Terminal operation management system, terminal operation management method, and terminal operation management program
Patent Information
- Application Number
- PCT/JP2026/006708
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-26
- Filing Date
- 2026-02-24
- Publication Date
- 2026-09-03
Smart Images

Figure JP2026006708_03092026_PF_FP_ABST
Abstract
Description
Terminal operation management system, terminal operation management method, and terminal operation management program
[0001] The present disclosure relates to a terminal operation management system, a terminal operation management method, and a terminal operation management program. This application claims priority based on Japanese Patent Application No. 2025-028909 filed on February 26, 2025, and incorporates all the content described in the said Japanese application by reference.
[0002] Conventionally, techniques have been developed to detect an abnormality in a monitored device based on information indicating the state of the device. For example, Patent Document 1 (Japanese Unexamined Patent Publication No. 2019-179395) discloses the following technique. Specifically, the abnormality detection system comprises: a control calculation unit that executes control calculations for controlling a controlled object; and a first abnormality detection unit that detects an abnormality that may occur in a monitored object by inputting a state value related to the monitored object among the state values collected by the control calculation unit to a model representing the monitored object defined by an abnormality detection parameter and a learning data set. The first abnormality detection unit comprises: a calculation unit that calculates a score using a feature amount calculated from the state value related to the monitored object in accordance with the abnormality detection parameter; and a determination unit that performs determination using the score calculated by the calculation unit and a first determination criterion and a second determination criterion included in the abnormality detection parameter respectively, outputs a first determination result when the first determination criterion is satisfied, and outputs a second determination result when the second determination criterion is satisfied.
[0003] Japanese Unexamined Patent Publication No. 2019-179395
[0004] The terminal operation management system of the present disclosure comprises: an acquisition unit that acquires log data related to a terminal device; a changing unit that adds and deletes an analysis module including an analysis program that analyzes the operation of the terminal device based on the log data acquired by the acquisition unit, and a database of analysis data indicating an analysis result obtained by the analysis program; and a combining unit that combines the log data acquired by the acquisition unit and the analysis data.
[0005] One aspect of this disclosure can be implemented not only as a terminal operation management system equipped with such characteristic processing units, but also as a semiconductor integrated circuit that implements part or all of the terminal operation management system.
[0006] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Figure 2 is a diagram showing an example of the configuration of a terminal device according to an embodiment of the present disclosure. Figure 3 is a diagram showing an example of the configuration of an analysis server according to an embodiment of the present disclosure. Figure 4 is a diagram showing an example of a database and programs stored in the storage unit of the analysis server according to an embodiment of the present disclosure. Figure 5 is a diagram showing an example of a knowledge database held by the analysis server according to an embodiment of the present disclosure. Figure 6 is a diagram showing another example of a knowledge database held by the analysis server according to an embodiment of the present disclosure. Figure 7 is a diagram showing an example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 8 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 9 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 10 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 11 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 12 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to an embodiment of the present disclosure. Figure 13 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure. Figure 14 is a diagram showing another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure. Figure 15 is a flowchart defining an example of the operation procedure when a terminal device according to the embodiment of this disclosure performs a process to transmit terminal information. Figure 16 is a flowchart defining an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a conversion process. Figure 17 is a flowchart defining an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a status determination process. Figure 18 is a flowchart defining an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a status determination process. Figure 19 is a flowchart defining an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a status determination process.Figure 20 is a flowchart showing an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a merging process. Figure 21 is a flowchart showing an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a display process. Figure 22 is a flowchart showing an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a process to add an analysis module. Figure 23 is a flowchart showing an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a process to delete an analysis module.
[0007] <Problems this disclosure aims to solve> Users such as manufacturers of terminal devices manage the operating status of terminal devices by performing various analyses, such as analyzing the operating status of the terminal devices. For example, in the analysis of terminal devices, various elements related to the terminal device are monitored according to various analysis logics.
[0008] In this context, users may wish to modify the analysis of terminal devices. Specifically, users may wish to add elements to be monitored, update the criteria for determining abnormal terminal device operation, and add analysis logic. A technology is desired that allows for easy modification of the above analysis content and easy understanding of the terminal device's operating status.
[0009] This disclosure was made to solve the above-mentioned problems, and its purpose is to provide a terminal operation management system, a terminal operation management method, and a terminal operation management program that allow for easy modification of the analysis content of terminal devices and easy understanding of the operating status of terminal devices.
[0010] <Effects of this disclosure> According to this disclosure, it is possible to easily change the analysis content of the terminal device and to easily understand the operating status of the terminal device.
[0011] <Outline of Embodiments of the Disclosure> First, the contents of the embodiments of the disclosure will be listed and explained. (1) The terminal operation management system according to the embodiments of the disclosure includes an acquisition unit that acquires log data relating to a terminal device, an analysis program that analyzes the operation of the terminal device based on the log data acquired by the acquisition unit, a modification unit that adds and deletes analysis modules including a database of analysis data showing the analysis results by the analysis program, and a coupling unit that combines the log data acquired by the acquisition unit with the analysis data.
[0012] Thus, the configuration, which allows for the addition and removal of analysis modules, makes it easy to change various elements related to the terminal device that need to be monitored for the analysis of the terminal device's operation, as well as the judgment criteria and analysis logic used in the analysis. Furthermore, by combining log data with the analysis data output by the analysis program of the analysis module, users can easily understand the need for maintenance work and security measures for the terminal device by reviewing the combined data. Therefore, it is possible to easily change the content of the analysis of the terminal device and easily understand the operating status of the terminal device.
[0013] (2) In (1) above, the modification unit may add or delete at least one of the first analysis module, the second analysis module, and the third analysis module, the analysis program of the first analysis module may output the cause of the operation of the terminal device from the knowledge database as analysis data, the analysis program of the second analysis module may output the cause of the operation as analysis data from a trained model generated by machine learning the relationship between the log data and the cause of the operation, and the analysis program of the third analysis module may output the cause of the operation as analysis data from related data which is data different from the log data and shows the result of monitoring or measurement by a device other than the terminal device.
[0014] In this way, by adding or removing the first, second, or third analysis module, the analysis content of the terminal device can be flexibly changed to the analysis content desired by the user. Furthermore, by combining log data with the cause of occurrence output from the analysis program of the analysis module, the user can comprehensively consider the log data and the cause of occurrence to understand the necessity of maintenance work and security measures for the terminal device. In addition, when the first analysis module is added, the cause of occurrence can be easily obtained from a knowledge database that reflects the experience and know-how of experts such as developers who are proficient in log data analysis. When the second analysis module is added, the cause of occurrence can be easily obtained using machine learning methods. When the third analysis module is added, a variety of cause of occurrence can be obtained from various related data such as data on the environment surrounding the terminal device.
[0015] (3) In (1) or (2) above, the modified part may be modified by adding or removing the coupling part for each analysis module.
[0016] This configuration allows for the addition or removal of sets of analysis modules and connectors, making it easy to manage which modules are being added and which are being removed.
[0017] (4) In any of (1) to (3) above, the coupling unit may combine the log data and the analysis data for each analysis module to create visualization data, and the terminal operation management system may further include a display control unit that selects the visualization data to be hidden from among a plurality of visualization data.
[0018] This configuration allows for flexible changes to the displayed visualization data, for example, according to the user's selection, thereby improving user convenience.
[0019] (5) In any of (1) to (4) above, the coupling unit may combine the log data and the analysis data for each analysis module to create visualization data, the coupling unit may store the created visualization data in a separate visualization database for each analysis module, and the terminal operation management system may further include an access restriction unit for each visualization database that restricts access to the visualization database.
[0020] This configuration prevents a user managing one terminal device from unauthorizedly accessing a visualization database that stores visualization data related to terminal devices managed by other users.
[0021] (6) A terminal operation management method according to an embodiment of the present disclosure is a terminal operation management method in a terminal operation management system, comprising the steps of: acquiring log data relating to a terminal device; adding or deleting an analysis module which includes an analysis program that analyzes the operation of the terminal device based on the acquired log data and a database of analysis data showing the analysis results by the analysis program; and combining the acquired log data and the analysis data.
[0022] In this way, by adding or removing analysis modules, various elements related to the terminal device that need to be monitored for the analysis of the terminal device's operation, as well as the judgment criteria and analysis logic used in the analysis, can be easily changed. Furthermore, by combining log data with analysis data output by the analysis program of the analysis module, users can easily understand the need for maintenance work and security measures for the terminal device by reviewing the combined data. Therefore, it is possible to easily change the content of the analysis of the terminal device and easily understand the operating status of the terminal device.
[0023] (7) The terminal operation management program according to the embodiment of the present disclosure is a terminal operation management program used in a terminal operation management system, and is a program that causes a computer to function as an acquisition unit that acquires log data relating to a terminal device, an analysis program that analyzes the operation of the terminal device based on the log data acquired by the acquisition unit, a modification unit that adds and deletes analysis modules including a database of analysis data showing the analysis results by the analysis program, and a coupling unit that combines the log data acquired by the acquisition unit and the analysis data.
[0024] Thus, the configuration, which allows for the addition and removal of analysis modules, makes it easy to change various elements related to the terminal device that need to be monitored for the analysis of the terminal device's operation, as well as the judgment criteria and analysis logic used in the analysis. Furthermore, by combining log data with the analysis data output by the analysis program of the analysis module, users can easily understand the need for maintenance work and security measures for the terminal device by reviewing the combined data. Therefore, it is possible to easily change the content of the analysis of the terminal device and easily understand the operating status of the terminal device.
[0025] <Details of Embodiments in This Disclosure> Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.
[0026] [Communication System] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Referring to Figure 1, the communication system 501 comprises one or more terminal devices 101, an analysis server 151, and a user terminal 301. The analysis server 151 is an example of a terminal operation management system.
[0027] In the example shown in Figure 1, the communication system 501 includes multiple terminal devices 101, namely terminal devices 101A and 101B.
[0028] Each terminal device 101 belongs to a certain system S. Specifically, the system S to which each terminal device 101 belongs includes mobile objects such as vehicles, equipment such as chargers and generators, factories, and plants.
[0029] The terminal device 101 includes a smartphone, an ECU (Electronic Control Unit), and various sensors.
[0030] The user terminal 301 is, for example, a device owned by the manufacturer of the terminal device 101, or by an individual (hereinafter collectively referred to as the user). The user terminal 301 is a communication terminal device such as a notebook PC (Personal Computer).
[0031] The user terminal 301 and the analysis server 151 transmit and receive information via an external network 171, such as the Internet.
[0032] The analysis server 151 collects log data from the terminal device 101 and uses the collected log data to analyze the operating status of the terminal device 101. The analysis server 151 then displays the analysis results on a display unit such as a monitor on the user terminal 301.
[0033] [Terminal Device] Figure 2 is a diagram showing an example of the configuration of a terminal device according to an embodiment of the present disclosure. Referring to Figure 2, the terminal device 101 comprises a communication unit 11, a log creation unit 12, a collection unit 13, and a storage unit 14. Some or all of the communication unit 11, the log creation unit 12, and the collection unit 13 are implemented by a processing circuit (Circuitry) including one or more processors. The storage unit 14 is, for example, a non-volatile memory included in the processing circuit.
[0034] (Creation and transmission of log data) The log creation unit 12 performs log creation processing to create log data about its own terminal device 101, for example, periodically. More specifically, the log creation unit 12 monitors the operation of its own terminal device 101 each time the processing timing T11 of the log creation process arrives.
[0035] The log creation unit 12 then creates log data including the monitoring time and monitoring results and saves it to the storage unit 14.
[0036] Hereafter, log data when monitoring results are normal will also be referred to as normal logs. Log data when monitoring results are abnormal will also be referred to as error logs.
[0037] A normal log includes the keyword Kn. The keyword Kn indicates the details of the operation of the terminal device 101 under normal conditions, and identification information (hereinafter also referred to as "event ID") for identifying events related to the terminal device 101.
[0038] The error log includes, for example, the number of abnormalities that occurred during the period from the previous processing timing T11 to the current processing timing T11 (hereinafter also referred to as "error occurrence count N") and the keyword Ke. The keyword Ke indicates the event ID and the type of abnormality in the terminal device 101, etc.
[0039] The collection unit 13 performs log collection processing to collect log data to be sent to the analysis server 151. More specifically, when the processing timing T12 for the log collection processing arrives, the collection unit 13 retrieves multiple log data (hereinafter also referred to as the "log data group") that have been stored in the storage unit 14 by the log creation unit 12 during the period from the previous processing timing T12 to the current processing timing T12. The collection unit 13 then outputs the retrieved log data group to the communication unit 11.
[0040] For example, the storage unit 14 stores identification information for identifying its own terminal device 101 (hereinafter also referred to as "terminal ID"), identification information for identifying the type of system S to which the terminal device 101 belongs (hereinafter also referred to as "system ID"), and destination information indicating the destination of the terminal device 101.
[0041] The communication unit 11 transmits the log data collected by the collection unit 13 to the analysis server 151.
[0042] More specifically, the communication unit 11 communicates with the analysis server 151 via the external network 171 by wirelessly communicating with the wireless base station equipment according to a communication method such as Wi-Fi (registered trademark), LTE (Long Term Evolution) (registered trademark), or 5G.
[0043] Specifically, the communication unit 11 transmits, to the analysis server 151, the log data group received from the collection unit 13 and the terminal information including a terminal ID, a system ID, and destination information stored in the storage unit 14.
[0044] [Analysis Server] FIG. 3 is a diagram illustrating an example configuration of the analysis server according to an embodiment of the present disclosure. Referring to FIG. 3, the analysis server 151 includes a communication unit 21, a processing unit 22, and a storage unit 23. The processing unit 22 includes a format conversion unit 31, an analysis unit 32, a plurality of coupling units 33, an access restriction unit 34, a display control unit 35, and a change unit 36. One or both of the communication unit 21 and the processing unit 22 is / are implemented, for example, by a processing circuit including one or more processors. The storage unit 23 is, for example, a non-volatile memory included in the processing circuit. The communication unit 21 is an example of an obtaining unit.
[0045] (Obtaining Log Data) The communication unit 21 obtains log data related to the terminal device 101. More specifically, for example, the communication unit 21 obtains log data from each of a plurality of terminal devices 101.
[0046] Specifically, the communication unit 21 receives terminal information including a log data group from each terminal device 101 via an external network 171. The communication unit 21 outputs the received terminal information to the format conversion unit 31.
[0047] FIG. 4 is a diagram illustrating an example of a database and programs stored in a storage unit of the analysis server according to an embodiment of the present disclosure.
[0048] Referring to FIG. 4, for example, the storage unit 23 stores a plurality of log databases 40. The log database 40 is provided for each type of system S to which the terminal device 101 belongs. Specifically, the storage unit 23 stores the log database 40 for each system ID of the system S.
[0049] (Format Conversion) Referring again to FIG. 3, for example, the format conversion unit 31 performs conversion processing that converts log data of each of the plurality of terminal devices 101 belonging to mutually different systems S into a common format.
[0050] More specifically, the format conversion unit 31 performs conversion processing on each log data in the log data group included in the terminal information received from the communication unit 21. Specifically, in the conversion process, the format conversion unit 31 performs tasks such as imputing missing values and standardizing inconsistencies in notation in the log data.
[0051] Referring to Figures 3 and 4, once the format conversion unit 31 completes the conversion process, it creates analysis log information that includes each log data after the conversion process, as well as the terminal ID, system ID, and destination information contained in the terminal information received from the communication unit 21. The format conversion unit 31 then saves the created analysis log information to the log database 40 corresponding to the system ID contained in the analysis log information.
[0052] (Determination of the operating status of terminal device 101) The analysis unit 32 performs a status determination process to determine the operating status of terminal device 101 based on the log data acquired by the communication unit 21.
[0053] More specifically, when the processing timing T21 for the status determination process arrives, the analysis unit 32 performs a status determination process for each log database 40 in the storage unit 23 using multiple analysis log information stored in the log database 40.
[0054] Specifically, the analysis unit 32 acquires multiple log information for analysis stored in each log database 40 by the format conversion unit 31 during the period E1 from the previous processing timing T21 to the current processing timing T21. The period E1 is, for example, half a day.
[0055] The analysis unit 32 then uses the acquired analysis log information to determine the operating status of the terminal device 101 at predetermined intervals during period E1. For example, the analysis unit 32 determines the operating status of the terminal device 101 at one-hour intervals during period E1. Hereinafter, each of the multiple time points to be determined during period E1 will also be referred to as the time point to be determined.
[0056] The analysis unit 32 determines the operating status of the terminal device 101 for each time period to be determined. The analysis unit 32 determines that the terminal device 101 was not operating at time ta1 if the log data for the monitoring time (hereinafter also referred to as "monitoring time tk") during the period between a certain time period to be determined ta1 and a time period to be determined ta2 one hour later from time ta1 is not included in any of the acquired log information for analysis.
[0057] Furthermore, if the analysis unit 32 finds that the log data containing an error log at the monitoring time tk is included in the acquired analysis log information, it determines that the operating status of the terminal device 101 at the time of determination ta1 is abnormal. On the other hand, if the analysis unit 32 finds that the log data containing an error log at the monitoring time tk is not included in the acquired analysis log information, it determines that the operating status is normal.
[0058] When the analysis unit 32 completes the status determination process, it creates operational determination information for each log database 40, including the determination result for each target time and the system ID and destination information included in the acquired analysis log information. If the analysis unit 32 determines that the operational status of the terminal device 101 is abnormal at one or more target time ta1, it includes the keyword Ke from the error log at the monitoring time tk corresponding to the target time ta1 in the created operational determination information. If the analysis unit 32 determines that the operational status of the terminal device 101 is normal at each target time, it includes the keyword Kn from the normal log at each of the multiple monitoring times tk corresponding to each of the multiple target time periods in the created operational determination information.
[0059] Furthermore, the analysis unit 32 is not limited to a configuration that determines the operating status is abnormal if the acquired analysis log information includes error logs; it may also be configured to determine the operating status is abnormal if the log data satisfies other conditions.
[0060] Specifically, the analysis unit 32 may be configured to determine that the operating status is abnormal if some of the log data that should be acquired periodically is not included in the log information for analysis, or if multiple types of log data are not acquired in a pre-set order.
[0061] Furthermore, the analysis unit 32 may be configured to determine that the operating status is abnormal if the number of specific log data included in the analysis log information is greater than or equal to a threshold, or if the log data that should be acquired during a predetermined operation of the terminal device 101 is not included in the analysis log information.
[0062] Furthermore, the analysis unit 32 may be configured to create a distribution of log data according to statistical methods such as regression models and PCA (Principal Component Analysis), and to determine that the operating status is abnormal if outliers are included in the distribution. Alternatively, the analysis unit 32 may be configured to determine that the operating status is abnormal if log data indicating a predetermined operation is included in the analysis log information. This predetermined operation is, for example, an operation different from the operation assumed during the design of the terminal device 101.
[0063] (Analysis of the operation of terminal device 101) For example, the analysis unit 32 performs analysis processing to analyze the operation of terminal device 101. More specifically, the analysis unit 32 performs the process of obtaining the cause H of the operation of terminal device 101 as part of the analysis processing.
[0064] Specifically, the analysis unit 32 acquires the cause of the malfunction in the terminal device 101 as the cause H.
[0065] For example, the storage unit 23 stores multiple analysis modules 50. Each analysis module 50 includes an analysis program 51 and an analysis database 52. The analysis program 51 is a program that analyzes the operation of the terminal device 101 based on log data acquired by the communication unit 21. The analysis database 52 is a database of analysis data that shows the data output by the analysis program 51, i.e., the analysis results by the analysis program 51.
[0066] In the example shown in Figure 4, the storage unit 23 stores multiple analysis modules 50, namely analysis modules 50A, 50B, and 50C. Analysis modules 50A, 50B, and 50C are examples of the first, second, and third analysis modules, respectively.
[0067] The analysis modules 50A, 50B, and 50C each include analysis programs 51A, 51B, and 51C, which are analysis programs 51, and analysis databases 52A, 52B, and 52C, which are analysis databases 52. Analysis databases 52A, 52B, and 52C correspond to analysis programs 51A, 51B, and 51C, respectively.
[0068] For example, analysis program 51A is a program that outputs the cause H of the operation of the terminal device 101 as analysis data from the knowledge database 81.
[0069] For example, the analysis program 51B is a program that outputs the cause H of the operation of the terminal device 101 as analysis data from a trained model M generated by machine learning the relationship between log data and the cause H of occurrence.
[0070] For example, the analysis program 51C is a program that outputs the cause of occurrence H as analysis data from related data (hereinafter also referred to as "related data") which is separate from the log data of the terminal device 101 and shows the results of monitoring or measurement by a device other than the terminal device 101.
[0071] For example, each analysis program 51 is a program for detecting abnormalities in the operation of the terminal device 101. The analysis data output by the analysis program 51 indicates the cause H of the abnormality.
[0072] For example, the memory unit 23 stores an analysis module 50 for each type of abnormality in the terminal device 101. Hereinafter, abnormalities corresponding to the cause H output by the analysis program 51A of analysis module 50A, abnormalities corresponding to the cause H output by the analysis program 51B of analysis module 50B, and abnormalities corresponding to the cause H output by the analysis program 51C of analysis module 50C will also be referred to as "abnormality 1," "abnormality 2," and "abnormality 3," respectively.
[0073] <Example 1> If the operating status of terminal device 101 is determined to be abnormal, the analysis unit 32 analyzes the cause H of occurrence according to the type of abnormality corresponding to the keyword Ke in the error log if the created operating determination information contains the keyword Ke.
[0074] For example, if the analysis unit 32 determines in the status determination process that the operating status of the terminal device 101 is abnormal at one or more determination target time ta1, it obtains the cause H for each determination target time ta1. Hereinafter, the determination target time ta1 at which the operating status of the terminal device 101 is determined to be abnormal will also be referred to as the determination target time te.
[0075] (a1) Knowledge database For example, the storage unit 23 stores multiple knowledge databases 81. A knowledge database 81 exists for each type of system S to which the terminal device 101 belongs. Specifically, the storage unit 23 stores a knowledge database 81 for each system ID of system S.
[0076] If the created operational judgment information contains the keyword Ke (hereinafter also referred to as "keyword Ke1") corresponding to "abnormality 1", the analysis unit 32 executes the analysis program 51A to obtain the cause of occurrence H from the knowledge database 81. Hereinafter, the cause of occurrence H obtained by the analysis unit 32 from the knowledge database 81 will also be referred to as cause of occurrence H1.
[0077] Figure 5 shows an example of a knowledge database held by an analysis server according to an embodiment of the present disclosure. Figure 6 shows another example of a knowledge database held by an analysis server according to an embodiment of the present disclosure.
[0078] Referring to Figures 5 and 6, for example, the knowledge database 81 includes the cause H1 of the operation of the terminal device 101, based on past failure records of the terminal device 101.
[0079] More specifically, for example, the knowledge database 81 includes the correspondence between keyword Ke1, the threshold Th for the number of occurrences of events related to terminal device 101, and the cause H1 of the occurrence.
[0080] The keyword Ke1 registered in the knowledge database 81 shown in Figure 5 is the event ID. The keyword Ke1 registered in the knowledge database 81 shown in Figure 6 is the type of abnormality in the terminal device 101.
[0081] In the example shown in Figure 5, if the event with event ID "1111111" occurs 10 or more times within a predetermined period, the cause H1 is "communication abnormality from board A to board B".
[0082] In the example shown in Figure 6, if the number of times the "file open error" error occurs within a predetermined period is "20 times" or more, the cause H1 is "communication error on board B". If the number of times the "update filed" error occurs within a predetermined period is "1 time" or more, the cause H1 is "failure to update the software incorporated in terminal device 101".
[0083] Referring again to Figure 3, for example, the analysis unit 32 obtains the cause of occurrence H1 from the knowledge database 81 (hereinafter also referred to as the "corresponding knowledge database") corresponding to the type of system S to which the terminal device 101 being analyzed belongs.
[0084] Specifically, the analysis unit 32 checks, by referring to the corresponding knowledge database, whether the number of errors N included in the error log at a certain target time te is greater than or equal to the threshold Th corresponding to the keyword Ke1 included in the error log.
[0085] The analysis unit 32 retrieves the cause of occurrence H1 corresponding to keyword Ke1 from the corresponding knowledge database if the number of error occurrences N is greater than or equal to the threshold Th.
[0086] The analysis unit 32 then stores the created operational judgment information, including the pair K1 of the acquired occurrence reason H1 and the judgment target time te corresponding to the occurrence reason H1, in the analysis database 52A.
[0087] On the other hand, if the number of error occurrences N is less than the threshold Th, the analysis unit 32 does not retrieve the cause of occurrence H1 from the corresponding knowledge database. Then, the analysis unit 32 saves the created operational judgment information to the analysis database 52A.
[0088] (a2) Trained model For example, the memory unit 23 stores a trained model M. The trained model M outputs the cause H when a keyword included in the log data is input. As an example, the trained model M is a generating AI.
[0089] If the created operation judgment information contains the keyword Ke (hereinafter also referred to as "keyword Ke2") corresponding to "abnormality 2", the analysis unit 32 executes the analysis program 51B to obtain the cause of occurrence H from the trained model M. Hereinafter, the cause of occurrence H obtained by the analysis unit 32 from the trained model M will also be referred to as cause of occurrence H2.
[0090] Specifically, the analysis unit 32 inputs the keyword Ke2 to the trained model M for each time point te corresponding to the keyword Ke2. Then, the analysis unit 32 obtains the cause H2 output from the trained model M.
[0091] When the analysis unit 32 obtains the cause of occurrence H2, it saves the created operation judgment information, including the pair K2 of the obtained cause of occurrence H2 and the judgment target time te corresponding to the cause of occurrence H2, in the analysis database 52B.
[0092] Furthermore, the configuration is not limited to the storage unit 23 of the analysis server 151 storing the trained model M; the storage unit of another device other than the analysis server 151 may also store the trained model M. In this case, for example, the analysis server 151 and the other device exchange various types of information, such as analysis log information and information indicating the cause of occurrence H, using an API (Application Programming Interface).
[0093] (a3) Related data Related data includes environmental data relating to the environment at the installation location of the terminal device 101, communication log data relating to the communication of the terminal device 101, and user data relating to the user of the terminal device 101.
[0094] Environmental data indicates the temperature, humidity, and atmospheric pressure at the installation location of the terminal device 101. Communication log data indicates whether the terminal device 101 is communicating with a device with a specific IP address. User data indicates whether there are users at the installation location of the terminal device 101.
[0095] If the created operation judgment information contains the keyword Ke (hereinafter also referred to as "keyword Ke3") corresponding to "abnormality 3", the analysis unit 32 executes the analysis program 51C to obtain the cause of occurrence H from the related data. Hereinafter, the cause of occurrence H obtained by the analysis unit 32 from the related data will also be referred to as cause of occurrence H3.
[0096] For example, the storage unit 23 stores multiple databases of related data (hereinafter also referred to as "related databases 91"). A related database 91 exists for each system S to which the terminal device 101 belongs. Specifically, the storage unit 23 stores a related database 91 for each system ID of the system S to which the terminal device 101 belongs.
[0097] For example, the analysis unit 32 obtains the cause of occurrence H3 from the related database 91 (hereinafter also referred to as the "corresponding related database") which corresponds to the type of system S to which the terminal device 101 being analyzed belongs.
[0098] Specifically, the analysis unit 32 obtains relevant data from the corresponding related database for each target time te corresponding to the keyword Ke3, where the time difference from the target time te is less than a threshold. Then, the analysis unit 32 obtains the occurrence reason H3 based on the keyword Ke3 corresponding to the target time te and the obtained related data.
[0099] For example, if keyword Ke3 indicates an event ID, and the acquired related data is environmental data showing the temperature at the installation location of terminal device 101, and that temperature is above a standard value, then occurrence reason H3 indicates that the temperature at the installation location is abnormal.
[0100] Furthermore, for example, if keyword Ke3 indicates a certain event ID and the acquired related data is communication log data indicating that the terminal device is communicating with a device with a specific IP address, then occurrence H3 indicates that the terminal device 101 may be infected with malware.
[0101] Furthermore, for example, if keyword Ke3 indicates a function that is executed when a user is present at the installation location of terminal device 101, and the acquired related data is user data indicating that a user is not present at the installation location, then occurrence H3 indicates an abnormality in the user detection function of terminal device 101.
[0102] The analysis unit 32 stores the created operational judgment information, including the pair K3 of the acquired occurrence reason H3 and the judgment target time te corresponding to the occurrence reason H3, in the analysis database 52C.
[0103] <Example 2> When it is determined that the operating status of the terminal device 101 is normal, the analysis unit 32 determines whether or not there is an abnormality in the operation of the terminal device 101 if it determines that the operating status at each target time is normal.
[0104] For example, in the status determination process, if the analysis unit 32 determines that the operating status of the terminal device 101 at each target time ta1 is normal, it obtains relevant data from the corresponding related database for each target time ta1 at times when the time difference with that target time ta1 is less than a threshold.
[0105] Then, for each time ta1 to be determined, the analysis unit 32 determines whether or not there is an abnormality in the operation of the terminal device 101 at that time ta1, based on the keyword Kn corresponding to that time ta1 and the acquired related data.
[0106] If the analysis unit 32 determines that the operation of the terminal device 101 is abnormal at a certain target time ta1, it obtains the cause of occurrence H3 based on the keyword Kn and related data corresponding to the target time ta1, similar to the process of obtaining the cause of occurrence H3 based on the keyword Ke and related data.
[0107] The analysis unit 32 stores the created operational judgment information, including the pair K4 of the acquired occurrence reason H3 and the judgment target time ta1 corresponding to the occurrence reason H3, in the analysis database 52C. The analysis unit 32 may be configured not to determine whether there is an abnormality in the operation of the terminal device 101 if the operational status at each judgment target time is normal.
[0108] The analysis unit 32 performs a collection process to collect the results of the status determination process and analysis process performed during a predetermined period, that is, the operational determination information stored in each analysis database 52 during that period.
[0109] More specifically, when the data collection processing timing T31 arrives, the analysis unit 32 acquires multiple operational judgment information stored in each analysis database 52 for each terminal device 101 during the period E2 from the previous processing timing T31 to the current processing timing T31. Period E2 is, for example, a longer period than period E1.
[0110] For example, the storage unit 23 stores a visualization database 70 for storing operational judgment information used to display the results of the status determination processing by the analysis unit 32 on the user terminal 301. The analysis unit 32 stores multiple acquired operational judgment information in the visualization database 70.
[0111] (Combination Unit) Each combination unit 33 performs a combination process P that combines the log data acquired by the communication unit 21 with the analysis data output by the analysis program 51.
[0112] In the example shown in Figure 3, the analysis server 151 includes multiple coupling units 33A, 33B, and 33C. Hereinafter, the coupling processes P performed by coupling unit 33A, coupling process P performed by coupling unit 33B, and coupling process P performed by coupling unit 33C will also be referred to as coupling process P1, coupling process P2, and coupling process P3, respectively.
[0113] When the processing timing T41 of the coupling process P arrives, each coupling unit 33 retrieves multiple analysis log pieces stored in the log database 40 by the communication unit 21 for each terminal device 101 during the period E3 from the previous processing timing T41 to the current processing timing T41. The period E3 is, for example, one day.
[0114] When each coupling unit 33 acquires multiple analysis log information, it acquires multiple operation determination information corresponding to each of the multiple analysis log information from the analysis database 52.
[0115] (b1) Combination process P1 The combination unit 33A performs a process called combination process P1, which combines the log data acquired by the communication unit 21 with the cause of occurrence H1 acquired from the knowledge database 81 to create visualization data Q1.
[0116] For example, the storage unit 23 stores a combination program 60A, which is a combination program 60 for combining log data with the cause of occurrence H1 obtained from the knowledge database 81. The combination unit 33A performs the combination process P1 by executing the combination program 60A.
[0117] The coupling unit 33A performs coupling processing P1 for each terminal device 101 using the acquired multiple analysis log information and multiple operation determination information.
[0118] Specifically, for example, the coupling unit 33A checks whether, for each piece of analysis log information acquired, the operation determination information corresponding to that analysis log information contains at least one of the occurrence events H1.
[0119] Then, if the operation determination information corresponding to the acquired analysis log information includes at least one occurrence reason H1, the coupling unit 33A creates visualization data Q1 by associating the log data at the monitoring time corresponding to the occurrence reason H1 with the occurrence reason H1.
[0120] On the other hand, the coupling unit 33A does not create visualization data Q1 if the occurrence reason H1 is not included in the operation determination information corresponding to the acquired analysis log information.
[0121] (b2) Combination process P2 The combination unit 33B performs a process called combination process P2, which combines the log data acquired by the communication unit 21 with the cause of occurrence H2 acquired from the trained model M to create visualization data Q2.
[0122] For example, the storage unit 23 stores a coupling program 60B, which is a coupling program 60 for combining log data with the cause of occurrence H2 obtained from the trained model M. The coupling unit 33B performs the coupling process P2 by executing the coupling program 60B.
[0123] The coupling unit 33B performs coupling processing P2 for each terminal device 101 using the acquired multiple analysis log information and multiple operation determination information.
[0124] Specifically, for example, the coupling unit 33B checks whether, for each piece of analysis log information acquired, the operation determination information corresponding to that analysis log information contains at least one of the occurrence events H2.
[0125] Then, if the operation determination information corresponding to the acquired analysis log information includes at least one occurrence reason H2, the coupling unit 33B creates visualization data Q2 by associating the log data at the monitoring time corresponding to the occurrence reason H2 with the occurrence reason H2.
[0126] On the other hand, the coupling unit 33B does not create visualization data Q2 if the operation determination information corresponding to the acquired analysis log information does not include the cause of occurrence H2.
[0127] (b3) Combination process P3 The combination unit 33C performs a process called combination process P3, which combines the log data acquired by the communication unit 21 with the cause of occurrence H3 acquired from related data to create visualization data Q3.
[0128] For example, the storage unit 23 stores a combining program 60C, which is a combining program 60 for combining log data and the cause of occurrence H3 obtained from related data. The combining unit 33C performs the combining process P3 by executing the combining program 60C.
[0129] The coupling unit 33C performs coupling processing P3 for each terminal device 101 using the acquired multiple analysis log information and multiple operation determination information.
[0130] Specifically, for example, the coupling unit 33C checks whether, for each piece of analysis log information acquired, the operation determination information corresponding to that analysis log information contains at least one of the occurrence events H3.
[0131] Then, if the operation determination information corresponding to the acquired analysis log information includes at least one occurrence reason H3, the coupling unit 33C creates visualization data Q3 by associating the log data at the monitoring time corresponding to occurrence reason H3 with the occurrence reason H3.
[0132] On the other hand, the coupling unit 33C does not create visualization data Q3 if the operation determination information corresponding to the acquired analysis log information does not include the cause of occurrence H3.
[0133] For example, the storage unit 23 stores multiple visualization databases 71 for saving the results of the merging process P.
[0134] More specifically, the storage unit 23 stores a visualization database 71 for each connecting unit 33.
[0135] In the example shown in Figure 4, the storage unit 23 stores multiple visualization databases 71, namely visualization databases 71A, 71B, and 71C. Visualization databases 71A, 71B, and 71C correspond to the connecting units 33A, 33B, and 33C, respectively.
[0136] For example, each connecting unit 33 saves the created visualization data to a separate visualization database 71 for each analysis module 50. More specifically, each connecting unit 33 stores the created visualization data in the visualization database 71 corresponding to that visualization data. Then, each connecting unit 33 outputs a connection completion notification to the access restriction unit 34 indicating that the connection process P has been completed and the location of the visualization database 71 where the visualization data is saved.
[0137] (Access restriction unit) For example, the access restriction unit 34 performs access restriction processing to restrict access to each visualization database 71.
[0138] More specifically, when the access restriction unit 34 receives a connection completion notification from a connection unit 33, it creates authentication information F to authenticate access to the visualization database 71 indicated in the connection completion notification, and transmits it to the user terminal 301 via the communication unit 21 and the external network 171. The authentication information F consists of a certificate and a private key, etc.
[0139] (Display Control Unit) Referring again to Figures 1 and 3, for example, the display control unit 35 displays a screen G1 on the user terminal 301 that prompts the user to input user request information.
[0140] User request information includes, for example, the terminal ID of one or more terminal devices 101 on which the user wishes to display the analysis results from the analysis server 151, the period for which the analysis results are to be displayed (hereinafter also referred to as "display period C"), and the width of the time period for which the analysis results are to be displayed (hereinafter also referred to as "time period width W"). Display period C is, for example, a period of one hour or more.
[0141] More specifically, the storage unit 23 stores screen information B1 that represents screen G1. When its analysis server 151 is started and, for example, a predetermined operation is performed by the user, the display control unit 35 retrieves the screen information B1 from the storage unit 23. The display control unit 35 then outputs the retrieved screen information B1 to the communication unit 21.
[0142] The communication unit 21 transmits the screen information B1 received from the display control unit 35 to the user terminal 301 via the external network 171.
[0143] The user terminal 301 renders screen G1 on the web browser displayed on its own display unit, based on screen information B1 received from the analysis server 151.
[0144] While screen G1 is displayed on user terminal 301, the user performs an operation to input one or more terminal IDs, display target period C, and time range W. Here, it is assumed that the user performed an operation to input multiple terminal IDs.
[0145] The user terminal 301 transmits user request information, which includes multiple terminal IDs, the display target period C, and the time range W, to the analysis server 151 via the external network 171.
[0146] In the analysis server 151, when the display control unit 35 receives user request information from the user terminal 301 via the external network 171 and the communication unit 21, it performs a display process V1 that displays a screen G2 showing the result of the status determination process by the analysis unit 32. For example, the display control unit 35 performs the display process V1 by executing the visualization program 72 shown in Figure 4.
[0147] Specifically, the display control unit 35 obtains operational determination information for the display target period C indicated by the user request information received from the user terminal 301, for each terminal ID indicated by the user request information, from the visualization database 70. Then, the display control unit 35 uses the multiple operational determination pieces of information obtained to create screen information B2 that shows screen G2.
[0148] The display control unit 35 transmits the created screen information B2 to the user terminal 301 via the communication unit 21 and the external network 171.
[0149] The user terminal 301 renders screen G2 on the web browser displayed on itself, based on screen information B2 received from the analysis server 151.
[0150] Figure 7 shows an example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0151] Referring to Figure 7, screen G2 includes areas R1 and R2. Area R1 shows the history of the determination results of the operating status of each terminal device 101 during the display target period C.
[0152] In the example shown in Figure 7, region R1 shows the destination of each terminal device 101 and the determination results of the operating status of each terminal device 101 every hour during the period from 0:00 to 13:00 on January 1, 2024.
[0153] For example, the display control unit 35 changes the display pattern for the portion of the time period corresponding to the operating status of the terminal device 101, depending on the type of operating status of that device.
[0154] Specifically, for example, the display control unit 35 fills in green with a determination result indicating that the operating status is normal, fills in red with a determination result indicating that the operating status is abnormal, and displays no determination result indicating that the operating status is not operational. In Figure 7, green fills are indicated by diagonal hatching lines, and red fills are indicated by black fills.
[0155] (Adding and removing analysis modules) Area R2 includes a button Bt1 for selecting the results of an analysis process to add to screen G2, or a button Bt2 for selecting the results of an analysis process to remove from screen G2.
[0156] In the example shown in Figure 7, region R2 includes button Bt11, which is button Bt1 for adding the results of the analysis process for "anomaly 1", button Bt12, which is button Bt1 for adding the results of the analysis process for "anomaly 2", and button Bt13, which is button Bt1 for adding the analysis process for "anomaly 3".
[0157] When the user terminal 301 is displaying screen G2 on its display unit and the user presses button Bt1, it sends operation information D1, which indicates the operation content and the display period C on screen G2, to the analysis server 151 via the external network 171. Specifically, for example, the user terminal 301 sends the operation information D1 to the analysis server 151, including authentication information F corresponding to the button Bt1.
[0158] In the example shown in Figure 7, assume that the user moves the pointer Pt on screen G2 and presses button Bt11.
[0159] Referring again to Figure 3, in the analysis server 151, the communication unit 21 outputs the operation information D1 received from the user terminal 301 via the external network 171 to the modification unit 36.
[0160] The modification unit 36 adds and removes analysis modules 50 as functions to be provided to a particular user. More specifically, the modification unit 36 adds or removes at least one of analysis modules 50A, 50B, and 50C.
[0161] (c1) Addition of analysis module 50 Specifically, the modification unit 36 uses the authentication information F contained in the operation information D1 received from the communication unit 21 to perform authentication processing on the user terminal 301 that sent the operation information D1.
[0162] If the authentication process fails, the modification unit 36 sends authentication failure information indicating that the authentication process failed to the user terminal 301 via the communication unit 21 and the external network 171.
[0163] The user terminal 301 performs notification processing based on authentication failure information received from the analysis server 151. Specifically, for example, the user terminal 301 displays a screen on its own display unit indicating that the authentication process on the analysis server 151 has failed.
[0164] On the other hand, if the authentication process is successful, the modification unit 36 adds an analysis module 50 according to the operation content indicated by the operation information D1 received from the communication unit 21.
[0165] Specifically, the modification unit 36 outputs display request information U1 to the display control unit 35, which indicates an analysis module 50 corresponding to the operation content indicated by the operation information D1 received from the communication unit 21, a request to display the results of the analysis processing using the analysis module 50, and the display target period C indicated by the operation information D1.
[0166] As described above, in the example shown in Figure 7, the operation information D1 transmitted from the user terminal 301 indicates that the user performed the operation of pressing button Bt11. In this case, the modification unit 36 outputs display request information U1 to the display control unit 35, indicating a request for the display of the analysis module 50A corresponding to the operation, a request for the display of the results of the analysis processing using the analysis module 50A, and the display target period C indicated by the operation information D1.
[0167] The display control unit 35 checks whether the visualization data Q1 for the display target period C indicated by the display request information U1 received from the modification unit 36 is stored in the visualization database 71A.
[0168] Figure 8 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0169] Referring to Figure 8, the display control unit 35 performs a display process V2 to display screen G3 on the user terminal 301 if the visualization data Q1 for the display target period C indicated by the display request information U1 received from the modification unit 36 is stored in the visualization database 71A.
[0170] More specifically, in the display process V2, the display control unit 35 performs the process of displaying analysis completion information J1, which indicates that the cause H1 of the operation of the terminal device 101 has been analyzed, superimposed on the judgment result for the time period including the judgment target time te corresponding to the cause H1. For example, the display control unit 35 performs the display process V2 by executing the visualization program 72 shown in Figure 4.
[0171] In the example shown in Figure 8, the text Y1, which indicates that the cause of occurrence H1 has been analyzed, is displayed on screen G3 as analysis completion information J1. Specifically, the text Y1 is displayed superimposed on the judgment result for the time period from 11:00 to 12:00 on January 1, 2024, where the operating status of terminal device 101 with terminal ID "00001" was "abnormal 1".
[0172] Furthermore, in screen G3, compared to screen G2 shown in Figure 7, button Bt21, which is button Bt2 for deleting the result of the analysis process for "Anomaly 1," is displayed instead of button Bt11.
[0173] The display control unit 35 creates screen information B3 indicating screen G3 if the visualization data Q1 for the display target period C indicated by the display request information U1 received from the modification unit 36 is stored in the visualization database 71A.
[0174] The display control unit 35 transmits the created screen information B3 to the user terminal 301 via the communication unit 21 and the external network 171.
[0175] The user terminal 301 draws screen G3 on the web browser displayed on itself, based on screen information B3 received from the analysis server 151.
[0176] When the user terminal 301 is displaying screen G3 on its display unit and the user performs an operation to specify a judgment result on which analysis completion information J1 is superimposed, the user terminal 301 transmits operation information D2 indicating the content of the operation to the analysis server 151 via the external network 171.
[0177] Specifically, for example, suppose the user performs an operation on screen G3 where the pointer Pt is moved to a position that overlaps with the text Y1 that says "Analysis Available".
[0178] In this case, the user terminal 301 sends to the analysis server 151 operation information D2, which includes analysis completion information J1 selected by the pointer Pt, and information indicating the terminal ID and time zone corresponding to the analysis completion information J1.
[0179] Referring again to Figures 3 and 4, in the analysis server 151, for example, the modification unit 36 adds and deletes the coupling unit 33 for each analysis module 50.
[0180] More specifically, the modification unit 36 obtains visualization data Q1 corresponding to the operation information D2 received from the user terminal 301 via the external network 171 and the communication unit 21 from the visualization database 71A. Specifically, the modification unit 36 obtains visualization data Q1 corresponding to the analysis completion information J1 included in the operation information D2 from the visualization database 71A. The modification unit 36 then outputs the obtained visualization data Q1 to the display control unit 35.
[0181] Figure 9 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0182] Referring to Figures 3 and 9, the display control unit 35 performs a display process V3 that displays a screen G4 including an explanation field L1 on the user terminal 301 based on the visualization data Q1 received from the modification unit 36. The explanation field L1 shows multiple log data and one or more occurrence reasons H1 included in the time period corresponding to the analysis completion information J1 selected by the pointer Pt.
[0183] For example, the display control unit 35 performs display processing V3 by executing the visualization program 72 shown in Figure 4. Specifically, the display control unit 35 creates screen information B4 showing screen G4 based on the visualization data Q1 received from the modification unit 36, and the display control unit 35 transmits the screen information B4 to the user terminal 301 via the communication unit 21 and the external network 171.
[0184] The user terminal 301 renders screen G4 on the web browser displayed on itself, based on screen information B4 received from the analysis server 151.
[0185] Figure 10 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0186] Referring to Figures 3 and 10, when the user presses button Bt12 while screen G3 is displayed on the display unit of the user terminal 301, the analysis server 151 performs a display process V4, similar to the display process V2, to display screen G5 on the user terminal 301.
[0187] On screen G5, compared to screen G3 shown in Figure 8, analysis completion information J2, indicating that the cause H2 of the operation of the terminal device 101 has been analyzed, is displayed superimposed on the determination result of the operating status for the time period including the determination target time te corresponding to the visualization data Q2.
[0188] In the example shown in Figure 10, the text Y2, which indicates that the cause of occurrence H2 has been analyzed, is displayed on screen G5 as analysis completion information J2. Specifically, the text Y2 is displayed superimposed on the judgment result for the time period from 9:00 to 10:00 on January 1, 2024, indicating that the operating status of terminal device 101 with terminal ID "00006" is abnormal.
[0189] Furthermore, in screen G5, compared to screen G3 shown in Figure 8, button Bt22, which is button Bt2 for deleting the result of the "Anomaly 2" analysis process, is displayed instead of button Bt12.
[0190] Figure 11 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0191] Referring to Figures 3 and 11, when the user performs an operation to specify analysis completion information J2 while screen G5 is displayed on the display unit of the user terminal 301, the analysis server 151 performs a display process V5, similar to display process V3, to display screen G6, which includes an explanation field L2, on the user terminal 301. The explanation field L2 shows multiple log data and one or more occurrence reasons H2 included in the time period corresponding to the analysis completion information J2 selected by the pointer Pt.
[0192] Figure 12 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0193] Referring to Figures 3 and 12, when the user presses button Bt13 while screen G5 is displayed on the display unit of the user terminal 301, the analysis server 151 performs a display process V6 to display screen G7 on the user terminal 301, similar to display processes V2 and V4.
[0194] On screen G7, compared to screen G5 shown in Figure 10, analysis completion information J3, indicating that the cause H3 of the operation of the terminal device 101 has been analyzed, is displayed superimposed on the determination result of the operating status for the time period including the determination target time te corresponding to the visualization data Q3.
[0195] In the example shown in Figure 12, the text Y3, which indicates that the cause of occurrence H3 has been analyzed, is displayed on screen G7 as analysis completion information J3. Specifically, the text Y3 is displayed superimposed on the judgment result for the time period from 3:00 to 4:00 on January 1, 2024, indicating that the operating status of terminal device 101 with terminal ID "00006" was abnormal.
[0196] Furthermore, in screen G7, compared to screen G5 shown in Figure 10, button Bt23, which is button Bt2 for deleting the result of the "Anomaly 3" analysis process, is displayed instead of button Bt13.
[0197] Figure 13 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0198] Referring to Figures 3 and 13, when the user specifies analysis completion information J3 while screen G7 is displayed on the display unit of the user terminal 301, the analysis server 151 performs display processing V7, similar to display processing V3 and V5, to display screen G8, which includes an explanation field L3, on the user terminal 301. The explanation field L3 shows multiple log data and one or more occurrence events H3 included in the time period corresponding to the analysis completion information J3 selected by the pointer Pt.
[0199] (c2) Deletion of analysis module When the user terminal 301 presses button Bt2, it sends operation information D7 indicating the operation to the analysis server 151 via the external network 171. The following describes the case when the user presses button Bt21 while the screen G3 shown in Figure 8 is displayed on the user terminal 301. Specifically, it describes the case when the result of the analysis process for "abnormality 1" using the analysis module 50A is deleted from screen G3.
[0200] In the analysis server 151, when the modification unit 36 receives operation information D7 from the user terminal 301 via the external network 171 and the communication unit 21, it outputs to the display control unit 35 the analysis module 50A corresponding to the operation content indicated by the received operation information D7, and deletion request information indicating a request to stop the display of the results of the analysis processing using the analysis module 50A.
[0201] When the display control unit 35 receives deletion request information from the modification unit 36, it creates screen information B2 showing screen G2, which is a screen with the analysis completion information J1 corresponding to the analysis module 50A indicated by the deletion request information deleted, as shown in Figure 7.
[0202] The display control unit 35 then transmits the created screen information B2 to the user terminal 301 via the communication unit 21 and the external network 171.
[0203] The user terminal 301 renders screen G2 on the web browser displayed on itself, based on screen information B2 received from the analysis server 151.
[0204] Furthermore, the analysis server 151 may be configured to delete one analysis module 50 and add another analysis module 50. In other words, the analysis server 151 may be configured to change the analysis module 50. For example, if a user presses button Bt21 and button Bt12 on screen G3 shown in Figure 8, the analysis server 151 deletes the analysis completion information J1, i.e., the character Y1, from screen G3 and displays the analysis completion information J2, i.e., the character Y2 shown in Figure 10, on screen G3.
[0205] As described above, the analysis server 151 can add and remove analysis modules 50 as functions provided to users. With this configuration, the analysis results provided to each user can be changed.
[0206] (Selection of data for visualization) Referring again to Figure 3, for example, in the analysis server 151, the display control unit 35 performs a selection process to select the data to be hidden from among the multiple data for visualization.
[0207] More specifically, the display control unit 35 displays a screen G11 on the user terminal 301 prompting the user to input the results of an analysis process that they wish to hide.
[0208] For example, the storage unit 23 stores screen information B11 that represents screen G11. Specifically, when screen G2 shown in Figure 7 is displayed on the user terminal 301, the display control unit 35 retrieves screen information B11 from the storage unit 23 when a predetermined operation is performed by the user. The display control unit 35 then transmits the retrieved screen information B11 to the user terminal 301 via the communication unit 21 and the external network 171.
[0209] The user terminal 301 renders screen G11 on the web browser displayed on itself, based on the screen information B11 received from the analysis server 151.
[0210] With screen G11 displayed on the user terminal 301, the user performs an operation to input the type of analysis process they wish to hide. Here, it is assumed that the user inputs "Abnormal 1" as the type to be hidden.
[0211] The user terminal 301 sends a hide request information to the analysis server 151 via the external network 171, indicating the type of analysis process that the user wishes to hide.
[0212] Figure 14 shows another example of a screen displayed by the display processing performed by the analysis server according to the embodiment of this disclosure.
[0213] Referring to Figures 3 and 14, in the analysis server 151, when the display control unit 35 receives a do not display request information from the user terminal 301 via the external network 171 and the communication unit 21, it performs a display process V21 that displays screen G21 on the user terminal 301.
[0214] Screen G21 differs from screen G2 shown in Figure 7 in that it does not display button Bt1, which is used by the user to add types of analysis processes that they wish to hide.
[0215] In other words, unlike screen G2 shown in Figure 7, the button Bt11 for adding the results of the "Anomaly 1" analysis process is hidden on screen G21.
[0216] Furthermore, the display control unit 35 may be configured to perform selection processing not only for the type of analysis processing that the user wishes to hide, but also according to the type of analysis module 50 used by the analysis unit 32 in the analysis processing.
[0217] [Operation Flow] Next, the operation flow of each device in the communication system 501 according to the embodiment of this disclosure will be explained with reference to the drawings.
[0218] Figure 15 is a flowchart illustrating an example of the operation procedure when a terminal device according to an embodiment of the present disclosure performs a process to transmit terminal information.
[0219] Referring to Figure 15, first, the terminal device 101 waits for the processing timing T12 of the log collection process, which collects log data, to arrive (NO in step ST101).
[0220] Then, when the processing timing T12 arrives (YES in step ST101), the terminal device 101 collects multiple log data stored in the storage unit 14 during the period from the previous processing timing T12 to the current processing timing T12 (step ST102).
[0221] Next, the terminal device 101 transmits the collected log data and terminal information, including the terminal ID, system ID, and destination information stored in the storage unit 14, to the analysis server 151 (step ST103), and waits for the next processing timing T12 to arrive (NO in step ST101).
[0222] Figure 16 is a flowchart that shows an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs conversion processing.
[0223] Referring to Figure 16, first, the analysis server 151 waits for the reception of terminal information from the terminal device 101 (NO in step ST201).
[0224] Then, when the analysis server 151 receives terminal information from the terminal device 101 (YES in step ST201), it performs a conversion process to convert each log data in the log data group included in the received terminal information into a common format (step ST202).
[0225] Next, the analysis server 151 creates analysis log information that includes each log data after the conversion process, as well as the terminal ID, system ID, and destination information contained in the received terminal information (step ST203).
[0226] Next, the analysis server 151 saves the created analysis log information to the log database 40 in the storage unit 23 that corresponds to the system ID included in the analysis log information (step ST204), and waits for the reception of new terminal information from the terminal device 101 (NO in step ST201).
[0227] Figures 17, 18, and 19 are flowcharts illustrating an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a status determination process. Figures 17, 18, and 19 show the case when the analysis server 151 determines the operating status of the terminal device 101A.
[0228] Referring to Figures 17, 18, and 19, first, the analysis server 151 waits for the processing timing T21 of the status determination process to arrive (NO in step ST301).
[0229] Then, when processing timing T21 arrives (YES in step ST301), the analysis server 151 performs a status determination process. For example, as described above, the analysis server 151 acquires multiple analysis log information stored in the log database 40 corresponding to the system S to which the terminal device 101A belongs during the period E1 from the previous processing timing T21 to the current processing timing T21. Then, the analysis server 151 uses the acquired multiple analysis log information to determine the operating status of the terminal device 101A at each determination target time included in period E1 (step ST302).
[0230] Next, if the analysis server 151 determines that the operating status of the terminal device 101A is abnormal at one or more target time points (YES in step ST303), it creates operational determination information that includes the operational status determination result at each target time point, the system ID and destination information included in the acquired analysis log information, and the keyword Ke from the error log at monitoring time tk (step ST304). Here, it is assumed that the analysis server 151 determined that the operating status of the terminal device 101A was abnormal at one target time point. That is, it is assumed that there is only one keyword Ke included in the created operational determination information.
[0231] Next, the analysis server 151 obtains the cause H1 of the anomaly, according to the type of anomaly corresponding to the keyword Ke included in the created operational judgment information.
[0232] More specifically, if the analysis server 151 finds that the created operational judgment information includes the keyword Ke1 corresponding to "abnormality 1" (YES in step ST305), it obtains the cause H1 of "abnormality 1" from the corresponding knowledge database corresponding to the system S to which the terminal device 101A belongs (step ST306).
[0233] Next, when the analysis server 151 obtains the occurrence reason H1, it saves the created operation judgment information, including the pair K1 of the obtained occurrence reason H1 and the judgment target time corresponding to the occurrence reason H1, to the analysis database 52A (step ST307), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0234] Meanwhile, if the created operational judgment information contains the keyword Ke1 corresponding to "abnormality 2" (NO in step ST305 and YES in step ST308), the analysis server 151 obtains the cause H2 of "abnormality 2" from the trained model M (step ST309).
[0235] Next, the analysis server 151 saves the created operational judgment information, including the acquired occurrence reason H2 and the judgment target time corresponding to the occurrence reason H2, to the analysis database 52B (step ST310), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0236] Furthermore, if the created operational judgment information contains the keyword Ke1 corresponding to "abnormality 3" (NO in step ST305 and NO in step ST308), the analysis server 151 obtains related data from the corresponding related database to the system S to which the terminal device 101A belongs, at a time when the time difference with the judgment target time te of the analysis target is less than a threshold (step ST311).
[0237] Next, the analysis server 151 obtains the cause of occurrence H3 based on the determination result at the target time te of the analysis target and the acquired related data (step ST312).
[0238] Next, the analysis server 151 saves the created operational judgment information, including the pair K3 of the acquired occurrence reason H3 and the judgment target time te corresponding to the occurrence reason H3, to the analysis database 52C (step ST313), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0239] On the other hand, if the analysis server 151 determines that the operational status at each target time is normal (NO in step ST303 and YES in step ST314), it creates operational determination information that includes the determination result, the system ID and destination information included in the acquired analysis log information, and the keyword Kn of the normal log at each target time (step ST315).
[0240] Next, the analysis server 151 retrieves relevant data from the corresponding database for the system S to which the terminal device 101A belongs, for each time period to be determined, where the time difference from the time period to be determined is less than a threshold (step ST316).
[0241] Next, the analysis server 151 determines, for each time period to be determined, whether or not there was an abnormality in the operation of the terminal device 101 at that time period, based on the keyword Kn at that time period and the acquired related data (step ST317).
[0242] Then, if the analysis server 151 determines that the operation of the terminal device 101 is abnormal at at least one of the multiple target time periods (YES in step ST317), it obtains the cause H3 of the abnormality. For example, as described above, the analysis server 151 obtains the cause H3 based on the keyword Kn and the acquired related data (step ST318).
[0243] Next, the analysis server 151 saves the created operational judgment information, including the acquired occurrence reason H3 and the judgment target time corresponding to the occurrence reason H3, into the analysis database 52C (step ST319), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0244] On the other hand, if the analysis server 151 determines that the operation of the terminal device 101 is normal at each target time (NO in step ST317), it creates operational determination information including the determination result at each target time and the system ID and destination information contained in the acquired analysis log information, saves it to each analysis database 52 (step ST320), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0245] Furthermore, if the determination result of the operational status at each target time is non-operational (NO in step ST303 and NO in step ST314), the analysis server 151 creates operational determination information including the determination result and the system ID and destination information contained in the acquired analysis log information, and saves it in each analysis database 52 (step ST320), and waits for the arrival of the next processing timing T21 (NO in step ST301).
[0246] Figure 20 is a flowchart illustrating an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs a merge process. Figure 20 shows the operation when the analysis server 151 performs the merge process P1.
[0247] Referring to Figure 20, first, the analysis server 151 waits for the processing timing T41 of the merging process P1 to arrive (NO in step ST401).
[0248] Then, when the processing timing T41 arrives (YES in step ST401), the analysis server 151 retrieves multiple analysis log information stored in the log database 40 during the period E3 from the previous processing timing T41 to the current processing timing T41 (step ST402).
[0249] Next, the analysis server 151 obtains multiple operational judgment information corresponding to each of the multiple analysis log information obtained from the analysis database 52A (step ST403).
[0250] Next, the analysis server 151 performs a merging process P1 using the acquired multiple analysis log information and multiple operation determination information. For example, as described above, the analysis server 151 combines an error log at a monitoring time tk included in a certain analysis log information with the cause of occurrence H1 at the determination target time te corresponding to the monitoring time tk to create visualization data Q1 (step ST404). Here, it is assumed that each acquired analysis log information includes an error log.
[0251] Next, if there is analysis log information for which the merging process P1 is not yet completed (YES in step ST405), the analysis server 151 performs the merging process P1 on the incomplete analysis log information (step ST404).
[0252] On the other hand, if there is no analysis log information for which the merging process P1 is incomplete (NO in step ST405), the analysis server 151 saves each created visualization data Q1 to the visualization database 71A (step ST406) and waits for the next processing timing T41 to arrive (NO in step ST401).
[0253] Figure 21 is a flowchart illustrating an example of the operation procedure when the analysis server according to the embodiment of this disclosure performs display processing. Figure 21 shows a case in which the analysis server 151 displays a screen G2 on the user terminal 301 that shows the history of the determination results of the operating status of each terminal device 101.
[0254] Referring to Figure 21, first, the analysis server 151 waits for the user request information to be received from the user terminal 301 (NO in step ST501).
[0255] Then, when the analysis server 151 receives user request information from the user terminal 301 (YES in step ST501), it obtains operational determination information for the display target period C indicated by the received user request information from the visualization database 70 for each terminal ID indicated by the user request information (step ST502).
[0256] Next, the analysis server 151 obtains operational determination information for each terminal ID indicated by the received user request information, and then performs a display process V1 to display screen G2 on the user terminal 301, which shows the history of the operational status determination results for each terminal device 101 during the display target period C indicated by the user request information. For example, as described above, the analysis server 151 uses the acquired operational determination information for each terminal device 101 to create screen information B2 that shows screen G2. Then, the analysis server 151 sends the created screen information B2 to the user terminal 301 (step ST503).
[0257] Figure 22 is a flowchart showing an example of the operation procedure when an analysis server according to an embodiment of the present disclosure performs the process of adding an analysis module. Figure 22 shows the case in which the analysis server 151 adds an analysis module 50A when screen G2 shown in Figure 7 is displayed on the user terminal 301.
[0258] Referring to Figure 22, first, the analysis server 151 waits for the reception of operation information D1 from the user terminal 301 while screen G2 is displayed on the user terminal 301 (NO in step ST601).
[0259] Next, when the analysis server 151 receives operation information D1 from the user terminal 301 (YES in step ST601), it checks whether the visualization data Q1 obtained by combining the occurrence reason H1 acquired using the analysis module 50A corresponding to the operation content indicated by the received operation information D1 with the log data, and whether the visualization data Q1 for the display target period C indicated by the operation information D1 is stored in the visualization database 71A (step ST602).
[0260] Then, if the analysis server 151 has visualization data Q1 corresponding to the operation content indicated by the received operation information D1 stored in the visualization database 71A (YES in step ST602), it performs display processing V2 to display screen G3 on the user terminal 301. For example, as described above, in display processing V2, the analysis server 151 displays analysis completion information J1 indicating that the occurrence cause H1 has been analyzed, superimposed on the judgment result for the time period including the judgment target time te corresponding to the occurrence cause H1 (step ST603).
[0261] Next, the analysis server 151 displays screen G3 on the user terminal 301 and waits for the reception of operation information D2 from the user terminal 301 (NO in step ST604).
[0262] Then, when the analysis server 151 receives operation information D2 from the user terminal 301 (YES in step ST604), it obtains visualization data Q1 corresponding to the analysis completion information J1 indicated by the received operation information D2 from the visualization database 71A (step ST605).
[0263] Next, when the analysis server 151 acquires the visualization data Q1, it performs a display process V3 that displays a screen G4 including the explanation field L1 on the user terminal 301 (step ST606).
[0264] On the other hand, if the visualization data Q1 corresponding to the operation content indicated by the received operation information D1 is not stored in the visualization database 71A (NO in step ST602), the analysis server 151 maintains the display of screen G2 on the user terminal 301 (step ST607).
[0265] Figure 23 is a flowchart showing an example of the operation procedure when an analysis server according to an embodiment of the present disclosure performs a process to delete an analysis module. Figure 23 shows the case when the analysis server 151 deletes the analysis module 50A while screen G3 shown in Figure 8 is displayed on the user terminal 301.
[0266] Referring to Figure 23, first, the analysis server 151 waits for the reception of operation information D7 from the user terminal 301 while screen G3 is displayed on the user terminal 301 (NO in step ST701).
[0267] Then, when the analysis server 151 receives operation information D7 from the user terminal 301 (YES in step ST701), it confirms the analysis completion information corresponding to the operation content indicated by the received operation information D7, i.e., the analysis completion information to be deleted from screen G3 (step ST702).
[0268] Next, the analysis server 151 displays screen G2 on the user terminal 301, which is the screen with the analysis completion information J1, i.e., the character Y1, deleted, corresponding to the operation content indicated by the received operation information D7. For example, as described above, the analysis server 151 creates screen information B2 showing screen G2 and sends it to the user terminal 301 (step ST703).
[0269] In the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to combine log data and analysis data output by the analysis program 51 to create visualization data and to display the created visualization data on the user terminal 301, but it is not limited to this configuration. The analysis server 151 may also be configured to perform processes such as creating an email containing the contents of the combined data of log data and analysis data and sending it to the user, and notifying the user of the contents of the combined data by voice.
[0270] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to hold analysis modules 50A, 50B, and 50C, and to add or remove at least one of these three analysis modules 50, but it is not limited to this. The analysis server 151 may be configured to hold any two of these three analysis modules 50. Also, the analysis module 50 may be configured to hold other analysis modules 50 in place of some or all of these three analysis modules 50, or in addition to these three analysis modules 50.
[0271] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to have a plurality of coupling units 33, and when an analysis module 50 is added or deleted, the coupling unit 33 corresponding to the analysis module 50, i.e., the visualization data corresponding to the analysis module 50, is added or deleted. However, the system is not limited to this configuration. The analysis server 151 may also be configured to have a single coupling unit 33. In this case, the coupling unit 33 performs a coupling process that creates correspondence data showing the correspondence relationship between log data and occurrence causes H1, H2, and H3. When an analysis module 50 is added or deleted, the analysis server 151 creates visualization data corresponding to the analysis module 50 based on the correspondence data.
[0272] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to create visualization data in advance and store it in the visualization database 71, and when an operation to specify analysis completion information is performed on the screen displayed on the user terminal 301, the visualization data corresponding to the analysis completion information is retrieved from the visualization database 71 and displayed. However, the system is not limited to this configuration. The analysis server 151 may also be configured to create visualization data after the operation is performed and to display the created visualization data.
[0273] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to perform a selection process to select visualization data to be hidden from among the multiple visualization data created, but it is not limited to this configuration. The analysis server 151 may be configured not to perform a selection process.
[0274] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the analysis server 151 is configured to perform access restriction processing for each visualization data created using the coupling program 60, but it is not limited to this configuration. The analysis server 151 may be configured not to perform access restriction processing. In this case, the analysis server 151 stores the created visualization data in a visualization database 71 common to each coupling program 60.
[0275] Furthermore, some or all of the functions of the analysis server 151 according to the embodiment of this disclosure may be provided by cloud computing. That is, the analysis server 151 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.
[0276] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.
[0277] Each process (each function) in the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of an integrated circuit, etc., which combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been designed in advance to execute each of the above processes. The above-mentioned processor may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, multiple physically separated processors may cooperate with each other to perform the above-mentioned processes. For example, processors installed in multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above-mentioned processes. The above program may be installed on the above memory via the above network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or semiconductor memory, and then installed on the above memory from the above recording medium.
[0278] The above description includes the following features: [Addendum 1] A terminal operation management system comprising: an acquisition unit for acquiring log data relating to a terminal device; an analysis program for analyzing the operation of the terminal device based on the log data acquired by the acquisition unit; a modification unit for adding and deleting analysis modules including a database of analysis data showing the analysis results by the analysis program; and a coupling unit for combining the log data acquired by the acquisition unit with the analysis data, wherein the analysis program is a program for detecting abnormalities in the terminal device, and the analysis data indicates the cause of the abnormality.
[0279] [Appendix 2] A terminal operation management system comprising a processing circuit, wherein the processing circuit adds and deletes analysis modules that include an analysis program that acquires log data relating to a terminal device and analyzes the operation of the terminal device based on the acquired log data, and a database of analysis data showing the analysis results by the analysis program, and combines the acquired log data and the analysis data.
[0280] 11, 21 Communication Unit 12 Log Creation Unit 13 Collection Unit 14, 23 Storage Unit 22 Processing Unit 31 Format Conversion Unit 32 Analysis Unit 33, 33A, 33B, 33C Integration Unit 34 Access Restriction Unit 35 Display Control Unit 36 Modification Unit 40 Log Database 50, 50A, 50B, 50C Analysis Module 51, 51A, 51B, 51C Analysis Program 52, 52A, 52B, 52C Analysis Database 60, 60A, 60B, 60C Integration Program 70, 71, 71A, 71B, 71C Visualization Database 72 Visualization Program 81 Knowledge Database 91 Related Database 101, 101A, 101B Terminal Device 151 Analysis Server 171 External Network 301 User Terminal 501 Communication system M: Trained model S: System
Claims
1. A terminal operation management system comprising: an acquisition unit for acquiring log data relating to a terminal device; an analysis program for analyzing the operation of the terminal device based on the log data acquired by the acquisition unit; a modification unit for adding and deleting analysis modules, including a database of analysis data showing the analysis results by the analysis program; and a merging unit for combining the log data acquired by the acquisition unit with the analysis data.
2. The modified unit adds or deletes at least one of the first analysis module, the second analysis module, and the third analysis module; the analysis program of the first analysis module outputs the cause of operation of the terminal device from a knowledge database as analysis data; the analysis program of the second analysis module outputs the cause of operation as analysis data from a trained model generated by machine learning the relationship between the log data and the cause of operation; and the analysis program of the third analysis module outputs the cause of operation as analysis data from related data, which is data separate from the log data and indicates results monitored or measured by a device other than the terminal device.
3. The terminal operation management system according to claim 1 or claim 2, wherein the modification unit adds or deletes the coupling unit for each analysis module.
4. The terminal operation management system according to claim 1 or 2, wherein the coupling unit combines the log data and the analysis data for each analysis module to create visualization data, and the terminal operation management system further includes a display control unit that selects visualization data to be hidden from among a plurality of visualization data.
5. The terminal operation management system according to claim 1 or 2, wherein the combining unit combines the log data and the analysis data for each analysis module to create visualization data, the combining unit stores the created visualization data in a separate visualization database for each analysis module, and the terminal operation management system further includes an access restriction unit for each visualization database to restrict access to the visualization database.
6. A terminal operation management method in a terminal operation management system, comprising the steps of: acquiring log data relating to a terminal device; adding or deleting an analysis module which includes an analysis program that analyzes the operation of the terminal device based on the acquired log data and a database of analysis data showing the analysis results by the analysis program; and combining the acquired log data and the analysis data.
7. A terminal operation management program used in a terminal operation management system, which causes a computer to function as: an acquisition unit for acquiring log data relating to a terminal device; an analysis program for analyzing the operation of the terminal device based on the log data acquired by the acquisition unit; a modification unit for adding and deleting analysis modules, including a database of analysis data showing the analysis results by the analysis program; and a coupling unit for combining the log data acquired by the acquisition unit with the analysis data.