Database exception analysis method and device, equipment and storage medium
By determining the causal path from the abnormal indicator knowledge graph in database anomaly analysis and using the reinforcement learning network to optimize the prompt word parameters and generate the optimal prompt word, the problem that the existing technology cannot adapt to complex abnormal scenarios is solved, and a more accurate root cause analysis is achieved.
Patent Information
- Application Number
- CN202510896230.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-30
AI Technical Summary
Existing database anomaly analysis methods rely on static prompt words or fixed rules, which are difficult to adapt to complex and changeable abnormal scenarios and cannot fully mine the causal information in the knowledge graph for root cause reasoning.
By determining the causal path from the abnormal indicator knowledge graph and inputting the abnormal indicators and causal path into the prompt word generation model, the reinforcement learning network is used to dynamically optimize the prompt word parameters, generate the optimal prompt word, and combine the current indicator data for root cause inference.
It achieves more accurate and comprehensive root cause analysis, adapts to the complex and changing database operating environment, and provides higher analysis accuracy and adaptability.
Smart Images

Figure CN120723749A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a database anomaly analysis method, device, equipment and medium. Background Art
[0002] In database management, database anomaly detection and root cause analysis are important technical means to ensure the stability and availability of database systems. Existing database anomaly analysis methods obtain multi-source heterogeneous data from the database and rely on static prompt words or fixed rules to perform root cause analysis of abnormal scenarios.
[0003] However, static prompt words or fixed rules are pre-set based on historical experience and specific scenarios, and are difficult to adapt to the analysis needs of complex and changing abnormal scenarios. Summary of the Invention
[0004] The present application provides a database anomaly analysis method, apparatus, device and medium to solve the technical problem that existing technologies are difficult to adapt to the analysis needs of complex and changeable anomaly scenarios.
[0005] In a first aspect, the present application provides a database anomaly analysis method, comprising:
[0006] When an abnormal indicator is detected, determining at least one causal path from the abnormal indicator knowledge graph, the causal path including at least one related indicator of the abnormal indicator;
[0007] Inputting the abnormality indicator and at least one of the causal paths into a prompt word generation model, dynamically optimizing prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word, wherein the prompt word generation model is trained based on historical abnormality indicators, the causal paths corresponding to the historical abnormality indicators, historical prompt words, and feedback from operation and maintenance personnel;
[0008] Current indicator data corresponding to the abnormal indicator and the plurality of related indicators are obtained, and root cause reasoning is performed based on the plurality of current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report.
[0009] In a second aspect, the present application provides a database anomaly analysis device, comprising:
[0010] a determination module, configured to, when an abnormal indicator is detected, determine at least one causal path from the abnormal indicator knowledge graph, the causal path including at least one related indicator of the abnormal indicator;
[0011] an input module, configured to input the abnormality indicator and at least one of the causal paths into a prompt word generation model;
[0012] a prompt word generation module, configured to dynamically optimize prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word, wherein the prompt word generation model is trained based on historical anomaly indicators, causal paths corresponding to the historical anomaly indicators, historical prompt words, and feedback from operations and maintenance personnel;
[0013] An acquisition module, configured to acquire current indicator data corresponding to the abnormal indicator and the plurality of related indicators;
[0014] The root cause reasoning module is used to perform root cause reasoning based on the multiple current indicator data, the causal path and the optimal prompt word to obtain a root cause analysis report.
[0015] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0016] The memory stores computer-executable instructions;
[0017] The processor executes the computer-executable instructions stored in the memory to implement the above first aspect and / or various possible implementations of the first aspect.
[0018] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0019] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0020] The database anomaly analysis method provided by this application determines at least one causal path from the anomaly indicator knowledge graph when an anomaly indicator is detected. The anomaly indicator and the at least one causal path are then input into a prompt word generation model. The prompt word parameters are dynamically optimized by a reinforcement learning network within the prompt word generation model to obtain an optimal prompt word. The causal path includes at least one related indicator of the anomaly indicator. Current indicator data corresponding to the anomaly indicator and multiple related indicators are obtained. Root cause inference is then performed based on the multiple current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report. This method dynamically optimizes prompt word parameters through a reinforcement learning network to obtain an optimal prompt word that is more suitable for the current anomaly scenario. Root cause inference is then performed based on the optimal prompt word, the causal path, and multiple current indicator data. This method further considers the complex and changing database operating environment, thereby obtaining a more accurate and comprehensive root cause analysis report. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0022] Figure 1 Schematic diagram of the process of the abnormality analysis method provided in the embodiment of the present application Figure 1 ;
[0023] Figure 2 An abnormality analysis system provided in an embodiment of the present application;
[0024] Figure 3 Schematic diagram of the process of the database anomaly analysis method provided in the embodiment of the application Figure 2 ;
[0025] Figure 4 Schematic diagram of the process of the database anomaly analysis method provided in the embodiment of the application Figure 3 ;
[0026] Figure 5 A schematic diagram of the structure of the database anomaly analysis device provided in this application;
[0027] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application.
[0028] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0029] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] In addition, this application involves conducting big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and using artificial intelligence technology to make automated decisions, and making technical solutions that have a significant impact on personal rights and interests based on the results of automated decisions. The application provides users with corresponding operation entrances for them to choose to agree or reject the results of automated decisions; if the user chooses to reject, the expert decision-making process will be entered.
[0032] It should be noted that the database anomaly analysis method, device, equipment and storage medium provided in this application can be used in the field of data processing, and can also be used in any field other than data processing. The application field of the database anomaly analysis method, device, equipment and storage medium in this application is not limited.
[0033] The innovative development of financial services requires databases to be able to handle complex business scenarios and accommodate massive amounts of business data. However, the richness of database functionality and the expansion of database capacity have brought numerous challenges to database management. In database management, database anomaly detection and root cause analysis are important technical means to ensure the stability and availability of database systems.
[0034] Existing database anomaly analysis methods rely on manual experience, static rules, or simple statistical models for root cause analysis. For example, they obtain heterogeneous data from multiple sources, such as specific types of database logs and performance reports, and analyze and process this data using static prompts or fixed rules to obtain root cause analysis results.
[0035] However, due to its reliance on static prompt words or fixed rules, existing technologies cannot fully mine the causal information in the knowledge graph for root cause reasoning. Moreover, static prompt words and fixed rules are preset based on historical data and experience, and are difficult to adapt to the analysis needs of complex and changeable abnormal scenarios.
[0036] The database anomaly analysis method provided in this application determines at least one causal path from the anomaly indicator knowledge graph when an anomaly indicator is detected, and inputs the above-mentioned anomaly indicator and causal path into the prompt word generation model. The prompt word parameters are dynamically optimized through the reinforcement learning network in the prompt word generation model to obtain the optimal prompt word that is more suitable for the current anomaly scenario. The root cause reasoning is then performed by combining the optimal prompt word, the causal path and multiple current indicator data, further considering the complex and changeable database operating environment, thereby obtaining a more accurate and comprehensive root cause analysis report.
[0037] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0038] Figure 1 Schematic diagram of the process of the abnormality analysis method provided in the embodiment of the present application Figure 1 , Figure 2 An abnormality analysis system is provided in the embodiment of the present application. Figure 1 As shown, the method includes:
[0039] S101. When an abnormal indicator is detected, determine at least one causal path from the abnormal indicator knowledge graph.
[0040] The anomaly indicator knowledge graph is pre-built based on multi-source data in the database. The anomaly indicator knowledge graph includes multiple causal paths, each of which starts with the anomaly indicator and is constructed based on entities of preset types and the relationships between these entities. The anomaly indicator knowledge graph is then generated based on these multiple causal paths. This causal path includes at least one related indicator of the anomaly indicator. For example, the causal path is: anomaly indicator → [root cause is]: root cause → [located in]: region. "Anomaly indicator" and "root cause" are entities, acting as nodes in the construction of the anomaly indicator knowledge graph, while "root cause is" and "located in" are relationships, acting as directed edges in the construction of the anomaly indicator knowledge graph.
[0041] Specifically, when an abnormal indicator is detected, the position of the abnormal node is located from a pre-built abnormal indicator knowledge graph. Then, starting with the abnormal indicator, the abnormal indicator knowledge graph is traversed to obtain at least one causal path corresponding to the abnormal indicator. For example, if the abnormal indicator is a sudden increase in database query latency, the pre-built abnormal indicator knowledge graph is traversed starting with the abnormal indicator. The first causal path corresponding to the sudden increase in database query latency is: sudden increase in database query latency → [cause]: increased lock wait time → [root cause is]: decreased TPS (Transactions Per Second) → [cause]: customer complaints. The second causal path is: sudden increase in database query latency → [root cause is]: sudden increase in data volume + index table.
[0042] S102: Input the abnormality indicator and at least one causal path into a prompt word generation model, and dynamically optimize prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word.
[0043] Among them, the prompt word generation model is trained based on historical abnormal indicators, the causal paths corresponding to historical abnormal indicators, historical prompt words, and feedback information from operation and maintenance personnel.
[0044] Specifically, the prompt word generation model integrates a reinforcement learning network. The model inputs anomaly indicators and corresponding causal paths into the prompt word generation model, generating at least one prompt word. This prompt word guides root cause analysis of the anomaly indicators and causal paths, and generates an evaluation report corresponding to the root cause analysis results. The reinforcement learning network then analyzes and processes the evaluation report, iteratively optimizes the prompt word parameters based on the analysis results, and outputs the optimal prompt word when preset conditions are met. These preset conditions include, but are not limited to, convergence of the reinforcement learning network's reward function or a maximum number of iterations.
[0045] This method continuously adjusts the prompt words through the reinforcement learning network to adapt the prompt words to the current abnormal scenario, and outputs the optimal prompt words. The optimal prompt words are used for root cause inference, which is conducive to highly targeted and accurate root cause analysis results of the current abnormal indicators.
[0046] S103: Obtain current indicator data corresponding to the abnormal indicator and multiple related indicators, and perform root cause reasoning based on the multiple current indicator data, causal paths, and optimal prompt words to obtain a root cause analysis report.
[0047] Specifically, in order to achieve accurate root cause location and abnormality diagnosis in the current abnormal scenario, the current indicator data corresponding to the abnormal indicator and multiple related indicators are obtained, and then the root cause analysis of multiple current indicator data and causal paths is performed based on the optimal prompt words to obtain a more accurate root cause analysis report. For example, Figure 2 As shown, multiple current indicator data, causal paths, and optimal prompt words are input into the LLM (large language model) reasoning model 242. The optimal prompt words guide the LLM reasoning model 242 to perform root cause reasoning on the multiple current indicator data and causal paths, obtain a root cause analysis report, and generate repair suggestions for the database indicators corresponding to the root causes.
[0048] This method collaboratively performs root cause analysis on the optimal prompt words after dynamic optimization and the current indicator data. Therefore, not only is a high-confidence target causal path determined from at least one causal path, but the resulting root cause analysis report is also highly adapted to the current abnormal scenario.
[0049] The database anomaly analysis method provided in this embodiment determines at least one causal path from the anomaly indicator knowledge graph when an anomaly indicator is detected. The anomaly indicator and causal path are then input into a prompt word generation model. The prompt word generation model then dynamically optimizes the prompt word using a reinforcement learning network to obtain an optimal prompt word. The causal path includes at least one related indicator of the anomaly indicator. Current indicator data corresponding to the anomaly indicator and multiple related indicators is obtained. Root cause inference is then performed based on the multiple current indicator data, the causal path, and the optimal prompt word to generate a root cause analysis report. This method dynamically optimizes the prompt word using a reinforcement learning network to obtain an optimal prompt word that is more suitable for the current anomaly scenario. Root cause inference is then performed based on the optimal prompt word, the causal path, and multiple current indicator data. This method further considers the complex and changing database operating environment, resulting in a more accurate and comprehensive root cause analysis report.
[0050] Figure 3 Schematic diagram of the process of the database anomaly analysis method provided in the embodiment of the application Figure 2 .like Figure 3 As shown, this embodiment Figure 1-2 Based on the embodiment, a possible database anomaly analysis method is described in detail, and the method includes:
[0051] S301 , obtaining multi-source data; pre-processing the multi-source data to obtain target multi-source data.
[0052] The multi-source data includes but is not limited to: database monitoring data, database logs, execution plans, and table structures and statistical information.
[0053] Specifically, database monitoring data, database logs, execution plans, table structures, and statistical information corresponding to preset indicators are obtained. These multi-source data are then preprocessed to unify the structure and format of the multi-source data, as well as the names of each indicator, to obtain the target multi-source data. Preset indicators include, for example, key indicators that affect database performance and operational efficiency.
[0054] For example, Figure 2 As shown, within the data layer 210, the database monitoring data, database logs, execution plans, table structures and statistical information for preset indicators are obtained from the database 211 through the monitoring indicator collection module 212, the log and execution plan collection module 213, and the table structure and statistical information collection module 214, and these multi-source data are preprocessed to establish a standardized data model to facilitate the subsequent construction of the abnormal indicator knowledge graph.
[0055] Optionally, a method for preprocessing multi-source data is provided, comprising: processing the multi-source data according to preset rules to obtain first multi-source data; and performing semantic analysis on the first multi-source data to standardize the names of indicators in the first multi-source data to obtain target multi-source data. The preset rules include, but are not limited to, a preset format, a preset data structure, and preset attributes.
[0056] This method uniformly models and standardizes the monitoring data, logs and execution plans, as well as table structures and statistical information, to obtain target multi-source data. Due to the standardized and unified representation of the data, the abnormal indicator knowledge graph constructed based on the target multi-source data can be migrated to a variety of databases for use, which improves the versatility and extensibility of the abnormal indicator knowledge graph and avoids the problem that the abnormal indicator knowledge graph is tightly coupled with a specific database and cannot be used in other databases.
[0057] S302. Extract multiple entities and relationships between entities from the target multi-source data according to preset rules; use multiple entities as nodes and relationships as edges to construct an abnormal indicator knowledge graph.
[0058] Among them, the preset rules include entity types and relationship types.
[0059] Specifically, based on a pre-trained extraction model, multiple entities and relationships corresponding to the aforementioned entity types and relationship types are extracted from the target multi-source data. Based on the relationships between these multiple entities, causal paths are constructed, using entities as nodes and relationships as edges. Each entity corresponds to at least one causal path, and then an anomaly indicator knowledge graph is constructed based on these multiple causal paths. Examples of entity types include anomaly indicators, events, root causes, and solutions, and examples of relationship types include causes, root causes are, and recommendations. For example, the causal path can be: anomaly indicator → [cause]: event → [root cause is]: root cause → [recommendation]: solution.
[0060] For example, Figure 2 As shown, the data layer 210 sends the acquired target multi-source data to the knowledge graph module 220, and then extracts entity data of preset entity types and relationship data of preset relationship types from the above target multi-source data through the entity and relationship extraction module 221 in the knowledge graph module 220, and sends the extracted entity data and relationship data to the causal path construction module 222. The causal path construction module 222 constructs a causal path with entities as nodes and relationships as edges, and then integrates and analyzes multiple causal paths to construct an abnormal indicator knowledge graph. In addition, the abnormal indicator knowledge graph is stored in the graph database to facilitate the graph storage and query module 223 to query and update the abnormal indicator knowledge graph.
[0061] S303: When an abnormal indicator is detected, determine at least one causal path from the abnormal indicator knowledge graph.
[0062] This step S303 is similar to the explanation of the above step S101 and will not be repeated here.
[0063] S304: Input the abnormality indicator and at least one causal path into a prompt word generation model to obtain at least one prompt word.
[0064] The prompt word generation model is trained based on multiple historical anomaly indicators, at least one causal path corresponding to each historical anomaly indicator, and at least one historical prompt word associated with each causal path. For example, a first historical anomaly indicator corresponds to a first causal path and a second causal path, and the first historical anomaly indicator and the first causal path are associated with a first historical prompt word. The first historical anomaly indicator and the second causal path are associated with a second historical prompt word and a third historical prompt word.
[0065] Specifically, the anomaly indicator corresponds to at least one causal path, and the anomaly indicator is associated with each causal path to obtain a corresponding relationship between the anomaly indicator and each causal path. Multiple corresponding relationships are input into a prompt word generation model to obtain at least one prompt word corresponding to each corresponding relationship. Optionally, the prompt word generation model includes a prompt word generator and a reinforcement learning network. After receiving the anomaly indicator and the causal path, the trained prompt word generator outputs at least one prompt word based on the anomaly indicator and the corresponding causal path.
[0066] Optionally, a training method for a prompt word generation model is provided herein, the method comprising: constructing a training set based on multiple historical abnormality indicators, at least one causal path corresponding to each historical abnormality indicator, and at least one historical prompt word corresponding to each causal path of each historical abnormality indicator; training an initial prompt word generation model with the training set to obtain multiple prompt words to be output, and then performing root cause reasoning for each of the multiple prompt words to be output based on the prompt word to be output and the corresponding historical abnormality indicator and historical causal path to obtain a second root cause analysis report; obtaining a second evaluation report corresponding to the second root cause analysis report, and performing a multi-dimensional analysis of the second evaluation report through a reinforcement learning network to obtain a reward value for the prompt word to be output; determining whether the reward function in the reinforcement learning network has reached convergence; if the reward function has reached convergence, taking the prompt word to be output as the optimal prompt word, and optimizing and updating the initial prompt word generation model based on the optimal prompt word and the corresponding historical prompt word to obtain a prompt word generation model.
[0067] In addition, when the reward function has not reached convergence, the corresponding prompt word to be output is optimized based on at least one reward value and the second evaluation report, and the reinforcement learning network is updated based on at least one reward value until the reward function reaches convergence, thereby obtaining a prompt word generation model to be determined, and outputting the optimal prompt word. Then, based on the optimal prompt word and the corresponding historical prompt word, the prompt word generation model to be determined is optimized and updated to obtain a prompt word generation model.
[0068] It can be understood that the maximum number of iterations is set. In the process of iterative optimization of the output prompt word, when the current number of iterations reaches the maximum number of iterations, the optimization and update of the output prompt word and the reinforcement learning network are stopped, and the optimal prompt word and the pending prompt word generation model are obtained. Then, based on the optimal prompt word and the corresponding historical prompt word, the pending prompt word generation model is optimized and updated to obtain the prompt word generation model.
[0069] The second evaluation report includes: feedback information from the operation and maintenance personnel. For example, Figure 2As shown, prompt word generation module 230 includes: prompt word generator 231, prompt strategy network 231, and feedback information acquisition module 233. Feedback information acquisition module 233 is used to obtain feedback information from operation and maintenance personnel and send the feedback information to prompt strategy network 231. Prompt generator 231 continuously optimizes prompt words based on the strategy output by prompt strategy network 231 to generate the optimal prompt word.
[0070] For example, prompt word generation module 230 receives historical anomaly indicators and corresponding causal paths. Prompt generator 231 generates a prompt word to be output based on the historical anomaly indicators and the corresponding causal paths, and sends the prompt word to be output to input module 241. Furthermore, input module 241 obtains the historical anomaly indicators and the corresponding causal paths from graph storage and query module 223. Input module 241 extracts and fuses features from the historical anomaly indicators, the corresponding causal paths, and the prompt word to be output. It then inputs the fused features into the LLM reasoning model for root cause reasoning, generating a second root cause analysis report. This second root cause analysis report is then sent to visualization feedback module 260 for display. Feedback from operation and maintenance personnel is then received via operation and maintenance feedback module 261 and sent to feedback information acquisition module 233. Prompt policy network 232 obtains the feedback information from feedback information acquisition module 233 and, based on the feedback information, performs a multi-dimensional quality assessment on the prompt word to be output, obtaining a corresponding reward value. It then determines whether the reward function in prompt policy network 232 has converged. If so, it outputs the optimal prompt word. In addition, if the above-mentioned reward function has not reached convergence, the corresponding prompt word to be output is optimized based on the reward value and the first evaluation report, and the parameters of the Prompt strategy network 232 are updated based on the reward value. The prompt word to be output is iteratively optimized until the reward function reaches convergence or the number of iterations reaches the maximum number of iterations, and the optimal prompt word is output. Then, based on the optimal prompt word and the corresponding historical prompt word, the updated initial prompt word generation model is further optimized and updated to obtain the prompt word generation model 230.
[0071] S305: For each prompt word in the at least one prompt word, perform a root cause analysis on the abnormal indicator, the causal path, and the current indicator data based on the prompt word to obtain a corresponding first root cause analysis report, and obtain a first evaluation report corresponding to the first root cause analysis report.
[0072] The prompt word guides the root cause analysis of the abnormal indicator, causal path, and current indicator data. Specifically, a root cause analysis is performed based on the prompt word, resulting in a corresponding first root cause analysis report. This first root cause analysis report includes, but is not limited to, the root cause location, detailed explanation, and solution for the abnormal indicator. This solution is a pre-set solution to the root cause, and the LLM reasoning model can also be used to optimize and update the pre-set solution to obtain a more complete solution.
[0073] Optionally, the first root cause analysis report is analyzed and evaluated using a root cause analysis model, and / or feedback information regarding the first root cause analysis report from operation and maintenance personnel is received to generate a first evaluation report.
[0074] S306 , performing a multi-dimensional analysis on the at least one first evaluation report through a reinforcement learning network, and iteratively optimizing prompt word parameters based on the analysis results to obtain an optimal prompt word.
[0075] Specifically, the reinforcement learning network performs a multi-dimensional evaluation of the generated prompt words based on the first evaluation report, and calculates the reward value corresponding to the prompt words based on the evaluation results and the reinforcement learning network's reward function. If the reward function does not reach convergence, the prompt word parameters are continuously iteratively optimized until the reward function reaches convergence or the number of iterations reaches the maximum number of iterations. The prompt word corresponding to the maximum reward value is output as the optimal prompt word. The evaluation dimensions include accuracy, relevance, and interpretability, and the evaluation results include the evaluation value corresponding to each dimension. Accuracy, for example, refers to whether the root cause location is consistent with the actual fault. Relevance, for example, refers to whether the prompt word includes key indicators. Interpretability, for example, refers to whether the logic of the root cause analysis report is clear.
[0076] S307: Obtain current indicator data corresponding to the abnormal indicator and the multiple related indicators.
[0077] Specifically, the current indicator data corresponding to the abnormal indicator and multiple related indicators is obtained. For example, the abnormal indicator is: CPU (central processing unit) utilization reaches 95%. The related indicators included in the causal path corresponding to this abnormal indicator include: network traffic, number of threads, and disk I / O (input and output). The current indicator data corresponding to CPU utilization, network traffic, number of threads, and disk I / O are obtained.
[0078] The current indicator data reflects the dynamic changes of the current abnormal environment. Using the current indicator data for root cause reasoning is conducive to obtaining root cause analysis results that adapt to the current abnormal environment.
[0079] S308: Analyze at least one causal path and multiple current indicator data according to the optimal prompt word, and determine a target causal path that meets the multiple current indicator data from the at least one causal path.
[0080] If an abnormal indicator corresponds to a single causal path, that path is used as the target causal path. If an abnormal indicator corresponds to multiple causal paths, the multiple causal paths are verified based on the current indicator data, and the confidence level corresponding to each causal path is determined. Based on the path screening criteria in the optimal prompt word, the causal path corresponding to the confidence level that meets the path screening criteria is determined as the target causal path. For example, the causal path corresponding to the highest confidence level is determined as the target causal path, resulting in an accurate target causal path that is highly adapted to the current abnormal environment, thereby improving the accuracy of root cause analysis.
[0081] Optionally, if all causal paths fail to meet the path screening criteria in the optimal prompt, an alarm is triggered, prompting the operation and maintenance personnel to identify a target causal path. Furthermore, there may be multiple target causal paths. In step S308, the root cause analysis results corresponding to the multiple target causal paths are simply integrated to generate a root cause analysis report.
[0082] It is understandable that the path screening condition in this application can also be: combining the confidence level and the historical abnormal causal paths in the database to determine the target causal path. This application does not impose any restrictions on the path screening condition.
[0083] S309: Based on the optimal prompt word, perform reasoning analysis on the target causal path and current indicator data to obtain a root cause analysis report.
[0084] Specifically, based on the optimal prompt words, the target causal path and real-time indicator data are jointly inferred, and a root cause analysis report is generated based on the inference results. The root cause analysis report includes but is not limited to: root cause, analysis and explanation of the target causal path, risk warning and solution for the root cause. For example, Figure 2 As shown, the large model reasoning module 240 includes an input module 241 and an LLM reasoning model 242. The input module 241 is used to obtain the optimal prompt word, the target causal path, and the current indicator data, and input the optimal prompt word, the target causal path, and the current indicator data into the LLM reasoning model 242. The LLM reasoning model 242 is used to perform reasoning analysis on the target causal path and the current indicator data based on the optimal prompt word for root cause reasoning, and generate a root cause analysis report.
[0085] This method combines the optimal prompt words obtained by dynamic optimization, the target causal path, and the current indicator data for root cause reasoning, and obtains an accurate root cause analysis report that is highly adaptable to the current abnormal scenario.
[0086] S310: Send the root cause analysis report to the operation and maintenance personnel, and obtain feedback information from the operation and maintenance personnel; optimize and update the prompt word generation model based on the feedback information.
[0087] Specifically, after obtaining the root cause analysis report, the report is sent to the operations and maintenance personnel, and feedback is obtained from them. This feedback includes, but is not limited to, the accuracy of the root cause, the completeness of the target path, and the effectiveness and operability of the solution. Furthermore, as explained in step S304 above, the prompt word generation model is optimized and updated based on this feedback.
[0088] It is understandable that when the feedback information indicates that the target causal path is incomplete and / or the nodes are incorrect, the abnormal indicator knowledge graph is updated based on the correct target causal path fed back by the operation and maintenance personnel.
[0089] The database anomaly analysis method provided in this embodiment obtains and preprocesses multi-source data to obtain standardized and unified target multi-source data. It then extracts multiple entities and their relationships from this target multi-source data according to preset rules, constructing an anomaly indicator knowledge graph using the entities as nodes and the relationships as edges. This anomaly indicator knowledge graph, constructed based on the standardized and unified target multi-source data, can be migrated and reused across various database types, improving its versatility. Furthermore, when an abnormal indicator is detected, at least one causal path is determined from the abnormal indicator knowledge graph. The abnormal indicator and the at least one causal path are input into a prompt word generation model to obtain at least one prompt word. Then, for each of the at least one prompt word, a root cause analysis is performed on the abnormal indicator, the causal path, and the current indicator data based on the prompt word, resulting in a corresponding first root cause analysis report. A first evaluation report corresponding to the first root cause analysis report is also obtained. A multi-dimensional analysis of the at least one first evaluation report is performed using a reinforcement learning network. Based on the analysis results, prompt word parameters are iteratively optimized to obtain an optimal prompt word that is highly adapted to the current abnormal environment. This facilitates a more accurate root cause analysis report in subsequent root cause reasoning. After obtaining the optimal prompt word, the current indicator data corresponding to the abnormal indicator and the multiple related indicators are obtained. The at least one causal path and the multiple current indicator data are analyzed based on the optimal prompt word to obtain a target causal path that is accurate and highly adapted to the current abnormal environment. Based on the optimal prompt word, the target causal path and the current indicator data are then reasoned and analyzed to obtain a root cause analysis report. This method combines the optimal prompt word obtained through dynamic optimization, the target causal path, and current indicator data to perform root cause inference, resulting in an accurate root cause analysis report that is highly adapted to the current anomaly scenario. Furthermore, this root cause analysis report is sent to operations and maintenance personnel to obtain feedback, which is then used to optimize and update the prompt word generation model. This method not only enables automatic optimization of the prompt word generation model but also enables operations and maintenance personnel to promptly obtain the current abnormal state of the database and take effective measures to resolve the current abnormal state based on the solutions provided in the root cause analysis report.
[0090] Figure 4 Schematic diagram of the process of the database anomaly analysis method provided in the embodiment of the application Figure 3 .like Figure 4 As shown, this embodiment Figure 1-3 Based on the embodiment, after completing the root cause analysis of the abnormal indicators and obtaining the root cause analysis report, a method for predicting database indicators is described in detail. The method includes:
[0091] S401: Obtain indicator data within a preset time period.
[0092] Among them, the indicator data carries a time series label, and the preset time period is, for example: indicator data within 72 hours before the current moment. The preset time period is set based on the predicted needs of the database, and can also be set according to experience values. This application does not limit the setting method of the preset time period.
[0093] Optionally, the root cause analysis report includes a target causal path, determines at least one first indicator included in the target causal path, and obtains indicator data for the at least one first indicator and a preset key indicator within a preset time period, the indicator data carrying a time series tag. The key indicator is an indicator that affects database performance.
[0094] It is understandable that multiple indicator data are preprocessed to obtain a unified and standardized time series model. Figure 2 As shown, the time series model building module 251 obtains the above-mentioned multiple indicator data from the data layer 210, and builds a time series model based on the multiple indicator data, so as to perform trend prediction according to the time series model later.
[0095] S402: Input the indicator data and the root cause analysis report into the prediction model to obtain prediction values corresponding to a plurality of indicators to be predicted.
[0096] The prediction model is trained based on historical indicator data, root cause analysis report features, and the actual values of the indicators to be predicted. The indicators to be predicted carry time series labels and include, but are not limited to, multiple key indicators that affect database performance.
[0097] Specifically, after receiving the indicator data and root cause analysis report, the prediction model extracts and analyzes the indicator data and root cause analysis report to obtain prediction values corresponding to multiple indicators to be predicted. It can be understood that each indicator to be predicted corresponds to multiple prediction values, and the prediction values carry time series labels.
[0098] S403: Determine a change trend of each indicator to be predicted based on multiple predicted values corresponding to each indicator to be predicted.
[0099] Specifically, for each of the multiple indicators to be predicted, a change trend of the indicator to be predicted is calculated based on the multiple predicted values corresponding to the indicator to be predicted and the time series labels carried by each predicted value. For example, multiple discrete predicted values are preprocessed to obtain multiple preprocessed predicted values, and the change trend of the indicator to be predicted is analyzed based on the multiple preprocessed predicted values and the time series labels carried by the multiple predicted values. The change trend includes, but is not limited to, an upward / downward trend of the indicator to be predicted, a change slope, a trend graph, and the maximum and minimum predicted values corresponding to the indicator to be predicted.
[0100] S404. Determine whether each change trend satisfies the warning condition of the corresponding indicator to be predicted; if at least one change trend satisfies the corresponding warning condition, execute the following step S405; if multiple change trends do not meet the corresponding warning condition, execute the following step S406.
[0101] Each indicator to be predicted has a corresponding warning condition. Multiple predicted values for each indicator are evaluated based on the corresponding warning condition, pre-identifying database indicators that may be experiencing anomalies. This allows operations and maintenance personnel to take preventive measures based on the evaluation results, thereby ensuring the smooth operation of the database. Specifically, for any of the multiple indicators to be predicted, the system determines whether the trend of the indicator meets the corresponding warning condition to assess whether the indicator is a risk indicator.
[0102] Among them, the warning conditions can be, for example: the first indicator to be predicted shows an upward trend, and the maximum predicted value of the first indicator to be predicted is greater than the first preset threshold, and the absolute value of the change slope of the second indicator to be predicted is greater than the second preset slope.
[0103] Optionally, specific warning conditions are set based on the impact of each indicator to be predicted on database performance. This application does not limit the method for determining the warning conditions.
[0104] S405: Determine the indicators to be predicted that meet the corresponding warning conditions as risk indicators, and generate warning information and prevention suggestions based on the risk indicators and corresponding change trends; and send the warning information and prevention suggestions to operation and maintenance personnel.
[0105] Specifically, if the judgment result of step S404 indicates that at least one change trend meets the corresponding warning condition, the indicator to be predicted that meets the corresponding warning condition is determined to be a risk indicator. A warning analysis is then performed on the risk indicator and the change trend corresponding to the risk indicator. Based on the analysis results, warning information and preventive suggestions are generated. These warning information and preventive suggestions are then sent to operations and maintenance personnel so that they can take preventive measures in advance based on the preventive suggestions to ensure the smooth operation of the database. The warning information includes, but is not limited to, the name of the risk indicator, its warning level, its trend chart, and its impact on the database.
[0106] For example, Figure 2As shown, the trend prediction module 250 includes: a time series model construction module 251, a prediction module 252, and an early warning module 253. Among them, the time series model construction module 251 constructs a time series model based on the indicator data, and the prediction module 252 receives the root cause analysis report sent by the LLM reasoning model 242. Based on the above time series model and the root cause analysis report, it predicts the trend of the indicators to be predicted, obtains the change trend corresponding to each indicator to be predicted, and sends the change trend to the early warning module 253. The early warning module 253 makes a judgment based on the preset early warning conditions, determines the risk indicator from the multiple indicators to be predicted, and generates early warning information and prevention suggestions based on the risk indicator and the corresponding change trend. The early warning information and prevention suggestions are sent to the visualization interface 262 for display processing.
[0107] S406: Send the multiple indicators to be predicted and the change trend corresponding to each indicator to be predicted to the operation and maintenance personnel.
[0108] After obtaining the change trends corresponding to multiple indicators to be predicted, the multiple indicators to be predicted and the change trends corresponding to each indicator to be predicted are sent to the operation and maintenance personnel, so that the operation and maintenance personnel can optimize the allocation of database resources according to needs, improve the service effect of database resources, and thus help improve the operation efficiency of the corresponding business system.
[0109] The database anomaly analysis method provided in this embodiment obtains indicator data within a preset time period and inputs the indicator data and root cause analysis report into a prediction model to obtain prediction values corresponding to multiple indicators to be predicted. Then, based on the multiple prediction values corresponding to each indicator to be predicted, the change trend of each indicator to be predicted is determined, and each change trend is judged to determine whether it meets the warning condition of the corresponding indicator to be predicted. If at least one change trend meets the corresponding warning condition, the indicator to be predicted that meets the corresponding warning condition is determined as a risk indicator. Based on the risk indicator and the change trend corresponding to the risk indicator, warning information and prevention suggestions are generated, and then the warning information and prevention suggestions are sent to the operation and maintenance personnel so that the operation and maintenance personnel can grasp the risk indicators of the database in a timely manner and take corresponding measures to ensure efficient service of the database. In addition, if multiple change trends do not meet the corresponding warning conditions, the multiple indicators to be predicted and the change trend corresponding to each indicator to be predicted are sent to the operation and maintenance personnel so that the operation and maintenance personnel can optimize the allocation of database resources according to needs and improve the service effect of database resources.
[0110] Figure 5 The schematic diagram of the structure of the database anomaly analysis device provided by this application is as follows: Figure 5 As shown, the database anomaly analysis device 50 provided in this embodiment includes:
[0111] Determination module 501, configured to determine at least one causal path from the abnormal indicator knowledge graph when an abnormal indicator is detected, wherein the causal path includes at least one related indicator of the abnormal indicator;
[0112] An input module 502 is configured to input the abnormality indicator and at least one causal path into a prompt word generation model;
[0113] A prompt word generation module 503 is configured to dynamically optimize prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word. The prompt word generation model is trained based on historical anomaly indicators, causal paths corresponding to the historical anomaly indicators, historical prompt words, and feedback from operation and maintenance personnel.
[0114] An acquisition module 504 is configured to acquire current indicator data corresponding to the abnormal indicator and the plurality of related indicators;
[0115] The root cause reasoning module 505 is configured to perform root cause reasoning based on the multiple current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report.
[0116] In a possible implementation, the apparatus further includes: a construction module 506, a training module 507, a processing module 508, a judgment module 509, and an optimization module 510;
[0117] The construction module 506 is configured to construct a training set based on a plurality of historical abnormal indicators, at least one causal path corresponding to each of the historical abnormal indicators, and at least one historical prompt word associated with each of the historical abnormal indicators and the corresponding causal path;
[0118] The training module 507 is used to train the initial prompt word generation model using the training set to obtain multiple prompt words to be output;
[0119] The root cause reasoning module 505 is specifically configured to perform root cause reasoning on each of the plurality of prompt words to be output based on the prompt word to be output and the corresponding historical abnormality indicator and historical causal path to obtain a second root cause analysis report;
[0120] The acquisition module 504 is further configured to acquire a second evaluation report corresponding to the second root cause analysis report, wherein the second evaluation report includes feedback information from an operation and maintenance personnel;
[0121] The processing module 508 is configured to perform a multi-dimensional analysis on the second evaluation report through the reinforcement learning network to obtain a reward value for the prompt word to be output;
[0122] The judgment module 509 is used to judge whether the reward function in the reinforcement learning network has reached convergence;
[0123] The determining module 501 is further configured to, when the reward function reaches convergence, use the prompt word to be output as the optimal prompt word;
[0124] The optimization module 510 is configured to optimize and update the initial prompt word generation model based on the optimal prompt word and the corresponding historical prompt words to obtain the prompt word generation model, wherein the historical prompt words include: the historical abnormality indicator corresponding to the optimal prompt word and at least one historical prompt word associated with a causal path;
[0125] The optimization module 510 is further configured to, if the reward function has not reached convergence, optimize the corresponding prompt word to be output based on at least one reward value and the second evaluation report, and update the reinforcement learning network based on at least one reward value until the reward function reaches convergence, thereby obtaining a prompt word generation model to be determined and outputting an optimal prompt word;
[0126] The optimization module 510 is further configured to optimize and update the pending prompt word generation model based on the optimal prompt word and the corresponding historical prompt word to obtain the prompt word generation model.
[0127] In a possible implementation, the input module 502 is specifically configured to input the abnormality indicator and the causal path into a prompt word generation model to obtain at least one prompt word;
[0128] The root cause reasoning module 505 is further configured to perform a root cause analysis on the abnormal indicator, the causal path, and the current indicator data based on each prompt word in the at least one prompt word, obtain a corresponding first root cause analysis report, and acquire a first evaluation report corresponding to the first root cause analysis report;
[0129] The prompt word generation module 503 is specifically configured to perform a multi-dimensional analysis on at least one of the first evaluation reports through the reinforcement learning network, and iteratively optimize prompt word parameters based on the analysis results to obtain an optimal prompt word.
[0130] In a possible implementation, the apparatus further includes: a sending module 511;
[0131] The acquisition module 504 is further configured to acquire indicator data within a preset period, wherein the indicator data carries a time series tag;
[0132] The input module 502 is further configured to input the indicator data and the root cause analysis report into the prediction model to obtain prediction values corresponding to a plurality of indicators to be predicted, wherein the prediction values carry time series labels;
[0133] The determining module 501 is further configured to determine a change trend of each of the indicators to be predicted based on a plurality of predicted values corresponding to each of the indicators to be predicted;
[0134] The judgment module 509 is further configured to judge whether each of the change trends satisfies the warning condition of the corresponding indicator to be predicted;
[0135] The determining module 501 is further configured to, when at least one of the change trends satisfies a corresponding warning condition, determine the indicator to be predicted that satisfies the corresponding warning condition as a risk indicator, and generate warning information and preventive suggestions based on the risk indicator and the corresponding change trend;
[0136] The sending module 511 is used to send the warning information and the preventive suggestions to the operation and maintenance personnel.
[0137] In a possible implementation, the apparatus further includes: an extraction module 512;
[0138] The acquisition module 504 is further configured to acquire multi-source data, including database monitoring data and database logs;
[0139] The processing module 508 is further configured to pre-process the multi-source data to obtain target multi-source data;
[0140] The extraction module 512 is used to extract multiple entities and relationships between entities from the target multi-source data according to preset rules, wherein the preset rules include entity types and relationship types;
[0141] The construction module 506 is specifically used to construct the abnormal indicator knowledge graph by using the multiple entities as nodes and the relationships as edges.
[0142] In a possible implementation, the sending module 511 is further configured to send the root cause analysis report to an operation and maintenance personnel;
[0143] The acquisition module 504 is further configured to obtain feedback information from the operation and maintenance personnel;
[0144] The optimization module 510 is further configured to optimize and update the prompt word generation model based on the feedback information.
[0145] In one possible implementation, the root cause reasoning module 505 is specifically used to analyze at least one of the causal paths and multiple current indicator data based on the optimal prompt word, and determine a target causal path that meets multiple current indicators from the at least one causal path; based on the optimal prompt word, perform reasoning analysis on the target causal path and the current indicator data to obtain the root cause analysis report.
[0146] The database anomaly analysis device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0147] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 6 As shown, the electronic device 60 provided in this embodiment includes: at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. The processor 601, the memory 602 and the communication component 603 are connected via a bus 604.
[0148] During the specific implementation process, at least one processor 601 executes the computer-executable instructions stored in the memory 602, so that the at least one processor 601 performs the above method.
[0149] The specific implementation process of the processor 601 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0150] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules within the processor.
[0151] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage.
[0152] A bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0153] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0154] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0155] The readable storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0156] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0157] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0158] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0159] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0160] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0161] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0162] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.
[0163] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0164] It should be understood that the above-described device embodiments are merely illustrative, and the device of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0165] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.
[0166] If an integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.
[0167] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk, or optical disk, etc., various media that can store program code.
[0168] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0169] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0170] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A database anomaly analysis method, characterized in that: include: When an abnormal indicator is detected, determining at least one causal path from the abnormal indicator knowledge graph, the causal path including at least one related indicator of the abnormal indicator; Inputting the abnormality indicator and at least one of the causal paths into a prompt word generation model, dynamically optimizing prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word, wherein the prompt word generation model is trained based on historical abnormality indicators, the causal paths corresponding to the historical abnormality indicators, historical prompt words, and feedback from operation and maintenance personnel; Current indicator data corresponding to the abnormal indicator and the plurality of related indicators are obtained, and root cause reasoning is performed based on the plurality of current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report.
2. The method according to claim 1, characterized in that The method further comprises: Constructing a training set based on a plurality of historical abnormal indicators, at least one causal path corresponding to each of the historical abnormal indicators, and at least one historical prompt word associated with each of the historical abnormal indicators and the corresponding causal path; Using the training set to train the initial prompt word generation model to obtain multiple prompt words to be output; For each prompt word to be output among the plurality of prompt words to be output, performing root cause reasoning based on the prompt word to be output and the corresponding historical abnormality indicator and historical causal path to obtain a second root cause analysis report; Obtaining a second evaluation report corresponding to the second root cause analysis report, where the second evaluation report includes feedback information from an operation and maintenance personnel; Performing a multi-dimensional analysis on the second evaluation report through the reinforcement learning network to obtain a reward value for the prompt word to be output; Determining whether the reward function in the reinforcement learning network has reached convergence; When the reward function reaches convergence, the prompt word to be output is used as the optimal prompt word; Based on the optimal prompt word and the corresponding historical prompt word, the initial prompt word generation model is optimized and updated to obtain the prompt word generation model, wherein the historical prompt word includes: the historical abnormality indicator corresponding to the optimal prompt word and at least one historical prompt word associated with a causal path; If the reward function has not reached convergence, optimizing the corresponding prompt word to be output based on at least one of the reward values and the second evaluation report, and updating the reinforcement learning network based on at least one of the reward values until the reward function reaches convergence, thereby obtaining a prompt word generation model to be determined, and outputting an optimal prompt word; Based on the optimal prompt word and the corresponding historical prompt word, the pending prompt word generation model is optimized and updated to obtain the prompt word generation model.
3. The method according to claim 2, characterized in that Inputting the abnormality indicator and at least one of the causal paths into a prompt word generation model, and dynamically optimizing prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word, includes: Inputting the abnormality indicator and the causal path into a prompt word generation model to obtain at least one prompt word; For each prompt word in the at least one prompt word, performing a root cause analysis on the abnormal indicator, the causal path, and the current indicator data based on the prompt word to obtain a corresponding first root cause analysis report, and obtaining a first evaluation report corresponding to the first root cause analysis report; A multi-dimensional analysis is performed on at least one of the first evaluation reports through the reinforcement learning network, and prompt word parameters are iteratively optimized based on the analysis results to obtain an optimal prompt word.
4. The method according to claim 1, wherein After performing root cause reasoning based on the plurality of current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report, the method further includes: Obtaining indicator data within a preset time period, wherein the indicator data carries a time series tag; Inputting the indicator data and the root cause analysis report into a prediction model to obtain predicted values corresponding to a plurality of indicators to be predicted, wherein the predicted values carry time series labels; Determining a change trend of each of the indicators to be predicted based on a plurality of predicted values corresponding to each of the indicators to be predicted; Determining whether each of the change trends satisfies the warning conditions of the corresponding indicator to be predicted; When at least one of the change trends satisfies a corresponding warning condition, determining the indicator to be predicted that satisfies the corresponding warning condition as a risk indicator, and generating warning information and preventive suggestions based on the risk indicator and the corresponding change trend; The warning information and the preventive suggestions are sent to the operation and maintenance personnel.
5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: Acquiring multi-source data, the multi-source data including: database monitoring data and database logs; Preprocessing the multi-source data to obtain target multi-source data; Extracting multiple entities and relationships between entities from target multi-source data according to preset rules, wherein the preset rules include entity types and relationship types; The abnormal indicator knowledge graph is constructed by taking the multiple entities as nodes and the relationships as edges.
6. The method according to claim 5, characterized in that After performing root cause reasoning based on the plurality of current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report, the method further includes: Sending the root cause analysis report to the operation and maintenance personnel and obtaining feedback from the operation and maintenance personnel; The prompt word generation model is optimized and updated based on the feedback information.
7. The method according to claim 6, characterized in that The root cause reasoning is performed based on the multiple current indicator data, the causal path, and the optimal prompt word to obtain a root cause analysis report, including: Analyzing at least one of the causal paths and the plurality of current indicator data according to the optimal prompt word, and determining a target causal path that meets the plurality of current indicators from the at least one causal path; Based on the optimal prompt word, the target causal path and the current indicator data are subjected to reasoning analysis to obtain the root cause analysis report.
8. A database anomaly analysis device, characterized in that: include: a determination module, configured to, when an abnormal indicator is detected, determine at least one causal path from the abnormal indicator knowledge graph, the causal path including at least one related indicator of the abnormal indicator; an input module, configured to input the abnormality indicator and at least one of the causal paths into a prompt word generation model; a prompt word generation module, configured to dynamically optimize prompt word parameters through a reinforcement learning network in the prompt word generation model to obtain an optimal prompt word, wherein the prompt word generation model is trained based on historical anomaly indicators, causal paths corresponding to the historical anomaly indicators, historical prompt words, and feedback from operations and maintenance personnel; An acquisition module, configured to acquire current indicator data corresponding to the abnormal indicator and the plurality of related indicators; The root cause reasoning module is used to perform root cause reasoning based on the multiple current indicator data, the causal path and the optimal prompt word to obtain a root cause analysis report.
9. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.
11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.
Citation Information
Cited By
Large model-based multi-dimensional index abnormal reason generation and intervention path recommendation method
CN121543746A