleanup operation which identifies and archives old logs or unnecessary data to free up space in a database related to the wellsite equipment, and adjusting data retention policies to prevent future overflows in a database related to the wellsite equipment.
[0015] It will be appreciated that this summary is intended merely to introduce some aspects of the present methods, systems, and media, which are more fully described and / or claimed below. Accordingly, this summary is not intended to be limiting.PATENT Attorney Docket No.: IS24.0625-WOBrief Description of the Drawings
[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the present teachings and together with the description, serve to explain the principles of the present teachings. In the figures:
[0017] Figure 1 illustrates an example of a system that includes various management components to manage various aspects of a geologic environment, according to an embodiment.
[0018] Figure 2 illustrates a schematic diagram representing edge and cloud infrastructures for implementing the current method, according to an embodiment.
[0019] Figure 3 illustrates a schematic diagram representing a ELK stack for implementing the current method, according to an embodiment.
[0020] Figure 4 illustrates a flowchart for detecting an anomaly using the current method, according to an embodiment.
[0021] Figure 5 illustrates a schematic diagram representing how a log is embedded into a 384- dimension vector, according to an embodiment.
[0022] Figure 6 illustrates a series of plots for a variety of different similarity metrics used by the current method, according to an embodiment.
[0023] Figure 7 illustrates a series of t-distributed Stochastic Neighbor Embedding (t-SNE) plots of the normal and abnormal logs used by the present disclosure according to an embodiment.
[0024] Figure 8 illustrates a graphical interface displaying the results of an anomaly detection process performed by the current method, according to an embodiment.
[0025] Figure 9 illustrates a schematic diagram of an architecture of the autonomous anomaly detection and resolution process performed by the current method, according to an embodiment.
[0026] Figure 10 illustrates a flowchart for resolving a firewall anomaly used by the current method, according to an embodiment.
[0027] Figure 11 illustrates a graphical interface displaying a document generated by the current method which details the steps included for resolving a firewall anomaly, according to an embodiment.
[0028] Figure 12 illustrates a flowchart of a large language model used by the current method, according to an embodiment.
[0029] Figure 13 illustrates a schematic diagram of a large language model powered agent used by the current method, according to an embodiment.PATENT Attorney Docket No.: IS24.0625-WO
[0030] Figure 14 illustrates a schematic diagram of the architecture of the current method employing a large language model powered agent, according to an embodiment.
[0031] Figure 15 illustrates a graphical interface of an example of a generational Al agent executing the current method, according to an embodiment.
[0032] Figure 16 illustrates a graphical interface of an example of a generational Al adding a firewall, according to an embodiment.
[0033] Figure 17 illustrates a flowchart of a method for monitoring and autonomously addressing anomalies related to a site, according to an embodiment.
[0034] Figure 18 illustrates a schematic view of a computing system for performing at least a portion of the method(s) described herein, according to an embodiment.Detailed Description
[0035] Reference will now be made in detail to embodiments, examples of which are illustrated in the accompanying drawings and figures. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it will be apparent to one of ordinary skill in the art that the present disclosure may be practiced without these specific details. In other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure aspects of the embodiments.
[0036] It will also be understood that, although the terms first, second, etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first object or step could be termed a second object or step, and, similarly, a second object or step could be termed a first object or step, without departing from the scope of the present disclosure. The first object or step, and the second object or step, are both, objects or steps, respectively, but they are not to be considered the same object or step.
[0037] The terminology used in the description herein is for the purpose of describing particular embodiments and is not intended to be limiting. As used in this description and the appended claims, the singular forms “a,” “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term “and / or” as used herein refers to and encompasses any possible combinations of one or more of the associatedPATENT Attorney Docket No.: IS24.0625-WO listed items. It will be further understood that the terms “includes,” “including,” “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Further, as used herein, the term “if’ may be construed to mean “when” or “upon” or “in response to determining” or “in response to detecting,” depending on the context.
[0038] Attention is now directed to processing procedures, methods, techniques, and workflows that are in accordance with some embodiments. Some operations in the processing procedures, methods, techniques, and workflows disclosed herein may be combined and / or the order of some operations may be changed.System Overview
[0039] Figure 1 illustrates an example of a system 100 that includes various management components 110 to manage various aspects of a geologic environment 150 (e.g., an environment that includes a sedimentary basin, a reservoir 151, one ormore faults 153-1, one or more geobodies 153-2, etc.). For example, the management components 110 may allow for direct or indirect management of sensing, drilling, injecting, extracting, etc., with respect to the geologic environment 150. In turn, further information about the geologic environment 150 may become available as feedback 160 (e.g., optionally as input to one or more of the management components 110).
[0040] In the example of Figure 1, the management components 110 include a seismic data component 112, an additional information component 114 (e.g., well / logging data), a processing component 116, a simulation component 120, an attribute component 130, an analysis / visualization component 142 and a workflow component 144. In operation, seismic data and other information provided per the components 112 and 114 may be input to the simulation component 120.
[0041] In an example embodiment, the simulation component 120 may rely on entities 122. Entities 122 may include earth entities or geological objects such as wells, surfaces, bodies, reservoirs, etc. In the system 100, the entities 122 can include virtual representations of actual physical entities that are reconstructed for purposes of simulation. The entities 122 may include entities based on data acquired via sensing, observation, etc. (e.g., the seismic data 112 and otherPATENT Attorney Docket No.: IS24.0625-WO information 114). An entity may be characterized by one or more properties (e.g., a geometrical pillar grid entity of an earth model may be characterized by a porosity property). Such properties may represent one or more measurements (e.g., acquired data), calculations, etc.
[0042] In an example embodiment, the simulation component 120 may operate in conjunction with a software framework such as an object-based framework. In such a framework, entities may include entities based on pre-defined classes to facilitate modeling and simulation. A commercially available example of an object-based framework is the MICROSOFT® .NET® framework (Redmond, Washington), which provides a set of extensible object classes. In the .NET® framework, an object class encapsulates a module of reusable code and associated data structures. Obj ect classes can be used to instantiate obj ect instances for use in by a program, script, etc. For example, borehole classes may define objects for representing boreholes based on well data.
[0043] In the example of Figure 1, the simulation component 120 may process information to conform to one or more attributes specified by the attribute component 130, which may include a library of attributes. Such processing may occur prior to input to the simulation component 120 (e.g., consider the processing component 116). As an example, the simulation component 120 may perform operations on input information based on one or more attributes specified by the attribute component 130. In an example embodiment, the simulation component 120 may construct one or more models of the geologic environment 150, which may be relied on to simulate behavior of the geologic environment 150 (e.g., responsive to one or more acts, whether natural or artificial). In the example of Figure 1, the analysis / visualization component 142 may allow for interaction with a model or model-based results (e.g., simulation results, etc.). As an example, output from the simulation component 120 may be input to one or more other workflows, as indicated by a workflow component 144.
[0044] As an example, the simulation component 120 may include one or more features of a simulator such as the ECLIPSE™ reservoir simulator (SLB, Houston Texas), the INTERSECT™ reservoir simulator (SLB, Houston Texas), etc. As an example, a simulation component, a simulator, etc. may include features to implement one or more meshless techniques (e.g., to solve one or more equations, etc.). As an example, a reservoir or reservoirs may be simulated with respect to one or more enhanced recovery techniques (e.g., consider a thermal process such as SAGD, etc ).PATENT Attorney Docket No.: IS24.0625-WO
[0045] In an example embodiment, the management components 110 may include features of a commercially available framework such as the PETREL® seismic to simulation software framework (SLB, Houston, Texas). The PETREL® framework provides components that allow for optimization of exploration and development operations. The PETREL® framework includes seismic to simulation software components that can output information for use in increasing reservoir performance, for example, by improving asset team productivity. Through use of such a framework, various professionals (e.g., geophysicists, geologists, and reservoir engineers) can develop collaborative workflows and integrate operations to streamline processes. Such a framework may be considered an application and may be considered a data-driven application (e.g., where data is input for purposes of modeling, simulating, etc.).
[0046] In an example embodiment, various aspects of the management components 110 may include add-ons or plug-ins that operate according to specifications of a framework environment. For example, a commercially available framework environment marketed as the OCEAN® framework environment (SLB, Houston, Texas) allows for integration of add-ons (or plug-ins) into a PETREL® framework workflow. The OCEAN® framework environment leverages .NET® tools (Microsoft Corporation, Redmond, Washington) and offers stable, user-friendly interfaces for efficient development. In an example embodiment, various components may be implemented as add-ons (or plug-ins) that conform to and operate according to specifications of a framework environment (e.g., according to application programming interface (API) specifications, etc.).
[0047] Figure 1 also shows an example of a framework 170 that includes a model simulation layer 180 along with a framework services layer 190, a framework core layer 195 and a modules layer 175. The framework 170 may include the commercially available OCEAN® framework where the model simulation layer 180 is the commercially available PETREL® model-centric software package that hosts OCEAN® framework applications. In an example embodiment, the PETREL® software may be considered a data-driven application. The PETREL® software can include a framework for model building and visualization.
[0048] As an example, a framework may include features for implementing one or more mesh generation techniques. For example, a framework may include an input component for receipt of information from interpretation of seismic data, one or more attributes based at least in part on seismic data, log data, image data, etc. Such a framework may include a mesh generationPATENT Attorney Docket No.: IS24.0625-WO component that processes input information, optionally in conjunction with other information, to generate a mesh.
[0049] In the example of Figure 1, the model simulation layer 180 may provide domain objects 182, act as a data source 184, provide for rendering 186 and provide for various user interfaces 188. Rendering 186 may provide a graphical environment in which applications can display their data while the user interfaces 188 may provide a common look and feel for application user interface components.
[0050] As an example, the domain objects 182 can include entity objects, property objects and optionally other objects. Entity objects may be used to geometrically represent wells, surfaces, bodies, reservoirs, etc., while property objects may be used to provide property values as well as data versions and display parameters. For example, an entity object may represent a well where a property object provides log information as well as version information and display information (e.g., to display the well as part of a model).
[0051] In the example of Figure 1, data may be stored in one or more data sources (or data stores, generally physical data storage devices), which may be at the same or different physical sites and accessible via one or more networks. The model simulation layer 180 may be configured to model projects. As such, a particular project may be stored where stored project information may include inputs, models, results and cases. Thus, upon completion of a modeling session, a user may store a project. At a later time, the project can be accessed and restored using the model simulation layer 180, which can recreate instances of the relevant domain objects.
[0052] In the example of Figure 1, the geologic environment 150 may include layers (e.g., stratification) that include a reservoir 151 and one or more other features such as the fault 153-1, the geobody 153-2, etc. As an example, the geologic environment 150 may be outfitted with any of a variety of sensors, detectors, actuators, etc. For example, equipment 152 may include communication circuitry to receive and to transmit information with respect to one or more networks 155. Such information may include information associated with downhole equipment 154, which may be equipment to acquire information, to assist with resource recovery, etc. Other equipment 156 may be located remote from a well site and include sensing, detecting, emitting or other circuitry. Such equipment may include storage and communication circuitry to store and to communicate data, instructions, etc. As an example, one or more satellites may be provided for purposes of communications, data acquisition, etc. For example, Figure 1 shows a satellite inPATENT Attorney Docket No.: IS24.0625-WO communication with the network 155 that may be configured for communications, noting that the satellite may additionally or instead include circuitry for imagery (e.g., spatial, spectral, temporal, radiometric, etc.).
[0053] Figure 1 also shows the geologic environment 150 as optionally including equipment 157 and 158 associated with a well that includes a substantially horizontal portion that may intersect with one or more fractures 159. For example, consider a well in a shale formation that may include natural fractures, artificial fractures (e.g., hydraulic fractures) or a combination of natural and artificial fractures. As an example, a well may be drilled for a reservoir that is laterally extensive. In such an example, lateral variations in properties, stresses, etc. may exist where an assessment of such variations may assist with planning, operations, etc. to develop a laterally extensive reservoir (e.g., via fracturing, injecting, extracting, etc.). As an example, the equipment 157 and / or 158 may include components, a system, systems, etc. for fracturing, seismic sensing, analysis of seismic data, assessment of one or more fractures, etc.
[0054] As mentioned, the system 100 may be used to perform one or more workflows. A workflow may be a process that includes a number of worksteps. A workstep may operate on data, for example, to create new data, to update existing data, etc. As an example, a may operate on one or more inputs and create one or more results, for example, based on one or more algorithms. As an example, a system may include a workflow editor for creation, editing, executing, etc. of a workflow. In such an example, the workflow editor may provide for selection of one or more predefined worksteps, one or more customized worksteps, etc. As an example, a workflow may be a workflow implementable in the PETREL® software, for example, that operates on seismic data, seismic attribute(s), etc. As an example, a workflow may be a process implementable in the OCEAN® framework. As an example, a workflow may include one or more worksteps that access a module such as a plug-in (e g., external executable code, etc.).Method and System for Monitoring and Addressing Anomalies Detected During a Field Operation
[0055] A network architecture 200 for drilling operations typically involves a multi-layered setup designed to handle the complexities of rig environments, as shown in Figure 2. The infrastructure of the network architecture 200 may be segmented into distinct network zones, such as an information technology (IT) network 202, an operational technology (OT) network 204, and a rig network 206, to ensure security and manageability. In certain embodiments, the IT networkPATENT Attorney Docket No.: IS24.0625-WO202 includes a generative Al agent system 222 that may be configured to send commands to a number of edge devices 220 through the OT network 204 which in turn may include a communications hub.
[0056] The IT network 202 may include centralized support and monitoring systems, such as a Service Provider Central Support Network 208, which interacts with the rig networks 206 via a secure cloud infrastructure 216. The secure cloud infrastructure 216 may include a fleet management system 224, which according to certain embodiments, may be an Elasticsearch- Logstash-Kibana (ELK)-based fleet management system. The OT network or communications hub 204 may operate within a more restrictive environment, managing essential control systems and acquisition networks of the rig network 206, including surface acquisition devices 212 and downhole data acquisition devices 214. Each network segment is further isolated using firewalls 210 and hypervisor technologies, enabling network segmentation and perimeter security.
[0057] The rig network 206 connects critical edge devices 220, such as drilling control units, acquisition systems, and other wellsite equipment which perform various automation and data processing tasks. These edge devices 220 often operate with limited bandwidth, making it challenging to transmit large amounts of data in real time. Therefore, a robust strategy for monitoring and data collection is preferred to ensure efficient operation without overwhelming the network.Log Analysis
[0058] To address the challenges associated with monitoring geographically distributed rigs and remote edge devices, a fleet management approach may be implemented. According to certain embodiments, the fleet management system may be an Elasticsearch-Logstash-Kibana (ELK)- based fleet management system, or management systems provided by Datadog, NewRelik, Azure Arc, or Dynatrace. An ELK stack 302, for example as seen in Figure 3, may enable comprehensive log and metric collection across all network layers. By integrating fleet management agents on edge devices, system and application logs, resource usage data, and network metrics can be gathered in real time. This setup allows the centralized support team or other users to proactively monitor the health and performance of the rigs.
[0059] The flexibility of fleet management is advantageous for operating in environments with constrained bandwidth. During field testing, metrics may be collected at carefully selectedPATENT Attorney Docket No.: IS24.0625-WO intervals to avoid excessive network load, ensuring compliance with Rig-to-Town latency requirements. For example, CPU metrics may be polled every 30 seconds, while memory and filesystem data were collected every 15 minutes, resulting in minimal traffic impact on the network.
[0060] The use of fleet management may also improve incident response capabilities by integrating alerting with tools like those provided by SaaS incident management platforms. This integration may enable the SRE team or other users to receive real-time alerts for anomalies or performance issues, allowing them to intervene proactively and prevent system downtime. The use of fleet management monitoring tools in drilling operation and similar deployments indicates a shift towards more proactive support practices.
[0061] According to certain embodiments, logs are produced by software-driven applications running on various systems or devices to provide critical information that helps developers and system engineers analyze the system’s condition and status. They may also serve as an audit trail, documenting events in chronological order. Log analysis is often used to investigate incidents related to the system, such as defects or unauthorized access. By examining the logs, investigators can reconstruct the sequence of events leading to a particular incident or event. Through this analysis, system engineers or investigators aim to identify unusual or suspicious activities. However, detecting these anomalies requires time and expertise in spotting irregularities within the vast number of log entries.
[0062] One objective of performing analysis on logs is to facilitate the detection of anomalous activities so that immediate or corresponding remediation may be done to contain or remediate the issue recorded in the logs. This is part of the attempt to enhance system resiliency against system faults, degradation and intentionally induced cyber physical attacks. It may also be used to facilitate the investigation or analysis of what may have induced the occurrence of such anomalous activities. Due to the characteristics of logs, namely being voluminous, varied, and contextual, regular log analysis is difficult, warranting the need for automation. While rule or signature-based automation solution helps, the contextual or semantic complexity of logs limits its efficacy.
[0063] There are many Al algorithms for log analysis. Traditional Al algorithms, such as Support Vector Machines (SVM), have been applied for anomaly detection tasks. However, these methods have several challenges and constraints to deal with before they contribute significantly to their intended objectives of keeping system resilient. For supervised models, there is thePATENT Attorney Docket No.: IS24.0625-WO challenge of acquiring sufficient anomalous data points to train such models. For unsupervised models, it will be the ability to detect the variety and variations of anomalies in logs.
[0064] In contrast, embedding models may offer a more resource-efficient solution for log anomaly detection on edge devices. According to certain embodiments, embedded models may be able to transform unstructured log data into meaningful multi-dimensional vectors (embeddings) that capture semantic meanings within the logs, making it easier to detect deviations that indicate potential anomalies. One of the strengths of embedding models is their efficiency in real-time applications. Given the constrained computational resources, especially on edge devices with limited GPU capacity, embedding models offer a lightweight solution that processes data with reduced overhead. This may enable real-time anomaly detection, which is crucial in industrial environments where immediate detection and response are required to maintain system reliability and prevent failures. Moreover, with transformer-based architectures, it maintains historical data with memory capability to enhance their understanding of contextual information within logs.
[0065] By directly utilizing embedding models at the edge or wellsite, systems can detect anomalies without the latency typically associated with cloud-based detection, allowing for faster responses and reducing operational risks. This approach is particularly valuable in resource- constrained environments, where bandwidth limitations make transferring large volumes of log data impractical. Instead of sending all logs to a central system, the anomaly detection process at the edge or wellsite filters out normal activity, allowing only abnormal logs to be transmitted for further analysis by the SRE team. This strategy may not only conserve network bandwidth but may also ensure that critical issues are prioritized and addressed promptly.Anomaly Detection
[0066] As shown in Figure 4, a producer-consumer pattern may be employed to decouple log input and processing tasks, enhancing both scalability and efficiency. According to certain embodiments, a detection service 400 may read logs in real time from various sources 402, including application logs, system logs, and firewall logs. In certain embodiments, logs may be acquired from a log server of an edge device 402, as at step 404, and then maintained within a queue store 406. The service may continuously process these logs, leveraging an embedding model to compare real-time log entries against a baseline of normal log embeddings stored in a vectorPATENT Attorney Docket No.: IS24.0625-WO database 412. If the calculated distance between a real-time log and its corresponding normal log exceeds a predefined threshold, the log is flagged as an anomaly.
[0067] In certain embodiments, the architecture may minimize the need for extensive data preprocessing or log parsing, allowing for efficient and robust detection. By filtering out normal logs locally and only sending identified anomalies to a remote health monitoring platform, the solution may reduce bandwidth consumption and ensures that significant events receive timely attention. The combination of embedding models and vector databases provides a powerful, scalable framework for real-time anomaly detection at the edge or wellsite.
[0068] According to certain embodiments, creating vector embeddings from logs involves several steps including popping the logs from the queue as at step 408 and then transforming the unstructured or semi-structured text in logs into meaningful vectors as at step 410 that can be stored and queried efficiently in a vector database 412. In certain embodiments, the process to create vector embeddings from logs includes preprocessing the logs, choosing or training a text embedding model, storing embeddings in a vector database, and querying and using the embeddings. For example, a similarity search may be conducted as at step 414 and if the calculated distance between a real-time log and its corresponding normal log exceeds a predefined threshold as at step 416, the log is flagged as an anomaly and pushed to an anomalous list and may be further published to a user, as at step 418.
[0069] Because software logs are often messy, containing timestamps, error codes, messages, stack traces, etc., preprocessing is helpful when removing unnecessary noise and focusing on useful information. Preprocessing may also include removing timestamps, special characters, and other irrelevant metadata. Logs typically contain timestamps, host details, etc., which may not be useful for embeddings. In certain embodiments, preprocessing includes tokenization or the splitting the logs into tokens such as words or phrases, and word removal so as to remove common words like "the", "is", etc., if they do not add meaning to the log content. In certain embodiments, preprocessing may also include lowercasing which is the conversion of all text within the logs to lowercase for uniformity.
[0070] According to certain embodiments, choosing or training a text embedding model includes choosing or training an embedding model that can convert the processed log data into vector embeddings as needed. In certain embodiments, the model encodes the log entries into vector embedding representations using a pre-trained embeddingPATENT Attorney Docket No.: IS24.0625-WO
[0071] Table 1 below shows the comparison between the models in the state of the art. Based on the performances of the models based on average performance, speed, and model size, it was found that using all-MiniLM-L6-v2 is suitable, according to an embodiment, however it is to be expressly understood that alternative models may be chosen based on any specific needs or uses. Figure 5 further shows an example of embedding a log 502 into 384-dimension vector 504 according to an embodiment.Table 1
[0072] Returning to Figure 4, once embeddings are generated, a vector database 412 is required to store them for conducting a fast retrieval and similarity search, as at step 414. Popular vector databases include Pinecone, Weaviate, or Milvus, however other vector databases may be used, according to certain embodiments.
[0073] Once the embeddings are in a vector database 412, a similarity search as at step 414 can be performed using vector-based computation to find logs that are semantically similar to a given log, detect anomalous patterns by comparing log embeddings to expected behaviors as at step 416, and categorize logs based on embedding proximity.
[0074] According to certain embodiments, the present disclosure may use a similarity search to detect log anomalies. In one embodiment, the store is a vector database which contains normal log entries. The input log is vectorized using an embedded model model, which transforms it into 384- dimension embeddings that capture semantic relationships between log data. According to certain embodiments, the embedded model may be any appropriate model including the models listed in Table 1. These vector representations are then compared with stored normal log vectors using similarity search techniques. If a queried log entry deviates significantly from the stored normalPATENT Attorney Docket No.: IS24.0625-WO entries, it is detected as anomalous. To compare these embeddings, certain similarity metrics are used, depending on the nature of the data and the specific problem being solved. Figure 6 shows several examples of different similarity metrics which may use including but limited to Cosine Similarity 602, Dot Product 604, Euclidean Distance 606, and Manhattan Distance (not shown) may be used. Figure 6 shows several examples of different similarity metrics.
[0075] According to certain embodiments, the Euclidean distance similarity metric 606 is preferably used. The similarity score may be computed through Euclidean distance between the incoming log embeddings against normal log embeddings stored in the vector database, according to an embodiment, however it is to be expressly understood that alternative parameters may be chosen based on any specific needs or uses. When the similarity score matches the criteria such as highest similarity score or minimal threshold score, an anomalous log is detected. Figure 7 shows the t-distributed Stochastic Neighbor Embedding (t-SNE) plots of the normal and abnormal logs. The similarity score demonstrates the differences between normal logs and anomalies, according to an embodiment.
[0076] According to certain embodiments, the fleet management system among other monitoring tools may be used to monitor a system’s metrics such as CPU usage, memory usage, disk space, and network traffic in real-time. By visualizing these metrics in dashboards presented within a graphical interface 800, for example as seen in Figure 8, performance bottlenecks, resource constraints, and anomalies 802 may be detected. In certain embodiments, the fleet management system may also enhance security by analyzing logs from firewalls, intrusion detection systems (IDS), and other security tools, and correlating real-time logs or alerts to identify potential security incidents, such as unauthorized access attempts, malware, and suspicious network activity.Autonomous Resolution Workflow
[0077] According to certain embodiments, the present disclosure may include LLM generative Al agents to generate actions to be sent through communication infrastructure to the edge devices. An example architecture of the autonomous anomaly detection and resolution solution of the present disclosure may be seen in Figure 9, according to an embodiment.
[0078] Procedures may serve as systematic, step-by-step instructions aimed at resolving specific errors in an efficient and structured manner. The creation of such procedures typically starts withPATENT Attorney Docket No.: IS24.0625-WO the development of a flowchart, where each block may represent conditions, execution steps or results, providing a clear roadmap for decision-making and action sequences. Figure 10 shows an example of a procedure flowchart to solve a firewall issue, according to an embodiment. Following the flowchart design, a detailed document is crafted that outlines the objectives, such as the error types and step-by-step instructions. These steps may specify the condition statement and corresponding actions, which can be defined as function calls. Figure 11 shows an example of a generated procedure document, according to an embodiment.
[0079] According to certain embodiments, the LLM agent can intelligently analyze the procedure’s condition, identify the necessary logic, and execute the correct steps. Instead of manually coding extensive logic for each scenario, the LLM may autonomously determine the appropriate logic pathways, reducing the need for complex, hardcoded solutions and software development time.
[0080] To enhance accessibility and streamline the retrieval of relevant procedures, a vector database in certain embodiments may be utilized to store these procedure documents, enabling fast and efficient retrieval. By leveraging similarity search algorithms, the system can identify and recommend the most relevant procedure by comparing the characteristics of the queried error with stored procedures. This not only improves the precision and speed of error resolution but also reduces system downtime and minimizes development complexity, as the LLM can efficiently deduce logic and execute the necessary steps without the need for extensive, manual intervention.
[0081] According to certain embodiments, LLMs are one type of Al model that may leverage deep learning techniques and transformer architectures to understand and generate human-like text. These models are trained on vast datasets, enabling them to grasp context, semantics, and intricate language patterns, which facilitates a wide range of applications, from text generation to conversational agents. According to certain embodiments, the LLM architecture may be as seen in Figure 12 where the LLM-powered agent 1200 may generate actions based on the insights. In certain embodiments, there may be several LLM-powered agents, each specialized in a specific field. For example, the present disclosure may include a LLM-powered agent to detect operational issues (high latency, high load ...etc.) and execute actions such as service restart, while another LLM-powered agent may be used to detect security threats and execute actions such as blocking access and changing firewall configurations.PATENT Attorney Docket No.: IS24.0625-WO
[0082] In certain embodiments, an LLM-powered agent may extend its capabilities by autonomously interacting with users and systems to perform complex tasks. This includes not only generating responses based on user inputs but also analyzing data, drawing inferences, and making decisions based on contextual understanding. The versatility of LLM agents can enable them to enhance productivity and efficiency through automation and intelligent problem-solving. Figure 13 describes an overview of an example of a LLM powered agent 1302, according to an embodiment.
[0083] According to certain embodiments, in an LLM-powered autonomous agent system 1300, the LLM-powered agent 1302 functions as the “brain”, complemented by several key components including self-organizing or planning 1304, memory 1306, and tool use 1308.
[0084] In certain embodiments, larger tasks can be systematically broken down into smaller, manageable subgoals (subgoal decomposition enabling more efficient execution by following user-defined procedures) with each step designed to address specific issues under predetermined conditions. A LLM agent possesses the capability to autonomously analyze task logic and make informed decisions for executing the appropriate steps. This approach may facilitate the efficient handling of intricate tasks, allowing agents to execute complex operations with greater precision. Furthermore, agents may engage in self-criticism and self-reflection regarding their past actions, enabling them to learn from mistakes and refine their strategies for subsequent steps. This reflection and refinement process significantly enhances the quality of results produced by the agent.
[0085] According to certain embodiments, an LLM-powered agent may employ in-context learning to utilize short-term memory, allowing for immediate adjustments based on recent experiences. In addition, the integration of long-term memory capabilities equips the agent with the ability to retain and recall vast amounts of information over extended periods. This is often achieved using external vector stores, facilitating rapid information retrieval and enhancing the agent's knowledge base.
[0086] According to certain embodiments, the LLM-powered agent can interact with external Application Programming Interfaces (APIs) to perform actions defined by the user. This functionality encompasses a wide range of tasks, including but not limited to retrieving current information, executing code, and performing external operations.PATENT Attorney Docket No.: IS24.0625-WO
[0087] According to certain embodiments, the present disclosure includes an LLM-powered autonomous agent system 1400 that incorporates a supervisor 1402 and specialized agents 1404 to optimize task execution. Figure 14 shows an architecture of the LLM-powered agent system 1400, according to an embodiment. The supervisor 1402 may be a type of LLM-powered agent that plays a critical role by analyzing incoming procedures and determining the most appropriate specialized agent 1404 to handle the tasks. Once the routing decision is made, the designated specialized agent 1404 receives a procedure 1406, executes the corresponding actions in accordance with predefined steps, and generates the output 1408. In certain embodiments, the output 1408 may be a generated insight. The output 1408 may then be sent back to the supervisor 1402, who compiles the response and delivers it to the end user. In certain embodiments, the insight or output 1408 may be displayed to the end user through a graphical interface on a screen. According to certain embodiments, the architecture seen in Figure 14 can be further improved by adding additional hierarchy or collaborative structure to support more diverse and difficult tasks and scenarios besides those discussed herein.
[0088] Specifically, in certain embodiments, upon receiving an abnormal log 1410 from the log anomaly detection service, an LLM may be employed to extract key information 1412, such as exceptions, from the log 1410 in order to diagnose the issue. The appropriate resolution procedure may then be retrieved from a procedure database 1414 using a similarity search. In certain embodiments of the current LLM-based agent system 1400, a LangGraph may be utilized to manage the coordination, task assignment, and overall workflow among LLM agents. In certain other embodiments, other frameworks such as LangChain or Llamalndex may be used by the current LLM-based agent system 1400 as well. More specifically, each LLM agent 1404, along with the Supervisor 1402, may be represented as a node within the graph structure, where task assignments are regulated by conditional edges linking the Supervisor 1402 node to agent 1404 nodes. The Supervisor 1402 node may assign the retrieved procedure to the designated specialist agent 1404 node. This agent 1404 node may be equipped with a set of tools 1416 specific to the issue. For instance, in the case of a firewall issue, the agent 1404 node can perform actions such as retrieving firewall configuration or checking connectivity status, which are implemented as Python functions. The specialized agent 1404 node may execute the procedure step by step to resolve the issue. Upon completion, the results or output 1408 may be reported back to the SRE team or end user through the Supervisor 1402 node, facilitating full automation of the issuePATENT Attorney Docket No.: IS24.0625-WO resolution process, according to an embodiment. This hierarchical structure, combining a supervisory decision-making layer with specialized execution capabilities, ensures efficient task allocation and precise execution, thereby enhancing overall system performance and reliability.
[0089] Like any connected industrial system, automation brings many advantages and improvements in terms of efficiency and performances, however many industrial systems need to be operational all the time and risks of cyber-attacks increase. For example, many digital drilling systems require real-time operations with minimal latency. Implementing cybersecurity measures that introduce delays can be unacceptable, thus limiting the range of possible security solutions. Additionally, ensuring availability and reliability is paramount, sometimes leading to trade-offs where security measures are deprioritized. Increased remote access capabilities for maintenance and monitoring introduce new vectors for cyber-attacks. Secure remote access solutions are not always implemented, leading to potential vulnerabilities. Industrial environments (for instance drilling systems) often lack the advanced monitoring and detection capabilities found in modem IT systems. Incident response can be slower due to the critical nature of industrial processes and the potential safety implications of shutting down operations. Furthermore, physical access to drilling systems can compromise cybersecurity. Protecting the physical infrastructure from tampering is crucial but can be challenging in dispersed or remote locations.
[0090] According to certain embodiments, the present disclosure aims to reduce the unnecessary presence of personal, thereby reducing HSE risk exposure and optimizing operational costs. The present disclosure enables reduced staffing levels on mechanized rigs and delivers unparalleled consistency of repetitive tasks, helping users reach their technical limit on every well.
[0091] According to certain embodiments, system metrics related to a wellsite are collected from edge device rigs and sent to a fleet management system in real-time. Returning to Fig. 14, abnormal logs 1410 may be detected by a log anomaly detection service and then sent to a LLM agent system 1400. A GenAI supervisor 1402 may then process abnormal log data 1410 by extracting the key relevant information, then an embedder may be used to generate embeddings. Specifically, in certain embodiments, the GenAI supervisor 1402 may analyze logs and performance metrics from edge devices or wellsite equipment and use embeddings from the fleet management system to understand context and enhance prompts. In certain embodiments, the GenAI supervisor 1402 may perform actions such as testing network and SSL connections, opening firewall rules, and providing user prompts.PATENT Attorney Docket No.: IS24.0625-WO
[0092] In certain embodiments, a closely relevant procedure may be extracted from the procedure database 1414 through a similarity search and then passed to a GenAI specialized agent 1404 communicated to the GenAI supervisor 1402.
[0093] In certain embodiments, the present disclosure includes performing a query and response, namely wherein the SRE or user queries the GenAI supervisor 1402 for specific response insights or logs. The GenAI agent system 1400 may then retrieve and process the necessary data from the fleet management system, providing the required information, namely the generated response insight and / or the requested data logs, to the SRE. According to certain embodiments, the GenAI supervisor 1402 may assign tasks to a number of specialized agents 1404 based on the retrieved procedure. Each of the GenAI specialized agents 1404 may then perform the tasks, and the result is then sent back to the GenAI supervisor 1402. In certain embodiments, based on insights the GenAI agent system 1400 may send commands to a communication hub, namely the OT network 204 seen in Figure 2. The communication hub or OT network 204 in turn may forward these commands to the edge device 220 such as wellsite equipment, which executes the commands.
[0094] With the rise of edge computing services rising in the oil and gas industry, the demand for an effective monitoring and alerting system became critical. The introduction of the present disclosure marks a significant enhancement in service delivery, as it enables SRE teams to monitor an edge fleet and be alerted in real-time. The present disclosure may drastically reduce the incidence of NET. The present disclosure may ease deploying, configuring, managing fleet monitoring agents, logging, and storing device telemetry. In certain embodiments, the present disclosure may enable fast troubleshooting supported by intuitive visualizations. On top of this foundation, the present disclosure introduces Al-powered enhancements that take observable solution capabilities to the next level. For example, by analyzing firewall logs, the current system can autonomously detect abnormal network activities suggesting an intrusion attempt and automatically block the hacker's connection. Similarly, according to certain embodiments, an unexpected increase in the volume of data written to the system due to internal logs may trigger an anomaly alert, prompting proactive data management actions such as archiving or deleting old logs. These Al-driven innovations aim to further minimize future NPT by ensuring that operational anomalies are not just detected but resolved autonomously. The present disclosure represents a breakthrough towards operations with minimal human intervention. In the following section, some use cases of the proposed solution are highlighted.PATENT Attorney Docket No.: IS24.0625-WO
[0095] According to certain embodiments, the present disclosure may be used in operational issue detection and resolution. For example, when an edge device 220 or wellsite equipment is experiencing high latency and load and affecting drilling operations, a GenAI agent 1404 specialized in operational issues may analyzes the performance metrics and identify the high latency and load. In certain embodiments, the specialized GenAI agent 1404 may send a generated command or insight via a communication hub or OT network 204 to the edge device 220 as seen in Figure 2 or wellsite equipment to restart specific services performed by the edge devices 220 with the aim of reducing the load and latency. According to certain embodiments, the present disclosure may be used to adjust resource allocations or prioritize certain tasks to balance the load. In certain embodiments, the system performance may be restored without manual intervention, ensuring minimal disruption to drilling operations at the wellsite.
[0096] According to certain embodiments, the present disclosure may be used in security threat detection and mitigation. For example, when suspicious network activity is detected or when a potential security breach is suggested, a GenAI agent 1404 which is specialized in security, analyzes firewall logs and IDS alerts to confirm suspicious activities. According to certain embodiments, the specialized GenAI agent 1404 may send commands to block the malicious IP address and tighten firewall rules in order to prevent unauthorized access. The specialized GenAI agent 1404 may also initiate a thorough network scan to identify any additional vulnerabilities or threats. In certain embodiments, the security threat is neutralized swiftly thereby protecting the integrity of the drilling operations and preventing data breaches.
[0097] According to certain embodiments, the present disclosure may be used to address network connectivity issues. For example, when a rig-to-town connection is unstable which then causes data transmission delays and potential operational inefficiencies, a specialized GenAI agent 104 may identify repeated connection errors and latency spikes from the logs. In certain embodiments, the specialized GenAI agent 1404 may also test network and SSL connections to diagnose the root cause of the instability as seen in Figure 15. In certain embodiments, the specialized GenAI agent 1404 may adjust network settings or open necessary firewall rules to stabilize the connection as seen in Figure 16. In certain embodiments, the network connectivity is restored, thereby ensuring continuous and reliable data transmission between the rig and the town operations center.PATENT Attorney Docket No.: IS24.0625-WO
[0098] According to certain embodiments, the present disclosure may be used to perform database cleanup. For example, when a database on an edge device is fdling up rapidly, thereby risking data overflow and operational disruptions, a specialized GenAI agent 1404 may monitor the database size and identify a rapid increase in data volume. In certain embodiments, the specialized GenAI agent 1404 may send a command via the loT or communications hub 204 to the edge device 220 as seen in Figure 2 or wellsite equipment to perform a cleanup operation. In certain embodiments, the specialized GenAI agent 1404 may identify and archive old logs or unnecessary data to free up space in the database, and may also adjust data retention policies to prevent future overflows. In certain embodiments, the database space may be reclaimed, thereby preventing potential data loss or operational disruptions due to a full database.
[0099] In summary, the present disclosure provides an Al-driven observability and security suite with a GenAI agent system for autonomous anomaly detection and resolution. The integration of a GenAI SRE agent directly at the edge or wellsite marks a significant innovation in proactive and intelligent monitoring solutions. According to certain embodiments, the GenAI agent may continuously analyzes system metrics — including CPU usage, memory utilization, disk space, and network traffic in real-time, enabling it to detect performance bottlenecks, resource constraints, and security threats by examining logs from firewalls, intrusion detection systems (IDS), and other security tools. Upon identifying anomalies, the GenAI agent may autonomously initiates corrective actions, such as blocking unauthorized access attempts and managing resource allocation, thereby ensuring continuous system integrity and security. As optimizing drilling operations to guarantee peak rig performance and productivity, the global expansion of edge or wellsite deployments has underscored the critical need for an intelligent monitoring and alerting system. According to certain embodiments, the GenAI SRE agent may effectively resolve complex issues, including firewall breaches, through autonomous analysis and mitigation of malicious network activities. Furthermore, the GenAI may proactively manage data anomalies, ensuring that operational disruptions were not only detected but also resolved without human intervention. These GenAL driven innovations of the present disclosure are setting a new standard for future operations, wherein human oversight is minimized, and autonomous systems maintain continuous operational integrity.Exemplary MethodPATENT Attorney Docket No.: IS24.0625-WO
[0100] Figure 17 illustrates a flowchart of a method 1700 for monitoring and autonomously addressing anomalies related to a site. The method 1700 may include receiving data from a plurality of sources, as at 1702. According to certain embodiments, the data may be received from equipment that is disposed or located within a wellsite. The received data may performance metrics of the equipment, firewall logs and alerts from intrusion detection systems (IDS), network connectivity data, and database data related to the equipment within the wellsite. In certain embodiments, the received data may include data related to a wellsite action and received by a fleet management system.
[0101] According to certain embodiments, the method 1700 also includes identifying an anomaly within the received data, as at 1704. In certain embodiments, identifying the anomaly includes analyzing performance metrics in order to determine a high latency and load related to the equipment within the wellsite, analyzing firewall logs and IDS alerts to confirm if there has been suspicious network activity related to the wellsite, identifying repeated connection errors and latency spikes from the network connectivity data, or identifying a rapid increase in data volume within the database data related to the wellsite equipment.
[0102] According to certain embodiments, the method 1700 may also include generating an insight based on the identified anomaly, as at 1706. In certain embodiments, generating an insight includes generating the insight autonomously. Generating an insight may include submitting a query via a graphical interface that is communicated to the fleet management system and the wellsite equipment and then displaying the generated insight on the graphical interface.
[0103] According to certain embodiments, the method 1700 may also include transmitting a command based on the generated insight to the wellsite equipment, as at 1708. In certain embodiments, transmitting a command includes transmitting the command through a hub that may be communicated to the wellsite equipment.
[0104] According to certain embodiments, the method 1700 may also include performing a wellsite action based on the transmitted command, as at 1710. In certain embodiments, performing the wellsite action may include restarting services in order to reduce the load and latency related to the wellsite equipment, adjusting resource allocations to balance the load related to the wellsite equipment, and blocking a determined malicious IP address and tightening firewall rules to prevent unauthorized network activity related to the wellsite. In further embodiments, performing a wellsite action may include performing a network scan to identify any vulnerabilities or threatsPATENT Attorney Docket No.: IS24.0625-WO related to the use of the wellsite equipment, testing network and secure socket layer (SSL) connections to determine a root cause of any network connectivity instability, adjusting network settings or opening necessary firewall rules to stabilize network connectivity, performing a cleanup operation which identifies and archives old logs or unnecessary data to free up space in a database related to the wellsite equipment, and adjusting data retention policies to prevent future overflows in a database related to the wellsite equipment.Exemplary Computing System
[0105] In some embodiments, the methods of the present disclosure may be executed by a computing system. Figure 18 illustrates an example of such a computing system 1800, in accordance with some embodiments. The computing system 1800 may include a computer or computer system 1801 A, which may be an individual computer system 1801 A or an arrangement of distributed computer systems. The computer system 1801 A includes one or more analysis modules 1802 that are configured to perform various tasks according to some embodiments, such as one or more methods disclosed herein. To perform these various tasks, the analysis module 1802 executes independently, or in coordination with, one or more processors 1804, which is (or are) connected to one or more storage media 1806. The processor(s) 1804 is (or are) also connected to a network interface 1807 to allow the computer system 1801 A to communicate over a data network 1809 with one or more additional computer systems and / or computing systems, such as 1801B, 1801C, and / or 1801D (note that computer systems 1801B, 1801C and / or 1801D may or may not share the same architecture as computer system 1801 A, and may be located in different physical locations, e.g., computer systems 1801A and 1801B may be located in a processing facility, while in communication with one or more computer systems such as 1801C and / or 180 ID that are located in one or more data centers, and / or located in varying countries on different continents).
[0106] A processor may include a microprocessor, microcontroller, processor module or subsystem, programmable integrated circuit, programmable gate array, or another control or computing device.
[0107] The storage media 1806 may be implemented as one or more computer-readable or machine-readable storage media. Note that while in the example embodiment of Figure 18 storage media 1806 is depicted as within computer system 1801 A, in some embodiments, storage mediaPATENT Attorney Docket No.: IS24.0625-WO1806 may be distributed within and / or across multiple internal and / or external enclosures of computing system 1801A and / or additional computing systems. Storage media 1806 may include one or more different forms of memory including semiconductor memory devices such as dynamic or static random access memories (DRAMs or SRAMs), erasable and programmable read-only memories (EPROMs), electrically erasable and programmable read-only memories (EEPROMs) and flash memories, magnetic disks such as fixed, floppy and removable disks, other magnetic media including tape, optical media such as compact disks (CDs) or digital video disks (DVDs), B LURAY® disks, or other types of optical storage, or other types of storage devices. Note that the instructions discussed above may be provided on one computer-readable or machine-readable storage medium, or may be provided on multiple computer-readable or machine-readable storage media distributed in a large system having possibly plural nodes. Such computer-readable or machine-readable storage medium or media is (are) considered to be part of an article (or article of manufacture). An article or article of manufacture may refer to any manufactured single component or multiple components. The storage medium or media may be located either in the machine running the machine-readable instructions, or located at a remote site from which machine-readable instructions may be downloaded over a network for execution.
[0108] It should be appreciated that computing system 1800 is merely one example of a computing system, and that computing system 1800 may have more or fewer components than shown, may combine additional components not depicted in the example embodiment of Figure 18, and / or computing system 1800 may have a different configuration or arrangement of the components depicted in Figure 18. The various components shown in Figure 18 may be implemented in hardware, software, or a combination of both hardware and software, including one or more signal processing and / or application specific integrated circuits.
[0109] Further, the steps in the processing methods described herein may be implemented by running one or more functional modules in information processing apparatus such as general purpose processors or application specific chips, such as ASICs, FPGAs, PLDs, or other appropriate devices. These modules, combinations of these modules, and / or their combination with general hardware are included within the scope of the present disclosure.
[0110] Computational interpretations, models, and / or other interpretation aids may be refined in an iterative fashion; this concept is applicable to the methods discussed herein. This may include use of feedback loops executed on an algorithmic basis, such as at a computing device (e.g.,PATENT Attorney Docket No.: IS24.0625-WO computing system 1800, Figure 18), and / or through manual control by a user who may make determinations regarding whether a given step, action, template, model, or set of curves has become sufficiently accurate for the evaluation of the risk index.[oni] The foregoing description, for purpose of explanation, has been described with reference to specific embodiments. However, the illustrative discussions above are not intended to be exhaustive or limiting to the precise forms disclosed. Many modifications and variations are possible in view of the above teachings. Moreover, the order in which the elements of the methods described herein are illustrated and described may be re-arranged, and / or two or more elements may occur simultaneously. The embodiments were chosen and described in order to best explain the principles of the disclosure and its practical applications, to thereby enable others skilled in the art to best utilize the disclosed embodiments and various embodiments with various modifications as are suited to the particular use contemplated.
Claims
PATENT Attorney Docket No.: IS24.0625-WOCLAIMSWhat is claimed is:
1. A method for monitoring and autonomously addressing anomalies related to a site, the method comprising: receiving data from wellsite equipment disposed at the site, wherein the data is received by a fleet management system communicated to the wellsite equipment; identifying an anomaly within the received data; generating an insight based on the identified anomaly by an agent within the fleet management system; transmitting a command based on the generated insight to the wellsite equipment; and performing a wellsite action in response to the transmitted command, wherein performing the wellsite action comprises generating or transmitting a signal that instructs or causes an action to occur, wherein the action comprises a physical action, and wherein the physical action comprises adjusting a load associated with the wellsite equipment, preventing unauthorized access of the wellsite equipment or the fleet management system, adjusting a network connection between the fleet management system and the wellsite equipment, preventing an overload of data received from the wellsite equipment, or a combination thereof.
2. The method of claim 1, wherein the received data from the wellsite equipment comprises: performance metrics related to the wellsite equipment; firewall logs and alerts from intrusion detection systems (IDS) communicated to the wellsite equipment; network data related to the connectivity between the fleet management system and the wellsite equipment; and database data related to the wellsite equipment, wherein the database data comprises data related to a wellsite action.
3. The method of claim 2, wherein identifying an anomaly within the received data comprises: analyzing the performance metrics to determine a high latency and load related to the wellsite equipment;PATENT Attorney Docket No.: IS24.0625-WO analyzing the firewall logs and alerts from IDS to confirm if there has been any suspicious network activity related to the wellsite; identifying any repeated connection errors and latency spikes from the network data related to the connectivity between the fleet management system and the wellsite equipment; or identifying a rapid increase in data volume within the database data related to the wellsite equipment.
4. The method of claim 1, wherein adjusting a load associated with the wellsite equipment comprises: restarting a service performed by wellsite equipment in order to reduce the load and a latency related to the wellsite equipment; and adjusting at least one resource allocation to balance the load related to the wellsite equipment.
5. The method of claim 1, wherein preventing unauthorized access of the wellsite equipment or the fleet management system comprises: determining if an IP address is malicious and blocking the malicious IP address; changing at least one firewall rule to prevent unauthorized network activity related to the wellsite equipment; and performing a network scan of the wellsite equipment to identify any vulnerabilities or threats related to use of the wellsite equipment.
6. The method of claim 1, wherein adjusting a network connection between the fleet management system and the wellsite equipment comprises: testing a network and secure socket layer (SSL) connection to determine a root cause of any detected network connectivity instability; and changing a network setting or firewall rule in order to stabilize network connectivity.
7. The method of claim 1, wherein preventing an overload of data received from the wellsite equipment comprises:PATENT Attorney Docket No.: IS24.0625-WO identifying old logs or unnecessary data stored on a database communicated to the wellsite equipment; archiving the identified old logs or unnecessary data to free up space in the database communicated to the wellsite equipment; and changing a data retention policy to prevent future overflows in the database communicated to the wellsite equipment.
8. The method of claim 1, wherein transmitting a command comprises transmitting the command through a hub communicated to the wellsite equipment.
9. The method of claim 1, further comprising querying the agent within the fleet management system to generate a response insight related to the wellsite equipment or to retrieve data logs stored on a database communicated to the wellsite equipment.
10. The method of claim 9, wherein querying the agent within the fleet management system comprises: submitting a query via a graphical interface that is communicated to the fleet management system and the wellsite equipment; and displaying the generated response insight on the graphical interface.
11. A computing system, comprising: one or more processors; and a memory system comprising one or more non-transitory computer-readable media storing instructions that, when executed by at least one of the one or more processors, cause the computing system to perform operations, the operations comprising: receiving data from wellsite equipment disposed at a site, wherein the data is received by a fleet management system communicated to the wellsite equipment; identifying an anomaly within the received data, generating an insight based on the identified anomaly by an agent within the fleet management system;PATENT Attorney Docket No.: IS24.0625-WO transmitting a command based on the generated insight to the wellsite equipment; and performing a wellsite action in response to the transmitted command.
12. The computing system of claim 11, wherein the agent within the fleet management system comprises a supervisor agent communicated to a plurality of specialized agents.
13. The computing system of claim 12, wherein at least one of the plurality of specialized agents comprises a set of tools corresponding to the wellsite action.
14. The computing system of claim 13, wherein generating an insight based on the identified anomaly by an agent within the fleet management system comprises performing a similarity search between the identified anomaly and data stored on a procedure database communicated to the supervisor agent to generate a procedure.
15. The computing system of claim 14, further comprising assigning the procedure to one of the plurality of specialized agents by the supervisor agent.
16. The computing system of claim 15, further comprising performing the procedure by the specialized agent to provide a generated insight.
17. The computing system of claim 16, further comprising reporting the generated insight to the supervisor agent by the specialized agent.
18. The computing system of claim 16, wherein the generated insight is displayed on a graphical interface of a screen communicated to the computing system.
19. The computing system of claim 11, wherein performing the wellsite action in response to the generated command comprises: adjusting a load associated with the wellsite equipment; preventing unauthorized access of the wellsite equipment or the fleet management system;PATENT Attorney Docket No.: IS24.0625-WO adjusting a network connection between the fleet management system and the wellsite equipment; preventing an overload of data received from the wellsite equipment; or a combination thereof.
20. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations, the operations comprising: receiving data from wellsite equipment disposed at a site, wherein the data is received by a fleet management system communicated to the wellsite equipment and wherein the received data comprises: performance metrics of the equipment; firewall logs and alerts from intrusion detection systems (IDS); network connectivity data; and database data related to the equipment within the wellsite, identifying an anomaly within the received data, wherein identifying the anomaly comprises: analyzing performance metrics to determine a high latency and load related to the equipment within the wellsite; analyzing firewall logs and IDS alerts to confirm if there has been suspicious network activity related to the wellsite; identifying repeated connection errors and latency spikes from the network connectivity data; and identifying a rapid increase in data volume within the database data related to the wellsite equipment; generating an insight based on the identified anomaly, wherein generating an insight comprises submitting a query via a graphical interface that is communicated to the fleet management system and the wellsite equipment and displaying the generated insight on the graphical interface;PATENT Attorney Docket No.: IS24.0625-WO transmitting a command based on the generated insight to the wellsite equipment, wherein transmitting a command comprises transmitting the command is through a hub communicated to the wellsite equipment; and performing a wellsite action based on the transmitted command, wherein performing the wellsite action comprises generating or transmitting a signal that instructs or causes an action to occur, wherein the action comprises a physical action, and wherein the physical action comprises restarting services in order to reduce the load and latency related to the wellsite equipment, adjusting resource allocations to balance the load related to the wellsite equipment, blocking a determined malicious IP address and tightening firewall rules to prevent unauthorized network activity related to the wellsite, performing a network scan to identify any vulnerabilities or threats related to use of the wellsite equipment, testing network and secure socket layer (SSL) connections to determine a root cause of any network connectivity instability, adjusting network settings or opening necessary firewall rules to stabilize network connectivity, performing a cleanup operation which identifies and archives old logs or unnecessary data to free up space in a database related to the wellsite equipment, and adjusting data retention policies to prevent future overflows in a database related to the wellsite equipment.
Citation Information
Patent Citations
Cybersecurity with edge computing
US20200145440A1
Notification and task management system
US20220103499A1