src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher¶
PatternSearcher — coarse-to-fine similarity retrieval pipeline.
- Executes three-step retrieval against a pre-built IncidentIndex:
Inverted-index lookup — O(|query_event_set|) candidate set
Jaccard pre-filter — discard clearly dissimilar episodes
Full metric scoring — NLCS + EMD + combined weighted score
All three metric scores are always computed and returned so that callers can switch weight profiles or analyse individual signals without re-running.
Attributes¶
Classes¶
Retrieves the top-k most similar historical episodes for a query incident. |
Functions¶
|
Return the index_status string for a given index and staleness window. |
|
Return a sentinel HistoricalSignalEpisode for the no-data case. |
Module Contents¶
- src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher._INDEX_STATUS_INDEXED = 'indexed'[source]¶
- src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher._INDEX_STATUS_NO_DATA = 'no_episodes_indexed'[source]¶
- src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher._INDEX_STATUS_STALE = 'stale'[source]¶
- class src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher.PatternSearcher(index, config)[source]¶
Retrieves the top-k most similar historical episodes for a query incident.
- Pipeline per search() call:
Inverted-index lookup: episode_ids sharing ≥ 1 event type with query.
Jaccard pre-filter: discard candidates below config.min_jaccard.
NLCS computation on survivors.
EMD computation on survivors.
Combined score: weighted sum using the resolved weight profile.
Rank descending by combined_score; return the top-k HistoricalSignalEpisodes.
The coarse-to-fine design avoids computing NLCS and EMD on clearly dissimilar episodes (those failing the Jaccard gate).
- Parameters:
- search(query, weight_profile=None, staleness_window_days=None)[source]¶
Retrieves top-k most similar historical episodes for a query fingerprint.
Returns list[HistoricalSignalEpisode] with index_status populated on every result (§4.11):
“indexed” — normal result from a current, populated index
“no_episodes_indexed” — index is empty; returns a single sentinel episode
- “stale” — index is older than staleness_window_days; results
returned but flagged; link_confidence capped downstream
- Parameters:
query (src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.IncidentFingerprint) – IncidentFingerprint for the query incident.
weight_profile (Optional[str]) – Weight profile override; None → config.weight_profile.
staleness_window_days (Optional[int]) – If set and index.build_timestamp is known, episodes from an index older than this are marked “stale”. None disables the staleness check. By design the window lives on PatternSearchConfig.index_staleness_window_days; the orchestrator reads it there and passes it in here (PatternSearcher itself only carries a SearchConfig).
- Return type:
list[src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.HistoricalSignalEpisode]
Notes
All three metric scores (jaccard, nlcs, emd) are individually visible on every returned HistoricalSignalEpisode (§5).
matched_events, query_only_events, episode_only_events are derived from event_set comparison.
- _resolve_weights(weight_profile)[source]¶
Returns (alpha, beta_w, gamma) for the given weight profile name.
Delegates to SearchConfig.resolve_weights() which owns the profile registry and “custom” fallback logic.
- Raises:
ValueError for unrecognised profile names. –
- Parameters:
weight_profile (str)
- Return type:
tuple[float, float, float]
- src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher._compute_index_status(index, staleness_window_days)[source]¶
Return the index_status string for a given index and staleness window.
- Parameters:
index (src.dackar.RCA.log_pattern_recognition.rca_pattern_search.indexer.IncidentIndex)
staleness_window_days (Optional[int])
- Return type:
str
- src.dackar.RCA.log_pattern_recognition.rca_pattern_search.searcher._make_no_data_sentinel(asset_id, index_status=_INDEX_STATUS_NO_DATA)[source]¶
Return a sentinel HistoricalSignalEpisode for the no-data case.
Callers must check index_status before attempting cross-pattern linkage. A sentinel has episode_id == “” and similarity_to_current == 0.0.
- Parameters:
asset_id (str)
index_status (str)
- Return type:
src.dackar.RCA.log_pattern_recognition.rca_pattern_search.models.HistoricalSignalEpisode