Log Analysis Correlation and Influence Direction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anomaly analysis methods in information processing systems fail to accurately determine the root cause of failures, as they can only detect multiple data items experiencing correlation violations, leading to inefficient troubleshooting.
Innovation Solution
An analyzing program that collects and correlates logs from multiple sources, calculates influence directions between data items, and generates anomaly reports to identify the primary cause of failures by determining which data item is closest to the cause based on chronological relationships and correlation violations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional anomaly analysis methods are used to detect correlation violations, then multiple data items experiencing violations can be detected, but the root cause of failures cannot be accurately determined
Solution Approach 1:
The patent applies preliminary action by pre-calculating and storing influence directions between data items during a learning phase when the system is operating normally. This pre-computed influence information is then used during anomaly detection to quickly identify the root cause without complex real-time analysis, thereby improving measurement precision while reducing troubleshooting complexity.
Solution Approach 2:
The patent introduces an intermediary element - the influence direction information - that mediates between correlation violation detection and root cause identification. This intermediary contains pre-analyzed causal relationships that guide the troubleshooting process, enabling accurate root cause determination without requiring complex real-time analysis of all violated correlations.
2Reliability
If multiple correlations are violated at the same time, then comprehensive failure detection is achieved, but the load of troubleshooting increases
Solution Approach 1:
The patent performs preliminary analysis by pre-computing influence directions between all data items during normal system operation. This advance preparation creates a knowledge base that enables rapid root cause identification even when multiple correlations are violated simultaneously, maintaining comprehensive failure detection while reducing troubleshooting time.
Solution Approach 2:
The patent replaces the mechanical process of manually analyzing multiple violated correlations with an automated system that uses pre-computed influence directions. This substitution eliminates the need for troubleshooting personnel to manually evaluate each violated correlation, significantly reducing troubleshooting time while maintaining comprehensive failure detection.
3Ease of operation
If conventional methods only detect correlation violations without determining influence direction, then simple detection is achieved, but the ability to locate the real cause of failure is insufficient
Solution Approach 1:
The patent applies preliminary action by pre-calculating influence directions between data items during the learning phase. This advance computation adds causal relationship information to the system without complicating the detection process, enabling both simple operation and accurate cause location simultaneously.
Solution Approach 2:
The patent changes the parameter set by adding influence direction information to the traditional correlation violation detection. This parameter enhancement transforms the detection system from one that only identifies violated correlations to one that can also determine the direction of influence, thereby improving cause location accuracy while maintaining detection simplicity through automated processing.
Data Source
AI summary
A processor calculates a correlation between a first data item and a second data item, based on values of the first data item in a first log and values of the second data item in a second log, and determines an influence direction by comparing values of a first chronological item with values of a second chronological item. The processor collects third and fourth logs respectively generated later than the first and second logs. The processor determines whether the correlation holds with respect to values of the first data item in the third log and values of the second data item in the fourth log, and outputs an anomaly report, when the correlation does not hold, to indicate which of the first and second data items is a cause data item (i.e., the source of an anomaly), based on the influence direction.


