src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models¶
Classes¶
Canonical representation of a single event from any source. |
|
Pre-computed similarity representations for a single incident or detected |
|
Public output type for PatternSearcher.search(). |
|
A single entry in the ranked retrieval output. |
Module Contents¶
- class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.UnifiedEvent[source]¶
Canonical representation of a single event from any source.
All three input sources (alarm, SOE, anomaly) are normalised into this structure before any further processing.
- Lifecycle:
Created by IncidentExtractor.to_unified_events()
episode_id is None until EpisodeDetector assigns membership
timestamp_end is nullable and not used in current similarity metrics but carried for traceability and future use
- class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.IncidentFingerprint[source]¶
Pre-computed similarity representations for a single incident or detected historical episode. This is the unit of comparison in the retrieval pipeline.
Derived from a list of UnifiedEvents by IncidentExtractor.extract() or EpisodeDetector after episode boundary assignment.
- The three representations serve distinct metrics:
event_set → Jaccard (what types occurred, ignoring order/repetition) event_seq → NLCS (what types occurred and in what order) freq_vec → EMD (how many times each type occurred)
High-frequency event types (count > freq_threshold) are excluded from event_set and event_seq but retained in freq_vec.
- class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.HistoricalSignalEpisode[source]¶
Public output type for PatternSearcher.search().
Represents a single historical signal episode retrieved for a query incident. Carries all three metric scores individually (§5 of the integration plan) and an index_status field that governs cross-pattern linkage eligibility (§4.11).
Sentinel (no_episodes_indexed) instances have episode_id == “” and similarity_to_current == 0.0. Callers must check index_status before attempting linkage.