Alarm intelligent analysis processing method and system

By obtaining alarm data from a variety of monitoring tools and standardizing it and mapping it to multi-dimensional data cubes, identifying causal relationships and generating impact scope reports, the multi-source alarm management problem in the existing technology is solved, the operation and maintenance efficiency and accuracy are improved, and the risk of system downtime is reduced.

CN120416009APending Publication Date: 2025-08-01广州三七极耀网络科技有限公司
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510347640.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing monitoring system is difficult to manage multi-source alarm information uniformly in the cloud computing environment, which makes it difficult for operation and maintenance personnel to quickly locate the root cause and scope of alarms, and cannot accurately evaluate the business impact, reducing operation and maintenance efficiency and increasing the risk of system downtime.

Method used

By obtaining original alarm data from a variety of monitoring tools, standardizing processing and mapping to multi-dimensional data cubes, identifying alarm causality, generating impact range reports, and using knowledge graphs to locate root causes, practical evaluation results to improve accuracy.

Benefits of technology

It realizes unified collection and standardized processing of alarm data, quickly locates the alarm location and impact range, improves operation and maintenance efficiency, reduces the risk of misjudgment, and ensures that operation and maintenance personnel obtain accurate root cause positioning results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416009A_ABST
    Figure CN120416009A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of computers, and provides an alarm intelligent analysis processing method, which comprises the following steps: obtaining original alarm data from each monitoring tool for standardization processing to obtain an alarm message; obtaining network topology information and system architecture information based on the alarm messages, mapping the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube, judging a causal relationship between any two alarm messages, and generating an alarm causal relationship chain and an alarm influence range report; classifying the alarm messages, generating an alarm event set, marking the importance degree of the alarm event set, and triggering a corresponding alarm event processing flow; analyzing the alarm messages in the same alarm event set to generate a root cause positioning result; and carrying out practical evaluation on the root cause positioning result, judging the effectiveness of the root cause positioning result, and presenting the effective root cause positioning result to operation and maintenance personnel, so that the efficiency and accuracy of operation and maintenance work can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer technology, and in particular, relates to a method and system for intelligent analysis and processing of alarms. Background Art

[0002] With the rapid development and wide application of cloud computing technology, the complexity of enterprise IT infrastructure has been increasing day by day, covering multiple key levels such as the database layer, network layer, application layer, etc. As the complexity of enterprise IT infrastructure increases, the requirements for monitoring systems also increase accordingly.

[0003] When the current monitoring system meets the monitoring requirements of complex IT infrastructure in the cloud computing environment, it usually has the following problems: (1) Scattered management of alarm sources: In the current IT environment, alarm information comes from multiple different levels and components, such as databases, network devices, application programs, etc. The above alarm information lacks a unified management platform, resulting in difficulty for operation and maintenance personnel to comprehensively and quickly grasp the overall situation of the system. (2) Diverse and difficult-to-unify alarm types: The alarm types generated by different levels and components are numerous, and often have different formats and meanings. The diverse alarm types bring great difficulties to the classification and processing of alarms, making it difficult for operation and maintenance personnel to form a unified alarm processing process. (3) Insufficient transparency of alarm information: When an alarm is triggered, operation and maintenance personnel often have difficulty quickly locating the root cause and scope of influence of the alarm, which not only prolongs the time for troubleshooting, but also may increase the risks of false alarms and missed alarms. (4) Inaccurate assessment of business impact: The current monitoring system often cannot accurately assess the impact degree of alarms on actual business operations. When dealing with alarms, operation and maintenance personnel are difficult to prioritize according to the importance of the business, thus possibly ignoring alarms with greater impact on the business.

[0004] In summary, the problems existing in the above monitoring system usually lead to low operation and maintenance efficiency, increase the risk of system downtime, and thus cause serious business losses. Summary of the Invention

[0005] The embodiments of this application provide a method and system for intelligent analysis and processing of alarms, which can solve the problems existing in the above monitoring system and significantly improve the efficiency and accuracy of operation and maintenance work.

[0006] In a first aspect, the embodiments of this application provide a method for intelligent analysis and processing of alarms, including:

[0007] Obtain original alarm data from each monitoring tool, and perform standardization processing on the original alarm data to obtain standardized alarm messages;

[0008] Based on the alarm message, obtain network topology information and system architecture information from a preset network topology database and system architecture database, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube;

[0009] Based on the multi-dimensional data cube, judge the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain;

[0010] Classify the alarm messages in the alarm causal relationship chain to generate an alarm event set, mark the importance level of the alarm event set, and trigger the corresponding alarm event processing process;

[0011] Adopt an inference algorithm based on a knowledge graph to analyze the alarm messages in the same alarm event set and generate a root cause location result;

[0012] Conduct a practical evaluation of the root cause location result, judge the effectiveness of the root cause location result, and present the effective root cause location result to the operation and maintenance personnel.

[0013] Further, the obtaining of the original alarm data from each monitoring tool and the standardization processing of the original alarm data to obtain a standardized alarm message include:

[0014] According to a preset monitoring tool list, connect through an API interface, and obtain original alarm data from each monitoring tool in the monitoring tool list within a preset time;

[0015] Adopt predefined data mapping rules and conversion logic to convert the original alarm data into first standardized data with a standard format;

[0016] Parse and extract the first standardized data to obtain key information of the alarm message, where the alarm information includes alarm level, alarm type, alarm time, and alarm device;

[0017] According to the alarm level and alarm type, and in combination with preset alarm filtering rules, filter and deduplicate the first standardized data to obtain second standardized data;

[0018] Package the second standardized data according to a predefined data model to generate a standardized alarm message.

[0019] Further, the mapping of the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube based on the alarm message includes:

[0020] Retrieve the network topology information matching the alarm device from a preset network topology database and the system architecture information matching the alarm device from a preset system architecture database. The network topology information includes the network ID, network link ID, and subnet ID of the alarm device, and the system architecture information includes the system hierarchy, module ID, and component ID.

[0021] According to the mapping rules, map the network topology information and the system architecture information to the corresponding dimensions and measure values of the multi-dimensional data cube, so that each cell of the multi-dimensional data cube corresponds to an alarm state under a combination of network topology and system hierarchy.

[0022] Furthermore, based on the multi-dimensional data cube, judge the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and through the alarm causal relationship chain, generate an alarm impact scope report, including:

[0023] Based on the multi-dimensional data cube, divide each alarm message according to the system architecture level or network topology dimension to form a system level alarm data set and a network dimension alarm data set respectively.

[0024] For the system level alarm data set, obtain the topological similarity between two alarm messages by calculating the number of union elements and intersection elements of the network topology information sets of any two alarm messages.

[0025] For the network dimension alarm data set, judge whether any two alarm messages occur in the same system level, the same module, or the same component to generate the system architecture similarity between the two alarm messages.

[0026] Based on the topological similarity and the system architecture similarity, judge whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube and generate an alarm causal relationship chain.

[0027] Obtain the device information of the alarm device in the alarm causal relationship chain, and based on a preset device location database and service deployment location database, obtain the alarm location information and alarm impact information. The device information includes the device ID and service ID, and the alarm impact information includes the system components and service scope affected when the alarm message is triggered.

[0028] Fuse the alarm location information, the alarm impact information, the network topology information, and the system architecture information to generate an alarm impact scope report.

[0029] Further, determining whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube based on the topological similarity and the system architecture similarity, and generating an alarm causal relationship chain, includes:

[0030] For the topological similarity, the calculation formula of the topological similarity is: sim = |E1 ∩ E2| / |E1 ∪ E2|, where E1 represents the set of network topological elements of alarm 1, and E2 represents the set of network topological elements of alarm 2;

[0031] For the system architecture similarity, if any two alarm messages occur at the same system level or in the same module or the same component, then the system architecture similarity is 1, otherwise the system architecture similarity is 0;

[0032] If the topological similarity is greater than a preset topological similarity threshold, or the system architecture similarity is 1, then generate an alarm association relationship pair;

[0033] If the two alarm messages in the alarm relationship pair occur successively within a preset time, then form an alarm causal relationship chain.

[0034] Further, the alarm event set includes a network alarm event set and a system architecture alarm event set;

[0035] Classifying the alarm messages in the alarm causal relationship chain to generate an alarm event set, includes:

[0036] If the topological similarity of the alarm causal relationship chain is greater than the topological similarity threshold, then classify the corresponding alarm message into the network alarm event set;

[0037] If the system architecture similarity of the alarm causal relationship chain is 1, then classify the corresponding alarm message into the system architecture alarm event set.

[0038] Further, marking the importance level of the alarm event set and triggering the corresponding alarm event processing flow, includes:

[0039] Obtain the attribute information of the alarm messages in the alarm causal relationship chain, and the attribute information includes alarm level, alarm type, alarm time, service topology information, and system architecture information;

[0040] For each alarm message in the alarm event set, obtain the severity score corresponding to the alarm level and the duration of the alarm message;

[0041] Based on the severity score and the duration, use a preset service impact assessment function to calculate the service impact score of the alarm event;

[0042] The alarm messages with a business impact score higher than the first score threshold are marked as important alarms, triggering the alarm escalation processing flow;

[0043] The alarm messages with a business impact score lower than the second score threshold are marked as low-level alarms, triggering the alarm de-escalation processing flow.

[0044] Further, the inference algorithm based on the knowledge graph is used to analyze the alarm messages in the same set of alarm events, generating a root cause localization result, including:

[0045] Analyze the alarm triggering characteristics between alarm messages to construct a causal relationship graph between alarm messages, where the alarm triggering characteristics include time interval, frequency, and periodicity;

[0046] Based on the causal relationship graph, use the inference algorithm based on the knowledge graph to obtain the root cause localization result, where the root cause localization result includes a fault analysis report and fault handling suggestions.

[0047] Further, the practical evaluation of the root cause localization result is carried out to judge the effectiveness of the root cause localization result, and the effective root cause localization result is presented to the operation and maintenance personnel, including:

[0048] Obtain historical root cause localization results and the corresponding causal relationship graphs of the root cause localization results, use the support vector machine algorithm to obtain a confidence score model, and the confidence score model is used to obtain the confidence score of the root cause localization result;

[0049] Obtain the key information of the root cause localization result, and use the named entity recognition technology to convert the key information into structured data. The key information includes fault type, faulty device, fault time, and processing flow; [[ID=,23]]

[0050] Match the structured data with a preset business process to obtain a business process matching degree value;

[0051] Compare the structured data with a preset fault operation specification to obtain an operation specification similarity value;

[0052] Through a preset weight mapping table of practical evaluation items, obtain the scoring weight values corresponding to each practical evaluation item, and use the weighted average algorithm to calculate the comprehensive score value of the root cause localization result. The practical evaluation items include the confidence score, the business process matching degree value, and the operation specification similarity value;

[0053] If the comprehensive score value is greater than the preset score threshold, mark the corresponding root cause localization result as valid and send the root cause localization result to the operation and maintenance personnel;

[0054] If the comprehensive score value is less than the preset score threshold, mark the corresponding root cause location result as invalid and filter the root cause location result.

[0055] In a second aspect, an embodiment of the present application provides an intelligent alarm analysis and processing system, including:

[0056] A first processing module: configured to obtain original alarm data from each monitoring tool, perform standardization processing on the original alarm data, and obtain standardized alarm messages;

[0057] A second processing module: configured to obtain network topology information and system architecture information from a preset network topology database and system architecture database based on the alarm messages, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube;

[0058] A third processing module: configured to determine the causal relationship between any two alarm messages based on the multi-dimensional data cube, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain;

[0059] A fourth processing module: configured to classify the alarm messages in the alarm causal relationship chain, generate an alarm event set, mark the importance of the alarm event set, and trigger a corresponding alarm event processing process;

[0060] A fifth processing module: configured to analyze the alarm messages in the same alarm event set by using an inference algorithm based on a knowledge graph, and generate a root cause location result;

[0061] A sixth processing module: configured to perform a practical evaluation on the root cause location result, determine the validity of the root cause location result, and present the valid root cause location result to the operation and maintenance personnel.

[0062] The beneficial effects of the embodiment of the present application compared with the prior art are:

[0063] An intelligent alarm analysis and processing method of the present application, on the one hand, supports obtaining original alarm data from multiple monitoring tools to achieve unified collection of alarm data, and at the same time standardizes the original alarm data to ensure the unity and comparability of alarm data. In addition, mapping the network topology information and system architecture information of the alarm message into a pre-constructed multi-dimensional data cube enables the alarm data to be understood and analyzed in a broader context, and can quickly locate the specific network topology location and system level where the alarm occurs, thus accelerating the troubleshooting and resolution speed. On the other hand, the method can identify the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and then generate an alarm impact range report, so as to locate the impact range of the alarm event corresponding to the alarm message on the entire enterprise system or network topology, and thus formulate more effective countermeasures. In addition, a practical evaluation of the finally generated root cause location result is carried out to judge its effectiveness, which helps to ensure that the operation and maintenance personnel obtain accurate and reliable root cause location results, thus avoiding resource waste and time delay caused by misjudgment, and reducing the impact of equipment failures on the business in the enterprise system. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0065] Figure 1 is a schematic flowchart of an intelligent alarm analysis and processing method provided by an embodiment of the present invention;

[0066] Figure 2 is a schematic structural diagram of an intelligent alarm analysis and processing system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0067] In the following description, specific details such as specific system structures and technologies are proposed for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0068] It should be understood that when used in the specification of this application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0069] It should also be understood that the term "and / or" used in the specification of this application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0070] As used in the specification of this application and the appended claims, the term "if" can be interpreted according to the context as "when", "once", "in response to determining", or "in response to detecting". Similarly, the phrases "if determined" or "if [the described condition or event] is detected" can be interpreted according to the context as meaning "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0071] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0072] Reference to "one embodiment" or "some embodiments" etc. described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0073] Please refer to Figure 1 As shown, the present invention is an intelligent alarm analysis and processing method, including the following steps:

[0074] S100. Obtain original alarm data from each monitoring tool, perform standardization processing on the original alarm data, and obtain standardized alarm messages;

[0075] In some of these embodiments, the above step S100 includes:

[0076] According to a pre-configured list of monitoring tools, connect through the API interface, and obtain the original alarm data from each monitoring tool in the monitoring tool list within a preset time;

[0077] Adopt predefined data mapping rules and conversion logic to convert the original alarm data into first standardized data with a standard format;

[0078] Parse and extract the first standardized data to obtain the key information of the alarm message, where the alarm information includes the alarm level, alarm type, alarm time, and alarm device;

[0079] According to the alarm level and alarm type, combined with the preset alarm filtering rules, filter and deduplicate the first standardized data to obtain second standardized data;

[0080] Package the second standardized data according to a predefined data model to generate a standardized alarm message.

[0081] In this embodiment, by docking with the original alarm data generated by various monitoring tools, unifying the data format, realizing the standardization of multi-source data, eliminating the differences in data structure, field naming, data type, etc. between different monitoring tools, making the data more consistent in subsequent processing and analysis, and at the same time reducing the workload of data conversion and cleaning, significantly improving the speed and efficiency of data processing.

[0082] In this embodiment, for monitoring tools, which usually include Prometheus, Zabbix, or CloudWatch, etc., they are toolkits or servers that can monitor and alarm the enterprise's IT infrastructure. In an enterprise, there is usually at least one monitoring tool for collecting various alarm sources generated during the operation of the enterprise system, and the alarm source usually refers to the event or condition that triggers the alarm. In the above monitoring tools, the alarm sources include but are not limited to: system performance metrics such as CPU usage, memory occupancy, disk I / O, etc., application program metrics such as request response time, error rate, throughput, etc., custom metrics where users can define their own metrics according to needs and set corresponding alarm rules, logs and events such as system logs, application logs, security events, etc. When the monitoring tool monitors that the IT infrastructure of the enterprise system triggers the above alarm sources, it generates the original alarm data, and then performs standardized processing on the original alarm data to obtain a standardized alarm message.

[0083] In this embodiment, it is supported to obtain the original alarm data from multiple monitoring tools to achieve unified collection of alarm data. At the same time, through data mapping and conversion rules, the original alarm data in different formats from different monitoring tools or triggered by different alarm sources is converted into unified first standardized data. In addition, the first standardized data is parsed and extracted to obtain the key information of the alarm message, such as alarm level, alarm type, alarm time, and alarm device, etc., to form a structured alarm event record for subsequent processing and analysis. On this basis, combined with the preset alarm filtering rules, the alarm message is filtered and de-duplicated to eliminate duplicate or invalid alarm information, thereby reducing alarm noise and improving processing efficiency. Finally, the filtered second standardized data is encapsulated according to the predefined data model to generate alarm messages in a unified format for subsequent processing and analysis.

[0084] In some embodiments, the alarm level is usually divided into several levels, such as emergency, important, warning, and information. The emergency level indicates that a serious failure has occurred or is about to occur in the system or application and needs to be processed immediately; the important level indicates that there are potential risks and needs to be processed as soon as possible; the warning level indicates possible problems but does not affect the system operation temporarily; the information level is mainly used to record the system status and does not require special processing; and the alarm type may include high CPU usage, insufficient memory, full disk space, large network latency, application error, etc. according to different monitored contents.

[0085] In this embodiment, in order to filter alarm events, some alarm filtering rules are preset based on the alarm level and alarm type. According to the preset alarm filtering rules, the following operations are performed on these alarm events. In the following embodiments, each monitoring tool issues the following alarms: Alarm 1: Emergency level, high CPU usage rate, from Server A. Alarm 2: Important level, insufficient memory, from Server B. Alarm 3: Warning level, application error, from Application C, and this is the third time such an error has occurred in this application within 5 minutes. Alarm 4: Information level, disk space usage rate reaches 80%, from Server D. Alarm 5: Important level, high CPU usage rate, but from the same Server A as Alarm 1, and the time interval is less than 1 minute (possibly a duplicate alarm). For Alarm 1, since it is an emergency level and the CPU usage rate is too high, it is directly marked as the second standardized data that needs to notify the operation and maintenance personnel. For Alarm 2, since it is an important level and the memory is insufficient, it is marked as the second standardized data. For Alarm 3, which belongs to the warning level, application error, and the error count threshold has been reached, it is marked as the second standardized data. For Alarm 4, the information level belongs to the disk space usage rate type and does not need to notify the operation and maintenance personnel. For Alarm 5: It belongs to the important level and the CPU usage rate is too high, but since it comes from the same server as Alarm 1 and the time interval is short, it is considered a duplicate alarm, so the operation and maintenance personnel are not notified, or it can be selected to be merged into Alarm 1 for marking. Through the above process, alarm events that do not need to be processed are effectively filtered out, and the interference of duplicate alarms on subsequent analysis is reduced, thereby improving the efficiency and accuracy of alarm processing.

[0086] S200. Based on the alarm message, obtain network topology information and system architecture information from a preset network topology database and system architecture database, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube;

[0087] In some of the embodiments, the above step S200 includes:

[0088] According to the alarm device in the standard alarm data, retrieve the network topology information matching the alarm device from a preset network topology database, and retrieve the system architecture information matching the alarm device from a preset system architecture database. The network topology information includes the network ID, network link ID, and subnet ID of the alarm device, and the system architecture information includes the system hierarchy, module ID, and component ID;

[0089] According to the mapping rule, map the network topology information and the system architecture information to the corresponding dimensions and metric values of the multi-dimensional data cube, so that each unit of the multi-dimensional data cube corresponds to an alarm state under a network topology and system hierarchy combination.

[0090] In this embodiment, the preset network topology database stores information such as the network connection relationships, network IDs, network link IDs, and subnet IDs of all IT devices in the enterprise system. Through this information, the network connection situation between devices can be obtained. The preset system architecture database stores information such as the hierarchical relationships, module IDs, and component IDs of each system, module, and component in the enterprise system. Through this information, the internal structure and composition of the enterprise system can be described. Then, through the device identifier of the alarm device, the relevant network topology information and system architecture information can be retrieved from the above network topology database and system architecture database respectively.

[0091] In this embodiment, for the multi-dimensional data cube, it includes the network topology dimension and the system architecture dimension in the alarm message. When constructing the multi-dimensional data cube, through the network topology information and system architecture information corresponding to each alarm message, a multi-dimensional alarm space is generated. Then, using the data cube technology, the data in the multi-dimensional alarm space is converted into a multi-dimensional data cube.

[0092] In this embodiment, when mapping the network topology information and system architecture information to the pre-constructed multi-dimensional data cube, mapping rules for mapping the network topology information and system architecture information to the multi-dimensional data cube need to be formulated in advance. Through these mapping rules, it can be specified how each dimension and measure value correspond to the specific fields of the network topology information and system architecture information.

[0093] It can be understood that the multi-dimensional data cube combines the network topology information and system hierarchy information with the alarm status. Through the multi-dimensional data cube, the specific network topology location and system hierarchy where the alarm occurs can be quickly located, thus accelerating the problem troubleshooting and solving speed. For example, if an alarm message is mapped to the multi-dimensional data cube through the above method, the specific representation of its corresponding cell is "In the subnet with network ID 10.0.0.1 / 24, the Component A1 of the Module 201 in the secondary system has an alarm of excessive CPU usage". Through this cell, the specific information of the alarm status can be quickly understood, including which network subnet, which system hierarchy, and which component it occurs on.

[0094] S300. Based on the multi-dimensional data cube, determine the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain;

[0095] In this embodiment, by identifying the causal relationship between any two alarm messages, an alarm causal relationship chain is generated, and then an alarm impact range report is generated, so as to locate the impact range of the alarm event corresponding to the alarm message on the entire enterprise system or network topology, and thus formulate more effective countermeasures.

[0096] In some of these embodiments, the above step S300 includes:

[0097] Based on the multi-dimensional data cube, each alarm message is divided according to the system architecture level or the network topology dimension, respectively forming a system-level alarm data set and a network-dimension alarm data set;

[0098] For the system-level alarm data set, by calculating the number of union elements and the number of intersection elements of the network topology information sets of any two alarm messages, the topology similarity between the two alarm messages is obtained;

[0099] For the network-dimension alarm data set, it is judged whether any two alarm messages occur in the same system level, the same module, or the same component, and the system architecture similarity between the two alarm messages is generated;

[0100] Based on the topology similarity and the system architecture similarity, it is judged whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube, and an alarm causal relationship chain is generated;

[0101] Obtain the device information of the alarm devices in the alarm causal relationship chain, and based on the preset device location database and service deployment location database, obtain the alarm location information and alarm impact information, where the device information includes the device ID and the service ID;

[0102] Fuse the alarm location information, the alarm impact information, the network topology information, and the system architecture information to generate an alarm impact range report.

[0103] In this embodiment, for multiple alarm messages mapped in the multi-dimensional data cube, through the alarm space slicing operation, according to the preset system architecture level division rule, the alarm data slices of a specific system architecture level are extracted from the multi-dimensional data cube to form a system-level alarm data set, and through the alarm space rotation operation, according to the preset network topology structure association rule, the perspective of the multi-dimensional data cube is adjusted, and the alarm data is analyzed from different network topology perspectives to form a network-dimension alarm data set, so as to facilitate subsequent correlation analysis of alarm messages from the network topology dimension and the system architecture dimension respectively.

[0104] In this embodiment, by calculating the similarity degree of any two alarm messages in the network topology structure and the similarity degree in the system architecture level, it is determined whether there is a causal relationship between them. In addition, the two alarm messages with a causal relationship are further connected to form an alarm causal relationship chain, which is beneficial to showing the propagation path and logical order between the alarm events corresponding to the alarm messages, and helps to deeply understand the root cause and impact of the alarm events.

[0105] In this embodiment, according to the device information of the alarm devices in the alarm causal relationship chain, based on the pre-established device location database and service deployment location database, the precise geographical location triggered by the alarm message and the affected system components and service scope are obtained, so as to achieve fine-grained alarm positioning. At the same time, the alarm positioning information is fused with the network topology information and system architecture information to generate an alarm impact scope report. Through this alarm impact scope report, the business systems, system components, services, and geographical areas affected during the triggering process of the alarm message can be obtained, which is convenient for subsequent maintenance personnel to repair the alarm event.

[0106] In some embodiments, based on the topology similarity and the system architecture similarity, determining whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube and generating an alarm causal relationship chain includes:

[0107] For the topology similarity, the calculation formula of the topology similarity is: sim = |E1∩E2| / |E1∪E2|, where E1 represents the set of network topology elements of alarm 1, and E2 represents the set of network topology elements of alarm 2;

[0108] For the system architecture similarity, if any two alarm messages occur at the same system level or in the same module or the same component, the system architecture similarity is 1, otherwise the system architecture similarity is 0;

[0109] If the topology similarity is greater than the preset topology similarity threshold, or the system architecture similarity is 1, an alarm association relationship pair is generated;

[0110] If the two alarm messages in the alarm relationship pair occur successively within a preset time, an alarm causal relationship chain is formed.

[0111] In this embodiment, for topological similarity, a set of network topology elements in the network topology information of each alarm message is obtained. Specifically, for any two alarms, the sets of relevant network topology elements are obtained respectively, denoted as E1 and E2. By calculating the number of intersection elements |E1∩E2| between E1 and E2 and the number of union elements |E1∪E2| between E1 and E2, the calculation results are substituted into the topological similarity calculation formula sim = |E1∩E2| / |E1∪E2| to obtain the topological similarity sim between the two alarms.

[0112] In this embodiment, for system architecture similarity, by comparing the system levels, module IDs, and component IDs between two alarm messages, it is further determined whether the two alarm messages occur at the same system level, in the same module, or in the same component, so as to determine whether the two alarm messages are similar in terms of the system architecture dimension.

[0113] Specifically, for two alarm messages with a topological similarity greater than a preset topological similarity threshold or a system architecture similarity of 1, it indicates that there is an association relationship between the corresponding alarm events, so an alarm association relationship pair is generated. Further, if the two alarm messages occur successively within a preset time, it indicates that there is a causal relationship between the two alarm messages, and then an alarm causal relationship chain is generated in the order of occurrence, which helps to deeply understand the root cause and impact of the alarm event.

[0114] S400. Classify the alarm messages in the alarm causal relationship chain to generate an alarm event set, mark the importance level of the alarm event set, and trigger the corresponding alarm event processing process;

[0115] In some embodiments, the alarm event set includes a network alarm event set and a system architecture alarm event set;

[0116] Among them, the classification of the alarm messages in the alarm causal relationship chain to generate an alarm event set includes:

[0117] If the topological similarity of the alarm causal relationship chain is greater than the topological similarity threshold, the corresponding alarm message is classified into the network alarm event set;

[0118] If the system architecture similarity of the alarm causal relationship chain is 1, the corresponding alarm message is classified into the system architecture alarm event set.

[0119] In this embodiment, the alarm messages are classified into a set of network alarm events related to the network topology dimension and a set of system architecture alarm events related to the system architecture dimension. Then, the alarm messages in the two alarm event sets are processed separately, thereby improving the alarm processing efficiency, optimizing the operation and maintenance management, supporting decision-making, and providing a strong guarantee for the stable operation of the system architecture or network topology.

[0120] In some of these embodiments, marking the importance level of the alarm event set and triggering the corresponding alarm event processing flow includes:

[0121] Obtain the attribute information of the alarm message in the alarm causal relationship chain, where the attribute information includes the alarm level, alarm type, alarm time, service topology information, and system architecture information;

[0122] For each alarm message in each alarm event set, obtain the severity score corresponding to the alarm level and the duration of the alarm message;

[0123] Based on the severity score and the duration, use a preset service impact assessment function to calculate the service impact score of the alarm event;

[0124] Mark the alarm messages with a service impact score higher than the first score threshold as important alarms and trigger the alarm escalation processing flow;

[0125] Mark the alarm messages with a service impact score lower than the second score threshold as low-level alarms and trigger the alarm de-escalation processing flow.

[0126] In this embodiment, the alarm messages in the two alarm event sets are analyzed and processed separately. Specifically, obtain the alarm level corresponding to the alarm message in the network alarm event set or the system architecture alarm event set, and based on the preset mapping relationship between the alarm level and the severity score, convert the alarm level of each alarm message into the corresponding severity score. At the same time, obtain the start time and end time of the alarm message and calculate the duration of the alarm event.

[0127] In this embodiment, for the preset service impact assessment function, its calculation formula is service impact score = service weight value × severity score × duration function value, where the service weight value is used to measure the importance of the service corresponding to the alarm message in the overall enterprise system, and the duration function value is used to measure the impact of the duration of the service interruption or failure corresponding to the alarm message on the overall enterprise system. Specifically, the duration function value = duration × duration factor, where the duration factor is a constant factor used to adjust the impact degree of the duration on the overall enterprise system.

[0128] In this embodiment, the first scoring threshold and the second scoring threshold are two preset scoring boundaries. The first scoring threshold is used to distinguish important alarms from ordinary alarms. The setting of the first scoring threshold is based on the business requirements and operation and maintenance capabilities of the enterprise system. The first scoring threshold will be relatively high to ensure that only truly serious or urgent alarms will be marked as important alarms. When the business impact score of an alarm message is higher than the first scoring threshold, the alarm message is regarded as an important alarm. At this time, the alarm escalation processing flow is triggered to ensure that the corresponding alarm events can be noticed and processed in the subsequent process. For the second scoring threshold, it is used to distinguish low-level alarms from ordinary alarms. The corresponding second scoring threshold should be set lower than the first scoring threshold to ensure a clear distinction between important alarms and low-level alarms. When the business impact score of an alarm message is lower than this threshold, the alarm is regarded as a low-level alarm. At this time, the alarm downgrading processing flow is triggered to perform appropriate alarm compression and filtering on the corresponding alarm events to reduce the interference of alarm noise on the system. For alarm messages whose business impact scores are between the first scoring threshold and the second scoring threshold, they are marked as ordinary alarms and processed according to the normal alarm processing flow.

[0129] S500. Use an inference algorithm based on a knowledge graph to analyze the alarm messages in the same set of alarm events and generate a root cause location result.

[0130] In some embodiments, the above step S500 includes:

[0131] Analyze the alarm trigger characteristics between alarm messages to construct a causal relationship graph between alarm messages. The alarm trigger characteristics include time interval, frequency, and periodicity.

[0132] Based on the causal relationship graph, use an inference algorithm based on a knowledge graph to obtain a root cause location result. The root cause location result includes a fault analysis report and a fault handling suggestion.

[0133] In this embodiment, alarm messages that belong to the same network alarm event set or system architecture alarm event set generated during the processing of historical alarm messages are analyzed. For each alarm, calculate the time interval between it and the previous alarm, count the occurrence frequency of each alarm type within a preset time, and at the same time use a periodic detection algorithm to analyze the periodic characteristics in each alarm message.

[0134] In this embodiment, according to the alarm trigger characteristics, use a graph theory algorithm to construct a causal relationship graph between alarm messages. In the causal relationship graph, nodes represent alarm messages, and edges represent the causal relationships between alarms. Among them, the direction and weight of the edges are determined by the time interval, frequency, and periodic characteristics between alarms to reflect the strength of the causal relationships between alarms.

[0135] In this embodiment, for the alarm events in each alarm event set, according to the attribute information of the alarm events, matching is performed in the above-mentioned causal relationship graph to obtain the graph nodes and edges related to the current alarm event; a reasoning algorithm based on the knowledge graph is used to infer potential fault causes and influence scopes according to the matched graph nodes and edges, and a fault analysis report is generated. The fault analysis report includes key information such as fault types, fault causes, and fault propagation links. At the same time, historical cases that match the fault causes searched in the fault knowledge base and the expert experience base are used to generate fault handling suggestions for the current alarm event.

[0136] S600. Perform a practical evaluation on the root cause location result, judge the effectiveness of the root cause location result, and present the effective root cause location result to the operation and maintenance personnel.

[0137] In this embodiment, the root cause location result is retrieved and matched from the fault knowledge base and the expert experience base. Therefore, it is necessary to further perform a practical evaluation on the root cause location result to ensure the effectiveness of the finally matched root cause location result, which is beneficial for the operation and maintenance personnel to maintain each alarm message according to the root cause location result.

[0138] In some of these embodiments, the above step S600 includes:

[0139] Obtain historical root cause location results and the corresponding causal relationship graph of the root cause location results, and use the support vector machine algorithm to obtain a confidence score model, where the confidence score model is used to obtain the confidence score of the root cause location result;

[0140] Obtain the key information of the root cause location result, and use the named entity recognition technology to convert the key information into structured data. The key information includes fault types, faulty devices, fault times, and processing procedures;

[0141] Match the structured data with a preset business process to obtain a business process matching degree value;

[0142] Compare the structured data with a preset fault operation specification to obtain an operation specification similarity value;

[0143] Through a preset practical scoring item weight mapping table, obtain the scoring weight values corresponding to each practical scoring item, and use the weighted average algorithm to calculate the comprehensive scoring value of the root cause location result. The practical scoring items include the confidence score, the business process matching degree value, and the operation specification similarity value;

[0144] If the comprehensive scoring value is greater than a preset scoring threshold, mark the corresponding root cause location result as valid and send the root cause location result to the operation and maintenance personnel;

[0145] If the comprehensive score value is less than the preset score threshold, mark the corresponding root cause localization result as invalid and filter the root cause localization result.

[0146] In this embodiment, the historical output result set R of the root cause localization result is obtained history ={r1, r2,..., r n} and the causal relationship graph data set D of the corresponding root cause localization algorithm history ={d1, d2,..., d n}, preprocess and extract features from the historical output result set and the causal relationship graph data set, and extract features that can reflect the root cause of the fault. These features may include the number of nodes in the graph, the weights of the edges, the connectivity of the nodes, etc. Use the preprocessed historical output data set R history and D history to train the support vector machine model M svm . During the training process, find the optimal hyperplane to maximize the interval of historical data of different categories. The training objective function of the support vector machine model is: Its constraint condition is: y i (w×(d i )+b)≥1―δ i , δ i ≥0, where w is the weight vector, b is the bias term, C is the penalty coefficient, (d i ) is the function that maps the data to a high-dimensional space, and y i is the credibility corresponding to the historical root cause localization result, where 1 means credible and -1 means not credible. Through the above training, a confidence score model is obtained, and this model outputs a confidence score.

[0147] In this embodiment, according to the predefined fault type and device type, map the extracted key information into structured data, such as forming a multi-tuple (fault type, faulty device, fault time, processing flow).

[0148] In this embodiment, the text description of a preset business process is obtained, and the text description of the business process is converted into a business process semantic vector by using a word vector model in natural language processing technology. The business process keywords in the business process semantic vector are obtained, and the business process keywords are extracted from structured data by using keyword extraction technology. The weighted average method is used to calculate the structured data business process semantic vector, and the cosine similarity between the structured data business process semantic vector and the business process semantic vector is calculated to obtain the business process matching degree value. For the preset fault operation specification, the text description of the fault operation specification is converted into an operation specification semantic vector by using a word vector model in natural language processing technology, the operation specification keywords are extracted from structured data by using keyword extraction technology, the operation specification vector of the structured data is calculated by using the term frequency-inverse document frequency method, and the cosine similarity between the operation specification vector of the structured data and the operation specification semantic vector is calculated to obtain the operation specification similarity value.

[0149] In this embodiment, the weight mapping table of the practical scoring items is provided with the weights corresponding to each practical scoring item. Through this table, the scoring weight values corresponding to each practical scoring item can be obtained, and then the weighted average algorithm is used to calculate the comprehensive scoring value. By comparing the comprehensive scoring value with the preset scoring threshold, the effectiveness of its root cause location result is judged, and then corresponding processing is carried out.

[0150] Please refer to Figure 2 As shown, the present invention also provides an intelligent alarm analysis and processing system, and the system includes:

[0151] The first processing module 201: is used to obtain the original alarm data from each monitoring tool, and perform standardization processing on the original alarm data to obtain a standardized alarm message;

[0152] The second processing module 202: is used to obtain network topology information and system architecture information from a preset network topology database and system architecture database based on the alarm message, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube;

[0153] The third processing module 203: is used to judge the causal relationship between any two alarm messages based on the multi-dimensional data cube, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain;

[0154] The fourth processing module 204: is used to classify the alarm messages in the alarm causal relationship chain, generate an alarm event set, mark the importance level of the alarm event set, and trigger the corresponding alarm event processing process;

[0155] The fifth processing module 205: It is used to analyze the alarm messages in the same set of alarm events by using an inference algorithm based on a knowledge graph, and generate a root cause location result;

[0156] The sixth processing module 206: It is used to conduct a practical evaluation of the root cause location result, judge the effectiveness of the root cause location result, and present the valid root cause location results to the operation and maintenance personnel.

[0157] It can be understood that, as Figure 1 shown, the content in the embodiment of the alarm intelligent analysis processing method is applicable to the embodiment of this alarm intelligent analysis processing system. The functions specifically implemented by the embodiment of this alarm intelligent analysis processing system are the same as those in the embodiment of the alarm intelligent analysis processing method as Figure 1 shown, and the beneficial effects achieved are also the same as those in the embodiment of the alarm intelligent analysis processing method as Figure 1 shown.

[0158] It should be noted that, regarding the information interaction, execution process, etc. between the above systems, since they are based on the same concept as the method embodiment of the present invention, for their specific functions and the technical effects brought, reference can be specifically made to the method embodiment part, and details will not be elaborated here.

[0159] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the system is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiment, and details will not be elaborated here.

[0160] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and all should be included in the protection scope of the present application.

Claims

1. An intelligent alarm analysis and processing method, characterized in that, Including: Obtain the original alarm data from each monitoring tool, perform standardization processing on the original alarm data to obtain standardized alarm messages; Based on the alarm messages, obtain network topology information and system architecture information from a preset network topology database and system architecture database, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube; Based on the multi-dimensional data cube, judge the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain; Classify the alarm messages in the alarm causal relationship chain to generate an alarm event set, mark the importance level of the alarm event set, and trigger the corresponding alarm event processing process; Adopt an inference algorithm based on a knowledge graph to analyze the alarm messages in the same alarm event set to generate a root cause location result; Conduct a practical evaluation on the root cause location result, judge the effectiveness of the root cause location result, and present the effective root cause location result to the operation and maintenance personnel.

2. The method according to claim 1, characterized in that, The obtaining the original alarm data from each monitoring tool, performing standardization processing on the original alarm data to obtain standardized alarm messages includes: According to a preset monitoring tool list, connect through an API interface, and obtain the original alarm data from each monitoring tool in the monitoring tool list within a preset time; Adopt predefined data mapping rules and conversion logic to convert the original alarm data into first standardized data with a standard format; Parse and extract the first standardized data to obtain the key information of the alarm message, and the alarm information includes alarm level, alarm type, alarm time, and alarm device; According to the alarm level and alarm type, combined with preset alarm filtering rules, filter and deduplicate the first standardized data to obtain second standardized data; Package the second standardized data according to a predefined data model to generate standardized alarm messages.

3. The method according to claim 1, characterized in that The mapping the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube based on the alarm messages includes: According to the alarm device in the standard alarm data, retrieve the network topology information matching the alarm device from a preset network topology database, and retrieve the system architecture information matching the alarm device from a preset system architecture database. The network topology information includes the network ID, network link ID, and subnet ID of the alarm device, and the system architecture information includes system level, module ID, and component ID; According to the mapping rules, map the network topology information and the system architecture information to the corresponding dimensions and metrics of the multi-dimensional data cube, so that each unit of the multi-dimensional data cube corresponds to an alarm state under a combination of network topology and system level.

4. The method according to claim 3, wherein Based on the multi-dimensional data cube, determine the causal relationship between any two alarm messages, generate an alarm causal relationship chain, and generate an alarm impact scope report through the alarm causal relationship chain, including: Based on the multi-dimensional data cube, divide each alarm message according to the system architecture level or the network topology dimension to form a system-level alarm data set and a network-dimensional alarm data set respectively; For the system-level alarm data set, obtain the topological similarity between two alarm messages by calculating the number of union elements and the number of intersection elements of the network topology information sets of any two alarm messages; For the network-dimensional alarm data set, determine whether any two alarm messages occur at the same system level, in the same module, or in the same component to generate the system architecture similarity between the two alarm messages; Based on the topological similarity and the system architecture similarity, determine whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube, and generate an alarm causal relationship chain; Obtain the device information of the alarm device in the alarm causal relationship chain, and obtain the alarm location information and the alarm impact information based on the preset device location database and the service deployment location database. The device information includes the device ID and the service ID, and the alarm impact information includes the system components and service scopes affected when the alarm message is triggered; Fuse the alarm location information, the alarm impact information, the network topology information, and the system architecture information to generate an alarm impact scope report.

5. The method according to claim 4, wherein The determining whether there is a causal relationship between any two alarm messages in the multi-dimensional data cube based on the topological similarity and the system architecture similarity, and generating an alarm causal relationship chain includes: For the topological similarity, the calculation formula of the topological similarity is: sim = |E1∩E2| / |E1∪E2|, where E1 represents the network topology element set of alarm 1, and E2 represents the network topology element set of alarm 2; For the system architecture similarity, if any two alarm messages occur at the same system level, in the same module, or in the same component, the system architecture similarity is 1, otherwise the system architecture similarity is 0; If the topological similarity is greater than the preset topological similarity threshold, or the system architecture similarity is 1, generate an alarm association pair; If the two alarm messages in the alarm relationship pair occur successively within a preset time, form an alarm causal relationship chain.

6. The method according to claim 1, characterized in that, The alarm event set includes a network alarm event set and a system architecture alarm event set; [[ID= ​ ​ 7. The method according to claim 6, characterized in that, ​ Obtain the attribute information of the alarm messages in the alarm causality chain, where the attribute information includes alarm level, alarm type, alarm time, service topology information, and system architecture information; For each alarm message in each of the alarm event sets, obtain the severity score corresponding to the alarm level and the duration of the alarm message; Based on the severity score and the duration, use a preset service impact assessment function to calculate the service impact score of the alarm event; Mark the alarm messages with a service impact score higher than the first score threshold as important alarms and trigger the alarm escalation processing flow; Mark the alarm messages with a service impact score lower than the second score threshold as low-level alarms and trigger the alarm de-escalation processing flow.

8. The method according to claim 7, wherein, Using the reasoning algorithm based on the knowledge graph, analyze the alarm messages in the same alarm event set to generate a root cause localization result, including: Analyze the alarm trigger characteristics between alarm messages to construct a causality graph between alarm messages, where the alarm trigger characteristics include time interval, frequency, and periodicity; Based on the causality graph, use the reasoning algorithm based on the knowledge graph to obtain the root cause localization result, where the root cause localization result includes a fault analysis report and fault handling suggestions.

9. The method according to claim 1, wherein Practically evaluate the root cause localization result, judge the effectiveness of the root cause localization result, and present the effective root cause localization result to the operation and maintenance personnel, including: Obtain historical root cause localization results and the corresponding causality graphs of the root cause localization results, and use the support vector machine algorithm to obtain a confidence score model, where the confidence score model is used to obtain the confidence score of the root cause localization result; Obtain the key information of the root cause localization result, and use named entity recognition technology to convert the key information into structured data, where the key information includes fault type, faulty device, fault time, and processing flow; Match the structured data with a preset business process to obtain a business process matching degree value; Compare the structured data with a preset fault operation specification to obtain an operation specification similarity value; Through a preset weight mapping table of practical evaluation items, obtain the scoring weight values corresponding to each practical evaluation item, and use the weighted average algorithm to calculate the comprehensive scoring value of the root cause localization result. The practical evaluation items include the confidence score, the business process matching degree value, and the operation specification similarity value; If the comprehensive scoring value is greater than the preset scoring threshold, mark the corresponding root cause localization result as valid and send the root cause localization result to the operation and maintenance personnel; If the comprehensive scoring value is less than the preset scoring threshold, mark the corresponding root cause localization result as invalid and filter the root cause localization result.

10. An intelligent alarm analysis and processing system, characterized in that, Including: The first processing module: used to obtain the original alarm data from each monitoring tool, perform standardization processing on the original alarm data, and obtain standardized alarm messages; The second processing module: used to obtain network topology information and system architecture information from a preset network topology database and system architecture database based on the alarm message, and map the network topology information and the system architecture information to a pre-constructed multi-dimensional data cube; The third processing module: used to judge the causal relationship between any two alarm messages based on the multi-dimensional data cube, generate an alarm causal relationship chain, and generate an alarm impact range report through the alarm causal relationship chain; The fourth processing module: used to classify the alarm messages in the alarm causal relationship chain, generate an alarm event set, mark the importance level of the alarm event set, and trigger the corresponding alarm event processing flow; The fifth processing module: used to analyze the alarm messages in the same alarm event set by using an inference algorithm based on a knowledge graph, and generate a root cause location result; The sixth processing module: used to perform a practical evaluation on the root cause location result, judge the effectiveness of the root cause location result, and present the effective root cause location result to the operation and maintenance personnel.

Citation Information

Cited By

  • Electric power communication system fault positioning method and system

    CN121173663A

  • Alarm information processing method and device, electronic equipment and storage medium

    CN121278671A

  • Operation and maintenance event analysis method and device based on root cause aggregation and storage medium

    CN122247834A