Database alarm suppression method and related device
By establishing a category recognition model and data mining algorithm, combined with SVM and FP-growth algorithms, the fault event category is identified and corresponding alarms are sent, solving the alarm storm problem and improving fault handling efficiency.
Patent Information
- Application Number
- CN202210289221.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-23
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-03-23
AI Technical Summary
In banking IT systems, alarm storms caused by failures make it difficult for operations and maintenance personnel to handle them in a timely manner. Existing alarm compression technologies are inefficient and poorly maintainable, and cannot effectively reduce the number of alarms.
By establishing a category recognition model and data mining algorithm, the fault event category is identified and the corresponding alarm information is sent according to the alarm suppression rules. Combined with the SVM classifier and FP-growth algorithm, the alarm information is correlated and analyzed to reduce invalid alarms.
It effectively reduces alarm information, improves the effectiveness of fault handling, and enhances the emergency response efficiency of operation and maintenance personnel.
Smart Images

Figure CN114706736B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of databases, and in particular to a database alarm suppression method and related devices. Background Art
[0002] With the rapid development of banking, various business scenarios are rapidly evolving. While emerging technologies are driving business growth, they are also significantly increasing the complexity of IT systems. To cope with high pressure and high concurrency, the number of database servers in application systems continues to increase, resulting in increasing pressure to handle various database failures. While the most effective means of fault detection is through alerts, due to the large number of servers and their complex relationships, a single failure can generate multiple alerts. Major failures trigger a flood of alerts, creating a storm. With limited operations and maintenance personnel, these numerous alerts cannot be addressed promptly. Summary of the Invention
[0003] In view of the above problems, the present invention provides a database alarm suppression method and related devices that overcome the above problems or at least partially solve the above problems.
[0004] In a first aspect, a database alarm suppression method includes:
[0005] Obtain current troubleshooting tickets;
[0006] Determine the event category corresponding to the fault event ticket by using a pre-established category recognition model, wherein one fault event ticket corresponds to one event category;
[0007] According to the event category and the alarm suppression rule established in advance by a data mining algorithm, corresponding alarm information is sent, wherein the alarm suppression rule records the corresponding relationship between different event categories and the alarm information.
[0008] In conjunction with the first aspect, in certain optional implementations, the training process of the category recognition model includes:
[0009] Constructing a corresponding word segmentation dictionary based on different predefined event categories, wherein the event categories include database performance, database status, database availability, and database capacity, and the word segmentation dictionary records the characteristic word segmentations corresponding to each event category;
[0010] The word segmentation dictionary is called by a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining characteristic word segmentations of each historical fault event sheet;
[0011] Performing text vectorization on each of the historical fault event sheets based on the feature word segmentation of each of the historical fault event sheets, thereby obtaining vector features of each of the historical fault event sheets;
[0012] The vector features of each of the historical fault event sheets are input into the model to be trained for training, thereby training to obtain the classification model.
[0013] In combination with the previous embodiment, in some optional embodiments, inputting the vector features of each of the historical fault event sheets into the model to be trained for training, thereby training to obtain the classification model, includes:
[0014] The SVM classifier is called, and the vector features of each of the historical fault event sheets are input into the SVM classifier for training, thereby obtaining the classification model.
[0015] In conjunction with the first aspect, in some optional implementations, the process of establishing the alarm suppression rule includes:
[0016] Obtaining each of the historical fault event tickets from a fault event ticket database;
[0017] Determine the event category corresponding to each of the historical fault event sheets using the category recognition model, and extract corresponding subcategory keywords, fault start time, and fault recovery time from each of the historical fault event sheets;
[0018] Acquire historical alarm information sent for each of the historical fault event sheets from the alarm database, wherein one of the historical fault event sheets corresponds to at least one piece of the historical alarm information;
[0019] Extracting corresponding event categories, subcategory keywords, fault start time, and fault recovery time from each of the historical alarm information;
[0020] According to the event category, subcategory keyword, fault start time and fault recovery time of each historical fault event ticket, and the event category, subcategory keyword, fault start time and fault recovery time of each historical alarm information, each historical fault event ticket is associated with the corresponding historical alarm information, wherein one piece of historical alarm information is associated with one historical fault event ticket, and one historical fault event ticket is associated with at least one piece of historical alarm information;
[0021] The historical fault event sheets and the associated historical alarm information are grouped according to different event categories and input into a data mining algorithm FP-growth, thereby obtaining data mining results of the FP-growth, wherein historical fault event sheets and the associated historical alarm information of the same event category are grouped together, and the data mining results reflect the degree of association between the historical alarm information and the corresponding event category;
[0022] The alarm suppression rule is established according to the correlation between each of the historical alarm information and the corresponding event category.
[0023] In combination with the previous embodiment, in some optional embodiments, establishing the alarm suppression rule according to the correlation between each historical alarm information and the corresponding event category includes:
[0024] For any of the event categories, the following steps are performed: arranging the corresponding historical alarm information in order of their relevance;
[0025] Set the historical alarm information with a correlation greater than the correlation threshold as the sendable information of the corresponding event category;
[0026] The sending of corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm includes:
[0027] According to the event category, corresponding sendable information is determined and sent.
[0028] In combination with the previous embodiment, in certain optional embodiments, after sending the corresponding alarm information according to the event category and the alarm suppression rule pre-established by the data mining algorithm, the method further includes:
[0029] The relevance threshold is adjusted according to the current suppression status of the alarm information by the alarm suppression rule.
[0030] In a second aspect, a database alarm suppression device includes: a current event single acquisition unit, an event category identification unit, and an alarm suppression unit;
[0031] The current event sheet obtaining unit is used to obtain the current fault event sheet;
[0032] The event category identification unit is configured to determine the event category corresponding to the fault event ticket using a pre-established category identification model, wherein one fault event ticket corresponds to one event category;
[0033] The alarm suppression unit is used to send corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm, wherein the alarm suppression rules record the corresponding relationship between different event categories and the alarm information.
[0034] In conjunction with the second aspect, in certain optional embodiments, the apparatus further includes a model training unit;
[0035] The model training unit is used to perform the training process of the category recognition model;
[0036] The model training unit includes: a dictionary construction unit, a word segmentation unit, a vectorization unit and a training unit;
[0037] The dictionary construction unit is configured to construct a corresponding word segmentation dictionary according to different predefined event categories, wherein the event categories include database performance, database status, database availability, and database capacity, and the word segmentation dictionary records the characteristic word segmentations corresponding to each of the event categories;
[0038] The word segmentation unit is used to call the word segmentation dictionary through a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining the characteristic word segmentation of each historical fault event sheet;
[0039] The vectorization unit is used to perform text vectorization on each of the historical fault event sheets according to the feature segmentation of each of the historical fault event sheets, thereby obtaining the vector features of each of the historical fault event sheets;
[0040] The training unit is used to input the vector features of each of the historical fault event sheets into the model to be trained for training, thereby training to obtain the classification model.
[0041] In a third aspect, a computer-readable storage medium stores a program, which, when executed by a processor, implements any of the above-mentioned database alarm suppression methods.
[0042] In a fourth aspect, an electronic device comprises at least one processor, and at least one memory and a bus connected to the processor; wherein the processor and the memory communicate with each other through the bus; and the processor is used to call program instructions in the memory to execute any of the above-mentioned database alarm suppression methods.
[0043] By means of the above technical solution, the database alarm suppression method and related device provided by the present invention can obtain the current fault event sheet; determine the event category corresponding to the fault event sheet through a pre-established category recognition model, wherein one fault event sheet corresponds to one event category; send corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm, wherein the alarm suppression rules record the correspondence between different event categories and the alarm information. It can be seen from this that the present invention will send corresponding alarm information according to the different event categories of the fault event sheet through the pre-established alarm suppression rules, which can reduce the alarm information to a certain extent, avoid the formation of an alarm storm, and thus improve the effectiveness of handling alarms.
[0044] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0046] Figure 1 A flowchart of a database alarm suppression method provided by the present invention is shown;
[0047] Figure 2 A schematic structural diagram of a database alarm suppression device provided by the present invention is shown;
[0048] Figure 3 A schematic structural diagram of an electronic device provided by the present invention is shown. DETAILED DESCRIPTION
[0049] With the rapid development of banking business, various business scenarios are iterating rapidly. While promoting business development, emerging technologies have greatly increased the complexity of IT systems. In order to cope with high pressure and high concurrency, the number of application system database machines continues to increase, and the corresponding emergency response to various database failures is facing increasing pressure. The most effective means of fault detection is through alarms. Due to the large number of machines and the complex relationships, one fault will cause multiple alarms. When a major fault occurs, a large number of alarms are triggered to form a storm. With limited operation and maintenance personnel, a large number of alarms cannot be processed in time. Therefore, the inventors believe that compressing or merging alarms can reduce the number of alarms and improve the effectiveness of alarms. However, existing alarm compression technologies still find it difficult to meet enterprise-level fault detection needs, especially the need to mine or configure a large number of alarm compression rules, which are inefficient and poorly maintainable, resulting in an inevitable increase in the number of monitoring alarms.
[0050] Most current alarm systems rely on pre-set thresholds or on operations personnel personally reviewing various metrics for monitoring. These static thresholds are often derived from experience and are subjective. Excessively high alarm thresholds can easily miss system failures, resulting in missed alarms. To prevent missed alarms, operations teams must increase alarm sensitivity, which in turn leads to a large number of invalid alarms, or false alarms. These false alarms fail to accurately reflect the scope of an event's business impact, preventing system administrators from accurately diagnosing the problem. Furthermore, a single metric change can trigger a chain reaction of alarms. Invalid alarms overwhelm valid ones, overwhelming system administrators and making it difficult to respond quickly to the flood of alarms, reducing operations efficiency.
[0051] Existing alarm association methods are based on rule-based reasoning. In this approach, general domain knowledge is represented as a set of rules, while knowledge related to specific situations consists of facts. A rule-based system consists of three components: a working memory area, a knowledge base, and an inference engine. The inference mechanism of a rule-based system is a cyclical process of identifying "actions": matching all rules that satisfy the current state to form a conflict set; selecting the best matching rule in the conflict set; and executing the rule. This process is repeated until no matching rules are found.
[0052] Maintain, the present invention provides a scenario-based open system database alarm correlation analysis method, which combines the scenario- and rule-based correlation analysis with the FPGrowth (association rule algorithm) algorithm based on data mining. Through accurate correlation analysis, it suppresses alarm storms, reduces the number of alarms, and thus improves the emergency efficiency of operation and maintenance personnel in analyzing and troubleshooting.
[0053] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0054] like Figure 1 As shown, the present invention provides a database alarm suppression method, including: S100, S200 and S300;
[0055] S100, obtaining a current fault event list;
[0056] Optionally, during the operation of the database system, some faults may occur, requiring prompt handling by operations and maintenance personnel. These faults will generate corresponding fault event tickets and alerts. Because we can obtain newly generated fault event tickets, referred to herein as current fault event tickets, this is not a limitation of the present invention.
[0057] Optionally, the fault event sheet is a well-known concept in the art, and the fault event sheet records the fault information of the corresponding fault, which will not be described in detail in the present invention.
[0058] S200, determining the event category corresponding to the fault event ticket using a pre-established category recognition model;
[0059] Wherein, one fault event corresponds to one event category;
[0060] Optionally, the present invention can pre-define multiple event categories and establish a category recognition model based on the defined event categories, so as to facilitate the subsequent classification of different fault event sheets into corresponding event categories. Figure 1 In the embodiment shown, in certain optional embodiments, the training process of the category recognition model includes: step 1.1, step 1.2, step 1.3 and step 1.4;
[0061] Step 1.1: Construct a corresponding word segmentation dictionary based on predefined event categories, wherein the event categories include database performance, database status, database availability, and database capacity, and the word segmentation dictionary records the feature word segmentations corresponding to each event category;
[0062] Optionally, the present invention can set multiple corresponding feature segmentation words for different event categories, including professional terms in the database and some terms in the default dictionary. For feature segmentation words, the present invention can select and set them according to actual needs, and the present invention does not limit this.
[0063] Step 1.2: The word segmentation dictionary is called by a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining characteristic word segmentations of each historical fault event sheet;
[0064] Optionally, the present invention can perform word segmentation processing on the fault event sheet by calling the word segmentation dictionary through the NLP word segmenter. The NLP word segmenter is a well-known concept in the field and the present invention does not describe it in detail. Word segmentation processing refers to splitting the recorded information in the fault event sheet into multiple independent words (including Chinese words and English words), and then comparing and matching the split words with the characteristic word segmentations in the word segmentation dictionary to determine the characteristic word segmentations involved in the fault event.
[0065] It should be noted that the NLP tokenizer uses the widely used open-source Jieba tokenizer. Jieba performs various functions, including token segmentation, part-of-speech tagging, and named entity recognition. It supports token segmentation in precise, full, and search modes, and supports custom dictionaries. For fault event tickets to be tokenized, the Jieba lexicon must first be imported, followed by data cleansing. Stop words and symbols are removed from the original data using the Jieba lexicon's stop word list. Jieba tokenizes the sentences, concatenating the tokens with spaces. After token segmentation and stop word removal, feature extraction is performed. Jieba uses the TF-IDF algorithm, which selects features based on word frequency and combines them with weights. The TF-IDF algorithm is a commonly used weighting technique in information retrieval and data mining. Once the TF (term frequency) and IDF (inverse document frequency) are obtained, the TF-IDF value for each word is obtained by multiplying them. The top few words are then ranked from highest to lowest, and the feature tokens corresponding to the fault event category are identified.
[0066] Optionally, the historical fault event ticket refers to a fault event ticket that has been generated before, and the present invention does not limit this.
[0067] Step 1.3: performing text vectorization on each of the historical fault event sheets based on the feature word segmentation of each of the historical fault event sheets, thereby obtaining vector features of each of the historical fault event sheets;
[0068] Optionally, to improve the accuracy of the classification model, the present invention does not directly use feature segmentation for training. Instead, the text of the historical fault incident records is vectorized based on the distribution of each feature segmentation in the historical fault incident records, so that the vector features can be used to train the classification model.
[0069] Optionally, text vectorization is a well-known technology in the art and will not be described in detail in this invention. For example, the characteristic segmentation in the historical fault event list is set to "1", and all other words that are not characteristic segmentation are set to "0", thereby achieving text vectorization of the historical fault event list. Among them, the string composed of "0" and "1" is the vector feature of the historical fault event list, and will not be described in detail in this invention.
[0070] Step 1.4: Input the vector features of each of the historical fault event sheets into the model to be trained, thereby training the classification model.
[0071] Optionally, the present invention does not limit the selection and training process of the classification model. For example, in combination with the previous embodiment, in some optional embodiments, the step 1.4 includes:
[0072] The SVM classifier is called, and the vector features of each of the historical fault event sheets are input into the SVM classifier for training, thereby obtaining the classification model.
[0073] Optionally, the SVM classifier is a well-known technology in the art and will not be described in detail in the present invention. It should be noted that the model is trained by calling svm-train in libsvm, an open source SVM classifier. libsvm is a simple, easy-to-use, fast and effective open source software package for SVM pattern recognition and regression.
[0074] S300, sending corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm;
[0075] The alarm suppression rule records the corresponding relationship between different event categories and the alarm information.
[0076] Optionally, as mentioned above, for any fault event ticket, the present invention can confirm the event category to which it belongs and send corresponding alarm information according to the event category, which can reduce the number of alarm messages to a certain extent. The present invention does not impose any restrictions on this.
[0077] Optionally, the present invention does not limit the alarm suppression rules and the process of establishing the alarm suppression rules, and any feasible method falls within the scope of protection of the present invention. Figure 1 In the illustrated embodiment, in certain optional embodiments, the process of establishing the alarm suppression rule includes: step 2.1, step 2.2, step 2.3, step 2.4, step 2.5, step 2.6, and step 2.7;
[0078] Step 2.1, obtaining each of the historical fault event sheets from the fault event sheet database;
[0079] Step 2.2: Determine the event category corresponding to each of the historical fault event sheets using the category recognition model, and extract corresponding subcategory keywords, fault start time, and fault recovery time from each of the historical fault event sheets;
[0080] Optionally, as mentioned above, the trained category recognition model can identify the event category of the historical fault event ticket, so as to facilitate the subsequent association of the fault event ticket with the historical alarm information according to the event category. The present invention does not impose any limitation on this.
[0081] Optionally, as previously mentioned, the fault event ticket records various fault information, including detailed category keywords, fault start time, and fault recovery time. The detailed category keywords further refine the event type, and the fault start time and fault recovery time are both well-known concepts in the art. Of course, the present invention can also extract other fault information, such as the fault event ticket code, alarm time, alarm location, alarm indicators, and alarm description, and the present invention is not limited thereto.
[0082] Step 2.3: Obtain historical alarm information sent for each of the historical fault event sheets from the alarm database, wherein one of the historical fault event sheets corresponds to at least one piece of historical alarm information;
[0083] Step 2.4: extract the corresponding event category, subcategory keyword, fault start time, and fault recovery time from each of the historical alarm information;
[0084] Optionally, the alarm information also records various fault information corresponding to the fault, corresponding to the fault event sheet of the corresponding fault. In order to subsequently associate historical alarm information with historical fault event sheets, the present invention can extract the corresponding event category, subcategory keywords, fault start time, and fault recovery time from the historical alarm information.
[0085] Optionally, there is no necessary order for executing step 2.1 and step 2.3 of the present invention. Step 2.1 may be executed first, or step 2.3 may be executed first, or step 2.1 and step 2.3 may be executed in parallel. The present invention does not impose any limitation on this.
[0086] Step 2.5: Associating each of the historical fault event sheets with the corresponding historical alarm information based on the event category, subcategory keyword, fault start time, and fault recovery time of each of the historical fault event sheets, and the event category, subcategory keyword, fault start time, and fault recovery time of each of the historical alarm information, wherein one piece of historical alarm information is associated with one historical fault event sheet, and one historical fault event sheet is associated with at least one piece of historical alarm information;
[0087] Optionally, as mentioned above, multiple alarms can be generated for a single historical fault event. Therefore, the event categories and subcategory keywords of the associated historical fault event and historical alarm information must be consistent, and the fault start time and fault recovery time of the historical alarm information must be within the time range of the historical fault event (the range from the fault start time to the fault recovery time of the historical fault event).
[0088] Optionally, by associating historical fault event sheets with historical alarm information, the corresponding relationship between the alarm information and the fault event sheets is determined, which is beneficial for subsequent data mining and determining alarm suppression rules. The present invention does not impose any restrictions on this.
[0089] Step 2.6: Grouping the historical fault event sheets and associated historical alarm information by event category and inputting them into the FP-growth data mining algorithm to obtain the FP-growth data mining results. The historical fault event sheets and associated historical alarm information of the same event category are grouped together, and the data mining results reflect the degree of association between the historical alarm information and the corresponding event category.
[0090] Optionally, the data mining algorithm FP-growth is a well-known concept in the art, and the present invention will not describe it in detail. For details, please refer to the relevant description in the art.
[0091] Optionally, before inputting historical alarm information into the data mining algorithm FP-growth, the present invention can first perform data cleaning on the historical alarm information associated with each historical fault event ticket. For example, the present invention can remove active maintenance alarms, which are considered noise data for data mining and need to be filtered out. This can be determined based on whether the alarm information contains a system maintenance flag. The system maintenance flag is a period of system maintenance time manually set in advance by system operations personnel. During this period, a large number of alarms generated by system maintenance will occur. Such alarms are within the expected range and should not be associated with fault events. They are considered noise data and need to be removed. The present invention can also eliminate duplicate alarm data. That is, for the same fault event ticket code, only one alarm with the same alarm indicator and alarm location during the fault period is retained. Here, the fault event ticket code refers to the code that uniquely identifies a fault event ticket. The present invention can also remove alarms with missing key fields. Generally, a transaction database contains multiple transactions. The alarm set corresponding to each fault event ticket code is considered a transaction (historical alarms are associated by event category, fault event ticket code, subcategory keyword, and fault recovery time). The alarms associated with each fault event ticket are considered items. Therefore, the transaction database contains multiple transactions, each transaction contains multiple items, and the alarms after the historical alarm discretization and denoising operations are the items in the transaction database.
[0092] Step 2.7: Establish the alarm suppression rule according to the correlation between each historical alarm information and the corresponding event category.
[0093] Optionally, the present invention does not limit the process of establishing alarm suppression rules based on correlation, and any feasible method falls within the scope of protection of the present invention. For example, in combination with the previous embodiment, in some optional embodiments, step 2.7 includes: step 3.1 and step 3.2;
[0094] Step 3.1: for any of the event categories, execute: arranging the corresponding historical alarm information in order of their relevance;
[0095] Optionally, the correlation reflects the degree of correlation between the historical alarm information and the event type of the corresponding historical fault event ticket. The higher the correlation, the more likely the fault event ticket of the event type is to send a corresponding high-correlation alarm information.
[0096] Step 3.2: Set the historical alarm information with a correlation greater than the correlation threshold as the sendable information of the corresponding event category;
[0097] Optionally, the present invention can set and change the correlation threshold according to actual needs.
[0098] In combination with the previous embodiment, in some optional embodiments, after S300, the method further includes: adjusting the correlation threshold according to the current suppression status of the alarm information by the alarm suppression rule.
[0099] For example, if the correlation threshold is set to 80%, the alarm suppression rule will set historical alarms with a correlation higher than 80% as eligible messages for the corresponding event category. When a new fault event ticket is generated, only historical alarms with a correlation higher than 80% for the corresponding event category will be sent. There is no limit on the number of messages that can be sent, but this will reduce the number of alarms.
[0100] Of course, the present invention can also set the top N historical alarm information with higher correlation as the sendable information of the corresponding event category, where N is an integer greater than 1, and the present invention does not impose any limitation on this.
[0101] The step S300 includes: determining and sending corresponding sendable information according to the event category.
[0102] like Figure 2 As shown, the present invention provides a database alarm suppression device, comprising: a current event single obtaining unit 100, an event category identifying unit 200 and an alarm suppression unit 300;
[0103] The current event sheet obtaining unit 100 is used to obtain the current fault event sheet;
[0104] The event category identification unit 200 is configured to determine the event category corresponding to the fault event ticket using a pre-established category identification model, wherein one fault event ticket corresponds to one event category;
[0105] The alarm suppression unit 300 is configured to send corresponding alarm information according to the event category and an alarm suppression rule pre-established by a data mining algorithm, wherein the alarm suppression rule records the correspondence between different event categories and the alarm information.
[0106] Combine Figure 2 In the embodiment shown, in certain optional embodiments, the apparatus further comprises a model training unit;
[0107] The model training unit is used to perform the training process of the category recognition model;
[0108] The model training unit includes: a dictionary construction unit, a word segmentation unit, a vectorization unit and a training unit;
[0109] A dictionary construction unit is used to construct a corresponding word segmentation dictionary according to different predefined event categories, wherein the event categories include database performance, database status, database availability and database capacity, and the word segmentation dictionary records the characteristic word segmentations corresponding to each of the event categories;
[0110] A word segmentation unit, configured to call the word segmentation dictionary through a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining a characteristic word segmentation of each historical fault event sheet;
[0111] A vectorization unit, configured to perform text vectorization on each of the historical fault event sheets according to the feature word segmentation of each of the historical fault event sheets, thereby obtaining vector features of each of the historical fault event sheets;
[0112] The training unit is used to input the vector features of each of the historical fault event sheets into the model to be trained, thereby training the classification model.
[0113] In combination with the previous embodiment, in some optional embodiments, the training unit includes: a training subunit;
[0114] The training subunit is used to call the SVM classifier and input the vector features of each of the historical fault event sheets into the SVM classifier for training, thereby obtaining the classification model.
[0115] Combine Figure 2 In the illustrated embodiment, in certain optional embodiments, the apparatus further comprises a rule establishing unit;
[0116] The rule establishing unit is used to execute the process of establishing the alarm suppression rule;
[0117] The rule establishing unit includes: a historical event obtaining unit, a first information determining unit, a historical alarm obtaining unit, a second information determining unit, an association unit, a mining unit and a rule unit;
[0118] A historical event sheet obtaining unit, configured to obtain each of the historical fault event sheets from a fault event sheet database;
[0119] A first information determination unit is configured to determine the event category corresponding to each of the historical fault event sheets using the category recognition model, and extract corresponding subcategory keywords, fault start time, and fault recovery time from each of the historical fault event sheets;
[0120] A historical alarm obtaining unit, configured to obtain, from an alarm database, historical alarm information sent for each of the historical fault event sheets, wherein one of the historical fault event sheets corresponds to at least one piece of the historical alarm information;
[0121] The second information determination unit is used to extract the corresponding event category, subcategory keyword, fault start time and fault recovery time from each of the historical alarm information;
[0122] an associating unit, configured to associate each of the historical fault event sheets with the corresponding historical alarm information according to the event category, subcategory keyword, fault start time, and fault recovery time of each of the historical fault event sheets, and the event category, subcategory keyword, fault start time, and fault recovery time of each of the historical alarm information, wherein one piece of the historical alarm information is associated with one historical fault event sheet, and one historical fault event sheet is associated with at least one piece of the historical alarm information;
[0123] a mining unit, configured to group the historical fault event sheets and the associated historical alarm information by different event categories and input them into a data mining algorithm FP-growth, thereby obtaining data mining results of the FP-growth, wherein historical fault event sheets and the associated historical alarm information of the same event category are grouped together, and the data mining results reflect the degree of association between the historical alarm information and the corresponding event category;
[0124] The rule unit is used to establish the alarm suppression rule according to the correlation between each historical alarm information and the corresponding event category.
[0125] In combination with the previous embodiment, in some optional embodiments, the rule unit includes: a sorting unit and a setting unit;
[0126] The sorting unit is configured to, for any of the event categories, execute: arranging the corresponding historical alarm information in order according to the magnitude of the corresponding relevance;
[0127] A setting unit, configured to set historical alarm information with a relevance greater than a relevance threshold as transmittable information of a corresponding event category;
[0128] The alarm suppression unit 300 includes: an alarm suppression subunit;
[0129] The alarm suppression subunit is used to determine and send corresponding sendable information according to the event category.
[0130] In combination with the previous embodiment, in some optional embodiments, the apparatus further includes: a threshold adjustment unit;
[0131] The threshold adjustment unit is used to adjust the correlation threshold according to the current suppression of the alarm information by the alarm suppression rule after sending the corresponding alarm information according to the event category and the alarm suppression rule established in advance through the data mining algorithm.
[0132] The present invention provides a computer-readable storage medium having a program stored thereon, wherein when the program is executed by a processor, the method for suppressing database alarms described in any one of the above is implemented.
[0133] like Figure 3 As shown, the present invention provides an electronic device 70, which includes at least one processor 701, and at least one memory 702 and a bus 703 connected to the processor 701; wherein the processor 701 and the memory 702 communicate with each other through the bus 703; the processor 701 is used to call the program instructions in the memory 702 to execute any of the database alarm suppression methods described above.
[0134] In this application, relational terms such as first and second, etc. are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0135] Each embodiment in this specification is described in a related manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiment is generally similar to the method embodiment, so the description is relatively simple. For related parts, refer to the description of the method embodiment.
[0136] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
[0137] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.
Claims
1. A database alarm suppression method, characterized in that: include: Obtain current troubleshooting tickets; Determine the event category corresponding to the fault event ticket by using a pre-established category recognition model, wherein one fault event ticket corresponds to one event category; Sending corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm, wherein the alarm suppression rules record the corresponding relationship between different event categories and the alarm information; The process of establishing the alarm suppression rule includes: Obtain each historical fault event ticket from the fault event ticket database; Determine the event category corresponding to each of the historical fault event sheets using the category recognition model, and extract corresponding subcategory keywords, fault start time, and fault recovery time from each of the historical fault event sheets; Acquire historical alarm information sent for each of the historical fault event sheets from the alarm database, wherein one of the historical fault event sheets corresponds to at least one piece of the historical alarm information; Extracting corresponding event categories, subcategory keywords, fault start time, and fault recovery time from each of the historical alarm information; According to the event category, subcategory keyword, fault start time and fault recovery time of each historical fault event ticket, and the event category, subcategory keyword, fault start time and fault recovery time of each historical alarm information, each historical fault event ticket is associated with the corresponding historical alarm information, wherein one piece of historical alarm information is associated with one historical fault event ticket, and one historical fault event ticket is associated with at least one piece of historical alarm information; The historical fault event sheets and the associated historical alarm information are grouped according to different event categories and input into a data mining algorithm FP-growth, thereby obtaining data mining results of the FP-growth, wherein historical fault event sheets and the associated historical alarm information of the same event category are grouped together, and the data mining results reflect the degree of association between the historical alarm information and the corresponding event category; The alarm suppression rule is established according to the correlation between each of the historical alarm information and the corresponding event category.
2. The method according to claim 1, characterized in that The training process of the category recognition model includes: Constructing a corresponding word segmentation dictionary based on different predefined event categories, wherein the event categories include database performance, database status, database availability, and database capacity, and the word segmentation dictionary records the characteristic word segmentations corresponding to each event category; The word segmentation dictionary is called by a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining characteristic word segmentations of each historical fault event sheet; Performing text vectorization on each of the historical fault event sheets based on the feature word segmentation of each of the historical fault event sheets, thereby obtaining vector features of each of the historical fault event sheets; The vector features of each of the historical fault event sheets are input into the model to be trained for training, thereby training a classification model.
3. The method according to claim 2, characterized in that Inputting the vector features of each of the historical fault event sheets into the model to be trained for training, thereby training to obtain the classification model, includes: The SVM classifier is called, and the vector features of each of the historical fault event sheets are input into the SVM classifier for training, thereby obtaining the classification model.
4. The method according to claim 1, wherein The establishing of the alarm suppression rule according to the correlation between each of the historical alarm information and the corresponding event category includes: For any of the event categories, the following steps are performed: arranging the corresponding historical alarm information in order of their relevance; Set the historical alarm information with a correlation greater than the correlation threshold as the sendable information of the corresponding event category; The sending of corresponding alarm information according to the event category and the alarm suppression rules pre-established by the data mining algorithm includes: According to the event category, corresponding sendable information is determined and sent.
5. The method according to claim 4, characterized in that After sending the corresponding alarm information according to the event category and the alarm suppression rule pre-established by the data mining algorithm, the method further includes: The relevance threshold is adjusted according to the current suppression status of the alarm information by the alarm suppression rule.
6. A database alarm suppression device, characterized in that: include: Current event list acquisition unit, event category identification unit and alarm suppression unit; The current event sheet obtaining unit is used to obtain the current fault event sheet; The event category identification unit is configured to determine the event category corresponding to the fault event ticket using a pre-established category identification model, wherein one fault event ticket corresponds to one event category; The alarm suppression unit is configured to send corresponding alarm information according to the event category and an alarm suppression rule established in advance by a data mining algorithm, wherein the alarm suppression rule records the correspondence between different event categories and the alarm information; The process of establishing the alarm suppression rule includes: Obtain each historical fault event ticket from the fault event ticket database; Determine the event category corresponding to each of the historical fault event sheets using the category recognition model, and extract corresponding subcategory keywords, fault start time, and fault recovery time from each of the historical fault event sheets; Acquire historical alarm information sent for each of the historical fault event sheets from the alarm database, wherein one of the historical fault event sheets corresponds to at least one piece of the historical alarm information; Extracting corresponding event categories, subcategory keywords, fault start time, and fault recovery time from each of the historical alarm information; According to the event category, subcategory keyword, fault start time and fault recovery time of each historical fault event ticket, and the event category, subcategory keyword, fault start time and fault recovery time of each historical alarm information, each historical fault event ticket is associated with the corresponding historical alarm information, wherein one piece of historical alarm information is associated with one historical fault event ticket, and one historical fault event ticket is associated with at least one piece of historical alarm information; The historical fault event sheets and the associated historical alarm information are grouped according to different event categories and input into a data mining algorithm FP-growth, thereby obtaining data mining results of the FP-growth, wherein historical fault event sheets and the associated historical alarm information of the same event category are grouped together, and the data mining results reflect the degree of association between the historical alarm information and the corresponding event category; The alarm suppression rule is established according to the correlation between each of the historical alarm information and the corresponding event category.
7. The device according to claim 6, characterized in that The device also includes a model training unit; The model training unit is used to perform the training process of the category recognition model; The model training unit includes: a dictionary construction unit, a word segmentation unit, a vectorization unit and a training unit; The dictionary construction unit is configured to construct a corresponding word segmentation dictionary according to different predefined event categories, wherein the event categories include database performance, database status, database availability, and database capacity, and the word segmentation dictionary records the characteristic word segmentations corresponding to each of the event categories; The word segmentation unit is used to call the word segmentation dictionary through a word segmenter to perform word segmentation processing on each historical fault event sheet, thereby determining the characteristic word segmentation of each historical fault event sheet; The vectorization unit is used to perform text vectorization on each of the historical fault event sheets according to the feature segmentation of each of the historical fault event sheets, thereby obtaining the vector features of each of the historical fault event sheets; The training unit is used to input the vector features of each historical fault event list into the model to be trained for training, thereby training to obtain a classification model.
8. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the database alarm suppression method according to any one of claims 1 to 5 is implemented.
9. An electronic device, characterized in that: The electronic device includes at least one processor, and at least one memory and bus connected to the processor; wherein the processor and the memory communicate with each other through the bus; the processor is used to call program instructions in the memory to execute the database alarm suppression method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Alarm information processing method and apparatus
CN106713017A
Warning information filter method and device
CN108073611A