Alarm analysis method and device, computer equipment and storage medium

By calculating confidence levels and performing root cause analysis when receiving query results from some alarm-related data sources, the problem of low efficiency in alarm information root cause analysis is solved, and the stability of the business system is improved.

CN120832256APending Publication Date: 2025-10-24TENCENT TECH WUHAN
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410479619.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-18
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

In the existing technology, the efficiency of root cause analysis of alarm information is low, which affects the stability of the business system.

Method used

By acquiring alarm time period, range, and scenario information from alarm information, query data from multiple alarm-related data sources is generated. When partial query results are received, the confidence level of the analysis results is calculated based on the correlation. When the confidence level reaches a threshold, root cause analysis is performed to avoid waiting for all data sources to return results.

Benefits of technology

It improved the efficiency of root cause analysis of alarm information, shortened the mean time to repair, and enhanced the stability of business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832256A_ABST
    Figure CN120832256A_ABST
Patent Text Reader

Abstract

The invention provides an alarm analysis method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information; generating alarm query data corresponding to the plurality of alarm associated data sources according to the alarm time period information and the alarm range information, and sending the corresponding alarm query data to each alarm associated data source; when a query result returned by any alarm association data source based on the corresponding alarm query data is received, determining an association degree corresponding to at least one received query result according to the alarm scene information; calculating the confidence coefficient of the analysis result according to the correlation degree; and when the analysis result confidence is greater than a preset confidence threshold, analyzing the alarm root cause corresponding to the alarm information according to the at least one query result. According to the method, the alarm analysis efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, and particularly relates to an alarm analysis method and device, computer equipment and a storage medium. BACKGROUND

[0002] In the use process of a business system, when a detection device detects that there is an index exception, an abnormal behavior, a system failure or an event affecting safety in the system, alarm information is generated according to the detected specific exception information and an alarm is triggered.

[0003] When alarm information is generated in a business system, root cause analysis of the alarm information needs to be performed in a timely manner, and then abnormality elimination is performed according to the analysis result. However, the efficiency of the root cause analysis of the alarm information is low at present. SUMMARY

[0004] The alarm analysis method, device, computer equipment and storage medium provided by the embodiments of the present disclosure can improve the efficiency of alarm analysis.

[0005] The first aspect of the present disclosure provides an alarm analysis method, and the method comprises:

[0006] obtaining alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information;

[0007] generating alarm query data corresponding to a plurality of alarm associated data sources according to the alarm time period information and the alarm range information, and sending the alarm query data corresponding to each alarm associated data source to the alarm associated data source;

[0008] when receiving a query result returned by any alarm associated data source based on the corresponding alarm query data, determining an association degree corresponding to at least one query result that has been received according to the alarm scene information;

[0009] calculating an analysis result confidence according to the association degree;

[0010] when the analysis result confidence is greater than a preset confidence threshold, analyzing an alarm root cause corresponding to the alarm information according to the at least one query result.

[0011] The second aspect of the present disclosure provides an alarm analysis device, and the device comprises:

[0012] an obtaining unit, configured to obtain alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information;

[0013] The generating unit is configured to generate alarm query data corresponding to each alarm correlation data source according to the alarm period information and the alarm range information, and send the alarm query data to each alarm correlation data source;

[0014] The determining unit is configured to determine a correlation degree corresponding to at least one received query result according to the alarm scene information when receiving the query result returned by any alarm correlation data source based on the corresponding alarm query data;

[0015] The calculating unit is configured to calculate an analysis result confidence according to the correlation degree;

[0016] The analyzing unit is configured to analyze an alarm root cause corresponding to the alarm information according to the at least one query result when the analysis result confidence is greater than a preset confidence threshold.

[0017] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0018] The receiving sub-unit is configured to receive a query result returned by a next alarm correlation data source when the analysis result confidence is not greater than the preset confidence threshold.

[0019] The executing sub-unit is configured to return to execute the steps of determining a correlation degree corresponding to at least one received query result according to the alarm scene information, calculating an analysis result confidence according to the correlation degree, and comparing the analysis result confidence with a preset confidence threshold.

[0020] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0021] The first generating sub-unit is configured to generate query termination information corresponding to each target alarm correlation data source, the target alarm correlation data source being an alarm correlation data source that does not return a query result.

[0022] The sending sub-unit is configured to send a query termination instruction containing the query termination information to each target alarm correlation data source, so that the target alarm correlation data source terminates an alarm query task indicated by the alarm query data.

[0023] Optionally, in some embodiments, the determining unit comprises:

[0024] The first determining sub-unit is configured to determine a root cause correlation weight coefficient corresponding to each alarm correlation data source according to the alarm scene information.

[0025] The second determining sub-unit is configured to determine a query result completeness degree when receiving a query result returned by any alarm correlation data source based on the corresponding alarm query data.

[0026] The first calculation sub-unit is configured to calculate the correlation degree corresponding to the at least one query result according to the root cause correlation weight coefficient corresponding to the at least one query result and the query result completeness.

[0027] Optionally, in some embodiments, the first determination sub-unit comprises:

[0028] The acquisition module is configured to acquire historical root cause analysis data, wherein the historical root cause analysis data comprises a plurality of historical alarm data in a preset time period and a historical root cause analysis result corresponding to each historical alarm data.

[0029] The determination module is configured to determine historical alarm scene information corresponding to each historical alarm data and determine a historical root cause correlation weight coefficient between each historical root cause analysis result and a plurality of alarm correlation data sources.

[0030] The training module is configured to train a preset neural network model by taking each historical alarm scene information as a model input and taking a corresponding historical root cause correlation weight coefficient as an output.

[0031] The prediction module is configured to predict a root cause correlation weight coefficient based on the trained preset neural network model according to the alarm scene information, and obtain a root cause correlation weight coefficient corresponding to each alarm correlation data source.

[0032] Optionally, in some embodiments, the calculation unit comprises:

[0033] The second calculation sub-unit is configured to calculate a sum of the at least one correlation degree corresponding to the at least one query result to obtain a total correlation degree value.

[0034] The third calculation sub-unit is configured to calculate an analysis result confidence according to the total correlation degree value and a reference correlation degree value.

[0035] Optionally, in some embodiments, the generation unit comprises:

[0036] The second generation sub-unit is configured to generate a data query logic corresponding to each alarm correlation data source according to the alarm time period information and the alarm range information.

[0037] The third generation sub-unit is configured to generate a query data model corresponding to each alarm correlation data source based on the data query logic.

[0038] The sending sub-unit is configured to send the corresponding query data model to each alarm correlation data source.

[0039] The determination unit is further configured to:

[0040] When receiving any of the query results returned by the corresponding query data model based on the query data source, the correlation degree of at least one received query result corresponding to the alarm scene information is determined according to the alarm scene information.

[0041] Optionally, in some embodiments, the alarm analysis device provided by the present disclosure further comprises:

[0042] The identification subunit is configured to identify an alarm type corresponding to the alarm information.

[0043] The searching subunit is configured to search for a candidate alarm root cause in a preset alarm analysis database based on the alarm type.

[0044] The verification subunit is configured to verify the candidate alarm root cause to obtain a verification result.

[0045] The analysis unit is further configured to:

[0046] When the analysis result confidence is greater than a preset confidence threshold, the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result.

[0047] Optionally, in some embodiments, the analysis unit comprises:

[0048] The third determination subunit is configured to determine a first sub-alarm root cause according to the at least one query result when the analysis result confidence is greater than a preset confidence threshold.

[0049] The fourth determination subunit is configured to determine a candidate alarm root cause that passes the verification as a second sub-alarm root cause according to the verification result.

[0050] The fifth determination subunit is configured to determine any one of the first sub-alarm root cause and the second sub-alarm root cause as the alarm root cause corresponding to the alarm information when the first sub-alarm root cause is consistent with the second sub-alarm root cause.

[0051] The sixth determination subunit is configured to send the first sub-alarm root cause and the second sub-alarm root cause to a plurality of voting nodes for voting when the first sub-alarm root cause is inconsistent with the second sub-alarm root cause, and determine the alarm root cause corresponding to the alarm information according to the received voting result.

[0052] Optionally, in some embodiments, the analysis unit comprises:

[0053] The fourth generation subunit is configured to generate an alarm event case according to the alarm information and the alarm root cause corresponding to the alarm information.

[0054] The updating subunit is configured to update the preset alarm analysis database based on the alarm event case.

[0055] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0056] a seventh determining sub-unit, configured to determine a target alarm root cause from the candidate alarm root causes according to the verification result when the analysis result confidence is not greater than the preset confidence threshold;

[0057] an eighth determining sub-unit, configured to determine the target alarm root cause as an alarm root cause corresponding to the alarm information.

[0058] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0059] a first obtaining sub-unit, configured to obtain object information contained in the alarm information, and determine an object node corresponding to the object information in a preset object relationship network;

[0060] a second obtaining sub-unit, configured to determine an associated node associated with the object node in the preset object relationship network, and obtain an alarm root cause analysis record of each associated node, the associated node including the object node;

[0061] an evaluation sub-unit, configured to generate a system state evaluation feature based on the alarm root cause analysis record, and input the system state evaluation feature into a trained system state evaluation model to obtain system abnormal information.

[0062] The third aspect of the present disclosure provides a storage medium, the storage medium storing a computer program, the computer program being executed by a processor to implement the alarm analysis method according to the first aspect.

[0063] The fourth aspect of the present disclosure provides a computer device, comprising a memory and a processor, the memory storing a computer program, the processor implementing the alarm analysis method according to the first aspect when executing the computer program.

[0064] The fifth aspect of the present disclosure provides a computer program product, the computer program product comprising a computer program, the computer program being read and executed by a processor of a computer device, so that the computer device executes the alarm analysis method according to the first aspect.

[0065] The alarm analysis method provided by the embodiments of the present disclosure comprises the following steps: obtaining alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information; generating alarm query data corresponding to a plurality of alarm-associated data sources according to the alarm time period information and the alarm range information, and sending the alarm query data corresponding to each alarm-associated data source to the alarm-associated data source; determining the correlation degree corresponding to at least one query result received according to the alarm scene information when receiving the query result returned by any alarm-associated data source based on the corresponding alarm query data; calculating and analyzing the result confidence degree according to the correlation degree; and analyzing the alarm root cause corresponding to the alarm information according to the at least one query result when the analysis result confidence degree is greater than a preset confidence threshold.

[0066] The embodiments of the present disclosure set the correlation degree corresponding to the alarm scene for each alarm-associated data source, send alarm query to a plurality of alarm-associated data sources to query corresponding information when receiving alarm information, and then determine the confidence degree of the query result according to the correlation degree corresponding to the alarm scene when receiving the query result returned by different alarm-associated data sources. When the confidence degree meets the preset condition, the root cause can be analyzed according to the query result received, without waiting for all query data sources to return the query result, thereby avoiding the problem of low efficiency of root cause analysis caused by low efficiency of result return of part of the query data sources. In this way, the efficiency of root cause analysis of alarm information can be greatly improved, thereby improving the efficiency of solving alarm abnormalities, and further improving the stability of the business system.

[0067] Other features and advantages of the present disclosure will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present disclosure. The objects and other advantages of the present disclosure can be achieved and obtained by the structures specifically pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0068] The accompanying drawings are intended to provide a further understanding of the technical solutions of the present disclosure and constitute a part of the specification, and are used together with the embodiments of the present disclosure to explain the technical solutions of the present disclosure, and do not constitute a limitation on the technical solutions of the present disclosure.

[0069] Figure 1 A system architecture diagram applied to the alarm analysis method of the embodiments of the present disclosure;

[0070] Figure 2 Another system architecture diagram applied to the alarm analysis method of the embodiments of the present disclosure;

[0071] Figure 3 A flowchart of the alarm analysis method provided by the present disclosure;

[0072] Figure 4Another flowchart of the alarm analysis method provided by the present disclosure is shown in FIG. 6;

[0073] Figure 5 A data node flow diagram of the alarm analysis provided by the present disclosure is shown in FIG. 7;

[0074] Figure 6 Another flowchart of the alarm analysis method provided by the present disclosure is shown in FIG. 6;

[0075] Figure 7 A structure diagram of the alarm analysis device provided by the present embodiment of the present disclosure is shown in FIG. 8;

[0076] Figure 8 A terminal structure diagram for implementing the methods according to one embodiment of the present disclosure is shown in FIG. 9;

[0077] Figure 9 A server structure diagram for implementing the methods according to one embodiment of the present disclosure is shown in FIG. 10. DETAILED DESCRIPTION

[0078] In order to make the objectives, technical solutions and advantages of the present disclosure clearer and more apparent, the present disclosure will be further described in detail below in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present disclosure and do not limit the present disclosure.

[0079] Before the present embodiment of the present disclosure is further described in detail, the terms and phrases involved in the present embodiment of the present disclosure are explained, which are applicable to the following explanations:

[0080] Alarm analysis: Alarm analysis is a process of collecting, processing and interpreting alarm information generated by systems, networks or applications to identify potential problems, security risks and performance bottlenecks. The purpose of alarm analysis is to discover and respond to potential security threats in a timely manner in critical situations, ensuring the stable operation of the system and the continuity of the business.

[0081] Observability data: refers to information that can help an object understand the status of a system, application or business process. These data are usually derived from the internal and external of the system, including logs, metrics, traces and events, etc. By collecting, analyzing and visualizing these data, the object can better understand the running status of the system, find potential problems, optimize performance, and improve the reliability and security of the system.

[0082] Observability data mainly includes the following categories: log data (log), trace data (trace) and measurement data (metric), etc.

[0083] Log data: Log data records detailed information about the operation of a system, application, or business process. This information can help an object understand what happened to the system at a certain point in time, thus locating problems and analyzing causes.

[0084] Metric data: Metric data is used to measure system performance, resource utilization, and workload. These data usually include CPU usage, memory occupancy, disk I / O, network bandwidth, etc. Through real-time detection and analysis of metric data, we can find performance bottlenecks and resource shortages in time.

[0085] Trace data: Trace data records the propagation process of requests in a distributed system, including the calling order, delay, and result of requests between services. Through analysis of trace data, we can understand the processing flow of requests and find potential bottlenecks and performance problems.

[0086] Event data: Event data records important events that occur in the system, such as system startup, service deployment, error occurrence, etc. These data can help us understand the running state of the system and timely discover and handle abnormal situations.

[0087] Mean Time To Repair (MTTR): is a measure of the time required to restore a system, device or component to normal operation after failure. It is often used to evaluate the reliability, maintenance efficiency and repair ability of the system.

[0088] In the running process of a business system, system alarms may be generated due to various data anomalies, program anomalies, process anomalies, etc. After receiving the alarm information, the alarm information needs to be analyzed and repaired in time to restore the normal operation of the system. In related technologies, the root cause analysis of alarm information is generally to obtain multiple source system information according to alarm information one by one, and after obtaining the multiple source system information related to the alarm information, the obtained multiple source system information is analyzed according to the preset analysis rule to analyze and determine the alarm root cause. However, due to the frequent occurrence of alarm information in the business system and the huge amount of information of the multiple source system information associated with the alarm information, the efficiency of alarm analysis in related technologies is low, which further leads to a long average repair time of the system, affecting the stability of the business system.

[0089] To solve the problem of low efficiency of alarm analysis in the above scenario, which affects the stability of the business system, the present disclosure provides an alarm analysis method which can improve the efficiency of alarm analysis.

[0090] System architecture and scenario description to which the embodiments of the present disclosure are applied

[0091] Figure 1Fig. 1 is a system architecture diagram to which an alarm analysis method according to an embodiment of the present disclosure is applied. It includes a terminal 140, an Internet 130, a gateway 120, a server 110, and the like.

[0092] The terminal 140 includes a desktop computer, a laptop computer, a PDA (Personal Digital Assistant), a mobile phone, a vehicle-mounted terminal, a home theater terminal, a dedicated terminal, a smart voice interaction device, a smart home appliance, or an aircraft, and the like, in various forms of devices having a display screen. In addition, it can be a single device or a collection of multiple devices. The terminal 140 can communicate with the Internet 130 in a wired or wireless manner and exchange data.

[0093] The server 110 refers to a computer system capable of providing certain services to the terminal 140. Compared with the ordinary terminal 140, the server 110 has higher requirements in stability, security, performance, and the like. The server 110 can be a high-performance computer in a network platform, a cluster of multiple high-performance computers, a part of a high-performance computer (for example, a virtual machine), a combination of parts of multiple high-performance computers (for example, virtual machines), and the like. In the embodiment of the present disclosure, the server 110 specifically provides a storage function, that is, the server 110 here can be a database node of a distributed database, and the present disclosure has a cluster of multiple servers 110 to form a distributed database.

[0094] The gateway 120 is also called an inter-network connector or a protocol converter. The gateway realizes network interconnection at the transport layer and is a computer system or device that acts as a conversion role. In the use of different communication protocols, data formats or languages, or even two systems with completely different architectures, the gateway is a translator. At the same time, the gateway can also provide filtering and security functions. The messages sent by the terminal 140 to the server 110 are sent to the corresponding server 110 through the gateway 120. The messages sent by the server 110 to the terminal 140 are also sent to the corresponding terminal 140 through the gateway 120. In the embodiment of the present disclosure, the terminal 140 sends a data access request to the server 110 through the gateway 120, and the server 110 returns a data access result to the terminal 140 through the gateway 120.

[0095] The alarm analysis method provided by the embodiment of the present disclosure can be implemented in the terminal 140 or in the server 110. In some embodiments, the alarm analysis method can be partially implemented in the terminal 140 and partially implemented in the server 110.

[0096] When the alarm analysis method provided by the embodiments of the present disclosure is implemented in the terminal 140, the terminal 140 acquires alarm information, the alarm information including alarm time period information, alarm range information and alarm scene information; the terminal 140 generates alarm query data corresponding to a plurality of alarm-related data sources according to the alarm time period information and the alarm range information, and sends the corresponding alarm query data to each alarm-related data source; when receiving a query result returned by any alarm-related data source based on the corresponding alarm query data, the terminal 140 determines a correlation degree corresponding to the at least one query result received according to the alarm scene information; the terminal 140 calculates an analysis result confidence according to the correlation degree; when the analysis result confidence is greater than a preset confidence threshold, the terminal 140 analyzes an alarm root cause corresponding to the alarm information according to the at least one query result.

[0097] When the alarm analysis method provided by the embodiments of the present disclosure is implemented in the terminal 140, the terminal 140 acquires alarm information, the alarm information including alarm time period information, alarm range information and alarm scene information; the terminal 140 generates alarm query data corresponding to a plurality of alarm-related data sources according to the alarm time period information and the alarm range information, and sends the corresponding alarm query data to each alarm-related data source; when receiving a query result returned by any alarm-related data source based on the corresponding alarm query data, the terminal 140 determines a correlation degree corresponding to the at least one query result received according to the alarm scene information; the terminal 140 calculates an analysis result confidence according to the correlation degree; when the analysis result confidence is greater than a preset confidence threshold, the terminal 140 analyzes an alarm root cause corresponding to the alarm information according to the at least one query result.

[0098] When the alarm analysis method provided by the embodiments of the present disclosure is implemented in the terminal 140, the terminal 140 acquires alarm information, the alarm information including alarm time period information, alarm range information and alarm scene information; the terminal 140 generates alarm query data corresponding to a plurality of alarm-related data sources according to the alarm time period information and the alarm range information, and sends the corresponding alarm query data to each alarm-related data source; when receiving a query result returned by any alarm-related data source based on the corresponding alarm query data, the terminal 140 determines a correlation degree corresponding to the at least one query result received according to the alarm scene information; the terminal 140 calculates an analysis result confidence according to the correlation degree; when the analysis result confidence is greater than a preset confidence threshold, the terminal 140 analyzes an alarm root cause corresponding to the alarm information according to the at least one query result.

[0099] As Figure 2As shown, the system includes an alarm analysis device 210 and a plurality of data sources 220 in data connection with the alarm analysis device. When the alarm analysis device 210 receives alarm information sent by a business system, the alarm analysis device can perform data access, query on the plurality of data sources based on the alarm information, and determine alarm root cause based on the data query results returned by the plurality of data sources. The 210 in this embodiment can be the terminal 140 or the server 110; and the data source 220 can be implemented by the server 110.

[0100] The alarm analysis method provided by the embodiments of the present disclosure can be applied in various business systems, such as instant messaging application systems, online shopping platform application systems, online live broadcast application systems, music playing application systems, or information platform application systems.

[0101] For example, when the alarm analysis method provided by the present disclosure is applied in an instant messaging application system, when a detection module in the system detects system abnormalities and generates alarm information. The alarm analysis device obtains the alarm information and triggers an intelligent alarm analysis task. At this time, the alarm analysis device generates alarm query data corresponding to a plurality of alarm associated data sources according to the alarm information, and then sends the alarm query data to the plurality of alarm associated data sources for alarm data query. Then, each time a query result returned by an alarm associated data source is received, a query result correlation degree calculation can be performed, and an analysis result confidence can be calculated according to the query result correlation degree. When it is detected that the analysis result confidence reaches a preset confidence threshold, the alarm root cause corresponding to the alarm information can be obtained by directly performing alarm root cause analysis according to the query result that has been received without waiting for the data query result returned by other alarm associated data sources.

[0102] The above examples do not limit the scope of protection of the present case.

[0103] General description of the embodiments of the present disclosure

[0104] According to an embodiment of the present disclosure, an alarm analysis method is provided. As shown in Figure 3 As shown, the system includes an alarm analysis device 210 and a plurality of data sources 220 in data connection with the alarm analysis device. When the alarm analysis device 210 receives alarm information sent by a business system, the alarm analysis device can perform data access, query on the plurality of data sources based on the alarm information, and determine alarm root cause based on the data query results returned by the plurality of data sources. The 210 in this embodiment can be the terminal 140 or the server 110; and the data source 220 can be implemented by the server 110.

[0105] Step 310, obtaining alarm information.

[0106] Wherein, as previously described, the alarm analysis method provided by the present disclosure can be applied in various business systems for alarm analysis to maintain the stability of the system. The alarm analysis device provided by the alarm analysis method can be integrated in a dedicated terminal or in the background server of the business system. The embodiments of the present application will take the alarm analysis device integrated in the background server of the business system as an example to introduce the alarm analysis method provided by the present application in detail.

[0107] During the operation of the business system, a system detection module can be set in the background server of the business system to detect the running state of the system in real time. When the detection module of the business system detects system operation anomalies, it can generate alarm information and send the alarm information to the alarm analysis device. Wherein, the detection of the system running state by the detection module can be continuous detection or time period detection. Generally, the detection module uses a time period polling method to detect the running state of the business system, on the one hand to avoid resource waste caused by continuous detection, and on the other hand to avoid missing detection that leads to anomalies that cannot be timely fed back and processed. Thus, when the detection module detects system anomalies, it can add the current detection period as alarm period information to the alarm information. Similarly, the detection system uses a polling method to poll the data of different ranges of the business system, and when it detects system anomalies, it can also add alarm range information corresponding to the abnormal position to the alarm information.

[0108] Further, in some embodiments, for a business system, there can be multiple different business scenarios, and the program data, supporting data and functions implemented in different business scenarios can be different. For example, in an instant messaging application, it can include chat scenarios, virtual resource exchange scenarios, information viewing scenarios, content sharing scenarios, etc. For chat scenarios, it can be further divided into text chat scenarios, voice chat scenarios and video chat scenarios, etc. For different scenarios, the business system needs to provide different service support, and different data needs to be applied and processed. Therefore, in the embodiments of the present disclosure, when the detection system of the business system detects system anomalies to generate an alarm, not only the alarm period information and alarm range information need to be obtained, but also the alarm scenario information needs to be obtained.

[0109] The alarm scene information can be acquired in various possible ways. For example, thread information of the current operation of the business system can be acquired, and the alarm scene information is determined according to the thread information; or when the business system has a specific visual application product, GUI information of the application product when the system anomaly is detected can be acquired, and the alarm scene information is determined according to the acquired GUI information; or in some embodiments, the alarm scene information can be determined according to positioning information and time information when the system anomaly is detected. The above are only some possible acquisition methods of the alarm scene information, and other methods can also be used to acquire the alarm scene information, which is not limited herein.

[0110] In this way, when the alarm analysis device receives the alarm event sent by the detection device during the operation of the business system, the alarm analysis task can be triggered. Then, the alarm analysis device can acquire alarm information from the alarm event sent by the detection device, wherein the alarm information includes the alarm period information, the alarm range information and the alarm scene information. The alarm period information, the alarm range information and the alarm scene information included in the alarm information can be stored in the form of metadata. In some embodiments, the alarm information can further include alarm context information, label information and abnormal value information.

[0111] In step 320, alarm query data corresponding to each alarm-associated data source is generated according to the alarm period information and the alarm range information, and the alarm query data is sent to each alarm-associated data source.

[0112] After acquiring the alarm information, the alarm analysis device can further perform alarm analysis according to the alarm information. In the embodiments of the present disclosure, the alarm analysis device can first generate alarm query data corresponding to each alarm-associated data source according to the alarm period information and the alarm range information in the alarm information. The alarm-associated data source can specifically include a plurality of data sources that can be used for alarm analysis, and can specifically include but not limited to data in a plurality of observability systems (such as a log system, a tracing system and a detection system), abnormal event publishing data, active alarm publishing data, service and cloud storage associated cloud data and cloud storage detection data.

[0113] The log system can be queried to acquire detailed system error information and related context; the tracing system can be queried to find the specific link in the service call chain that has a problem; and the detection system can be queried to find the bottleneck and abnormality of service performance.

[0114] After determining the plurality of alarm-associated data sources related to the alarm analysis, alarm query data corresponding to each alarm-associated data source can be further generated according to the alarm time period information and the alarm range information. The alarm query data includes a data query request and a data range requested to be queried, including an event range and an interval range. Then, the alarm analysis device can send the alarm query data to the alarm-associated data source. After receiving the alarm query data sent by the alarm query device, the alarm analysis device can perform data query according to the data query request and the data range requested to be queried in the alarm query data.

[0115] In some embodiments, the alarm query data corresponding to each alarm-associated data source is generated according to the alarm time period information and the alarm range information, and the corresponding alarm query data is sent to each alarm-associated data source, including:

[0116] The data query logic corresponding to each alarm-associated data source is generated according to the alarm time period information and the alarm range information.

[0117] The query data model corresponding to each alarm-associated data source is generated based on the data query logic.

[0118] The corresponding query data model is sent to each alarm-associated data source.

[0119] In the embodiments of the present disclosure, the specific process of generating the alarm query data corresponding to the alarm-associated data source according to the alarm time period information and the alarm range information can be to design a unified query data model, and then generate the query data model corresponding to each alarm-associated data source. Specifically, the data query logic corresponding to each alarm-associated data source can be generated according to the alarm time period information and the alarm range information, and then the query data model corresponding to each alarm-associated data source is generated based on the data query logic. Wherein, a structure diagram of the query data model provided by the present case is shown as follows, which can be a query data model corresponding to a log system:

[0120]

[0121] The query data model of the above structure can also be constructed for other alarm correlation data sources. After constructing the query data model corresponding to each alarm correlation data source, the query data model corresponding to each alarm correlation data source can be sent to each alarm correlation data source for corresponding data query. After receiving the corresponding query data model, each alarm correlation data source can perform data query according to the data query logic therein and return the query result. When an alarm correlation data source receives multiple query data models at the same time, the multiple query data models can be queued in a query queue according to the time sequence of receiving the query data models, and then the query data models are processed one by one, that is, the data query task is executed according to the time sequence of receiving.

[0122] In some embodiments, there is a dependency relationship between the data queries of some alarm correlation data sources, for example, the data query of the second alarm correlation data source needs to depend on the data query result of the first alarm correlation data source. In this embodiment, a query data model including multiple alarm correlation data sources can be constructed. The following example is a query data model including a log system, a trace system, and a trace system:

[0123]

[0124]

[0125] In this query data model, the query of log information can depend on the query result of trace information, and the query of detection information can depend on the query result of log information. That is, the query data model can be circulated in the trace system, the log system, and the detection system, and the data in the query data model is perfected one by one. Even if there is no dependency relationship between the data query tasks of multiple alarm correlation data sources, the above query data model including multiple alarm correlation data sources can be constructed, and then each alarm correlation data source is accessed and queried one by one according to the order to obtain the required query data. However, this method will lengthen the data query time and is not conducive to improving the efficiency of alarm analysis. Therefore, in the embodiments of the present disclosure, when there is no dependency relationship between the data query tasks of multiple alarm correlation data sources, the query data model corresponding to each alarm correlation data source is generated, and the corresponding query data model is sent to each alarm correlation data source to realize parallel data query of multiple alarm correlation data sources and improve the efficiency of alarm analysis.

[0126] In addition, in the embodiments of the present disclosure, by designing the query data structure corresponding to each alarm correlation data source, then automatically filling the metadata and object data according to the data structure, and further sending the query data structure to each alarm correlation data source for corresponding data query and automatically filling the queried data into the query data model, the automation of alarm analysis can be improved, and the efficiency of alarm analysis can also be improved to a large extent.

[0127] Step 330, when receiving any alarm correlation data source based on the query result returned by the corresponding alarm query data, the correlation degree corresponding to the at least one query result received is determined according to the alarm scene information.

[0128] In addition, in the embodiments of the present disclosure, by designing the query data structure corresponding to each alarm correlation data source, then automatically filling the metadata and object data according to the data structure, and further sending the query data structure to each alarm correlation data source for corresponding data query and automatically filling the queried data into the query data model, the automation of alarm analysis can be improved, and the efficiency of alarm analysis can also be improved to a large extent.

[0129] Therefore, in the embodiments of the present disclosure, when receiving any alarm correlation data source based on the query result returned by the corresponding alarm query data, the alarm analysis device can determine the correlation degree corresponding to the at least one query result received according to the alarm scene information. Wherein, the correlation degree here can be the correlation degree between the data queried in the alarm correlation data source and the alarm analysis result in the current alarm scene information corresponding to the alarm scene; or it can be understood as the contribution degree of the data queried in each alarm correlation data source to the alarm analysis result in the current alarm scene. For example, when it is determined according to the alarm scene information that the current alarm scene is a voice chat scene, the contribution degree of the data queried in the log system to the alarm analysis result is 60%, the contribution degree of the data queried in the traceback system to the alarm analysis result is 10, and the contribution degree of the data queried in the detection system to the alarm analysis result is 25%.

[0130] Thus, when receiving the query result returned by any alarm correlation data source, it can be determined which alarm correlation data sources have returned the query result, and the correlation degree of the returned query result and the alarm analysis result is calculated respectively.

[0131] In some embodiments, when receiving the query result returned by any alarm correlation data source based on the corresponding alarm query data, the correlation degree corresponding to the received at least one query result is determined according to the alarm scene information, including:

[0132] According to the alarm scene information, the root cause correlation weight coefficient corresponding to each alarm correlation data source is determined;

[0133] When receiving the query result returned by any alarm correlation data source based on the corresponding alarm query data, the corresponding query result completeness is determined;

[0134] According to the root cause correlation weight coefficient corresponding to the received at least one query result and the corresponding query result completeness, the correlation degree corresponding to the at least one query result is calculated.

[0135] In the embodiments of the present disclosure, the specific process of calculating the correlation degree of the query result returned by each alarm correlation data source to the alarm analysis result can be calculated according to the root cause correlation weight coefficient corresponding to the alarm correlation data source and the query result completeness. The root cause correlation weight coefficient corresponding to the alarm correlation data source can be the influence weight of the data in the alarm correlation data source on the alarm analysis result in theory, and the query result completeness can be the proportion of the actually queried data to the data that should be theoretically queried. That is, in some embodiments, due to the abnormality in the data storage process or the abnormality in the data query process, the alarm correlation data source may not be able to query the complete query data indicated by the query data model when querying data according to the received query data model. At this time, the query result completeness can be determined according to the proportion of the actually queried data to the data that should be theoretically queried. For example, in the above voice chat scene, the root cause correlation weight coefficient of the data stored in the log system to the alarm root cause is 70%, and the query result completeness of the query data returned by the log system according to the query data model is 80%, so the correlation degree of the data queried in the log system to the alarm root cause can be calculated as 70%*80%=56%.

[0136] In some embodiments, according to the alarm scene information, the root cause correlation weight coefficient corresponding to each alarm correlation data source is determined, including:

[0137] Obtain historical root cause analysis data, the historical root cause analysis data including a plurality of historical alarm data in a preset time period and a historical root cause analysis result corresponding to each historical alarm data;

[0138] determine historical alarm scene information corresponding to each historical alarm data, and determine a historical root cause association weight coefficient between each historical root cause analysis result and a plurality of alarm association data sources;

[0139] train a preset neural network model by taking each historical alarm scene information as a model input and taking a corresponding historical root cause association weight coefficient as an output;

[0140] predict a root cause association weight coefficient based on the trained preset neural network model, to obtain a root cause association weight coefficient corresponding to each alarm association data source.

[0141] Since there are multiple business scenes in a business system, the same alarm association data source can have different root cause association weight coefficients in different business scenes. Among them, under each business scene, the root cause association weight coefficient corresponding to the alarm association data source can be pre-evaluated and determined, and a mapping relationship table of the alarm association data source and the root cause association weight coefficient in different business scenes is generated accordingly. In this way, when the alarm scene information is obtained from the alarm information, the target mapping relationship table under the alarm scene can be further obtained, and the root cause association weight coefficient corresponding to each alarm association data source can be obtained from the target mapping relationship table.

[0142] However, as the business continues to develop and change, the details of the business scene can change, which in turn can cause the root cause association weight coefficient corresponding to the alarm association data source under each business scene to change. If the root cause association weight coefficients corresponding to different alarm association data sources in a certain business scene are determined only according to the preset mapping relationship table, the obtained root cause association weight coefficients can not be accurate enough. Therefore, in the embodiments of the present disclosure, a method for determining a root cause association weight coefficient based on a neural network model is provided, so as to improve the accuracy of the determination of the root cause association weight coefficient.

[0143] Specifically, historical root cause analysis data can be acquired first, the historical root cause analysis data including a plurality of historical alarm data in a preset time period and a historical root cause analysis result corresponding to each historical alarm data. Specifically, the historical root cause analysis data can include historical alarm data in the past week, month or 2 months before the current time and a historical root cause analysis result corresponding to each historical alarm data. Then, historical alarm scene information corresponding to each historical alarm data is determined, and a historical root cause correlation weight coefficient between each historical root cause analysis result and a plurality of alarm-related data sources is determined. Wherein, the historical alarm scene information corresponding to the historical alarm data can be determined according to the foregoing scene information determination method, and the historical root cause correlation weight coefficient between the historical root cause analysis result and the plurality of alarm-related data sources can be determined according to the contribution degree of the query data in each alarm-related data source in the historical root cause analysis result. In this way, the training sample data for training the preset neural network model (root cause correlation weight coefficient prediction model) can be obtained, and the training sample data specifically includes a plurality of historical alarm scene information and a historical root cause correlation weight coefficient corresponding to each historical alarm scene information (specifically, multiple, that is, the root cause correlation weight coefficient prediction model is a multi-classification model).

[0144] After obtaining the training sample data, the root cause correlation weight coefficient prediction model can be trained. Wherein, the root cause correlation weight coefficient prediction model can be pre-trained with a large amount of data, and the actual historical data is used here for fine-tuning to make the model have better performance. Specifically, each historical alarm scene information is used as the model input, and the corresponding historical root cause correlation weight coefficient is used as the output to train the preset neural network model; then the root cause correlation weight coefficient of the alarm scene information is predicted based on the trained preset neural network model, and the root cause correlation weight coefficient corresponding to each alarm-related data source is obtained.

[0145] Step 340, according to the correlation degree calculation analysis result confidence.

[0146] Wherein, after determining the correlation degree corresponding to the at least one received query result according to the alarm scene information, the analysis result confidence can be further calculated according to the correlation degrees. Wherein, the analysis result confidence here can be the confidence degree of the analysis result obtained by performing alarm root cause analysis based on the query result that has been received.

[0147] In the embodiments of the present disclosure, only when the confidence degree of the alarm root cause analysis result reaches a preset threshold, the analysis can be performed and the alarm root cause analysis result can be output.

[0148] Wherein, in some embodiments, the analysis result confidence is calculated according to the correlation degree, including:

[0149] Sum the at least one correlation degree corresponding to the at least one query result to obtain a total correlation degree value;

[0150] Calculate the analysis result confidence according to the total correlation degree value and a reference correlation degree value.

[0151] That is, in the embodiments of the present disclosure, the specific method of calculating the analysis result confidence according to the correlation degree can be to sum the multiple correlation degrees corresponding to the multiple query results returned by the multiple alarm correlation data sources that have been received to obtain a total correlation degree value, and then the analysis result confidence can be calculated according to the total correlation degree value and a preset reference correlation degree value. When the total correlation degree value is a probability value indicating that the current received query data can obtain an accurate alarm root cause analysis result, the above-mentioned reference correlation degree value can be set to 1.

[0152] In this way, it can be understood that an analysis result confidence value can be calculated every time a query result returned by an alarm correlation data source based on alarm query data is received. With the increase in the number of query results received, the analysis result confidence value also gradually increases.

[0153] Step 350, when the analysis result confidence is greater than a preset confidence threshold, analyzing the alarm root cause corresponding to the alarm information according to the at least one query result.

[0154] As previously introduced, with the advancement of the alarm analysis process, the alarm analysis device continuously receives query data returned by various alarm correlation data sources, and the analysis result confidence value is in a positive proportional relationship with the value accumulated according to the correlation degree value of the received query data, so with the increase in the received query data, the analysis result confidence value also continuously increases. When the analysis result confidence value increases to be greater than a preset preset confidence threshold, the alarm root cause corresponding to the alarm information can be analyzed according to the at least one query result that has been received.

[0155] The preset confidence threshold here can be an empirical value obtained by studying historical alarm analysis data, or a value obtained by continuously iterating and optimizing a set value. Alternatively, it can also be a value obtained by theoretically analyzing the business system by relevant technical personnel, and the acquisition method of the preset confidence threshold is not limited here.

[0156] Thus, the alarm analysis method (or alarm root cause analysis method) provided by the embodiments of the present disclosure can perform evaluation once for each query data returned by the alarm query data source after the alarm query data is sent to the plurality of alarm correlation data sources, to determine whether the query data currently received is sufficient to support the system analysis to obtain an accurate alarm root cause. If the query data currently received is sufficient to support the system analysis to obtain an accurate alarm root cause, the alarm root cause analysis is directly performed according to the query data that has been received. In this way, without querying each alarm analysis data source, an accurate alarm root cause can be analyzed, thereby greatly improving the efficiency of alarm analysis.

[0157] The specific process of performing alarm root cause analysis according to the query data that has been received can be analyzed by alarm rule matching, analyzing the query result by using an alarm analysis model, and the like. The alarm analysis scheme based on query data has been studied in the related art, and thus will not be described herein.

[0158] In some embodiments, after the correlation degree is calculated and the analysis result confidence is calculated, the method further includes:

[0159] When the analysis result confidence is not greater than the preset confidence threshold, the query result returned by the next alarm correlation data source is received.

[0160] The step of determining the correlation degree corresponding to the at least one query result that has been received according to the alarm scene information, calculating the analysis result confidence according to the correlation degree, and comparing the analysis result confidence with the preset confidence threshold is returned.

[0161] When the analysis result confidence is not greater than the preset confidence threshold, that is, the query data currently received is not sufficient to support the analysis to obtain an accurate alarm root cause, the query result returned by the next alarm correlation data source can be continuously received. The next alarm correlation data source is not a specific data source, but is determined according to the processing efficiency of the data source to the query task indicated by the alarm query data. The next alarm correlation data source can be the data source that first completes the data query task and outputs the query result after the current time. After receiving the query result returned by the next alarm correlation data source, the steps of determining the correlation degree corresponding to each query result and calculating the analysis result confidence based on the correlation degree corresponding to the query result, and comparing the analysis result confidence with the preset confidence threshold can be repeatedly performed until the analysis result confidence is greater than the preset confidence threshold, otherwise the above-mentioned cycle is repeatedly performed until all alarm correlation data sources return the query result.

[0162] In some embodiments, when the confidence level of the analysis result is greater than a preset confidence threshold, after analyzing the alarm root cause corresponding to the alarm information according to at least one query result, the method further includes:

[0163] Generate query termination information corresponding to each target alarm associated data source, where the target alarm associated data source is the alarm associated data source that does not return a query result;

[0164] A query termination instruction including query termination information is sent to each target alarm associated data source, so that the target alarm associated data source terminates the alarm query task indicated by the alarm query data.

[0165] Among them, in the embodiment of the present disclosure, when the confidence of the analysis result is calculated and the confidence of the analysis result is compared with the preset confidence threshold to determine that the confidence of the analysis result is greater than the preset confidence threshold, query termination information corresponding to each target alarm-associated data source can be further generated. Among them, the target alarm-associated data source here can specifically be an alarm-associated data source that has not yet returned a query result. Then, a query termination instruction containing query termination information is sent to each alarm-associated data source that has not yet returned a query result, so that the alarm-associated data source that has not yet returned a query result terminates the alarm query task, that is, no longer executes the data query indicated by the alarm query data, so as to save query resources for queries of other alarm analysis tasks, thereby improving the alarm analysis efficiency of the entire business system.

[0166] like Figure 4 FIG. 1 is another flow chart of the alarm analysis method provided by the present disclosure. As shown in the figure, the method includes:

[0167] Step 410: Obtain alarm information:

[0168] Step 420, identifying the alarm type corresponding to the alarm information;

[0169] Step 430: searching for candidate alarm root causes in a preset alarm analysis database based on the alarm type;

[0170] Step 440: Verify the candidate alarm root cause and obtain a verification result;

[0171] Step 450: When the confidence level of the analysis result is greater than a preset confidence threshold, the root cause of the alarm corresponding to the alarm information is determined based on the at least one query result and the verification result.

[0172] In the embodiments of the present disclosure, two alarm analysis methods are provided for alarm analysis, and comprehensive alarm analysis is performed based on the two alarm analysis methods to improve the accuracy of alarm analysis. Specifically, in addition to the alarm analysis by the above method, after obtaining the alarm information, alarm type analysis can be performed on the alarm information to obtain the alarm type corresponding to the alarm information. The alarm type can be divided according to different dimensions, for example, it can be divided into data type alarm, process type alarm, and risk type alarm, and the like. Further, the candidate alarm root cause can be found in the preset alarm analysis database according to the alarm type. The candidate alarm root cause can be one or more. In this way, when the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information can be determined according to the at least one query result and the candidate alarm root cause. The preset alarm analysis database can include a large amount of historical alarm data and corresponding root cause analysis results. And the root cause analysis results corresponding to different alarm types are further summarized according to the historical alarm data and the corresponding root cause analysis results.

[0173] In some embodiments, when there are multiple candidate alarm root causes, after obtaining multiple alarm root causes corresponding to the alarm type, the multiple candidate alarm root causes can be further verified to obtain verification results. The specific method of verifying the candidate alarm root cause can be to verify the candidate alarm root cause by using the received query data. In theory, the accurate candidate alarm root cause is consistent with the analysis conclusion corresponding to the associated query data; when the candidate alarm root cause is inconsistent with the analysis conclusion of the associated data in the received query data, it can be determined that the verification result of the candidate alarm root cause is unqualified. In this way, the candidate alarm root cause that fails the verification can be deleted according to the verification result, and the candidate alarm root cause that passes the verification can be retained. Then, the alarm root cause corresponding to the alarm information is analyzed and determined according to the at least one query result and the candidate alarm root cause that passes the verification, so that the accuracy of alarm analysis can be improved.

[0174] In some embodiments, when the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result, which includes:

[0175] When the analysis result confidence is greater than the preset confidence threshold, the first sub-alarm root cause is determined according to the at least one query result;

[0176] The candidate alarm root cause that passes the verification is determined as the second sub-alarm root cause according to the verification result;

[0177] When the first sub-alarm root cause is consistent with the second sub-alarm root cause, any one of the first sub-alarm root cause and the second sub-alarm root cause is determined as the alarm root cause corresponding to the alarm information;

[0178] When the first sub-alarm root cause and the second sub-alarm root cause are inconsistent, the first sub-alarm root cause and the second sub-alarm root cause are sent to the plurality of voting nodes for voting, and the alarm root cause corresponding to the alarm information is determined according to the received voting result.

[0179] In the embodiments of the present disclosure, when the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verified candidate alarm root cause, the alarm root cause determined according to the at least one query result can be determined as the first sub-alarm root cause, and the verified candidate alarm root cause can be determined as the second sub-alarm root cause. Then, it is further judged whether the conclusions of the first sub-alarm root cause and the second sub-alarm root cause are consistent. If they remain consistent, any one of them can be determined as the alarm root cause corresponding to the alarm information; otherwise, if they are inconsistent, the first sub-alarm root cause and the second sub-alarm root cause can be further sent to the plurality of voting nodes for voting. The voting nodes here can be blockchain nodes, and the received query data can also be sent to the voting nodes along with the first sub-alarm root cause and the second sub-alarm root cause. The voting nodes can access the data in the preset alarm analysis database to make appropriate voting from the first sub-alarm root cause and the second sub-alarm root cause according to sufficient data. Further, when each voting node returns a voting result to the alarm analysis device, the final alarm root cause can be determined according to the voting result.

[0180] In some embodiments, when the analysis result confidence is greater than the preset confidence threshold, after the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result analysis, the method further comprises:

[0181] generating an alarm event case according to the alarm information and the alarm root cause corresponding to the alarm information;

[0182] updating the preset alarm analysis database based on the alarm event case.

[0183] In the embodiments of the present disclosure, the preset alarm analysis database can be continuously updated in the process of running the business system. Specifically, when the alarm information is generated, and the alarm analysis device in the business system performs root cause analysis on the alarm information to obtain the alarm root cause, the alarm event case can be further generated according to the alarm information and the corresponding alarm root cause, and then the alarm event case can be further added to the preset alarm analysis database to complete the update of the preset alarm analysis database.

[0184] In some embodiments, after the correlation degree is calculated to analyze the result confidence, the method further comprises:

[0185] When the analysis result confidence is not greater than the preset confidence threshold, determining a target alarm root cause from the candidate alarm root causes according to the verification result;

[0186] The target alarm root cause is determined as the alarm root cause corresponding to the alarm information.

[0187] In the embodiments of the present disclosure, when two alarm analysis methods are used for alarm analysis, the alarm root cause can be determined according to the method that can first obtain an analysis result, so that the alarm root cause analysis efficiency of the business system can be further improved.

[0188] Specifically, when the analysis result confidence calculated based on the received query data is not greater than the preset confidence threshold, the target alarm root cause can be determined from the candidate alarm root causes according to the verification result of the candidate alarm root causes, and then the target alarm root cause is determined as the alarm root cause corresponding to the alarm information. In this way, even if the received query data does not support making an accurate alarm root cause analysis conclusion, the candidate alarm root cause that passes the verification can be determined as the alarm root cause corresponding to the alarm information according to the verification result of the candidate alarm root cause. In this way, the efficiency of alarm analysis can be further improved.

[0189] In some embodiments, when the analysis result confidence is greater than the preset confidence threshold, after analyzing the alarm root cause corresponding to the alarm information according to at least one query result, the method further comprises:

[0190] Obtaining object information contained in the alarm information, and determining an object node corresponding to the object information in a preset object relationship network;

[0191] Determining an associated node associated with the object node in the preset object relationship network, and obtaining an alarm root cause analysis record of each associated node, the associated node including the object node;

[0192] Generating a system state evaluation feature based on the alarm root cause analysis record, and inputting the system state evaluation feature into a trained system state evaluation model to obtain system abnormal information.

[0193] In the embodiments of the present disclosure, the alarm information can also include object information, where the object information can be user information. In the business system, there can be an association relationship between objects in the business system, so that the alarm information related to the objects can also have certain associated alarm root causes, which can be caused by system-level abnormalities, rather than single-point data or process abnormalities. At this time, the system abnormality can be determined and evaluated according to the alarm root cause analysis record of the associated objects associated with the objects.

[0194] Specifically, after determining the alarm root cause corresponding to the alarm information according to the query result analysis, the object information contained in the alarm information can be further obtained, and the object node corresponding to the object information can be determined in the preset object relationship network. The preset object relationship network can be constructed according to the contact determined according to the object characteristics in the business system and the interaction, identity and other relationships between the object and other objects. Then, the associated node associated with the object node can be further determined in the preset object relationship network, where the associated node can include the object node and the node associated with the object. Then, the alarm root cause analysis record of each associated node can be obtained, and the alarm root cause analysis record can be the alarm information related to the object corresponding to each associated node and the corresponding root cause analysis record.

[0195] Then, the system state evaluation feature can be generated based on the alarm root cause analysis record, and the system state evaluation feature can be processed by using the preset trained system state evaluation model, so as to obtain the system abnormal information. After analyzing the system abnormal information, the system abnormal information can be further sent to the designated system developer or the designated device, so that the system abnormality can be corrected in time.

[0196] In some embodiments, after the alarm root cause is obtained by analyzing the alarm information, the analysis result can be automatically sent to the alarm receiving terminal by using API or Webhook technology, so that the corresponding developer can obtain the alarm root cause in time and exclude the alarm abnormality, thereby improving the stability of the business system. In some embodiments, when the alarm root cause is determined, the abnormality repair function can be automatically triggered. For example, when the system detects that a certain service has a performance bottleneck, the expansion operation can be automatically triggered; when a configuration error is detected, the system can be automatically rolled back to the last correct configuration. In this way, the self-healing ability and stability of the system can be further improved.

[0197] As shown in Figure 5 FIG. 1 is a schematic diagram of data node flow of alarm analysis provided by the present disclosure. As shown in the figure, when alarm information is generated in the business system, the generation of the alarm analysis task in the business system can be triggered. Then, the alarm analysis task confirms a plurality of alarm associated data sources associated with the alarm information by analyzing a plurality of data sources. The alarm associated data source can be a specific service / function system, and the data corresponding to different alarm associated data sources can be stored in the same database or different databases. The alarm analysis task performs data access on each alarm associated data source, which can specifically be data access on the corresponding database by the alarm associated data source.

[0198] The alarm analysis method provided in the embodiments of the present disclosure comprises the following steps:

[0199] The embodiments of the present disclosure set the correlation degree corresponding to the alarm scene for each alarm correlation data source. When the alarm information is received, the alarm query is sent to the multiple alarm correlation data sources to query the corresponding information. Then, when the query results returned by different alarm correlation data sources are received, the correlation degree of the received query results can be determined according to the correlation degree corresponding to the alarm scene to determine the confidence of the query results. When the confidence meets the preset condition, the root cause can be analyzed according to the received query results, without waiting for all query data sources to return the query results, thereby avoiding the problem of low efficiency of root cause analysis caused by low efficiency of result return of part of the query data sources. In this way, the efficiency of root cause analysis of the alarm information can be greatly improved, thereby improving the efficiency of solving the alarm abnormality, and further improving the stability of the business system.

[0200] Detailed description of the embodiments of the present disclosure in combination with specific application scenarios

[0201] As shown in FIG. 7, another flowchart of the alarm analysis method provided in the present disclosure is shown, and the alarm analysis method will be introduced in detail in combination with the execution subject of each step. The method specifically comprises the following steps: Figure 6

[0202] Step 601, a terminal receives alarm information sent by a business server.

[0203] In the embodiments of the present disclosure, in order to avoid that the alarm analysis occupies the resources of the server of the business system, a terminal can be separately set to perform the alarm analysis task of the business system. In order to further improve the stability of the business system, a high-performance special terminal can be used to perform the alarm analysis of the business system.

[0204] ​In the running process of the business system, the detection device in the business server can perform polling detection on the business system according to a certain event interval to determine whether the business system is running normally. When the detection device detects system abnormalities, it can trigger the acquisition of alarm information, which can specifically include alarm period information, alarm range information and alarm scene information. Then, the business server sends the alarm information generated by the detection device to the terminal to trigger the terminal to generate an alarm analysis task (or alarm root cause analysis task).

[0205] After receiving the alarm information from the business server, the terminal generates an alarm analysis task corresponding to the alarm information. Among them, multiple alarm analysis tasks can be run in the terminal at the same time to achieve rapid analysis of the alarm information of the business system.

[0206] Step 602, the terminal determines a plurality of data sources according to the alarm information, and generates a query data model corresponding to each data source.

[0207] After the terminal generates the alarm task according to the alarm information, it can further determine a plurality of data sources associated with the alarm information according to the alarm period information, alarm range information and alarm scene information contained in the alarm information, so as to further query sufficient and effective data for alarm analysis from these data sources. Among them, the business system can have a large number of data sources, and according to the alarm information, a plurality of data sources are determined from a large number of data sources, which not only can reduce the amount of queried data sources, but also can accurately locate the core data source, and can improve the efficiency and accuracy of alarm analysis. Among them, the data source includes but is not limited to the aforementioned log, metric and trace system.

[0208] After determining the plurality of data sources corresponding to the alarm information, the terminal can generate a query data model corresponding to each data source. The examples of the query data model have been described in detail in the foregoing embodiments, which will not be repeated here. The query data model can be a data structure that indicates the range of data to be queried and the logic of the query. After obtaining the required query data, the query data model can be updated with the query result, so as to store the query result in the query data model.

[0209] Step 603, the terminal sends the corresponding query data model to each data source.

[0210] Among them, after generating the query data model corresponding to each data source according to the alarm period information, the alarm range information and the alarm scene information, the query data model corresponding to each data source can be further sent to the corresponding data source.

[0211] At step 604, the data source performs data query based on the query data model, and updates the query data model according to the data obtained by the query.

[0212] The data source can obtain the data stored in the query data model from the query data model after receiving the query data model sent by the terminal, for example, including metadata and object information data. The metadata can include the aforementioned alarm period data, alarm range data and alarm scene data; the object information can include information of a user corresponding to the alarm information, for example, ID data and the like. Then, further data query is performed according to the data extracted from the query data model, so that the data required for alarm analysis can be efficiently and accurately queried, for example, specific trace ID, trace Link and corresponding log ID, log Link and the like.

[0213] After the corresponding query result data is obtained based on the query data model, the query result data can be stored in the corresponding field of the query data model to update the query data model.

[0214] The data source can receive a plurality of query data models from the terminal, and each query data model can correspond to a different alarm analysis task. The data source sequentially performs data query corresponding to each query data model according to the time sequence of the query data model received. In some cases, the data source can also perform data query work corresponding to a plurality of query data models in parallel. When the number of data query models received by the data source is greater than the maximum number of parallel query threads, the query data model received later needs to be queued in the query queue to wait for execution of the query.

[0215] When the data source performs data query based on the query data model, the data source can first perform query data analysis according to the metadata and object data carried in the query data model to determine a corresponding query plan, and then perform data query in the corresponding database based on the query plan to obtain data query result.

[0216] When the data source performs corresponding data query work based on the received query data model, the terminal can also receive a termination query instruction. When the data source receives the termination query instruction from the terminal, the data source immediately terminates the data query operation on the corresponding thread, and allocates a data query task corresponding to a new query data model to the thread.

[0217] At step 605, the data source sends the updated query data model to the terminal.

[0218] The data source can further send the updated query data model to the terminal after updating the query data model according to the data query result, so that the terminal performs alarm analysis according to the query result contained in the query data model.

[0219] In step 606, the terminal receives the updated query data model sent by the data source and accumulates the confidence value.

[0220] After receiving the updated query data model sent by the data source, the terminal can first analyze the query result completeness corresponding to the data query result contained in the updated query data model. Alternatively, in some embodiments, the data source can directly determine the query result completeness after completing the data query task, and update the query result completeness in the query data model (for example, a query result completeness field is set in the query data model). In this way, the terminal can directly read the query result completeness corresponding to the alarm scene information from the query result completeness field in the query data model after receiving the updated query data model.

[0221] Further, the terminal can also obtain the data source weight mapping table corresponding to the alarm scene information according to the alarm scene information. The data source weight mapping table contains the weight coefficient corresponding to each data source, which indicates the contribution of the data in the data source to the root cause analysis. After obtaining the data source weight mapping table corresponding to the alarm scene information, the terminal can further read the weight coefficient corresponding to each data source from the table. Then, the product of the weight coefficient corresponding to each data source and the query data completeness of the corresponding returned query result can be calculated to obtain the correlation value between each query result received and the alarm analysis result. The correlation values are accumulated to obtain the analysis result confidence value, which indicates the confidence of the analysis result obtained by performing alarm analysis according to the currently received query data.

[0222] In step 607, the terminal determines whether the confidence value is greater than a preset value.

[0223] Then, the terminal can compare the accumulated confidence value with a preset value, that is, determine whether the confidence value is greater than a preset confidence threshold. If the accumulated confidence value is greater than the preset confidence threshold, the terminal continues to step 608. Otherwise, the terminal returns to step 606.

[0224] In addition, when the accumulated confidence value is greater than the preset confidence threshold, in addition to performing step 608, the terminal can also send a query termination instruction to the data source that has not returned the query data model associated with the current alarm analysis, so as to make the data source terminate the data query work corresponding to the current alarm analysis task.

[0225] At step 608, the terminal performs alarm analysis according to the query data model that has been received, and determines the alarm root cause.

[0226] When the confidence value accumulated according to the query data model that has been received is greater than a preset value, it indicates that the alarm analysis result with reasonable confidence can be obtained according to the query data that has been queried.

[0227] At step 609, the terminal sends the alarm root cause to the terminal designated by the service server.

[0228] After the alarm information corresponding to the alarm root cause is analyzed, the terminal can further send the alarm root cause obtained by analysis to the terminal designated by the service server. So that the corresponding developer can perform system maintenance according to the alarm root cause obtained by analysis, thereby improving the stability of the business system.

[0229] Device and equipment description of the embodiments of the present disclosure

[0230] It can be understood that although each step in each flowchart above is displayed in sequence according to the arrow representation, these steps are not necessarily executed in the order represented by the arrow. Unless otherwise specified in this embodiment, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least part of the steps in the above flowchart can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.

[0231] It should be noted that in each specific embodiment of the present disclosure, when it is necessary to perform relevant processing according to the target object attribute information or attribute information set and other data related to the characteristics of the target object, the permission or consent of the target object will be obtained first, and the collection, use and processing of these data will comply with relevant laws, regulations and standards in the relevant region. In addition, when the target object attribute information is required by the embodiments of the present application, the separate permission or separate consent of the target object will be obtained through a pop-up window or by jumping to a confirmation page, and after obtaining the separate permission or separate consent of the target object, the necessary target object related data required for the normal operation of the embodiments of the present application will be obtained.

[0232] Figure 7 The structure schematic diagram of the alarm analysis device 700 provided by the embodiments of the present disclosure is shown. The device comprises:

[0233] The acquisition unit 710 is configured to acquire alarm information, wherein the alarm information comprises alarm period information, alarm range information and alarm scene information.

[0234] The generation unit 720 is configured to generate alarm query data corresponding to each alarm-associated data source according to the alarm period information and the alarm range information, and send the alarm query data corresponding to each alarm-associated data source.

[0235] The determination unit 730 is configured to determine a correlation degree corresponding to at least one received query result according to the alarm scene information when receiving the query result returned by any alarm-associated data source based on the corresponding alarm query data.

[0236] The calculation unit 740 is configured to calculate an analysis result confidence according to the correlation degree.

[0237] The analysis unit 750 is configured to analyze an alarm root cause corresponding to the alarm information according to the at least one query result when the analysis result confidence is greater than a preset confidence threshold.

[0238] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0239] The receiving sub-unit is configured to receive a query result returned by a next alarm-associated data source when the analysis result confidence is not greater than the preset confidence threshold.

[0240] The execution sub-unit is configured to return the steps of determining a correlation degree corresponding to at least one received query result according to the alarm scene information, calculating an analysis result confidence according to the correlation degree, and comparing the analysis result confidence with a preset confidence threshold.

[0241] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0242] The first generation sub-unit is configured to generate query termination information corresponding to each target alarm-associated data source, wherein the target alarm-associated data source is an alarm-associated data source that does not return a query result.

[0243] The sending sub-unit is configured to send a query termination instruction containing the query termination information to each target alarm-associated data source, so that the target alarm-associated data source terminates an alarm query task indicated by the alarm query data.

[0244] Optionally, in some embodiments, the determination unit comprises:

[0245] The first determination sub-unit is configured to determine a root cause correlation weight coefficient corresponding to each alarm-associated data source according to the alarm scene information.

[0246] a second determining sub-unit, configured to determine a corresponding query result completeness when receiving a query result returned by any of the alarm correlation data sources based on corresponding alarm query data;

[0247] a first calculating sub-unit, configured to calculate a correlation degree corresponding to at least one query result according to a root cause correlation weight coefficient corresponding to the at least one query result and a query result completeness corresponding to the at least one query result.

[0248] Optionally, in some embodiments, the first determining sub-unit comprises:

[0249] an acquisition module, configured to acquire historical root cause analysis data, wherein the historical root cause analysis data comprises a plurality of historical alarm data in a preset time period and a historical root cause analysis result corresponding to each historical alarm data;

[0250] a determination module, configured to determine historical alarm scene information corresponding to each historical alarm data and determine a historical root cause correlation weight coefficient between each historical root cause analysis result and a plurality of alarm correlation data sources;

[0251] a training module, configured to train a preset neural network model by taking each of the historical alarm scene information as a model input and taking a corresponding historical root cause correlation weight coefficient as an output;

[0252] a prediction module, configured to predict a root cause correlation weight coefficient based on the trained preset neural network model and the alarm scene information, to obtain a root cause correlation weight coefficient corresponding to each alarm correlation data source.

[0253] Optionally, in some embodiments, the calculating unit comprises:

[0254] a second calculating sub-unit, configured to calculate a sum of at least one correlation degree corresponding to the at least one query result, to obtain a correlation degree total value;

[0255] a third calculating sub-unit, configured to calculate an analysis result confidence according to the correlation degree total value and a reference correlation degree value.

[0256] Optionally, in some embodiments, the generating unit comprises:

[0257] a second generating sub-unit, configured to generate a data query logic corresponding to each alarm correlation data source according to the alarm time period information and the alarm range information;

[0258] a third generating sub-unit, configured to generate a query data model corresponding to each alarm correlation data source based on the data query logic;

[0259] a sending subunit, configured to send a corresponding query data model to each of the alarm-related data sources;

[0260] The determination unit is further configured to:

[0261] When receiving a query result returned by any of the alarm-related data sources based on the corresponding query data model, determine a correlation degree corresponding to the received at least one query result according to the alarm scenario information.

[0262] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0263] an identification subunit, configured to identify an alarm type corresponding to the alarm information;

[0264] a searching subunit, configured to search for a candidate alarm root cause in a preset alarm analysis database based on the alarm type;

[0265] a verification subunit, configured to verify the candidate alarm root cause to obtain a verification result;

[0266] The analysis unit is further configured to:

[0267] when the analysis result confidence is greater than a preset confidence threshold, determine an alarm root cause corresponding to the alarm information according to the at least one query result and the verification result.

[0268] Optionally, in some embodiments, the analysis unit comprises:

[0269] a third determination subunit, configured to, when the analysis result confidence is greater than a preset confidence threshold, determine a first sub-alarm root cause according to the at least one query result;

[0270] a fourth determination subunit, configured to determine a candidate alarm root cause that passes the verification as a second sub-alarm root cause according to the verification result;

[0271] a fifth determination subunit, configured to, when the first sub-alarm root cause is consistent with the second sub-alarm root cause, determine any one of the first sub-alarm root cause and the second sub-alarm root cause as the alarm root cause corresponding to the alarm information;

[0272] a sixth determination subunit, configured to, when the first sub-alarm root cause is inconsistent with the second sub-alarm root cause, send the first sub-alarm root cause and the second sub-alarm root cause to a plurality of voting nodes for voting, and determine the alarm root cause corresponding to the alarm information according to a received voting result.

[0273] Optionally, in some embodiments, the analysis unit comprises:

[0274] The fourth generating sub-unit is configured to generate an alarm event case according to the alarm information and an alarm root cause corresponding to the alarm information.

[0275] The updating sub-unit is configured to update the preset alarm analysis database based on the alarm event case.

[0276] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0277] The seventh determining sub-unit is configured to determine a target alarm root cause from the candidate alarm root causes according to the verification result when the analysis result confidence is not greater than the preset confidence threshold.

[0278] The eighth determining sub-unit is configured to determine that the target alarm root cause is an alarm root cause corresponding to the alarm information.

[0279] Optionally, in some embodiments, the alarm analysis apparatus provided by the present disclosure further comprises:

[0280] The first obtaining sub-unit is configured to obtain object information contained in the alarm information, and determine an object node corresponding to the object information in a preset object relationship network.

[0281] The second obtaining sub-unit is configured to determine an associated node associated with the object node in the preset object relationship network, and obtain an alarm root cause analysis record of each associated node, the associated node including the object node.

[0282] The evaluation sub-unit is configured to generate a system state evaluation feature based on the alarm root cause analysis record, and input the system state evaluation feature into a trained system state evaluation model to obtain system abnormal information.

[0283] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an integral module or unit that includes the functions of the module or unit.

[0284] Reference Figure 8 , Figure 8For a structure block diagram of a part of the terminal 140 of the alarm analysis method of the embodiments of the present disclosure, the terminal 140 includes the radio frequency (RF) circuit 810, the memory 815, the input unit 830, the display unit 840, the sensor 850, the voice circuit 860, the wireless fidelity (WiFi) module 870, the processor 880, and the power supply 890, and the like. Those skilled in the art can understand that the terminal 140 can include more or less components than those shown, or combine some components, or arrange different components. Figure 8 The structure of the terminal 140 shown does not constitute a limitation on the mobile phone or computer, and can include more or less components than those shown, or combine some components, or arrange different components.

[0285] The RF circuit 810 can be used for receiving and sending signals in the process of receiving or calling information, and in particular, receiving the downlink information of the base station and processing it by the processor 880; in addition, sending the uplink data to the base station.

[0286] The memory 815 can be used to store software programs and modules, and the processor 880 can execute various functions and document editing of the terminal by running the software programs and modules stored in the memory 815.

[0287] The input unit 830 can be used to receive input digital or character information, and generate key signal input related to the setting and function control of the terminal. Specifically, the input unit 830 can include a touch panel 831 and other input devices 832.

[0288] The display unit 840 can be used to display input information or provided information and various menus of the terminal. The display unit 840 can include a display panel 841.

[0289] The voice circuit 860, the speaker 861, and the microphone 862 can provide a voice interface.

[0290] In the embodiments, the processor 880 included in the terminal 140 can execute the alarm analysis method of the previous embodiments.

[0291] The terminal 140 of the embodiments of the present disclosure includes but is not limited to a mobile phone, a computer, a smart voice interactive device, a smart home appliance, a vehicle-mounted terminal, an aircraft, and the like.

[0292] Figure 9 Figure 9A structure block diagram of a server 110 for implementing the alarm analysis method of the embodiments of the present disclosure. The server 110 can be quite different due to different configurations or performances, and can include one or more central processing units (CPUs) 922 (e.g., one or more processors) and a storage device 932, one or more storage media 930 (e.g., one or more mass storage devices) storing applications 942 or data 944. Among them, the storage device 932 and the storage medium 930 can be temporary storage or persistent storage. The programs stored in the storage medium 930 can include one or more modules (not shown in the figure), each of which can include a series of instructions operated in the server 110. Further, the central processing unit 922 can be configured to communicate with the storage medium 930 to execute a series of instructions operated in the storage medium 930 on the server 110.

[0293] The server 110 can also include one or more power supplies V26, one or more wired or wireless network interfaces 950, one or more input / output interfaces 958, and / or one or more operating systems 941, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0294] The central processing unit 922 in the server 110 can be used to execute the alarm analysis method of the embodiments of the present disclosure.

[0295] The embodiments of the present disclosure also provide a storage medium for storing program code for executing the alarm analysis method of the various embodiments described above.

[0296] The embodiments of the present disclosure also provide a computer program product including a computer program. The processor of the computer device reads and executes the computer program, so that the computer device executes the alarm analysis method as described above.

[0297] The terms "first", "second", "third", "fourth", and the like in the description of the disclosure and the above drawings, if any, are used to distinguish similar objects, and do not necessarily have to be used to describe a particular order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the disclosure described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "contain" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device containing a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0298] It should be understood that in the present disclosure, "at least one" refers to one or more, and "multiple" refers to two or more. "And / or" is used to describe the relationship between the associated objects, which means that there can be three relationships, for example, "A and / or B" can represent three cases: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can mean a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0299] It should be understood that in the description of the embodiments of the present disclosure, the meaning of multiple (or multiple items) is two or more, and greater than, less than, more than, etc. are not included in the number, and above, below, etc. are included in the number.

[0300] In several embodiments provided by the present disclosure, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed objects can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0301] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0302] In addition, each functional unit in various embodiments of the present disclosure can be integrated into one processing unit, or each unit can exist physically, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0303] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on such understanding, the technical scheme of the present disclosure essentially or the part that contributes to the prior art or the whole or part of the technical scheme can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present disclosure. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0304] It should also be understood that the various embodiments provided by the present disclosure can be combined in any way to achieve different technical effects.

[0305] The above is a specific description of the embodiments of the present disclosure, but the present disclosure is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the present disclosure, and these equivalent modifications or replacements are all included in the scope defined by the claims of the present disclosure.

Claims

1. An alarm analysis method characterized by, The method comprises: obtaining alarm information, wherein the alarm information comprises alarm time period information, alarm range information and alarm scene information; generating alarm query data corresponding to a plurality of alarm correlation data sources according to the alarm time period information and the alarm range information, and sending the alarm query data corresponding to each alarm correlation data source to the alarm correlation data source; when receiving a query result returned by any alarm correlation data source based on corresponding alarm query data, determining a correlation degree corresponding to at least one received query result according to the alarm scene information; calculating an analysis result confidence degree according to the correlation degree; when the analysis result confidence degree is greater than a preset confidence threshold, analyzing an alarm root cause corresponding to the alarm information according to the at least one query result.

2. The method according to claim 1, characterized in that After the step of calculating the analysis result confidence degree according to the correlation degree, the method further comprises: when the analysis result confidence degree is not greater than the preset confidence threshold, receiving a query result returned by a next alarm correlation data source; returning to the step of determining the correlation degree corresponding to the at least one received query result according to the alarm scene information, calculating the analysis result confidence degree according to the correlation degree, and comparing the analysis result confidence degree with the preset confidence threshold.

3. The method of claim 2, wherein, After the step of analyzing the alarm root cause corresponding to the alarm information according to the at least one query result when the analysis result confidence degree is greater than the preset confidence threshold, the method further comprises: generating query termination information corresponding to each target alarm correlation data source, wherein the target alarm correlation data source is an alarm correlation data source that does not return a query result; sending a query termination instruction containing the query termination information to each target alarm correlation data source, so that the target alarm correlation data source terminates an alarm query task indicated by the alarm query data.

4. The method of claim 1, wherein, The step of determining the correlation degree corresponding to the at least one received query result according to the alarm scene information when receiving a query result returned by any alarm correlation data source based on corresponding alarm query data comprises: determining a root cause correlation weight coefficient corresponding to each alarm correlation data source according to the alarm scene information; when receiving a query result returned by any alarm correlation data source based on corresponding alarm query data, determining a query result completeness degree corresponding to the query result; calculating the correlation degree corresponding to the at least one query result according to the root cause correlation weight coefficient corresponding to the at least one received query result and the query result completeness degree corresponding to the at least one query result.

5. The method of claim 4, wherein, The step of determining the root cause correlation weight coefficient corresponding to each alarm correlation data source according to the alarm scene information comprises: obtaining historical root cause analysis data, wherein the historical root cause analysis data comprises a plurality of historical alarm data in a preset time period and a historical root cause analysis result corresponding to each historical alarm data; determining historical alarm scene information corresponding to each historical alarm data and a historical root cause correlation weight coefficient between each historical root cause analysis result and a plurality of alarm correlation data sources; training a preset neural network model by taking each historical alarm scene information as a model input and taking a corresponding historical root cause correlation weight coefficient as an output. Based on the trained preset neural network model, the alarm scene information is subjected to root cause correlation weight coefficient prediction, to obtain a root cause correlation weight coefficient corresponding to each alarm correlation data source.

6. The method of claim 4, wherein, The confidence of the analysis result is calculated according to the correlation degree, comprising: The sum of at least one correlation degree corresponding to the at least one query result is calculated to obtain a total correlation degree value; The confidence of the analysis result is calculated according to the total correlation degree value and a reference correlation degree value.

7. The method of claim 1, wherein, The alarm query data corresponding to each alarm correlation data source is generated according to the alarm time period information and the alarm range information, and the corresponding alarm query data is sent to each alarm correlation data source, comprising: The data query logic corresponding to each alarm correlation data source is generated according to the alarm time period information and the alarm range information; The query data model corresponding to each alarm correlation data source is generated based on the data query logic; The query data model corresponding to each alarm correlation data source is sent to each alarm correlation data source; When receiving the query result returned by any alarm correlation data source based on the corresponding alarm query data, the correlation degree corresponding to the at least one query result received is determined according to the alarm scene information, comprising: When receiving the query result returned by any alarm correlation data source based on the corresponding query data model, the correlation degree corresponding to the at least one query result received is determined according to the alarm scene information.

8. The method of claim 1, wherein, After obtaining the alarm information, it further comprises: Identifying the alarm type corresponding to the alarm information; Finding the candidate alarm root cause in the preset alarm analysis database based on the alarm type; Verifying the candidate alarm root cause to obtain a verification result; When the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information is analyzed according to the at least one query result, comprising: When the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result.

9. The method of claim 8, wherein, When the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result, comprising: When the analysis result confidence is greater than the preset confidence threshold, a first sub-alarm root cause is determined according to the at least one query result; A verification qualified candidate alarm root cause is determined as a second sub-alarm root cause according to the verification result; When the first sub-alarm root cause and the second sub-alarm root cause are consistent, any one of the first sub-alarm root cause and the second sub-alarm root cause is determined as the alarm root cause corresponding to the alarm information; When the first sub-alarm root cause and the second sub-alarm root cause are inconsistent, the first sub-alarm root cause and the second sub-alarm root cause are sent to multiple voting nodes for voting, and the alarm root cause corresponding to the alarm information is determined according to the received voting result.

10. The method of claim 8, wherein, After the analysis result confidence is greater than the preset confidence threshold, the alarm root cause corresponding to the alarm information is determined according to the at least one query result and the verification result, comprising: generate an alarm event case according to the alarm information and an alarm root cause corresponding to the alarm information; update the preset alarm analysis database based on the alarm event case.

11. The method of claim 8, wherein, The method further includes: when the analysis result confidence is not greater than the preset confidence threshold, determining a target alarm root cause from the candidate alarm root causes according to the verification result; determining that the target alarm root cause is the alarm root cause corresponding to the alarm information.

12. The method of claim 1, wherein, The method further includes: obtain object information included in the alarm information, and determine an object node corresponding to the object information in a preset object relationship network; determine an associated node associated with the object node in the preset object relationship network, and obtain an alarm root cause analysis record of each associated node, the associated node including the object node; generate a system state evaluation feature based on the alarm root cause analysis record, and input the system state evaluation feature into a trained system state evaluation model to obtain system abnormal information.

13. An alarm analysis apparatus characterized by comprising: The apparatus includes: an obtaining unit configured to obtain alarm information, the alarm information including alarm time period information, alarm range information, and alarm scene information; a generating unit configured to generate alarm query data corresponding to a plurality of alarm associated data sources according to the alarm time period information and the alarm range information, and send the corresponding alarm query data to each alarm associated data source; a determining unit configured to, when receiving a query result returned by any alarm associated data source based on the corresponding alarm query data, determine an association degree corresponding to the at least one received query result according to the alarm scene information; a calculating unit configured to calculate an analysis result confidence according to the association degree; an analyzing unit configured to, when the analysis result confidence is greater than a preset confidence threshold, analyze an alarm root cause corresponding to the alarm information according to the at least one query result.

14. A storage medium storing a computer program, characterized in that, The computer program, when executed by a processor, implements the alarm analysis method of any one of claims 1 to 12.

15. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor executes the computer program to implement the alarm analysis method of any one of claims 1 to 12.

16. A computer program product, comprising a computer program, the computer program being read and executed by a processor of a computer device, so that the computer device executes the alarm analysis method of any one of claims 1 to 12.