src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models

Classes

UnifiedEvent

Canonical representation of a single event from any source.

IncidentFingerprint

Pre-computed similarity representations for a single incident or detected

HistoricalSignalEpisode

Public output type for PatternSearcher.search().

SearchResult

A single entry in the ranked retrieval output.

Module Contents

class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.UnifiedEvent[source]

Canonical representation of a single event from any source.

All three input sources (alarm, SOE, anomaly) are normalised into this structure before any further processing.

Lifecycle:
  • Created by IncidentExtractor.to_unified_events()

  • episode_id is None until EpisodeDetector assigns membership

  • timestamp_end is nullable and not used in current similarity metrics but carried for traceability and future use

raw_id: str[source]
asset_id: str[source]
source: str[source]
event_type: str[source]
timestamp_start: datetime.datetime[source]
timestamp_end: datetime.datetime | None[source]
episode_id: str | None = None[source]
class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.IncidentFingerprint[source]

Pre-computed similarity representations for a single incident or detected historical episode. This is the unit of comparison in the retrieval pipeline.

Derived from a list of UnifiedEvents by IncidentExtractor.extract() or EpisodeDetector after episode boundary assignment.

The three representations serve distinct metrics:

event_set → Jaccard (what types occurred, ignoring order/repetition) event_seq → NLCS (what types occurred and in what order) freq_vec → EMD (how many times each type occurred)

High-frequency event types (count > freq_threshold) are excluded from event_set and event_seq but retained in freq_vec.

episode_id: str[source]
asset_id: str[source]
window_start: datetime.datetime[source]
window_end: datetime.datetime[source]
density: float[source]
event_set: frozenset[str][source]
event_seq: list[str][source]
freq_vec: dict[str, int][source]
known_rca: str | None = None[source]
source_types: list[str] = [][source]
class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.HistoricalSignalEpisode[source]

Public output type for PatternSearcher.search().

Represents a single historical signal episode retrieved for a query incident. Carries all three metric scores individually (§5 of the integration plan) and an index_status field that governs cross-pattern linkage eligibility (§4.11).

Sentinel (no_episodes_indexed) instances have episode_id == “” and similarity_to_current == 0.0. Callers must check index_status before attempting linkage.

episode_id: str[source]
asset_id: str[source]
window_start: datetime.datetime | None[source]
window_end: datetime.datetime | None[source]
source_types: list[str][source]
event_set: frozenset[str][source]
event_seq: list[str][source]
freq_vec: dict[str, int][source]
similarity_to_current: float[source]
jaccard_score: float[source]
nlcs_score: float[source]
emd_score: float[source]
weight_profile: str[source]
matched_events: set[str][source]
query_only_events: set[str][source]
episode_only_events: set[str][source]
episode_density: float[source]
known_rca: str | None[source]
linked_doc_ids: list[str][source]
index_status: str[source]
class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.SearchResult[source]

A single entry in the ranked retrieval output.

Returned by PatternSearcher.search() for each matching historical episode. Includes all three metric scores for transparency and downstream analysis.

episode_id: str[source]
jaccard_score: float[source]
nlcs_score: float[source]
emd_score: float[source]
combined_score: float[source]
weight_profile: str[source]
episode_window: tuple[datetime.datetime, datetime.datetime][source]
episode_density: float[source]
matched_events: set[str][source]
query_only_events: set[str][source]
episode_only_events: set[str][source]
known_rca: str | None = None[source]