Terminal operation management system, terminal operation management method, and terminal operation management program

The terminal operation management system uses a knowledge database and machine learning to simplify the identification of terminal device operation causes, addressing the need for expertise in log data analysis and enhancing maintenance efficiency.

WO2026105508A1PCT designated stage Publication Date: 2026-05-21SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SUMITOMO ELECTRIC INDUSTRIES LTD
Filing Date
2025-10-08
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing systems struggle to accurately identify the cause of terminal device operations due to the need for extensive expertise in log data analysis, as log data only indicates phenomena without clear cause indicators.

Method used

A terminal operation management system that utilizes a knowledge database to analyze log data, incorporating past failure records and machine learning, to easily identify the cause of terminal device operations, and provides visualization tools for users.

Benefits of technology

Enables easy identification of terminal device operation causes, reducing maintenance time and improving security by leveraging expert knowledge and automated analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025035676_21052026_PF_FP_ABST
    Figure JP2025035676_21052026_PF_FP_ABST
Patent Text Reader

Abstract

This terminal operation management system comprises: a first acquisition unit that acquires log data relating to a terminal device; a second acquisition unit that, on the basis of the log data acquired by the first acquisition unit, acquires a reason for the occurrence of an operation of the terminal device from a knowledge database; and an output unit that performs output processing for outputting analysis data including the reason for the occurrence acquired by the second acquisition unit.
Need to check novelty before this filing date? Find Prior Art

Description

Terminal operation management system, terminal operation management method, and terminal operation management program

[0001] The present disclosure relates to a terminal operation management system, a terminal operation management method, and a terminal operation management program. This application claims priority based on Japanese Patent Application No. 2024-197697 filed on November 12, 2024, and incorporates all of its disclosure herein.

[0002] Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2024-91218) discloses the following technology. That is, a production equipment operation status visualization system is a system that visualizes the operation status of each of a plurality of production equipment in a production line, and includes a data acquisition processing unit capable of executing a data acquisition process for acquiring operation status data indicating the operation status of the production equipment, and based on the acquired operation status data, first information for displaying the current operation status of the production equipment in a different manner for each type of the operation status and for each production equipment, and second information for displaying information regarding the history of the operation status of the production equipment for each production equipment, and a visualization processing unit capable of executing a visualization process for causing a display device to display the information.

[0003] Japanese Unexamined Patent Application Publication No. 2024-91218

[0004] The terminal operation management system of the present disclosure includes a first acquisition unit that acquires log data related to a terminal device, a second acquisition unit that acquires the cause of the operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit, and an output unit that performs an output process for outputting analysis data including the cause acquired by the second acquisition unit.

[0005] One aspect of the present disclosure can be realized not only as a terminal operation management system including such a characteristic processing unit, but also as a semiconductor integrated circuit that realizes part or all of the terminal operation management system.

[0006] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Figure 2 is a diagram showing an example of the configuration of a terminal device according to an embodiment of the present disclosure. Figure 3 is a diagram showing an example of the configuration of a log analysis server according to an embodiment of the present disclosure. Figure 4 is a diagram showing an example of a database stored in the storage unit of the log analysis server according to an embodiment of the present disclosure. Figure 5 is a diagram showing an example of a knowledge database stored in the storage unit of the log analysis server according to an embodiment of the present disclosure. Figure 6 is a diagram showing another example of a knowledge database stored in the storage unit of the log analysis server according to an embodiment of the present disclosure. Figure 7 is a diagram showing an example of a screen displayed by the output processing performed by the log analysis server according to an embodiment of the present disclosure. Figure 8 is a diagram showing another example of a screen displayed by the output processing performed by the log analysis server according to an embodiment of the present disclosure. Figure 9 is a flowchart defining an example of the operation procedure when a terminal device according to an embodiment of the present disclosure performs a process to transmit terminal information. Figure 10 is a flowchart defining an example of the operation procedure when a log analysis server according to an embodiment of the present disclosure performs a conversion process. Figure 11 is a flowchart defining an example of the operation procedure when a log analysis server according to an embodiment of the present disclosure performs a determination process. Figure 12 is a flowchart showing an example of the operation procedure when the log analysis server according to the embodiment of this disclosure performs a determination process. Figure 13 is a flowchart showing an example of the operation procedure when the log analysis server according to the embodiment of this disclosure performs an output process.

[0007] Technologies are being developed to monitor the operating status of terminal devices.

[0008] [Issues this disclosure aims to solve] Users such as manufacturers of terminal devices may analyze log data related to the terminal device to confirm whether or not an abnormality has occurred in the terminal device.

[0009] Understanding the causes of terminal device operation is crucial for reducing maintenance time and improving terminal device security. However, log data only indicates phenomena that occurred on the terminal device, making it difficult to pinpoint the cause of the operation from log data alone. Furthermore, users need extensive experience and expertise in log data analysis to identify the cause of such operation.

[0010] This disclosure was made to solve the above-mentioned problems, and its purpose is to provide a terminal operation management system, a terminal operation management method, and a terminal operation management program that can easily identify the causes of operation of terminal devices.

[0011] [Effects of this disclosure] According to this disclosure, the cause of operation of the terminal device can be easily identified.

[0012] [Description of Embodiments of the Disclosure] First, the contents of the embodiments of the disclosure will be listed and described. (1) The terminal operation management system according to the embodiment of the disclosure includes a first acquisition unit that acquires log data relating to a terminal device, a second acquisition unit that acquires the cause of operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit, and an output unit that performs output processing to output analysis data including the cause of operation acquired by the second acquisition unit.

[0013] This configuration allows for easy acquisition of the cause of an operation of a terminal device, corresponding to its log data, using a knowledge database that reflects the experience and know-how of experts, such as developers familiar with log data analysis. The user can then understand the cause by reviewing the outputted analysis data. Therefore, the cause of the terminal device's operation can be easily identified.

[0014] (2) In (1) above, the knowledge database may include the cause of occurrence based on past failure records in the terminal device.

[0015] This configuration allows for the output of analytical data that includes more accurate causes of failures, based on past failure records.

[0016] (3) In (1) or (2) above, the knowledge database may include a correspondence between the threshold number of occurrences and the cause of occurrence for each event relating to the terminal device.

[0017] This configuration allows for a more accurate determination of the cause of an event by using a threshold value set according to the number of occurrences of events that occur in the terminal device.

[0018] (4) In any of (1) to (3) above, the knowledge database may include a correspondence between keywords and the cause of occurrence, and the second acquisition unit may acquire the cause of occurrence corresponding to the keyword included in the log data acquired by the first acquisition unit from the knowledge database.

[0019] For example, terminal device log data may contain keywords related to the operation of the terminal device. With the configuration described above, the cause of the operation corresponding to that keyword can be easily obtained using the knowledge database.

[0020] (5) In any of (1) to (4) above, the knowledge database may exist for each system to which the terminal device belongs, and the second acquisition unit may acquire the cause of occurrence from the knowledge database for the system to which the terminal device that corresponds to the log data acquired by the first acquisition unit belongs.

[0021] This configuration allows for the acquisition of appropriate cause information for the system to which the terminal device belongs, from a knowledge database corresponding to that system.

[0022] (6) In any of (1) to (5) above, the terminal operation management system may further include a conversion unit that converts the log data of each of the multiple terminal devices belonging to different systems into data in a common format.

[0023] This configuration allows for the conversion of multiple log data sets, each with a different format, into a general-purpose format, thus facilitating the analysis of each log data set.

[0024] (7) In any of (1) to (6) above, the second acquisition unit may acquire a plurality of occurrence events corresponding to a plurality of terminal devices belonging to different systems, the second acquisition unit may store the acquired occurrence events in separate analysis databases for each system, and the terminal operation management system may further include an access restriction unit for each analysis database that restricts access to the analysis database.

[0025] This configuration prevents a user of one terminal device from gaining unauthorized access to an analysis database that stores the reasons for the operation of other terminal devices.

[0026] (8) In any of (1) to (7) above, the second acquisition unit may further acquire the cause of occurrence by providing the log data acquired by the first acquisition unit to a trained model generated by machine learning the relationship between the log data and the cause of occurrence.

[0027] This configuration allows for easy acquisition of the reasons for terminal device operation using machine learning techniques in addition to a knowledge database.

[0028] (9) In any of (1) to (8) above, the output unit may perform the process of displaying a screen showing the contents of the analysis data as the output process.

[0029] This configuration allows users to visualize the causes of terminal device operation included in the analysis data.

[0030] (10) A terminal operation management method according to an embodiment of the present disclosure is a terminal operation management method in a terminal operation management system, comprising the steps of: acquiring log data relating to a terminal device; acquiring the cause of operation of the terminal device from a knowledge database based on the acquired log data; and performing output processing to output analysis data including the acquired cause of operation.

[0031] This method allows for easy acquisition of the cause of a terminal device's operation, corresponding to its log data, using a knowledge database that reflects the experience and know-how of experts, such as developers proficient in log data analysis. The user can then understand the cause by reviewing the outputted analysis data. Therefore, the cause of the terminal device's operation can be easily identified.

[0032] (11) The terminal operation management program according to the embodiment of the present disclosure is a terminal operation management program used in a terminal operation management system, and is a program that causes a computer to function as a first acquisition unit that acquires log data relating to a terminal device, a second acquisition unit that acquires the cause of operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit, and an output unit that performs output processing to output analysis data including the cause of operation acquired by the second acquisition unit.

[0033] This configuration allows for easy acquisition of the cause of an operation of a terminal device, corresponding to its log data, using a knowledge database that reflects the experience and know-how of experts, such as developers familiar with log data analysis. The user can then understand the cause by reviewing the outputted analysis data. Therefore, the cause of the terminal device's operation can be easily identified.

[0034] Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.

[0035] [Communication System] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Referring to Figure 1, the communication system 501 comprises a plurality of terminal devices 101, a log analysis server 151, an analysis server 161, and a user terminal 301. The log analysis server 151 is an example of a terminal operation management system.

[0036] The terminal device 101 is, for example, an in-vehicle device mounted on vehicle 1. More specifically, for example, the terminal device 101 is an in-vehicle device retrofitted to vehicle 1.

[0037] In the example shown in Figure 1, the communication system 501 includes multiple terminal devices 101, namely terminal devices 101A and 101B. Terminal device 101A is mounted on vehicle 1A, namely vehicle 1. Terminal device 101B is mounted on vehicle 1B, namely vehicle 1.

[0038] In the example shown in Figure 1, the vehicle 1 on which the terminal device 101 is installed is a passenger car. However, the vehicle 1 is not limited to a passenger car; it may be any vehicle such as a truck.

[0039] The log analysis server 151 and the analysis server 161 are located outside the vehicle 1. The log analysis server 151 collects log data from the terminal device 101 and uses the collected log data to analyze the operating status of the terminal device 101, etc.

[0040] The analysis server 161 collects vehicle data related to vehicle 1 from the terminal device 101 and analyzes the collected vehicle data.

[0041] The user terminal 301 is, for example, a device owned by the manufacturer of the terminal device 101, or an individual (hereinafter collectively referred to as the user). The user terminal 301 is a communication terminal device such as a notebook PC (Personal Computer) or a tablet.

[0042] The user terminal 301 and the log analysis server 151 transmit and receive information via an external network 171 such as the Internet, for example.

[0043] [Terminal Device] FIG. 2 is a diagram showing an example of the configuration of a terminal device according to an embodiment of the present disclosure. Referring to FIG. 2, the terminal device 101 is connected to in-vehicle devices 202A and 202B, which are a plurality of in-vehicle devices 202, via a CAN (Controller Area Network) bus 2, for example.

[0044] The in-vehicle devices 202 include sensors, in-vehicle ECUs (Electronic Control Units), navigation devices, human machine interfaces, and cameras. The in-vehicle ECUs include a TCU (Telematics Communication Unit), an ECU for autonomous driving, an ECU for face authentication, and an ECU for door lock.

[0045] Each in-vehicle device 202 transmits vehicle data to the terminal device 101. Specifically, each in-vehicle device 202 includes the vehicle data and a CAN-ID (Identifier) indicating the type of the vehicle data in a CAN frame and transmits it to the terminal device 101. Each in-vehicle device 202 transmits the CAN frame to the terminal device 101, for example, periodically or irregularly.

[0046] The vehicle data is data indicating the measurement result of the in-vehicle device 202 that is the transmission source of the vehicle data, for example. Specifically, the vehicle data shows the measurement result of data related to the running of the vehicle 1 such as the vehicle speed as the measurement result.

[0047] Note that the terminal device 101 is not limited to the configuration connected to the in-vehicle device 202 via the CAN bus 2, and may be configured to be connected to the in-vehicle device 202 via a transmission line conforming to another communication standard such as Ethernet (registered trademark).

[0048] The terminal device 101 includes an in-vehicle communication unit 11, an out-vehicle communication unit 12, a collection unit 13, a log creation unit 14, and a storage unit 15. Part or all of the in-vehicle communication unit 11, the out-vehicle communication unit 12, the collection unit 13, and the log creation unit 14 are realized by, for example, a processing circuit (Circuitry) including one or more processors. The storage unit 15 is, for example, a non-volatile memory included in the above processing circuit.

[0049] (Collection and Transmission of Vehicle Data) The in-vehicle communication unit 11 stores the vehicle data received from each in-vehicle device 202 in the storage unit 15.

[0050] For example, the out-vehicle communication unit 12 performs wireless communication with a wireless base station device (not shown) according to a communication method such as Wi-Fi (registered trademark), LTE (Long Term Evolution) (registered trademark), or 5G, and communicates with the log analysis server 151 and the analysis server 161 via the external network 171.

[0051] The collection unit 13 performs a collection process S1 for collecting vehicle data to be transmitted to the analysis server 161. More specifically, when the processing timing T11 of the collection process S1 arrives, the collection unit 13 extracts a plurality of vehicle data (hereinafter, also referred to as "vehicle data group") stored in the storage unit 15 by the in-vehicle communication unit 11 during the period from the previous processing timing T11 to the current processing timing T11. Then, the collection unit 13 outputs the extracted vehicle data group to the out-vehicle communication unit 12.

[0052] For example, the storage unit 15 stores the vehicle ID of the vehicle 1 on which its own terminal device 101 is mounted.

[0053] The out-vehicle communication unit 12 transmits the vehicle data group collected by the collection unit 13 to the analysis server 161.

[0054] More specifically, the out-vehicle communication unit 12 transmits vehicle-related information including the vehicle data group received from the collection unit 13 and the vehicle ID stored in the storage unit 15 to the analysis server 161.

[0055] Referring again to Figure 1, the analysis server 161 performs various analyses, such as fault detection of the in-vehicle equipment 202 and evaluation of the driver's operation of the vehicle 1, based on the vehicle data group included in the vehicle-related information received from the terminal device 101.

[0056] (Creation and transmission of log data) Referring again to Figure 2, in the terminal device 101, the log creation unit 14 performs a creation process to create log data about its own terminal device 101, for example periodically. More specifically, for example, the log creation unit 14 monitors the operation of its own terminal device 101 each time the processing timing T20 of the creation process arrives.

[0057] The log creation unit 14 then creates log data including the monitoring time and monitoring result and stores it in the storage unit 15. Hereinafter, log data when the monitoring result is normal will also be referred to as a normal log. Log data when the monitoring result is abnormal will also be referred to as an error log. The error log includes, for example, the number of abnormalities that occurred during the period from the previous processing timing T20 to the current processing timing T20 (hereinafter also referred to as "number of errors N").

[0058] The collection unit 13 performs a collection process S2 to collect log data to be sent to the log analysis server 151. More specifically, when the processing timing T12 of the collection process S2 arrives, the collection unit 13 retrieves multiple log data (hereinafter also referred to as the "log data group") that have been stored in the storage unit 15 by the log creation unit 14 during the period from the previous processing timing T12 to the current processing timing T12. The collection unit 13 then outputs the retrieved log data group to the external communication unit 12.

[0059] For example, the memory unit 15 stores identification information (hereinafter also referred to as "terminal ID") for identifying its own terminal device 101.

[0060] The external communication unit 12 transmits the log data collected by the collection unit 13 to the log analysis server 151.

[0061] More specifically, the external communication unit 12 transmits the log data set received from the collection unit 13 and terminal information, including the terminal ID and vehicle ID, stored in the storage unit 15, to the log analysis server 151.

[0062] [Explanation of the problem] Users of terminal device 101 may check whether or not an abnormality has occurred by aggregating and analyzing log data related to terminal device 101.

[0063] To shorten the maintenance time for the terminal device 101 and improve its security, it is important to understand the cause H of the operation of the terminal device 101. Since log data only shows the phenomena that occurred in the terminal device 101, it is difficult to identify the cause H from the log data alone. Furthermore, in order to identify the cause H, the user needs to have extensive experience and know-how in analyzing log data, etc.

[0064] Furthermore, log data may indicate signs of malfunction in terminal device 101. To recognize such signs, the user needs to have extensive experience and know-how, as described above. Even if the user has extensive experience and know-how, they may not necessarily have specialized knowledge about all signs in terminal device 101.

[0065] Therefore, the communication system 501 according to the embodiment of this disclosure solves the above problem through the following configuration and operation.

[0066] [Log Analysis Server] Figure 3 is a diagram showing an example of the configuration of a log analysis server according to an embodiment of the present disclosure. Referring to Figure 3, the log analysis server 151 comprises a communication unit 21, a processing unit 22, and a storage unit 23. The processing unit 22 includes a conversion unit 31, a receiving unit 32, an analysis unit 33, an output unit 34, and an access restriction unit 35. One or both of the communication unit 21 and the processing unit 22 are implemented by a processing circuit including, for example, one or more processors. The storage unit 23 is, for example, a non-volatile memory included in the processing circuit. The communication unit 21 is an example of a first acquisition unit. The analysis unit 33 is an example of a second acquisition unit.

[0067] Figure 4 shows an example of a database stored in the storage unit of a log analysis server according to an embodiment of the present disclosure.

[0068] Referring to Figure 4, the storage unit 23 stores multiple log databases 41, multiple knowledge databases 51, and multiple analysis databases 61. For example, the log databases 41, knowledge databases 51, and analysis databases 61 exist for each system to which the terminal device 101 belongs.

[0069] Here, for example, the system to which the terminal device 101 belongs is vehicle 1. The storage unit 23 stores a log database 41, a knowledge database 51, and an analysis database 61 for each pair E of the terminal ID of the terminal device 101 and the vehicle ID of the vehicle 1 on which the terminal device 101 is installed.

[0070] (Acquisition of log data) Referring again to Figure 3, the communication unit 21 acquires log data related to the terminal device 101. More specifically, for example, the communication unit 21 acquires log data for each of the multiple terminal devices 101 belonging to different systems.

[0071] Specifically, the communication unit 21 receives terminal information, including log data sets, from each terminal device 101 via the external network 171. The communication unit 21 then outputs the received terminal information to the conversion unit 31.

[0072] (Conversion process) For example, the conversion unit 31 performs a conversion process to convert the log data of multiple terminal devices 101 belonging to different systems into a common format.

[0073] More specifically, for example, when the conversion unit 31 receives terminal information from the communication unit 21, it performs a conversion process on each log data in the group of log data included in the terminal information.

[0074] Specifically, the conversion unit 31 performs tasks such as imputing missing values ​​and standardizing inconsistencies in notation in the log data during the conversion process.

[0075] Referring to Figures 3 and 4, once the conversion unit 31 completes the conversion process, it creates analysis information that includes each log data after the conversion process and the terminal ID and vehicle ID included in the terminal information received from the communication unit 21. The conversion unit 31 then saves the created analysis information to the log database 41 corresponding to the terminal ID and vehicle ID included in the analysis information.

[0076] (Knowledge Database) Figure 5 shows an example of a knowledge database stored in the storage unit of a log analysis server according to an embodiment of the present disclosure. Figure 6 shows another example of a knowledge database stored in the storage unit of a log analysis server according to an embodiment of the present disclosure. Figure 5 shows knowledge database 51A, which is a knowledge database 51 corresponding to a vehicle 1A on which the terminal device 101A shown in Figure 1 is installed. Figure 6 shows knowledge database 51B, which is a knowledge database 51 corresponding to a vehicle 1B on which the terminal device 101B shown in Figure 1 is installed.

[0077] Referring to Figures 5 and 6, for example, each knowledge database 51 includes the cause H of the operation of the terminal device 101, based on past failure records of the terminal device 101.

[0078] More specifically, each knowledge database 51 includes, for example, a correspondence between keywords, a threshold Th for the number of occurrences of events related to the terminal device 101, and the cause H of the occurrence.

[0079] The keywords registered in the knowledge database 51 indicate identification information (hereinafter also referred to as "event ID") for identifying events related to the terminal device 101, and the type of abnormality in the terminal device 101.

[0080] The keywords registered in the knowledge database 51A shown in Figure 5 are event IDs. The keywords registered in the knowledge database 51B shown in Figure 6 are the types of abnormalities in the terminal device 101.

[0081] In the example shown in Figure 5, if the event with event ID "1111111" occurs 10 or more times within a predetermined period, the cause H is "communication abnormality from board A to board B".

[0082] In the example shown in Figure 6, if the number of times the "file open error" error occurs within a predetermined period is "20 times" or more, the cause H is "communication error on board B". If the number of times the "update filed" error occurs within a predetermined period is "1 time" or more, the cause H is "failure to update the software incorporated in terminal device 101".

[0083] (Determination process) The analysis unit 33 performs a determination process to determine the operating status of the terminal device 101 based on the log data acquired by the communication unit 21.

[0084] More specifically, when the processing timing T30 for the determination process arrives, the analysis unit 33 performs a determination process for each log database 41 in the storage unit 23 using multiple pieces of analysis information stored in the log database 41. That is, the analysis unit 33 performs a determination process based on multiple log data that have been converted into a common format by the conversion unit 31.

[0085] Specifically, the analysis unit 33 retrieves multiple pieces of analysis information stored in each log database 41 by the conversion unit 31 during the period R from the previous processing timing T30 to the current processing timing T30. The period R is, for example, one day.

[0086] The analysis unit 33 then uses the extracted analytical information to determine the operating status of the terminal device 101 at predetermined intervals during period R. For example, the analysis unit 33 determines the operating status of the terminal device 101 at one-hour intervals during period R. Hereinafter, each of the multiple time points to be determined during period R will also be referred to as the time point to be determined.

[0087] The analysis unit 33 determines the operating status of the terminal device 101 for each time period to be determined. If none of the extracted analytical information contains log data from a monitoring time (hereinafter also referred to as "monitoring time tk") where the time difference from the time period to be determined is less than a threshold, the analysis unit 33 determines that the terminal device 101 was not operating at that time period.

[0088] Furthermore, if the log data at monitoring time tk included in the extracted analysis information is a normal log, the analysis unit 33 determines that the operating status of the terminal device 101 at the time of determination corresponding to the monitoring time tk is normal.

[0089] Furthermore, if the log data at monitoring time tk included in the extracted analysis information is an error log, the analysis unit 33 determines that the operating status of the terminal device 101 at the time of determination corresponding to the monitoring time tk is abnormal.

[0090] When the analysis unit 33 completes the determination process, it creates operational determination information for each log database 41, including the determination result of the determination process and the group E corresponding to that log database 41.

[0091] Hereinafter, the time at which the analysis unit 33 determines that the operating status of the terminal device 101 is abnormal will also be referred to as the time at which determination is made te.

[0092] <Acquisition of Incident Cause H using Knowledge Database> The analysis unit 33 acquires Incident Cause H from the knowledge database 51 based on the log data acquired by the communication unit 21.

[0093] More specifically, for example, the analysis unit 33 obtains the cause H from the knowledge database 51 for the system to which the terminal device 101, corresponding to the log data acquired by the communication unit 21, belongs.

[0094] Specifically, if the analysis unit 33 determines that the operating status of the terminal device 101 at the time te is abnormal, it identifies the knowledge database 51 in the storage unit 23 that corresponds to the system to which the terminal device 101 belongs (hereinafter also referred to as the "corresponding knowledge database").

[0095] The analysis unit 33 identifies the corresponding knowledge database and checks whether the keyword included in the error log at the time of determination te is registered in that corresponding knowledge database.

[0096] Then, if the keyword included in the error log at the time of determination te is registered in the corresponding knowledge database, the analysis unit 33 refers to the corresponding knowledge database to check whether the number of errors N included in the error log is equal to or greater than the threshold Th corresponding to that keyword.

[0097] If the number of errors N is greater than or equal to the threshold Th, the analysis unit 33 retrieves the cause H corresponding to the keyword included in the error log at the time te from the knowledge database 51.

[0098] When the analysis unit 33 obtains an occurrence reason H, it includes a pair K of the obtained occurrence reason H and the determination target time te corresponding to the occurrence reason H in the created operation determination information. The analysis unit 33 then saves the operation determination information including pair K in the analysis database 61, which corresponds to the pair E of terminal ID and vehicle ID included in the operation determination information.

[0099] On the other hand, if the number of error occurrences N is less than the threshold Th, the analysis unit 33 does not obtain the cause of occurrence H from the corresponding knowledge database. The analysis unit 33 then stores the created operation judgment information in the analysis database 61 corresponding to the terminal ID and vehicle ID pair E included in the operation judgment information.

[0100] <Acquisition of the cause of occurrence H using a trained model> For example, if the keyword included in the error log at the time te to be determined is not registered in the corresponding knowledge database, the analysis unit 33 uses machine learning techniques to identify the cause of occurrence H corresponding to the error log.

[0101] For example, the memory unit 23 stores a trained model M. The trained model M is a trained model generated by machine learning the relationship between log data and the cause of occurrence H. The trained model M outputs the cause of occurrence H when a keyword included in the log data is input. The trained model M is, for example, a generative AI.

[0102] If the keyword included in the error log at the time of determination te is not registered in the corresponding knowledge database, the analysis unit 33 retrieves the trained model M from the storage unit 23.

[0103] For example, the analysis unit 33 obtains the cause of occurrence H by providing the trained model M with log data acquired by the communication unit 21.

[0104] More specifically, the analysis unit 33 inputs the keywords contained in the error log at the time of judgment te into the acquired trained model M. Then, the analysis unit 33 obtains the cause of occurrence H output from the trained model M.

[0105] For example, the analysis unit 33 stores the acquired cause of occurrence H in a separate analysis database 61 for each system to which the terminal device 101 belongs.

[0106] More specifically, when the analysis unit 33 obtains an occurrence reason H, it includes a pair K of the obtained occurrence reason H and the corresponding time te for determination in the created operation determination information. The analysis unit 33 then stores the operation determination information including pair K in the analysis database 61, which corresponds to the pair E of terminal ID and vehicle ID included in the operation determination information.

[0107] Each time the analysis unit 33 saves operational determination information for a terminal device 101 to the analysis database 61, it outputs a save completion notification to the access restriction unit 35 indicating that the operational determination information has been saved to the analysis database 61 and the set E of terminal ID and vehicle ID corresponding to the analysis database 61.

[0108] Furthermore, the storage unit of a device other than the log analysis server 151 may be configured to store the trained model M. In this case, for example, the log analysis server 151 and the other device exchange various types of information, such as analysis information and information indicating the cause of occurrence H, using an API (Application Programming Interface).

[0109] (Access Restriction Unit) For example, the access restriction unit 35 performs access restriction processing for each analysis database 61 to restrict access to that analysis database 61.

[0110] More specifically, when the access restriction unit 35 receives a save completion notification from the analysis unit 33, it creates authentication information F to authenticate access to the analysis database 61 corresponding to the set E indicated in the save completion notification.

[0111] The access restriction unit 35 then transmits the created authentication information F to the user terminal 301 via the communication unit 21 and the external network 171. The authentication information F consists of a certificate and a private key, etc.

[0112] When the user terminal 301 receives authentication information F from the log analysis server 151, it stores the received authentication information F in a storage unit (not shown).

[0113] (Reception Unit) Referring again to Figures 1 and 3, for example, the reception unit 32 displays a screen G0 on the user terminal 301 prompting the user to input display request information. The display request information is, for example, information indicating the period for which the analysis results by the log analysis server 151 are to be displayed (hereinafter also referred to as the "display target period"), multiple terminal IDs, and multiple vehicle IDs corresponding to each of the multiple terminal IDs. The display target period is, for example, a period of one hour or more. Note that the display request information may also be information indicating the display target period, one terminal ID, and one vehicle ID corresponding to that terminal ID.

[0114] More specifically, the storage unit 23 stores screen information B0 that represents screen G0. When its log analysis server 151 starts up and, for example, a predetermined operation is performed by the user, the reception unit 32 retrieves the screen information B0 from the storage unit 23. The reception unit 32 then outputs the retrieved screen information B0 to the communication unit 21.

[0115] When the communication unit 21 receives screen information B0 from the reception unit 32, it transmits the screen information B0 to the user terminal 301 via the external network 171.

[0116] When user terminal 301 receives screen information B0 from log analysis server 151, it draws screen G0 on the web browser displayed on its own display unit based on the received screen information B0.

[0117] While screen G0 is displayed on the user terminal 301, the user performs an operation to input the display period, multiple terminal IDs, and multiple vehicle IDs.

[0118] The user terminal 301 transmits the display request information, which includes the period to be displayed, multiple terminal IDs, and multiple vehicle IDs, along with the authentication information F stored in its own memory, to the log analysis server 151 via the external network 171.

[0119] In the log analysis server 151, when the reception unit 32 receives display request information from the user terminal 301 via the external network 171 and the communication unit 21, it performs authentication processing on the user terminal 301 using the authentication information F contained in the received display request information.

[0120] If the authentication process fails, the reception unit 32 sends authentication failure information indicating that the authentication process failed to the user terminal 301 via the communication unit 21 and the external network 171.

[0121] When user terminal 301 receives authentication failure information from log analysis server 151, it performs notification processing based on the received authentication failure information. Specifically, for example, user terminal 301 displays a screen on its own display unit indicating that the authentication process on log analysis server 151 has failed.

[0122] Meanwhile, if the authentication process is successful, the reception unit 32 outputs the received display request information to the output unit 34.

[0123] (Output Unit) The output unit 34 performs output processing to output analysis data D, which includes the cause of occurrence H acquired by the analysis unit 33.

[0124] More specifically, for example, the output unit 34 performs the output process of displaying screen G1, which includes the contents of the analysis data D.

[0125] Specifically, the output unit 34 obtains operational determination information from the analysis database 61 corresponding to each set E of terminal ID and vehicle ID indicated by the display request information received from the reception unit 32. Then, the output unit 34 uses the multiple operational determination information obtained to create screen information B1 that shows screen G1.

[0126] When the output unit 34 creates screen information B1, it transmits the created screen information B1 to the user terminal 301 via the communication unit 21 and the external network 171.

[0127] When user terminal 301 receives screen information B1 from log analysis server 151, it draws screen G1 on the web browser displayed on itself based on the received screen information B1.

[0128] Figure 7 shows an example of a screen displayed by the output processing performed by the log analysis server according to the embodiment of this disclosure.

[0129] Referring to Figure 7, in the log analysis server 151, the output unit 34 displays a screen G1 showing the history of the determination results of the operating status of each terminal device 101 during the display period.

[0130] In the example shown in Figure 7, the output unit 34 displays screen G1, which shows the results of the operational status determination for each hour during the period from 0:00 to 16:00 on January 1, 2024.

[0131] For example, the output unit 34 displays different portions of the time period corresponding to the operating status of the terminal device 101 depending on the type of operating status of that device.

[0132] Specifically, for example, the output unit 34 displays a result indicating that the operating status is normal by filling it with green, a result indicating that the operating status is abnormal by filling it with red, and a result indicating that the operating status is not operational without filling it with any color. In Figure 7, green fills are indicated by diagonal hatching lines, and red fills are indicated by black fills.

[0133] Figure 8 shows another example of a screen displayed by the output processing performed by the log analysis server according to the embodiment of this disclosure.

[0134] Referring to Figures 3 and 8, the output unit 34 acquires operation information Q, which indicates an operation that specifies a determination result indicating that the operating status is abnormal, when screen G1 is displayed on the user terminal 301.

[0135] Specifically, for example, suppose the user operates a mouse or keyboard, etc., to move the pointer P on screen G1 to a position that overlaps with the determination result indicating that the operating status of the terminal device 101 is abnormal.

[0136] In this case, the output unit 34 obtains operation information Q indicating the terminal ID and the time of determination, which corresponds to the determination result selected by the pointer P.

[0137] The output unit 34 then obtains operation determination information (hereinafter also referred to as "operation determination information C") corresponding to the target time indicated by the operation information Q from among the multiple analysis databases 61 in the storage unit 23, specifically from the analysis database 61 corresponding to the terminal ID indicated by the acquired operation information Q.

[0138] When the output unit 34 acquires operational judgment information C, it pops up an explanation field L that shows the type of abnormality, the time and reason H of the abnormality, corresponding to the judgment result selected by the pointer P, based on the operational judgment information C.

[0139] In the example shown in Figure 8, the output unit 34 indicates that the abnormality that occurred in terminal device 101 with terminal ID "00001" between 11:00 and 12:00 on January 1, 2024, was a "shutdown error". The time of the abnormality was 11:10:11 on January 1, 2024. The reason for the abnormality H was that the shutdown process did not complete normally, specifically because the terminal device 101 and the battery in vehicle 1 were not connected.

[0140] [Operation Flow] Next, the operation flow of each device in the communication system 501 according to the embodiment of this disclosure will be explained with reference to the drawings.

[0141] Figure 9 is a flowchart illustrating an example of the operation procedure when a terminal device according to an embodiment of this disclosure performs a process to transmit terminal information.

[0142] Referring to Figure 9, first, the terminal device 101 waits for the processing timing T12 of the collection process S2, which collects log data, to arrive (NO in step ST101).

[0143] Then, when the processing timing T12 arrives (YES in step ST101), the terminal device 101 collects multiple log data stored in the storage unit 15 during the period from the previous processing timing T12 to the current processing timing T12 (step ST102).

[0144] Next, the terminal device 101 sends the collected log data and terminal information, including the terminal ID and vehicle ID stored in the storage unit 15, to the log analysis server 151 (step ST103), and waits for the next processing timing T12 to arrive (NO in step ST101).

[0145] Figure 10 is a flowchart that shows an example of the operation procedure when the log analysis server according to the embodiment of this disclosure performs conversion processing.

[0146] Referring to Figure 10, first, the log analysis server 151 waits for the reception of terminal information from the terminal device 101 (NO in step ST201).

[0147] Then, when the log analysis server 151 receives terminal information from the terminal device 101 (YES in step ST201), it performs a conversion process to convert each log data in the log data group included in the received terminal information into a common format (step ST202).

[0148] Next, the log analysis server 151 creates analysis information that includes each log data after conversion processing and the set E of terminal ID and vehicle ID contained in the received terminal information (step ST203).

[0149] Next, the log analysis server 151 saves the created analysis information to the log database 41 in the storage unit 23 that corresponds to the set E included in the analysis information (step ST204), and waits for the reception of new terminal information from the terminal device 101 (NO in step ST201).

[0150] Figures 11 and 12 are flowcharts illustrating an example of the operation procedure when a log analysis server according to an embodiment of the present disclosure performs a determination process. Figures 11 and 12 show a case in which the log analysis server 151 determines the operating status of the terminal device 101A shown in Figure 1.

[0151] Referring to Figures 11 and 12, first, the log analysis server 151 waits for the arrival of the processing timing T30 for the determination process (NO in step ST301).

[0152] Then, when processing timing T30 arrives (YES in step ST301), the log analysis server 151 performs a determination process. For example, as described above, the log analysis server 151 retrieves multiple pieces of analysis information stored in the log database 41 during the period R from the previous processing timing T30 to the current processing timing T30. Then, using the retrieved pieces of analysis information, the log analysis server 151 determines the operating status of the terminal device 101A at each determination target time included in period R (step ST302).

[0153] Next, if the log analysis server 151 determines that the operating status of the terminal device 101A at a certain target time is non-operating or normal (YES in step ST303), and there are undetermined target times (YES in step ST304), it determines the operating status at those undetermined target times (step ST302).

[0154] On the other hand, if the log analysis server 151 determines that the operating status of terminal device 101A at a certain target time is non-operating or normal (YES in step ST303), and there are no undetermined target times (NO in step ST304), it creates operational determination information including the determination result, the terminal ID of terminal device 101A, and the vehicle ID of vehicle 1A on which terminal device 101A is installed (step ST305).

[0155] Next, the log analysis server 151 saves the created operation determination information to the analysis database 61 corresponding to the terminal ID and vehicle ID pair E included in the operation determination information (step ST306).

[0156] Next, the log analysis server 151 performs access restriction processing for each analysis database 61 in the storage unit 23 to restrict access to that analysis database 61. For example, as described above, the log analysis server 151 creates authentication information F for each analysis database 61 to authenticate access to that analysis database 61. Then, the log analysis server 151 sends the created authentication information F to the user terminal 301 owned by the user of the corresponding terminal device 101 (step ST307), and waits for the arrival of the next processing timing T30 (NO in step ST301).

[0157] On the other hand, if the log analysis server 151 determines that the operating status of the terminal device 101 at a certain target time is abnormal (NO in step ST303), it identifies the corresponding knowledge database among the multiple knowledge databases 51 in the storage unit 23 that corresponds to the system to which the terminal device 101 belongs (step ST308).

[0158] Next, the log analysis server 151 checks whether the keywords included in the log data corresponding to the time period in which the operating status was determined to be abnormal, i.e., the keywords included in the error log, are registered in the corresponding knowledge database (step ST309).

[0159] Next, if the keyword included in the error log is registered in the corresponding knowledge database (YES in step ST309), the log analysis server 151 checks whether the number of errors N included in the error log is greater than or equal to the threshold Th corresponding to that keyword (step ST310).

[0160] Next, the log analysis server 151, if the number of errors N included in the error log is greater than or equal to the threshold Th (YES in step ST310), obtains the cause H corresponding to the keyword from the corresponding knowledge database (step ST311), and if there are undetermined time periods (YES in step ST304), determines the operational status at those undetermined time periods (step ST302).

[0161] On the other hand, if the keyword included in the error log is not registered in the corresponding knowledge database (NO in step ST309), the log analysis server 151 retrieves the trained model M from the storage unit 23 (step ST312).

[0162] Next, the log analysis server 151 inputs the keywords contained in the error log into the trained model M, obtains the cause H output from the trained model M (step ST311), and if there are undetermined time periods (YES in step ST304), determines the operating status at those undetermined time periods (step ST302).

[0163] Furthermore, if the number of errors N included in the error log is less than the threshold Th (NO in step ST310), and there are undetermined time periods (YES in step ST304), the log analysis server 151 determines the operational status at those undetermined time periods (step ST302).

[0164] Figure 13 is a flowchart that shows an example of the operation procedure when the log analysis server according to the embodiment of this disclosure performs output processing.

[0165] Referring to Figure 13, first, the log analysis server 151 waits for the receipt of display request information from the user terminal 301 (NO in step ST401).

[0166] Then, when the log analysis server 151 receives display request information from the user terminal 301 (YES in step ST401), it obtains operational determination information from the analysis database 61 corresponding to each set E of terminal ID and vehicle ID indicated by the received display request information (step ST402).

[0167] Next, the log analysis server 151 performs output processing to output analysis data D, which includes the acquired cause H, using the acquired operational judgment information. For example, as described above, the log analysis server 151 performs processing to display a screen G1 showing the contents of the analysis data D on the user terminal 301 (step ST403), and waits for the reception of new display request information from the user terminal 301 (NO in step ST401).

[0168] In the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to include a communication unit 21, a conversion unit 31, a receiving unit 32, an analysis unit 33, an output unit 34, and an access restriction unit 35, but this is not the only configuration. For example, other devices besides the log analysis server 151 may be configured to include a communication unit 21, a conversion unit 31, a receiving unit 32, an analysis unit 33, an output unit 34, and an access restriction unit 35. Alternatively, multiple devices may share the communication unit 21, a conversion unit 31, a receiving unit 32, an analysis unit 33, an output unit 34, and an access restriction unit 35 as a terminal operation management system. For example, the log analysis server 151 may include some of these six units, while other devices include the remaining units.

[0169] Furthermore, in the log analysis server 151 according to the embodiment of this disclosure, the knowledge database 51 stored in the storage unit 23 is configured to include incident cause H based on past failure records in the terminal device 101, but it is not limited to this. The knowledge database 51 may also be configured to include incident cause H based on records of events other than past failures in the terminal device 101.

[0170] Furthermore, while the log analysis server 151 according to the embodiment of this disclosure has a configuration in which the knowledge database 51 stored in the storage unit 23 includes a correspondence between keywords, thresholds Th, and occurrence causes H, it is not limited to this. The knowledge database 51 may also have a configuration in which either keywords or thresholds Th and occurrence causes H are included. Alternatively, the knowledge database 51 may also have a configuration in which information other than keywords and thresholds Th and occurrence causes H are included.

[0171] Furthermore, in the log analysis server 151 according to the embodiment of this disclosure, the log database 41, knowledge database 51, and analysis database 61 stored in the storage unit 23 exist for each system to which the terminal device 101 belongs, but this is not limited to this. The log database 41, knowledge database 51, and analysis database 61 corresponding to one system may be common to the log database 41, knowledge database 51, and analysis database 61 corresponding to other systems.

[0172] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to perform a conversion process to convert the log data of each of the multiple terminal devices 101 belonging to different systems into a common format, but the system is not limited to this. The log analysis server 151 may be configured not to perform a conversion process.

[0173] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to store the occurrence cause H obtained from the knowledge database 51 in a separate analysis database 61 for each system to which the terminal device 101 subject to operational status determination belongs, but it is not limited to this. The log analysis server 151 may also be configured to store the acquired occurrence cause H in an analysis database 61 corresponding to a system to which a terminal device 101 different from the terminal device 101 subject to determination belongs.

[0174] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to perform access restriction processing for each analysis database 61, but it is not limited to this. The log analysis server 151 may be configured not to perform access restriction processing. In this case, the log analysis server 151 stores the incident cause H obtained from the knowledge database 51 in a common analysis database 61, regardless of the system to which the terminal device 101 belongs.

[0175] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to acquire the cause H using a trained model M when a keyword included in the error log is not registered in the knowledge database 51, but it is not limited to this. The log analysis server 151 may also be configured to acquire the cause H using methods other than machine learning, such as statistical analysis.

[0176] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the log analysis server 151 is configured to perform the process of displaying a screen G1 showing the contents of the analysis data D, including the acquired cause of occurrence H, on the user terminal 301 as an output process, but it is not limited to this. The log analysis server 151 may also be configured to perform the process of creating and sending an email containing the contents of the analysis data D to the user, and the process of notifying the user of the contents of the analysis data D by voice, as output processes.

[0177] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the system to which the terminal device 101 belongs is defined as a vehicle 1, but it is not limited to this. The system to which the terminal device 101 belongs may also be equipment such as batteries and generators, factories and plants, etc.

[0178] Furthermore, some or all of the functions of the log analysis server 151 according to the embodiment of this disclosure may be provided by cloud computing. That is, the log analysis server 151 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.

[0179] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.

[0180] Each process (each function) in the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of an integrated circuit, etc., which combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been designed in advance to execute each of the above processes. The above-mentioned processor may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, multiple physically separated processors may cooperate with each other to perform the above-mentioned processes. For example, processors installed in multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above-mentioned processes. The above program may be installed on the above memory via the above network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or semiconductor memory, and then installed on the above memory from the above recording medium.

[0181] The above description includes the following features: [Addendum 1] A terminal operation management system comprising: a first acquisition unit that acquires log data relating to a terminal device; a second acquisition unit that acquires the cause of operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit; and an output unit that performs output processing to output analysis data including the cause of operation acquired by the second acquisition unit, wherein the terminal operation management system further comprises: an analysis unit that determines the operating status of the terminal device based on the log data acquired by the first acquisition unit, and the analysis data further includes the determination result of the analysis unit.

[0182] [Note 2] The device is equipped with a processing circuit, the processing circuit comprising an output unit that acquires log data relating to a terminal device, acquires the cause of the operation of the terminal device from a knowledge database based on the acquired log data, and outputs analysis data including the acquired cause of the operation.

[0183] 1, 1A, 1B Vehicle 2 CAN bus 11 In-vehicle communication unit 12 External communication unit 13 Collection unit 14 Log creation unit 15, 23 Storage unit 21 Communication unit 22 Processing unit 31 Conversion unit 32 Reception unit 33 Analysis unit 34 Output unit 35 Access restriction unit 41 Log database 51, 51A, 51B Knowledge database 61 Analysis database 101, 101A, 101B Terminal device 151 Log analysis server 161 Analysis server 171 External network 202, 202A, 202B In-vehicle equipment 301 User terminal 501 Communication system

Claims

1. A terminal operation management system comprising: a first acquisition unit for acquiring log data relating to a terminal device; a second acquisition unit for acquiring the cause of operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit; and an output unit for performing output processing to output analysis data including the cause of operation acquired by the second acquisition unit.

2. The terminal operation management system according to claim 1, wherein the knowledge database includes the cause of occurrence based on past failure records in the terminal device.

3. The terminal operation management system according to claim 1 or 2, wherein the knowledge database includes a correspondence between a threshold for the number of occurrences and the cause of occurrence for each event relating to the terminal device.

4. The terminal operation management system according to any one of claims 1 to 3, wherein the knowledge database includes a correspondence between keywords and the events that occur, and the second acquisition unit acquires the events that occur corresponding to the keywords included in the log data acquired by the first acquisition unit from the knowledge database.

5. The terminal operation management system according to any one of claims 1 to 4, wherein the knowledge database exists for each system to which the terminal device belongs, and the second acquisition unit acquires the cause of occurrence from the knowledge database for the system to which the terminal device corresponding to the log data acquired by the first acquisition unit belongs.

6. The terminal operation management system according to any one of claims 1 to 5, further comprising a conversion unit that converts the log data of each of the multiple terminal devices belonging to different systems into data in a common format.

7. The terminal operation management system according to any one of claims 1 to 6, wherein the second acquisition unit acquires a plurality of occurrence events corresponding to a plurality of terminal devices belonging to different systems, the second acquisition unit stores the acquired occurrence events in a separate analysis database for each system, and the terminal operation management system further includes an access restriction unit for each analysis database that restricts access to the analysis database.

8. The terminal operation management system according to any one of claims 1 to 7, wherein the second acquisition unit further acquires the cause of occurrence by providing the log data acquired by the first acquisition unit to a trained model generated by machine learning the relationship between the log data and the cause of occurrence.

9. The terminal operation management system according to any one of claims 1 to 8, wherein the output unit performs the process of displaying a screen showing the contents of the analysis data as the output process.

10. A terminal operation management method in a terminal operation management system, comprising the steps of: acquiring log data relating to a terminal device; acquiring the cause of operation of the terminal device from a knowledge database based on the acquired log data; and performing output processing to output analysis data including the acquired cause of operation.

11. A terminal operation management program used in a terminal operation management system, which causes a computer to function as: a first acquisition unit that acquires log data relating to a terminal device; a second acquisition unit that acquires the cause of operation of the terminal device from a knowledge database based on the log data acquired by the first acquisition unit; and an output unit that performs output processing to output analysis data including the cause of operation acquired by the second acquisition unit.