Message abnormality automatic detection device, method and program
First Claim
1. A message abnormality automatic detection device comprising:
- a message collection unit for collecting messages generated by a distributed system;
a normal pattern memory unit for storing normal pattern of which the constituent element is message information data which are a combination of one or two or more consecutive messages generated when the distributed system is operating normally and have at least identifiers which uniquely identify the messages and the number of times each message indicated by the identifiers are generated;
and a collation unit for referencing the normal patterns stored within the normal pattern memory unit, retrieving the identifier which matches the identifier of the message collected within the message collection unit, counting the number of times the message indicated by the identifier is generated if relevant identifier exists, and determining abnormality if the number of times generated is higher or lower than a predetermined value or if relevant identifier does not exist.
1 Assignment
0 Petitions
Accused Products
Abstract
In order to provide a message abnormality automatic detection device, method and program for accurately detecting messages indicating abnormalities requiring response from a large amount of messages, the message abnormality automatic detection device 1 comprises a message collection unit 2 for collecting messages, a learning unit 3 for extracting patterns from the collected messages, a normal pattern memory unit 4 for storing normal patterns, a collation unit 5 for collating the collected messages with normal patterns and detecting message abnormalities, a warning unit 6 for outputting abnormalities to display 9 and the like, and a definition unit 7 for storing the definition data related to normal patterns.
-
Citations
19 Claims
-
1. A message abnormality automatic detection device comprising:
-
a message collection unit for collecting messages generated by a distributed system;
a normal pattern memory unit for storing normal pattern of which the constituent element is message information data which are a combination of one or two or more consecutive messages generated when the distributed system is operating normally and have at least identifiers which uniquely identify the messages and the number of times each message indicated by the identifiers are generated;
and a collation unit for referencing the normal patterns stored within the normal pattern memory unit, retrieving the identifier which matches the identifier of the message collected within the message collection unit, counting the number of times the message indicated by the identifier is generated if relevant identifier exists, and determining abnormality if the number of times generated is higher or lower than a predetermined value or if relevant identifier does not exist. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A message abnormality automatic detection method for enabling an information processing device to perform:
-
message collection processing for collecting messages generated by a distributed system; and
collation processing for referencing the normal pattern memory unit for storing normal pattern of which the constituent element is message information data which is a combination of one or two or more consecutive messages generated when the distributed system is operating normally and have at least identifiers which uniquely identify the messages and the number of times each message indicated by the identifiers are generated, retrieving the identifier which matches the identifier of the message collected through the message collection processing, counting the number of times the message indicated by the identifier is generated if relevant identifier exists, and determining abnormality if the number of times generated is higher or lower than a predetermined value or if relevant identifier does not exist. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. A recording medium for recording a program used to direct an information processing device to perform a message abnormality automatic detection process, comprising:
-
message collection processing for collecting messages generated by a distributed system; and
collation processing for referencing the normal pattern memory unit for storing normal pattern of which the constituent element is message information data which is a combination of one or two or more consecutive messages generated when the distributed system is operating normally and have at least identifiers which uniquely identifies the messages and the number of times each message indicated by the identifiers are generated, retrieving the identifier which matches the identifier of the message collected through the message collection processing, counting the number of times the message indicated by the identifier is generated if relevant identifier exists, and determining abnormality if the number of times generated is higher or lower than a predetermined value or if relevant identifier does not exist. - View Dependent Claims (15, 16, 17, 18, 19)
-
Specification