An event tree updating method and device

By having the machine autonomously update the event tree and using event chains and historical data to generate initial weights, the problems of manual effort and low accuracy caused by relying on expert experience are solved, and more efficient and accurate event tree analysis is achieved.

CN115249067BActive Publication Date: 2025-09-23XFUSION DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110452124.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-26
Publication Date
2025-09-23
Estimated Expiration
2041-04-26

AI Technical Summary

Technical Problem

The existing technology relies on expert experience to construct and update event trees, which consumes a lot of manual effort and has low accuracy.

Method used

By obtaining the event chain of the fault event, the machine is used to autonomously update the event tree, generate initial weights based on historical data, update the real-time weights of the target events based on the event chain, and receive user instructions to add or delete events when necessary, and adjust the causal relationship in the event tree.

Benefits of technology

It reduces labor costs, improves the accuracy and applicability of event trees, and can more accurately characterize the causal relationship and probability between events, supporting more accurate fault analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115249067B_ABST
    Figure CN115249067B_ABST
Patent Text Reader

Abstract

A method and device for updating an event tree is used to solve the problem in the prior art of manually constructing and updating an event tree, which consumes a lot of manual effort and has low accuracy. In this application, the method includes: obtaining a first event chain, the first event chain including N first events determined from the event tree according to a fault event, the first first event of the N first events being associated with the fault event, the nth first event of the N first events being the result event of the n+1th first event, and n being any positive integer from 1 to (N-1); determining a target event from the event tree based on the N first events; updating the real-time weight of the target event in the event tree, the real-time weight of the target event being used to characterize the probability that the target event leads to the result event of the target event after obtaining the first event chain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and device for updating an event tree. Background Art

[0002] Fault tree analysis (FTA) is a top-down deductive failure analysis method that uses Boolean logic to combine low-level events and analyze undesirable states in a device. Event tree analysis is primarily used in the fields of safety engineering and reliability engineering to understand the causes of device failures and find the best ways to reduce risks, or to confirm the incidence of a safety incident or specific device failure. The event tree is the core of FTA. An event tree is a logic diagram that indicates which device component failures, external events, or combinations thereof will cause a device to experience a predetermined failure. The main components of this logic diagram are events and logic gates. Events are used to describe the state of a system, unit, or component failure, and logic gates are used to identify the logical relationships between events.

[0003] Event trees are typically manually constructed and updated by experts based on their experience. For example, experts conduct a failure mode and effects analysis (FMEA) based on the equipment's design, extracting failure modes and constructing an event tree. However, if the cause of a device failure changes significantly during actual use, experts will need to re-examine the entire event tree and update it.

[0004] Based on this, the current event tree construction and updating methods that rely on expert experience consume a lot of manual effort, and the accuracy of the event tree is affected by manual experience. Summary of the Invention

[0005] The present application provides an event tree updating method and device, which are used to solve the problem in the prior art of manually constructing and updating event trees, which consumes a lot of manual effort and has low accuracy.

[0006] In a first aspect, the present application provides a method for updating an event tree, comprising: obtaining a first event chain, the first event chain including N first events determined from an event tree based on a fault event, the first first event among the N first events being associated with the fault event, the nth first event among the N first events being a result event of the n+1th first event, where n is any positive integer from 1 to (N-1); determining a target event from the event tree based on the N first events; updating the real-time weight of the target event in the event tree, the real-time weight of the target event being used to characterize the probability that the target event leads to a result event of the target event after obtaining the first event chain.

[0007] In the above technical solution, the first event chain corresponding to the fault event is determined based on the fault event and the event tree. This technical solution is based on machine autonomous implementation, does not require human intervention, can reduce labor costs, and is not affected by human experience. Furthermore, after determining the first event chain, the probability of the target event can be updated based on the multiple first events in the first event chain to obtain an updated event tree. The updated event tree can more accurately represent the causal relationship between the various events, as well as the probability of each event occurring, which facilitates subsequent more accurate event analysis.

[0008] In one possible implementation, before obtaining the first event chain, multiple historical data can also be obtained; for each historical data in the multiple historical data, the event chain corresponding to the historical data is determined, and the event chain corresponding to the historical data includes K events, and the kth event in the K events is the result event of the k+1th event, and k is any positive integer from 1 to (K-1); according to the event chains corresponding to the multiple historical data, an event tree in an initial state is generated, and in the event tree in the initial state, the initial weight corresponding to any event is used to characterize the probability of the result event of the event leading to the event, and the real-time weight of any event is the same as the initial weight.

[0009] In the above technical solution, based on the causally related events included in the historical data, the event chain corresponding to the historical data can be determined. Furthermore, based on the event chains corresponding to the multiple historical data, an event tree in its initial state is generated, where any node in the event tree in its initial state corresponds to both a real-time weight and an initial weight. This construction method, based on historical data, helps to obtain a more accurate event tree.

[0010] In one possible implementation, a target event is determined from an event tree based on N first events, including: for each first event in the N first events, the first event and the second event are determined as target events, where the second event is an event in the event tree that corresponds to the same result event as the first event.

[0011] In the above technical solution, the N first events in the first event chain can affect the real-time weights of the associated events in the event tree. When the event tree is updated according to the N first events in the first event chain, the second event associated with the first event is determined based on each first event, and the real-time weights of the first event and the second event are updated to obtain a more accurate event tree.

[0012] In one possible implementation, the method further includes: obtaining a user instruction, the user instruction including a second event chain, the second event chain including M third events, the first third event of the M third events being associated with a fault event, the mth third event of the M third events being a result event of the m+1th third event, where m is any positive integer from 1 to (M-1); and adding a new event to the event tree based on the M third events. Accordingly, determining a target event from the event tree based on the N first events may include: determining the target event from the event tree after the newly added event based on the N first events.

[0013] In the above technical solution, since the cause of the fault may change over time, the causal relationship between events in the event tree determined based on multiple historical data may not be applicable to the current fault analysis. Based on this, when it is determined that the solution corresponding to the first event chain cannot resolve the fault event, the system can receive instructions from the user, including a second event chain determined by an expert, add certain new events to the event tree, and promptly update the causal relationship between events in the event tree, thereby obtaining an event tree suitable for the current fault analysis.

[0014] In one possible implementation, based on M third events, a new event is added to the event tree, including: when the cause event of the mth third event in the event tree does not include the m+1th third event, the m+1th third event is added to the cause event of the mth third event in the event tree.

[0015] In the above technical solution, it is possible to determine whether the cause event of each third event in the second event chain is included in the event tree, thereby determining the events that need to be added to the event tree. The real-time weights and initial weights of the newly added events and the events corresponding to the same result event as the newly added events are updated to obtain a more accurate event tree.

[0016] In one possible implementation, after updating the real-time weight of the target event in the event tree, the fourth event can be deleted from the event tree when the real-time weight of the fourth event in the event tree meets the first condition, and the first condition is determined based on the initial weight of the fourth event and a preset growth factor.

[0017] In the above technical solution, since the cause of a fault may change over time, that is, the probability of certain events leading to the fault may gradually decrease, the real-time weight of certain events in the event tree may also gradually decrease. Deleting certain events that have not appeared for a long time in the event tree can help improve the efficiency of the entire fault analysis.

[0018] In one possible implementation, after deleting the fourth event from the event tree, the real-time weight and initial weight of the fifth event in the event tree may also be updated, where the fifth event is an event in the event tree that corresponds to the same result event as the fourth event. Exemplarily, the sum of the real-time weight of the fourth event and the real-time weight of the fifth event in the event tree may be 1, and / or the sum of the initial weight of the fourth event and the initial weight of the fifth event in the event tree may be 1.

[0019] In the above technical solution, after deleting the fourth event from the event tree, the real-time weight and initial weight of the fifth event corresponding to the same result event as the fourth event are updated, so that a more accurate event tree can be obtained.

[0020] In a second aspect, the present application provides an event tree updating device, including a processing module for obtaining a first event chain, the first event chain including N first events determined from the event tree according to the fault event, the first first event among the N first events being associated with the fault event, the nth first event among the N first events being the result event of the n+1th first event, and n being any positive integer from 1 to (N-1); determining a target event from the event tree according to the N first events; an updating module for updating the real-time weight of the target event in the event tree, the real-time weight of the target event being used to characterize the probability that the target event leads to a result event of the target event after the processing module obtains the first event chain.

[0021] In one possible implementation, the processing module may also obtain multiple historical data before obtaining the first event chain; for each historical data in the multiple historical data, determine the event chain corresponding to the historical data, the event chain corresponding to the historical data includes K events, the kth event in the K events is the result event of the k+1th event, and k is any positive integer from 1 to (K-1); according to the event chains corresponding to the multiple historical data, generate an event tree in an initial state, in the event tree in the initial state, the initial weight corresponding to any event is used to characterize the probability of the result event of the event leading to the event, and the real-time weight of any event is the same as the initial weight.

[0022] In one possible implementation, when the processing module determines the target event from the event tree based on the N first events, it is specifically used to: for each first event in the N first events, determine the first event and the second event as target events, where the second event is an event in the event tree that corresponds to the same result event as the first event.

[0023] In one possible implementation, the processing module can also obtain user instructions, which include a second event chain, the second event chain includes M third events, the first third event among the M third events is associated with the fault event, the mth third event among the M third events is the result event of the m+1th third event, and m is any positive integer from 1 to (M-1); according to the M third events, the control update module adds a new event to the event tree; when the processing module determines the target event from the event tree based on the N first events, it is specifically used to: determine the target event from the event tree after the newly added event based on the N first events.

[0024] In one possible implementation, when the processing module controls the update module to add a new event to the event tree based on the M third events, it is specifically used to: when the cause event of the mth third event in the event tree does not include the m+1th third event, control the update module to add the m+1th third event to the cause event of the mth third event in the event tree.

[0025] In one possible implementation, the update module may also delete the fourth event from the event tree after updating the real-time weight of the target event in the event tree if the real-time weight of the fourth event in the event tree meets the first condition, where the first condition is determined based on the initial weight of the fourth event and a preset growth factor.

[0026] In one possible implementation, the update module may further update the real-time weight of the fifth event and the initial weight of the fifth event in the event tree after deleting the fourth event from the event tree, where the fifth event is an event in the event tree that corresponds to the same result event as the fourth event.

[0027] Illustratively, the sum of the real-time weight of the fourth event and the real-time weight of the fifth event in the event tree may be 1, and / or the sum of the initial weight of the fourth event and the initial weight of the fifth event in the event tree may be 1.

[0028] In a third aspect, the present application provides a computer-readable storage medium storing a computer program or instructions. When the computer program or instructions are executed by a computing device, the computing device can execute the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0029] In a fourth aspect, the present application provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a computing device, it implements the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0030] In a fifth aspect, the present application provides a computing device comprising a processor, wherein the processor is connected to a memory, the memory stores a computer program, and the processor is used to execute the computer program stored in the memory, so that the computing device can implement the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0031] The technical effects that can be achieved in any of the second to fifth aspects mentioned above can refer to the description of the beneficial effects in the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A schematic diagram of the architecture of a fault analysis system provided in this application;

[0033] Figure 2 A schematic diagram of generating an event tree based on a historical data set provided by this application;

[0034] Figure 3 A schematic diagram of a process for generating a life event tree provided in this application;

[0035] Figure 4 A flowchart of the first method for updating an event tree provided in this application;

[0036] Figure 5 A schematic diagram of a set of update event trees provided for this application;

[0037] Figure 6 A flowchart of the second method for updating the event tree provided in this application;

[0038] Figure 7 A flowchart of the third method for updating the event tree provided in this application;

[0039] Figure 8 A flowchart of the fourth method for updating the event tree provided in this application;

[0040] Figure 9 A schematic diagram of an event tree corresponding to a server provided in this application;

[0041] Figure 10 A flowchart of a fault analysis method provided in this application;

[0042] Figure 11 A schematic diagram of the architecture of another fault analysis system provided in this application;

[0043] Figure 12 A schematic diagram of the structure of a device for updating an event tree provided by this application;

[0044] Figure 13This is a schematic diagram of the structure of another device for updating an event tree provided by this application. DETAILED DESCRIPTION

[0045] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0046] The embodiments of the present application are applicable to fault analysis of various devices, such as fault analysis of various production machines in manufacturing enterprises, fault analysis of servers, server clusters or network links in various network systems, etc.

[0047] In this application, a fault may be referred to as a fault event, an event, an accident, etc. Correspondingly, a fault analysis may be referred to as an event analysis, an accident analysis, etc., and an event tree may be referred to as a fault tree, etc.

[0048] like Figure 1 The present application provides an exemplary architectural diagram of a fault analysis system, which includes a target device, an analysis device, and a management device. Specifically, the management device includes a pre-generated event tree. The analysis device can obtain the event tree from the management device. After obtaining the fault event reported by the target device, the analysis device can analyze the fault event according to the event tree to obtain an event chain consisting of multiple events, and then determine a processing plan based on the event chain. Furthermore, the analysis device can also send the event chain to the management device, and the management device updates the current event tree based on the event chain from the analysis device.

[0049] The management device can generate an event tree in an initial state based on a pre-input historical data set. The historical data set includes multiple historical data. For each historical data set, the historical data may include K events, and the K events have a causal relationship, where K is a positive integer greater than or equal to 2.

[0050] Optionally, among the K events in any historical data, there is a causal relationship between the kth event and the k+1th event, where k is any positive integer from 1 to (K-1). Exemplarily, the kth event is caused by the k+1th event. It can be understood that the kth event is the result event of the k+1th event, or the k+1th event is the cause event of the kth event. Another exemplary embodiment is that the k+1th event is caused by the kth event. It can be understood that the kth event is the cause event of the k+1th event, or the k+1th event is the result event of the kth event. For the convenience of description, the following is an example in which the kth event is caused by the k+1th event.

[0051] The management device further includes a generation module. The generation module is used to generate multiple event chains based on the historical data set. In an optional implementation, the generation module can generate an event chain corresponding to any historical data in the historical data set based on K events included in the historical data set.

[0052] In this application, event trees can be divided into two types:

[0053] First, the event chain included in the event tree is specifically an event traceability chain (referred to as a traceability chain for short), where the kth event is caused by the k+1th event. For example, if a certain historical data includes event A, event B, and event C, where event A is caused by event B, and event B is caused by event C, the generation module can generate a traceability chain based on the causal relationship between event A, event B, and event C in the historical data. For example, the traceability chain is event A (the first event) → event B (the second event) → event C (the third event).

[0054] Second, the event chain included in the event tree is specifically an event propagation chain (abbreviated as a propagation chain), where the k+1th event is caused by the kth event. For example, if a certain historical data includes event A, event B, and event C, where event C is caused by event B, and event B is caused by event A, the generation module can generate a propagation chain based on the causal relationship between events A, B, and C in the historical data. For example, the propagation chain is event A (the first event) → event B (the second event) → event C (the third event).

[0055] It should be understood that in an event chain, an event can be embodied in the form of a node, that is, an event chain can include multiple nodes, each node can correspond to an event, and the causal relationship between two events in the historical data corresponds to the parent-child relationship between the two nodes in the event chain. For example, in the above-mentioned traceability chain, the node corresponding to event A is the parent node of the node corresponding to event B, and the node corresponding to event B is the child node of the node corresponding to event A; for example, in the above-mentioned propagation chain, the node corresponding to event A is the parent node of the node corresponding to event B, and the node corresponding to event B is the child node of the node corresponding to event A. In this application, any event in an event chain can be replaced by a node corresponding to the event; any two events with a causal relationship can be understood as two nodes with a parent-child relationship; for the convenience of description below, only events are used for explanation.

[0056] The management device may further include a synthesis module. The generation module generates an event chain corresponding to each historical data item in the historical data set, thereby obtaining multiple event chains corresponding to the historical data set. The synthesis module can merge events based on the causal relationships between events in each event chain to obtain an event tree. For example, the synthesis module can merge the same cause events that lead to the same result event into the same cause event.

[0057] like Figure 2 This application provides an exemplary schematic diagram of generating an event tree based on a historical data set. For example, Figure 2 The event chain included in the event tree is specifically a traceability chain. Figure 2 In (a), the generation module generates three event chains (which can be represented as chain 1, chain 2 and chain 3), where chain 1 includes event A → event B → event C, where event A is caused by event B, and event B is caused by event C. Chain 2 includes event A → event D → event E, where event A is caused by event D, and event D is caused by event E. Chain 3 includes event A → event D → event F, where event A is caused by event D, and event D is caused by event F. The synthesis module can perform event merging based on the events in each chain to obtain the following: Figure 2 The event tree shown in (b).

[0058] The management device may further include a value assignment module. The value assignment module may assign a corresponding weight to each event in the event tree. Furthermore, to facilitate calculation of the weight of each event, the weight of the event may be determined based on the probability of occurrence of the event in multiple historical data and the causal relationship of the event.

[0059] For example, Figure 2 In (c), event C is the only causal event of event B, so the weight of event C is 1. Event D may be caused by event E or event F. In this case, both event E and event F are causal events of event D. Based on the probability of event E causing event D and the probability of event F causing event D, we can further determine that the weights of event E and event F are both 1 / 2.

[0060] In this application, if a result event corresponds to a cause event, the weight of this cause event is 1; if a result event corresponds to multiple cause events, the sum of the weights of the multiple cause events corresponding to this result event is 1.

[0061] For example, the event tree generated by the management device can be as follows: Figure 2 As shown in (c), each event in the event tree corresponds to its own weight. The event tree currently generated by the management device can be understood as an event tree in an initial state, and the weight of each event in the event tree can be understood as an initial weight.

[0062] It should be noted that an event tree without weights assigned to each node can be called an inanimate event tree, while an event tree with weights assigned to each node can be called a living event tree. The growth of the event tree is measured by the weights of each event in the event tree. Accordingly, the weights of each event in the event tree can be called the life value of each event. Furthermore, the value assignment module in the management device can also be called a life-giving module.

[0063] like Figure 3 A flow chart of generating a living event tree is provided as an example in this application. The generation module obtains a historical data set, generates a corresponding event chain based on each historical data in the historical data set, and the synthesis module generates an inanimate event tree based on the event chain corresponding to each historical data. The life-giving module (also known as the assignment module) gives a life value (i.e., a weight) to each event in the inanimate event tree to obtain a living event tree.

[0064] Specifically, the analysis device includes a submission module and an analysis module. The analysis module can obtain fault events reported by target devices and analyze the fault events based on the event tree obtained from the management device to obtain the event chain corresponding to the fault event. The analysis module can also generate a fault analysis report corresponding to the fault event based on the event chain and provide a solution for handling the event. Furthermore, the submission module submits the event chain corresponding to the fault event to the management device, which then updates the current event tree.

[0065] Based on the event tree generated above, the present application provides a method for updating the event tree. In a specific implementation, the management device can add an event to the generated event tree, delete an event, or change the weight of an event. In one example, the management device also includes an update module, which is used to execute the method for updating the event tree.

[0066] It should be noted that the management device includes the generation module, synthesis module, assignment module, and update module, all of which are based on the logical functions of the management device. In other examples, the management device can also be divided into other modules. Similarly, the analysis device includes the submission module and analysis module, which are also based on the logical functions of the analysis device. In other examples, the analysis device can also be divided into other modules.

[0067] For ease of description, the following description directly uses the interaction between the management device and the analysis device.

[0068] like Figure 4 This is a flowchart of a first method for updating an event tree exemplified in this application, in which:

[0069] In step 401, the analysis device generates a first event chain based on the fault event and the event tree. The first event chain is the event chain corresponding to the fault event determined by the analysis device. Specifically, the first event chain includes N first events determined by the analysis device from the event tree based on the fault event, where N is a positive integer greater than or equal to 2.

[0070] If the target device determines that it is currently experiencing an operational fault, it generates a fault event and sends the fault event to the analysis device. Optionally, the target device may also send operational data to the analysis device, where the operational data refers to relevant data during the target device's operation, such as operational status data, operational monitoring indicators, and operational logs. In one optional approach, the analysis device may analyze the fault event based on a currently stored event tree to obtain a first event chain. Alternatively, the analysis device may analyze the target device's operational data and the fault event based on a currently stored event tree to obtain the first event chain.

[0071] Among them, the event tree stored in the analysis device can be obtained by the analysis device from the management device after the analysis device receives the fault event, or the event tree stored in the analysis device can be obtained by the analysis device from the management device in advance. For example, the analysis device can request the event tree in the current management device from the management device at a regular period.

[0072] In an optional manner, the first event among the N first events is associated with a fault event, and the first first event may be a fault event. The nth first event among the N first events is a result event of the n+1th first event, where n is any positive integer from 1 to (N-1). For example, the event tree in the analysis device is as follows: Figure 2 In (c), the fault event is event A. The analysis device determines that event A is caused by event B and event B is caused by event C based on event A and the operating data of the target device. The analysis device then determines that the first event chain is event A→event B→event C, where event A, event B, and event C are all the first events in the first event chain.

[0073] Step 402: The analysis device determines a first solution corresponding to the first event chain based on the first event chain, wherein the first solution is used to resolve the fault event of the target device.

[0074] In one example, the analysis device includes a plurality of first correspondences between event chains and solutions. The analysis device may determine a first solution from the plurality of first correspondences according to the first event chain.

[0075] In another example, the analysis device includes a second correspondence between events and solutions. The analysis device can determine a first solution from the plurality of second correspondences based on a root event in the first event chain. The root event in the first event chain is the root cause of the fault event. For example, if the first event chain is event A → event B → event C, then the fault event is event A, and event C is the root cause of event A.

[0076] The analysis device may send the first solution to the target device. Accordingly, after receiving the first solution, the target device executes the first solution and determines whether the fault event is successfully resolved by the first solution. Optionally, after executing the first solution, the target device may send feedback information to the analysis device, indicating whether the target device successfully resolved the fault event by using the first solution.

[0077] In addition, the analysis device may also present the first solution to the user, or the analysis device may present the first solution to the user via the target device, and the user may perform corresponding manual operations based on the first solution. Accordingly, the user may also provide feedback on the processing status to the analysis device via the target device. This application is not limited to this.

[0078] Step 403: The analysis device determines that the first solution successfully resolves the fault event and sends a first event chain to the management device. The first event chain is used by the management device to update the current event tree.

[0079] Step 404: The management device determines a target event in the event tree according to the N first events in the first event chain, and updates the real-time weight of the target event in the event tree.

[0080] It is previously stated that the weight of each event in the event tree may include a real-time weight and an initial weight, wherein the initial weight is the initial weight of each event preliminarily determined by the management device based on the historical data set when constructing the event tree in the above embodiment. The real-time weight may be the weight obtained by the management device updating the initial weight of the event in the event tree after receiving the first event chain from the analysis device. In an optional manner, when the management device determines the event tree based on the historical data set, the management device may set the real-time weight of the same event to be the same as the initial weight.

[0081] For example, referring to the example of the above-mentioned assignment module determining the initial weights of each event in the event tree, it can be seen that if a result event corresponds to a cause event, then the real-time weight of this cause event is 1; if a result event corresponds to multiple cause events, then the sum of the real-time weights of the multiple cause events corresponding to this result event is 1.

[0082] In one optional embodiment, for each of the N first events, the management device determines, based on the result event of the first event, a second event corresponding to the same result event as the first event, where the second event may be one or more. The first event and the second event are referred to as target events, and the real-time weight of the target event in the event tree is updated.

[0083] like Figure 5 A schematic diagram of a set of update event trees provided as an example in this application, exemplarily, Figure 5 The event chain included in the event tree is specifically a traceability chain. Figure 5 In (a), the first event chain is event A → event D → event F. For event D, the management device can determine that the cause event corresponding to the same result event A as event D also includes event B, that is, the target events are event B and event D. The management device updates the real-time weight of event B from 1 / 3 to 1 / 4, and updates the real-time weight of event D from 2 / 3 to 3 / 4. For event F, the management device can determine that the cause event corresponding to the same result event D as event F also includes event E, that is, the target events are event E and event F. The management device updates the real-time weight of event E from 1 / 2 to 1 / 3, and updates the real-time weight of event F from 1 / 2 to 2 / 3.

[0084] However, it should be noted that the cause of a target device failure may change over time. Therefore, the event tree determined by the management device based on historical data sets may not be applicable to the current target device failure analysis. For example, if event A occurs on the target device, the actual cause is event F, which leads to event B, which in turn leads to event A. However, since there is no causal relationship between event B and event F in the current event tree, the event chain determined based on the current event tree is not the actual event chain that led to the target device failure.

[0085] To this end, the present application provides a method for managing the device update event tree when the fault event is not successfully handled according to the first solution. Figure 6 A flowchart of the second method for updating an event tree is shown as an example.

[0086] Step 601: The management device receives a user instruction, where the user instruction includes a second event chain.

[0087] In one optional approach, after determining that the current first solution failed to successfully address the fault event, the analysis device can notify the expert that the event tree is not applicable to the analysis of the current fault event. Alternatively, the analysis device can send an instruction to the management device, which, based on the instruction, notifies the expert that the event tree is not applicable to the analysis of the current fault event. Accordingly, the expert can analyze the fault event and the target device's operating data based on prior experience, identify multiple causally related third events that led to the fault event, and then form a second event chain based on these multiple causally related third events.

[0088] In one optional embodiment, the second event chain includes M third events, the first of the M third events is associated with a fault event, and the first first event may be a fault event. The mth third event of the M third events is a result event of the m+1th third event, where m is any positive integer between 1 and (M-1).

[0089] Step 602: The management device adds a new event to the event tree according to the M third events in the second event chain.

[0090] Exemplarily, the management device can determine whether the cause event of the mth third event in the current event tree includes the m+1th third event. If not, a new cause event (i.e., the m+1th third event) can be added for the mth third event, thereby achieving the purpose of adding a new event in the event tree.

[0091] for example Figure 5 In (b), if the second event chain is event A→event B→event F, the management device can determine that the cause event corresponding to event B in the current event tree does not contain event F, then the management device can first add the cause event F of event B, thereby obtaining the event tree after the new event is added.

[0092] Step 603: The management device determines a target event from the event tree after the newly added event according to the M third events in the second event chain, and updates the real-time weight and initial weight of the target event.

[0093] In one optional approach, for each of the M third events, the management device determines, based on the third event, an event that corresponds to the same outcome event as the third event. The third event and the events that correspond to the same outcome event as the third event constitute the target event. The real-time weight of the target event in the event tree is then updated.

[0094] for example Figure 5In (b), the second event chain is event A→event B→event F. For event B, the management device can determine that the cause event corresponding to the same result event A as event B also includes event D, that is, the target events are event B and event D. The management device updates the real-time weight of event B from 1 / 3 to 2 / 4, and updates the real-time weight of event D from 2 / 3 to 2 / 4. For event F, the management device first adds event F as a new cause event of event B to the event tree, and then determines that the event corresponding to the same result event B as event F also includes event C, that is, the target events are event C and event F. The management device updates the real-time weight of event C from 1 to 1 / 2, and sets the real-time weight of event F to 1 / 2.

[0095] In addition, in the embodiment of the present application, after adding a new event in the event tree, it is also necessary to set the initial weight of the new event and update the initial weights of the events corresponding to the same result event as the new event. Figure 5 For example, in (b), the management device adds event F to the event tree as a new cause event of event B. It is necessary to set the initial weight of event F and update the initial weight of event C. The initial weight of event C can be updated from 1 to 1 / 2, and the initial weight of event F can be set to 1 / 2.

[0096] In this application, if a cause event corresponding to a result event is added to the event tree, the sum of the real-time weights corresponding to the multiple cause events under the result event is 1, and the sum of the initial weights corresponding to the multiple cause events is also 1.

[0097] In addition, the M third events in the second event chain may be added as historical data to the historical data set for use in subsequent event tree generation or update.

[0098] In this application, the probability of certain fault events occurring in the target device may gradually decrease, and accordingly, the real-time weights of certain events in the event tree may gradually decrease. In order to improve the operating efficiency of the entire fault analysis system, certain events that have not appeared for a long time in the event tree can be deleted.

[0099] like Figure 7 The flow chart of the third method for updating the event tree provided by the present application is as follows. The management device may execute the following after executing step 404 or after executing step 603: Figure 7 The process in .

[0100] In step 701, the management device deletes the fourth event from the event tree when determining that the real-time weight of the fourth event meets the first condition, wherein the fourth event is any event in the event tree.

[0101] Exemplarily, the management device predetermines the first threshold value based on the initial weight of the fourth event and a preset growth factor. For example, the management device determines the first threshold value to be the product of the initial weight of the fourth event and the preset growth factor. If the real-time weight of the fourth event is not greater than the first threshold value, the management device determines that the real-time weight of the fourth event meets the first condition and deletes the fourth event from the event tree.

[0102] The preset growth factor can be determined based on prior experience, and the preset growth factors for different fourth events can be the same or different. Furthermore, the preset growth factor can affect the update speed of events in the event tree. The preset growth factor corresponding to the target device can be set based on the type of target device. For example, a server with faster update iterations in a network scenario can be set with a larger preset growth factor, while a production device with slower update iterations in an industrial scenario can be set with a smaller preset growth factor.

[0103] Step 702: The management device updates the real-time weight and initial weight of the fifth event in the event tree, wherein the fifth event is an event in the event tree that corresponds to the same result event as the fourth event.

[0104] Exemplarily, the real-time weight of the fifth event after update can be determined based on the real-time weight of the fourth event and the real-time weight before the fifth event is updated. For example, the real-time weight of the fifth event after update = the real-time weight before the fifth event is updated / (1-the real-time weight of the fourth event).

[0105] Exemplarily, the updated initial weight of the fifth event can be determined based on the initial weight of the fourth event and the initial weight before the fifth event is updated. For example, the updated initial weight of the fifth event = the initial weight before the fifth event is updated / (1 - the initial weight of the fourth event).

[0106] like Figure 5 In (c), for the three cause events of event B, the initial weights of event C, event N, and event M are 1 / 2, 1 / 4, and 1 / 4 respectively. The preset growth factor of event C is 1 / 25, and the first threshold of event C is 1 / 50 (i.e., 1 / 2×1 / 25). The management device updates the event chain according to event A→event B→event N. Figure 5 When the event tree in (c) is displayed, the management device can determine that in the event tree after the weight is updated, the real-time weight of event C is 2 / 100 (ie 1 / 50), which is not greater than the first threshold, and the management device deletes event C from the event tree.

[0107] Furthermore, the management device determines that the events corresponding to the same result event B as event C also include events N and M. It updates the real-time weight of event N to 21 / 98 and the real-time weight of event M to 77 / 98. Furthermore, the management device also updates the initial weight of event N to 1 / 2 and the initial weight of event M to 1 / 2.

[0108] It should be pointed out that after the fourth event is deleted from the event tree, the initial weight of the fifth event changes. If the management device again determines whether a fifth event meets the first condition of the fifth event, the first condition of the fifth event needs to be determined based on the changed initial weight of the fifth event and the preset growth factor of the fifth event.

[0109] In the present application, in order to further improve efficiency, the management device can classify events in the event tree. Exemplarily, all events in the event tree can be divided into two categories. For any event in the first category of events, the real-time weight of the event is greater than the first threshold corresponding to the event, and the difference between the two is less than the second threshold of the event; for any event in the second category of events, the real-time weight of the event is greater than the first threshold corresponding to the event, and the difference between the two is not less than the second threshold of the event. When the management event determines the fourth event that needs to be deleted from the event tree, it can be determined directly from the first category of events without having to be determined from the second category of events to improve the determination efficiency.

[0110] Furthermore, before determining the fourth event, the management device may exclude events in the event chain (such as N first events in the first event chain, or M third events in the second event chain), and then determine the fourth event from the first type of events, thereby further improving the efficiency of determining the fourth event.

[0111] It should be noted that this application only uses the example of the sum of the real-time weights of multiple cause events corresponding to a result event being 1. In other examples, the sum of the real-time weights of multiple cause events corresponding to a result event can also be other preset values, which are not limited in this application. Similarly, the sum of the initial weights of multiple cause events corresponding to a result event can also be other preset values.

[0112] It should also be noted that the above embodiments are described using the interaction between a management device and an analysis device, meaning that the management device and the analysis device can be two different physical devices. In other examples, the management device and the analysis device can be the same physical device (referred to as a processing device), and the above methods can be executed by the processing device.

[0113] In this application, if Figure 3The event tree in the example is actually a living event tree, and the update of the event tree can be further divided into the growth, germination and shrinkage of the event tree. Figure 4 In a related embodiment, the weight growth of events in an event tree is called event tree growth. Figure 6 In the relevant embodiment, the newly added event in the event tree is called event tree sprouting. Figure 7 In a related embodiment, deleting an event in an event tree is called event tree shrinkage. It can be understood that:

[0114] Event tree growth: The fault events of the target device are compared with the event tree. When the event tree can cover all events that have a direct or indirect causal relationship with the fault event, the real-time weights of all events in the event tree that have a direct or indirect causal relationship with the fault event change, while the initial weight of each event remains unchanged.

[0115] Event tree germination: Compare the fault events of the target device with the event tree. When the event tree cannot cover all events that have a direct or indirect causal relationship with the fault event, add new events to the event tree, recalculate the real-time weight and initial weight of the new events, and update the real-time weight and initial weight of the events corresponding to the same result events as the new events to achieve event tree germination.

[0116] Event tree shrinkage: When the real-time weight of an event meets the first condition of the event, that is, the growth rate of the real-time weight of the event is slow, the event can be deleted and regarded as a shrinking event, and the real-time weight and initial weight of the event corresponding to the same result event as the deleted event can be re-determined.

[0117] Based on this, the present application provides a method for updating an event tree. The event tree updating method can be executed by a physical device (i.e., a processing device). The event tree updating method includes event tree growth, sprouting, and shrinkage. For details, see Figure 8 Flowchart of the fourth method for updating the event tree is shown as an example:

[0118] Step 801: The processing device generates a first event chain according to a fault event and an event tree.

[0119] Step 802: The processing device determines a fault analysis report and a first solution according to the first event chain.

[0120] In step 803, the processing device determines whether the first solution successfully resolves the fault event. If so, step 804 is executed; otherwise, step 806 is executed.

[0121] Step 804: The processing device executes the event tree growth process.

[0122] In step 805 , the processing device determines whether there is an event in the event tree that meets the first condition. If so, step 808 is executed; otherwise, step 809 is executed.

[0123] Step 806: The processing device obtains a second event chain.

[0124] Step 807: The processing device executes the event tree sprouting process.

[0125] Step 808: The processing device executes the event tree shrinking process.

[0126] Step 809: The processing device obtains a new event tree.

[0127] For the parts not described in detail in the above steps 801 to 809, please refer to Figures 4 to 7 The description of the method in the relevant embodiment is omitted here.

[0128] To better explain the embodiment of the present application, the target device is taken as an example to illustrate the server. For example, the event tree corresponding to the server is as follows: Figure 9 As shown, the first event is that the system is not running. The reasons for the system not running are system reset and restart, system startup failure and system hang and downtime. That is, the cause events of the system not running are system reset and restart, system startup failure and system hang and downtime, and so on. When the server has an event of system not running, the event chain (i.e., traceability chain) can be determined as system not running → system reset and restart → hardware failure → memory failure → memory UCE error based on the server's system not running event and the server's corresponding event tree. That is, it is determined that the root cause of the server's system not running is a memory UCE error. The processing device prompts the user that the current fault is caused by a memory UCE error. The user can execute the corresponding solution on the server based on the memory UCE error.

[0129] Based on the same inventive concept, Figure 10 This application provides a method for fault analysis. For example, the target device can report the fault log to the fault diagnosis and analysis tool (which can be Figure 1 The fault diagnosis and analysis tool can extract fault events from the fault log to obtain fault events. It then performs fault tree matching diagnostic delimitation, i.e., determines a first event chain corresponding to the fault event based on the fault tree. Based on the first event chain, the fault diagnosis and analysis tool generates a fault analysis report. The fault analysis report may include a treatment plan (i.e., a first solution) determined based on the first event chain. The fault diagnosis and analysis tool may also update the fault tree based on the first event chain.

[0130] Based on the same inventive concept, Figure 11This application provides another schematic diagram of the architecture of a fault analysis system, which includes a problem management system and a fault tree management system, wherein the problem management system can be Figure 1 The fault tree management system can be an analytical device in Figure 1 Furthermore, the problem management system can receive a fault event from a target device. Based on the fault tree obtained from the fault tree management system, the problem management system performs a fault analysis on the fault event, thereby outputting a fault analysis report. The fault analysis report may include the treatment plan (i.e., the first plan) determined by the problem management system based on the first event chain. The problem management system determines the effect of the target device executing the first plan and outputs a fault treatment result based on the effect. The problem management system may also instruct the fault tree management system to update the fault tree in the fault tree management system based on the first event chain.

[0131] In the above technical solution, in the process of constructing the event tree, the real-time weight and initial weight of each event in the event tree are determined based on the probability of occurrence of each event in the historical data set. When the target device generates a fault event, the first event chain corresponding to the fault event can be analyzed based on the fault event and the event tree, so that the first solution for solving the fault event can be determined based on the first event chain. Moreover, the real-time weight of the target event related to the fault event in the event tree can be updated based on the first event chain, which helps to obtain an event tree that is more relevant to the event of the target device. Further, if the first solution obtained according to the event tree cannot solve the fault event, a second event chain can be determined, and new events can be added to the event tree according to the second event chain to obtain an event tree that is more suitable for the target device. Moreover, certain events in the event tree can be deleted, thereby reducing the size of the event tree, which helps to improve the processing speed of fault analysis.

[0132] This solution is based on machine autonomy and does not require expert intervention, which can reduce labor costs. Moreover, it is determined based on the historical data set of the target device and is not affected by expert experience.

[0133] Based on the above content and the same idea, Figure 12 and Figure 13 This is a schematic diagram of the structure of a possible device for updating an event tree provided by the present application. These devices for updating an event tree can be used to implement the method in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment.

[0134] like Figure 12What is shown is a structural schematic diagram of an apparatus for updating an event tree exemplarily provided in the present application, the apparatus including: a processing module 1201, for obtaining a first event chain, the first event chain including N first events determined from the event tree according to the fault event, the first first event among the N first events being associated with the fault event, the nth first event among the N first events being the result event of the n+1th first event, and n being any positive integer from 1 to (N-1); determining a target event from the event tree according to the N first events; an updating module 1202, for updating the real-time weight of the target event in the event tree, the real-time weight of the target event being used to characterize the probability that the target event leads to a result event of the target event after the processing module 1201 obtains the first event chain.

[0135] like Figure 13 FIG. 1 is a schematic diagram showing a structure of another device for updating an event tree provided by the present application. Figure 13 The device shown can be Figure 12 The device shown is a hardware circuit implementation. The device can be applied to the flowchart shown above to execute the method in the above method embodiment.

[0136] For ease of explanation, Figure 13 Only the main components of the device are shown.

[0137] Figure 13 The illustrated apparatus 1300 includes a communication interface 1310, a processor 1320, and a memory 1330, wherein the memory 1330 is configured to store program instructions and / or data. The processor 1320 may operate in conjunction with the memory 1330. The processor 1320 may execute program instructions stored in the memory 1330. When the instructions or program stored in the memory 1330 are executed, the processor 1320 is configured to perform the operations performed by the processing module 1201 and the updating module 1202 in the above-described embodiments.

[0138] The memory 1330 is coupled to the processor 1320. In the embodiments of the present application, coupling refers to an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between the devices, units, or modules. At least one of the memories 1330 may be included in the processor 1320.

[0139] In the embodiments of the present application, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface. In the embodiments of the present application, when the communication interface is a transceiver, the transceiver may include an independent receiver or an independent transmitter; or a transceiver or communication interface that integrates transceiver functions.

[0140] The device 1300 may further include a communication line 1340. The communication interface 1310, the processor 1320, and the memory 1330 may be interconnected via the communication line 1340; the communication line 1340 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The communication line 1340 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0141] In the present application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can be represented by: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can be represented by: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the textual description of the present application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of the present application, the character " / " indicates that the previous and next associated objects are in a "division" relationship.

[0142] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

[0143] Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of protection of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A method for updating an event tree, characterized in that: include: Obtaining a first event chain, the first event chain including N first events determined from an event tree based on the fault event, wherein a first first event among the N first events is associated with the fault event, and an nth first event among the N first events is a result event of an n+1th first event, where n is any positive integer from 1 to (N-1); wherein the first event chain is generated by an analysis device based on the fault event and the event tree; and the fault event is generated when a target device determines that an operational fault has occurred; For each of the N first events, determining the first event and a second event as a target event, where the second event is an event in the event tree that corresponds to the same result event as the first event; The real-time weight of the target event in the event tree is updated, where the real-time weight of the target event is used to represent the probability that the target event leads to a result event of the target event after acquiring the first event chain.

2. The method according to claim 1, wherein Before obtaining the first event chain, the method further includes: Acquire a plurality of historical data, and for each of the plurality of historical data, determine an event chain corresponding to the historical data, wherein the event chain corresponding to the historical data includes K events, a kth event among the K events is a result event of a k+1th event, and k is any positive integer from 1 to (K-1); According to the event chains corresponding to the multiple historical data, the event tree in the initial state is generated. In the event tree in the initial state, the initial weight corresponding to any event is used to characterize the probability that the event leads to the result event of the event, and the real-time weight of any event is the same as the initial weight.

3. The method according to claim 1 or 2, wherein: Also includes: Obtaining a user instruction, where the user instruction includes a second event chain, where the second event chain includes M third events, where a first third event among the M third events is associated with the fault event, and where an mth third event among the M third events is a result event of an m+1th third event, where m is any positive integer between 1 and (M-1); Adding a new event to the event tree according to the M third events; Determining a target event from the event tree according to the N first events includes: According to the N first events, the target event is determined from the event tree after the newly added event.

4. The method according to claim 3, wherein The adding of a new event to the event tree according to the M third events includes: When the cause event of the mth third event in the event tree does not include the m+1th third event, the m+1th third event is added to the cause event of the mth third event in the event tree.

5. The method according to any one of claims 1 to 4, characterized in that After updating the real-time weight of the target event in the event tree, the method further includes: If the real-time weight of the fourth event in the event tree meets a first condition, the fourth event is deleted from the event tree, and the first condition is determined according to the initial weight of the fourth event and a preset growth factor.

6. The method according to claim 5, wherein After deleting the fourth event from the event tree, the method further includes: A real-time weight of a fifth event in the event tree and an initial weight of the fifth event are updated, wherein the fifth event is an event in the event tree corresponding to the same result event as the fourth event.

7. The method according to claim 6, wherein The sum of the real-time weight of the fourth event and the real-time weight of the fifth event in the event tree is 1, and / or the sum of the initial weight of the fourth event and the initial weight of the fifth event in the event tree is 1.

8. An event tree updating device, characterized in that: include: a processing module configured to obtain a first event chain, wherein the first event chain includes N first events determined from an event tree based on a fault event, wherein a first first event among the N first events is associated with the fault event, and an nth first event among the N first events is a result event of an n+1th first event, where n is any positive integer from 1 to (N-1); wherein the first event chain is generated by an analysis device based on the fault event and the event tree; and wherein the fault event is generated when a target device determines that an operational fault has occurred; Determining a target event from the event tree according to the N first events; an updating module, configured to update the real-time weight of the target event in the event tree, wherein the real-time weight of the target event is used to represent the probability that the target event leads to a result event of the target event after the processing module obtains the first event chain; When the processing module determines a target event from the event tree based on the N first events, it is specifically configured to: For each of the N first events, the first event and a second event are determined as the target events, where the second event is an event in the event tree that corresponds to the same result event as the first event.

9. The device according to claim 8, wherein The processing module is further configured to: Before obtaining the first event chain, a plurality of historical data are obtained; for each historical data in the plurality of historical data, an event chain corresponding to the historical data is determined, wherein the event chain corresponding to the historical data includes K events, and the kth event in the K events is a result event of the k+1th event, where k is any positive integer from 1 to (K-1); According to the event chains corresponding to the multiple historical data, the event tree in the initial state is generated. In the event tree in the initial state, the initial weight corresponding to any event is used to characterize the probability that the event leads to the result event of the event, and the real-time weight of any event is the same as the initial weight.

10. The device according to claim 8 or 9, characterized in that The processing module is further configured to: Obtaining a user instruction, the user instruction including a second event chain, the second event chain including M third events, a first third event among the M third events being associated with the fault event, an mth third event among the M third events being a result event of an m+1th third event, where m is any positive integer from 1 to (M-1); and controlling the update module to add a new event to the event tree based on the M third events; When the processing module determines a target event from the event tree based on the N first events, it is specifically configured to: According to the N first events, the target event is determined from the event tree after the newly added event.

11. The device according to claim 10, wherein When the processing module controls the updating module to add a new event to the event tree according to the M third events, the processing module is specifically configured to: When the cause event of the mth third event in the event tree does not include the m+1th third event, the updating module is controlled to add the m+1th third event to the cause event of the mth third event in the event tree.

12. The device according to any one of claims 8 to 11, characterized in that The update module is further configured to: After updating the real-time weight of the target event in the event tree, if the real-time weight of the fourth event in the event tree meets a first condition, the fourth event is deleted from the event tree, and the first condition is determined based on the initial weight of the fourth event and a preset growth factor.

13. The device according to claim 12, wherein The update module is further configured to: After deleting the fourth event from the event tree, updating the real-time weight of a fifth event and the initial weight of the fifth event in the event tree, wherein the fifth event is an event in the event tree corresponding to the same result event as the fourth event.

14. The device according to claim 13, wherein The sum of the real-time weight of the fourth event and the real-time weight of the fifth event in the event tree is 1, and / or the sum of the initial weight of the fourth event and the initial weight of the fifth event in the event tree is 1.

15. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program or instructions, and when the computer program or instructions are executed by a computing device, the method according to any one of claims 1 to 7 is implemented.

16. A computing device, characterized in that The computing device comprises a processor connected to a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory, so that the computing device executes the method according to any one of claims 1 to 7.

17. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, it is used to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Root cause analysis method, device and equipment and storage medium

    CN110147387A

  • Weight-based platform door fault diagnosis and analysis method

    CN111160579A