Your question is Detect Anomalous Infrastructure Log Events. Start with the requirements on the right.
Run and submit as often as you like. When you're ready, talk me through your approach or go straight to the code.
Given a list of log lines, identify anomalous events by counting how many times each (service, action) pair appears per minute. Each log line has the format "timestamp service action status", where timestamp is YYYY-MM-DDTHH:MM:SS. Return all (minute, service, action) groups whose count is strictly greater than a given threshold, sorted by minute, then service, then action.
def find_anomalies(logs, threshold):