Alarm automatic grading method and device of intelligent cloud storage system and server

By using deep learning models and classifiers to automatically process alarm data from intelligent cloud storage systems, the problem of time-consuming manual classification has been solved, achieving efficient alarm classification and response, and improving operational efficiency.

CN120856532APending Publication Date: 2025-10-28DUXIAOMAN TECH (BEIJING) CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510785926.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

The alarm classification of existing intelligent cloud storage systems relies on manual analysis, which is time-consuming and inflexible, and cannot adapt to system changes, resulting in low operation and maintenance efficiency.

Method used

It employs deep learning models and classifiers to automate the analysis and hierarchical analysis of alarm data. By acquiring alarm data samples, extracting feature vectors, and mapping alarm levels, it reduces reliance on manual intervention and achieves efficient classification and response.

Benefits of technology

It achieves automated identification of alarm levels, reducing manual classification time by more than 90%, improving system operation and maintenance efficiency, and reducing subjectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856532A_ABST
    Figure CN120856532A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm automatic grading method and device of an intelligent cloud storage system, a server and a computer readable storage medium. According to the method, after an alarm data sample stored in an intelligent cloud is obtained, alarm data at each moment is extracted and input into a deep learning model for feature extraction, manual feature design is replaced, an implicit mode is automatically learned from time sequence data, dependence on experience of operation and maintenance personnel is reduced, a multi-stage evolutionary complex fault mode is accurately identified, and the fault diagnosis efficiency is improved. The feature vectors generated by the deep learning model are mapped to alarm levels such as high / medium / low risks by using the classifier, subjectivity of manual classification is avoided, levels can be generated in real time and corresponding responses can be triggered, and compared with manual classification, consumed time is shortened by more than 90%, so that the operation and maintenance efficiency of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent cloud storage technology, specifically to an automatic alarm classification method, device, server, and computer-readable storage medium for an intelligent cloud storage system. Background Art

[0002] Intelligent cloud storage scenarios refer to application environments built using cloud computing technology that provide users with data storage, management, and access services. It centrally manages and distributes a large number of storage resources (such as hard drives and solid-state drives) to form a scalable storage cluster, meeting the needs of different users and businesses in terms of storage capacity, performance, and reliability. During the operation of intelligent cloud storage systems or devices, monitoring tools detect anomalies and potential problems to ensure normal system operation. When anomalies or potential problems are detected, alerts are sent to operations and maintenance personnel to remind them to pay attention to and address the issues promptly, preventing disruption to normal system operation.

[0003] Currently, intelligent cloud storage systems generate a large number of alarms. Furthermore, it's necessary to categorize these alarms into different levels based on their severity, scope of impact, and urgency, enabling operations and maintenance personnel to quickly identify critical issues and take appropriate measures. Currently, alarm classification relies on manual analysis and categorization by administrators, with notifications sent via phone, SMS, and other methods based on the analysis results. However, this traditional model has significant limitations; operations and maintenance personnel must spend a considerable amount of time on classification, and it heavily depends on their technical skills. As the number of alarms continues to increase, the inflexibility and time-consuming nature of this traditional method become increasingly apparent, making it unsuitable for the evolving landscape of intelligent cloud storage systems.

[0004] Therefore, how to achieve efficient alarm classification and response and improve system operation and maintenance efficiency is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0005] In view of the above-mentioned defects or deficiencies in the existing technology, it is desirable to provide an automatic alarm classification method, device, server and computer-readable storage medium for an intelligent cloud storage system, which can automatically analyze, classify and classify alarms, and efficiently classify and respond to alarms, thereby improving system operation and maintenance efficiency.

[0006] In a first aspect, embodiments of this application provide an automatic alarm classification method for an intelligent cloud storage system, including:

[0007] Obtain alarm data samples from intelligent cloud storage;

[0008] The alarm data at each time moment is extracted from the alarm data sample, input into a pre-trained deep learning model for feature extraction, and the alarm feature vector at each time moment is output.

[0009] The alarm feature vector is input into a classifier to map alarm levels and generate alarm levels.

[0010] In one embodiment, acquiring alarm data samples from intelligent cloud storage includes:

[0011] Obtain server alarm data and cluster performance alarm data of intelligent cloud storage as raw alarm data;

[0012] The original alarm data is subjected to data standardization preprocessing, and the preprocessed data is used as the alarm data sample.

[0013] In one embodiment, the raw alarm data undergoes data standardization preprocessing, including:

[0014] The original alarm data is processed by filling missing values, removing outliers, and standardizing.

[0015] In one embodiment, extracting alarm data for each time moment from the alarm data sample includes:

[0016] The alarm data samples are arranged in chronological order, and the alarm data for each time step is extracted. The alarm data includes at least one dimension of information, namely: timestamp, alarm description, alarm source, and alarm type.

[0017] In one embodiment, the training method of the deep learning model includes:

[0018] Optimize model parameters using historical alarm data and corresponding manually labeled levels through backpropagation algorithm;

[0019] The optimization algorithm for the model parameters includes the Adam optimizer.

[0020] In one embodiment, the deep learning model is specifically a long short-term memory neural network.

[0021] In one embodiment, the classifier is specifically a Softmax classifier.

[0022] Secondly, embodiments of this application provide an automatic alarm classification device for an intelligent cloud storage system, comprising:

[0023] The sample acquisition module is used to acquire alarm data samples from the intelligent cloud storage.

[0024] The feature extraction module is used to extract alarm data at each time from the alarm data sample, input it into a pre-trained deep learning model for feature extraction, and output the alarm feature vector at each time.

[0025] The level mapping module is used to input the alarm feature vector into the classifier to map the alarm level and generate the alarm level.

[0026] Thirdly, embodiments of this application provide a server, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps of an automatic alarm classification method, such as that of an intelligent cloud storage system.

[0027] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of an automatic alarm classification method such as that of an intelligent cloud storage system.

[0028] The automatic alarm classification method for intelligent cloud storage systems provided in this application obtains alarm data samples from intelligent cloud storage, extracts alarm data at various times, and inputs them into a deep learning model to extract features, replacing manual feature design. It automatically learns implicit patterns from time-series data, reducing reliance on the experience of operation and maintenance personnel, accurately identifying complex fault modes that evolve in multiple stages, and using a classifier to map the feature vectors generated by the deep learning model to alarm levels such as high / medium / low risk. This avoids the subjectivity of manual classification and can also generate levels in real time and trigger corresponding responses. Compared with manual classification, the time consumption is reduced by more than 90%, thereby improving the system operation and maintenance efficiency.

[0029] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0030] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0031] Figure 1 A flowchart illustrating an automatic alarm classification method for an intelligent cloud storage system provided in an embodiment of this application is shown.

[0032] Figure 2 This illustration shows a schematic diagram of the implementation process of feature extraction using an LSTM model according to an embodiment of this application;

[0033] Figure 3 An exemplary structural block diagram of an automatic alarm classification device for an intelligent cloud storage system provided in an embodiment of this application is shown;

[0034] Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the server of the present application is shown. Detailed Implementation

[0035] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0036] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present application will now be described in detail with reference to the accompanying drawings and embodiments. Although the embodiments of this application provide method operation instruction steps as shown in the following embodiments or drawings, more or fewer operation instruction steps may be included in the method based on conventional or non-inventive effort. In steps where there is no logically necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the device executes, the method may be executed sequentially or in parallel according to the method shown in the embodiments or drawings.

[0037] Example 1:

[0038] This embodiment proposes an automatic alarm classification method for an intelligent cloud storage system. Please refer to [reference needed]. Figure 1 , Figure 1 A flowchart illustrating the automatic alarm classification method of the intelligent cloud storage system provided in this embodiment is shown. Figure 1 As shown, the method includes:

[0039] S101. Obtain alarm data samples from intelligent cloud storage;

[0040] Alarm data sets for model analysis are collected from the intelligent cloud storage system as alarm data samples. This embodiment does not limit the specific data types included in the alarm data samples; they can match the alarm data types set by the intelligent cloud storage system in actual application scenarios. Specific examples include alarms generated by anomalies such as CPU utilization, memory usage, hard disk I / O performance, and power status; software-level alarm data such as server operating system errors, service failures (e.g., storage service crashes), and process anomalies (e.g., core process crashes); and alarm data generated by anomalies such as cluster SLA availability (service uptime percentage), read / write throughput, request / response latency, network inbound / outbound traffic, and I / O resource usage.

[0041] It should be noted that the acquired alarm data samples are standardized preprocessed data to ensure data integrity and standardization, thereby improving the recognition accuracy of the deep learning model. Of course, if the acquired raw data can meet the needs of the subsequent deep learning model, standardization preprocessing may not be necessary; this embodiment does not impose such a limitation.

[0042] S102. Extract alarm data at each time step from the alarm data sample, input it into the pre-trained deep learning model for feature extraction, and output the alarm feature vector at each time step.

[0043] The preprocessed alarm data samples are arranged in chronological order to form a time series. Each time point (moment) corresponds to a time step, and the input of each time step is a vector containing multiple alarm indicators.

[0044] For example, if the server generates two alarms at a certain time: CPU utilization exceeding the threshold and memory usage abnormal, then the input vector for that time step contains relevant dimensional information about these two alarms (such as timestamp, alarm description, alarm source, etc.).

[0045] The input vector at each time step integrates multi-dimensional alarm data at the same moment, ensuring that the model can capture the correlation features between different indicators (such as concurrent anomalies such as CPU overload and memory exhaustion).

[0046] The alarm data at each time point is input into a pre-trained deep learning model for feature extraction. In this embodiment, the specific model type of the deep learning model is not limited, and Long Short-Term Memory Neural Network (LSTM), Convolutional Neural Network (CNN), attention-based model (Transformer), etc. can be selected.

[0047] After feature extraction, the deep learning model outputs alarm feature vectors at each time step. The output feature vectors are an abstract representation of the original alarm data. Through the automatic learning of the deep learning model, redundant information is eliminated, and key features related to the alarm level are retained.

[0048] S103. Input the alarm feature vector into the classifier to map the alarm level and generate the alarm level.

[0049] By using a pre-trained classification model (such as a neural network classifier, support vector machine, random forest, etc.), the alarm feature vector is processed for multi-classification, and the abstract features are mapped to specific alarm levels (such as high / medium / low risk), outputting discrete alarm levels (such as N predefined levels), or the probability value corresponding to each level.

[0050] Based on the above introduction, the automatic alarm classification method for intelligent cloud storage systems provided in this embodiment obtains alarm data samples from intelligent cloud storage, extracts alarm data at various times, inputs them into a deep learning model to extract features, replaces manually designed features, automatically learns implicit patterns from time-series data, reduces reliance on the experience of operation and maintenance personnel, accurately identifies complex fault modes that evolve in multiple stages, and uses a classifier to map the feature vectors generated by the deep learning model to alarm levels such as high / medium / low risk, avoiding the subjectivity of manual classification. It can also generate levels in real time and trigger corresponding responses, reducing the time consumption by more than 90% compared to manual classification, thereby improving the system operation and maintenance efficiency.

[0051] Example 2:

[0052] The above embodiments do not limit the method of obtaining alarm data samples. In order to cover all-dimensional abnormal scenarios of intelligent cloud storage, the process of obtaining alarm data samples of intelligent cloud storage in step S101 can be specifically performed according to the following steps:

[0053] Step S11: Obtain server alarm data and cluster performance alarm data of intelligent cloud storage as raw alarm data;

[0054] When building an automatic alarm classification system based on deep learning, selecting appropriate alarm items is fundamental to the entire system, determining the quality and feature information of the model's input data. This embodiment selects the following two types of alarm data: intelligent cloud storage server alarm data and intelligent cloud storage cluster performance alarm data.

[0055] Among them, the alarm data of the intelligent cloud storage server refers to the alarm information generated when a single server node in the intelligent cloud storage system has an anomaly at the hardware or software level. It focuses on the server's own operating status and mainly includes: server hardware alarms (such as CPU utilization, memory usage, hard disk I / O, etc.) and software alarms (such as system errors, service failures, process crashes, etc.).

[0056] Intelligent cloud storage cluster performance alarm data refers to alarm information generated when the intelligent cloud storage cluster as a whole exhibits abnormalities in performance indicators or operational status. It focuses on the global operational status at the cluster level and mainly includes alarm data for core monitoring metrics of intelligent cloud storage, such as cluster SLA availability, cluster read / write capabilities, request latency, cluster inbound / outbound traffic, and IO usage.

[0057] Both types of data serve as input to the deep learning model: server alarm data helps identify local anomalies, while cluster performance alarm data helps assess the global impact. The combination of the two makes the classification results more comprehensive. For example, a single-node hard disk failure may be classified as medium risk, but if it causes a decrease in cluster throughput, it is upgraded to high risk, ensuring that the model can learn the full-scenario features from single-node anomalies to cluster-level failures.

[0058] Step S12: Perform data standardization preprocessing on the original alarm data, and use the preprocessed data as alarm data samples.

[0059] The original alarm data is preprocessed to standardize the data. The preprocessed alarm data samples are complete, accurate and consistent, ensuring that the deep learning model can effectively learn the temporal characteristics (such as the temporal correlation of multiple indicator anomalies) and patterns (such as the IO anomaly trend before hard disk failure) of the alarm data.

[0060] This embodiment does not limit the specific processing methods for data standardization preprocessing. In one embodiment, step S12, which performs data standardization preprocessing on the original alarm data, can specifically involve filling in missing values, removing outliers, and standardizing the original alarm data. First, missing values ​​are filled in or outliers are removed from the collected alarm items to ensure the completeness and accuracy of the input data. Then, standardization processing is performed so that data of different magnitudes can be compared within the same range.

[0061] The alarm data sample acquisition method provided in this embodiment can cover all-dimensional abnormal scenarios of intelligent cloud storage by comprehensively collecting alarm data from servers and clusters. At the same time, through standardized preprocessing, it ensures that subsequent deep learning models and classifiers can accurately learn and map alarm levels, avoiding classification errors caused by data quality issues, thereby solving the core defects of existing technologies that rely on manual expertise and are inefficient.

[0062] Example 3:

[0063] To ensure that the deep learning model integrates multi-dimensional information for comprehensive evaluation and to address the problem of difficulty in manually associating multi-dimensional features in existing technologies, this embodiment proposes to ensure the model's temporal feature capture and multi-dimensional feature fusion by inputting structured time step vectors before the deep learning model extracts temporal features. Specifically, step S102, which extracts alarm data from alarm data samples at each time step, can be performed as follows: arranging the alarm data samples in chronological order, extracting the alarm data for each time step, wherein the alarm data includes at least one dimension of information: timestamp, alarm description, alarm source, and alarm type.

[0064] Alarm data is essentially time-series data (e.g., a server CPU overload alarm occurs at 10:00:01, and a memory anomaly alarm occurs at 10:00:05). Arranging it in chronological order preserves the chronological dependencies between events, which is the foundation for deep learning models to capture temporal features. The arranged alarm data is divided into multiple time steps, each corresponding to a specific moment (e.g., one second, one minute), for progressive processing by the LSTM model. For example, with one minute as a time step, the alarm data within each time step is integrated into a single input vector.

[0065] Each alarm item contains information from multiple dimensions, such as a timestamp (recording the specific time the alarm was generated, used for time-series sorting and dependency analysis), an alarm description (a textual description of the alarm content, including key information such as fault type and impact scope), an alarm source (the specific component or device that generated the alarm, used to locate the fault source and help the model learn alarm characteristics from different sources), and an alarm type (at least one dimension of alarm business type classification (such as hardware failure, performance anomaly, service interruption, which can provide prior classification information for the model) to ensure the integrity and semantic richness of the input data. The alarm data at each time step is integrated into a vector, and each dimension of the vector corresponds to one or more of the above information.

[0066] The alarm data extraction method provided in this embodiment allows the deep learning model to selectively retain historical information based on the vector sequence input at each time step. For example, if the alarm source at a certain time step is the same as the alarm source 30 minutes ago (such as repeated IO anomalies on the same server), the deep learning model can continuously record this anomaly trend, ultimately affecting the classification result (such as upgrading from medium risk to high risk). Moreover, information such as timestamps and alarm descriptions in the input vector can be automatically fused by the deep learning model, avoiding the limitations of manual feature selection.

[0067] Example 4:

[0068] The training method for the deep learning model is not limited in the above embodiments. In order to cover the abnormal modes of the whole scene and ensure the balance between convergence speed and stability, this embodiment proposes a training method for the deep learning model, which includes: using historical alarm data and corresponding manual annotation levels, and optimizing the model parameters through the backpropagation algorithm.

[0069] Among them, the historical alarm data comes from the server alarm data (hardware / software anomalies) and cluster performance alarm data (throughput / latency anomalies, etc.) generated by the intelligent cloud storage system in the past, which provides learning samples for the model and can cover the feature patterns of various abnormal scenarios (such as hard disk failure and cluster crash).

[0070] Manually labeled alert levels refer to the alert levels (such as high risk, medium risk, low risk) manually labeled by operations and maintenance experts on historical alert data. These levels serve as the standard answers for model training, ensuring that the model learns a classification standard that meets business needs.

[0071] Backpropagation refers to the algorithm that calculates the error between the model's prediction level and the human annotation level (such as cross-entropy loss), and then adjusts the weight parameters of the LSTM model (such as the weight matrix in the gating mechanism) in reverse to make the model's predictions increasingly closer to the annotation results.

[0072] The optimization algorithm for model parameters includes the Adam optimizer. When the model is dealing with massive amounts of historical alarm data (such as 100,000 labeled samples), the Adam optimizer can bring the model to converge in fewer iterations.

[0073] In the deep learning model training method provided in this embodiment, historical alarm data includes multi-dimensional data such as server hardware / software alarms and cluster performance alarms. Combined with manual annotation, the model can learn full-scenario features from single-node failures to cluster-level disasters. Compared with training methods that only use a single type of data (such as only server alarms), this approach has stronger generalization ability and can cope with complex failure scenarios. At the same time, the Adam optimizer dynamically adjusts the learning rate according to the parameter update frequency, which can quickly converge to alarm features that change frequently (such as real-time fluctuations in CPU utilization) and retain memory for sparsely occurring key features (such as hard disk bad sector alarms), avoiding the slow convergence or oscillation problems caused by the fixed learning rate in traditional SGD (stochastic gradient descent).

[0074] Example 5:

[0075] In the above embodiments, there is no limitation on the specific model type of the deep learning model. In order to ensure the accurate extraction of temporal features, the deep learning model can specifically be a Long Short-Term Memory Neural Network (LSTM).

[0076] Specifically, one implementation process for feature extraction using the LSTM model is as follows: Figure 2 As shown, the process is as follows:

[0077] The existing alarm items are arranged in chronological order, and the alarm data at each time step is used as the input to the LSTM model. The input at each time step is a vector containing multiple alarm items (such as CPU utilization alarms, memory usage alarms, availability alarms, etc.).

[0078] The LSTM layer is responsible for learning time series features from the input data, capturing temporal dependencies and long-term change patterns. Each LSTM unit retains important temporal information and discards irrelevant information through forget gates, input gates, and output gates.

[0079] The output layer of the LSTM generates a vector representing the alarm features at the current time step, which is used for subsequent classification tasks.

[0080] The output of the LSTM network contains alarm features at the current time step, which are then used as input to the classifier.

[0081] In one embodiment, the classifier can specifically be a Softmax classifier, which maps the LSTM output to different alarm levels (high risk, medium risk, low risk). The Softmax classifier has strong adaptability to multi-classification scenarios and high efficiency in collaboration with LSTM. It can capture nonlinear relationships in the LSTM feature vector (such as the combined features of CPU overload duration × memory usage), which can enhance the recognition ability of key patterns.

[0082] It should be noted that this embodiment only introduces the power of the LSTM model and the Softmax classifier. The selection of other types of models can refer to the introduction of this embodiment, and will not be repeated here.

[0083] Example 6:

[0084] Further reference Figure 3 The diagram illustrates an exemplary structural block diagram of an automatic alarm classification device for an intelligent cloud storage system according to an embodiment of the present application. The device mainly includes a sample acquisition module, a feature extraction module, and a level mapping module. The automatic alarm classification device for the intelligent cloud storage system adopts a modular design and achieves efficient alarm classification and response through three core units.

[0085] Among them, the sample acquisition module is used to acquire alarm data samples from intelligent cloud storage;

[0086] The feature extraction module is used to extract alarm data at each time step from the alarm data sample, input it into the pre-trained deep learning model for feature extraction, and output the alarm feature vector at each time step.

[0087] The level mapping module is used to input alarm feature vectors into the classifier to map alarm levels and generate alarm levels.

[0088] In the automatic alarm grading device of the intelligent cloud storage system provided in this embodiment, the sample acquisition module ensures data comprehensiveness; the feature extraction module uses the time-series processing capability of LSTM to replace manual feature design; and the level mapping module achieves standardized grading through a classifier. The three modules form a closed loop of data acquisition, feature analysis, and decision output, requiring no manual intervention throughout the entire process. This solves the pain points of traditional solutions where manual grading relies on experience and is inefficient, and supports millisecond-level response to massive alarm data.

[0089] Embodiment seven:

[0090] The following is for reference. Figure 4 , Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the server of the present application is shown.

[0091] like Figure 4 As shown, the computer system includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 402 or programs loaded from storage section 408 into random access memory (RAM) 403. RAM 403 also stores various programs and data required for the system's operating instructions. CPU 401, ROM 402, and RAM 403 are interconnected via bus 404. Input / output (I / O) interface 405 is also connected to bus 404.

[0092] The following components are connected to I / O interface 405: an input section 406 including a keyboard, mouse, etc.; an output section 407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, modem, etc. The communication section 409 performs communication processing via a network such as the Internet. Drive 410 is also connected to I / O interface 405 as needed. Removable media 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 410 as needed so that computer programs read from them can be installed into storage section 408 as needed.

[0093] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 1 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such an embodiment, the computer program contains program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by central processing unit (CPU) 401, it performs the functions defined in the system of this application.

[0094] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0095] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operational instructions of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two connected blocks may actually be executed substantially in parallel, or they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified functions or operational instructions, or using a combination of dedicated hardware and computer instructions.

[0096] The units or modules described in the embodiments of this application can be implemented in software or hardware. The described units or modules can also be located in a processor. The names of these units or modules do not, in certain circumstances, constitute a limitation on the unit or module itself.

[0097] In another aspect, this application also provides a computer-readable storage medium, which may be included in the server described in the above embodiments, or may exist independently and not assembled into the server. The aforementioned computer-readable storage medium stores one or more programs that, when used by one or more processors, execute the data balancing method described in this application.

[0098] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. An automatic alarm classification method for an intelligent cloud storage system, characterized in that, include: Obtain alarm data samples from intelligent cloud storage; The alarm data at each time moment is extracted from the alarm data sample, input into a pre-trained deep learning model for feature extraction, and the alarm feature vector at each time moment is output. The alarm feature vector is input into a classifier to map alarm levels and generate alarm levels.

2. The method as described in claim 1, characterized in that, The acquisition of alarm data samples from intelligent cloud storage includes: Obtain server alarm data and cluster performance alarm data of intelligent cloud storage as raw alarm data; The original alarm data is subjected to data standardization preprocessing, and the preprocessed data is used as the alarm data sample.

3. The method as described in claim 2, characterized in that, The raw alarm data undergoes data standardization preprocessing, including: The original alarm data is processed by filling missing values, removing outliers, and standardizing.

4. The method as described in claim 1, characterized in that, The alarm data for each time moment is extracted from the alarm data sample, including: The alarm data samples are arranged in chronological order, and the alarm data for each time step is extracted. The alarm data includes at least one dimension of information, namely: timestamp, alarm description, alarm source, and alarm type.

5. The method as described in claim 1, characterized in that, The training method for the deep learning model includes: Optimize model parameters using historical alarm data and corresponding manually labeled levels through backpropagation algorithm; The optimization algorithm for the model parameters includes the Adam optimizer.

6. The method as described in claim 1, characterized in that, The deep learning model is specifically a long short-term memory neural network.

7. The method as described in claim 1, characterized in that, The classifier is specifically the Softmax classifier.

8. An automatic alarm classification device for an intelligent cloud storage system, characterized in that, include: The sample acquisition module is used to acquire alarm data samples from the intelligent cloud storage. The feature extraction module is used to extract alarm data at each time from the alarm data sample, input it into a pre-trained deep learning model for feature extraction, and output the alarm feature vector at each time. The level mapping module is used to input the alarm feature vector into the classifier to map the alarm level and generate the alarm level.

9. A server, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Power grid monitoring alarm event identification method based on convolution and long-term and short-term memory network

    CN111274395A

  • Tunnel post-disaster damage early warning method and system based on dynamic deep learning

    CN115238365A

  • Power production equipment fault and hidden danger intelligent diagnosis method and system based on knowledge graph

    CN117786043A

  • Cloud native application fault self-recovery method and device, electronic equipment and storage medium

    CN119621403A

  • Distributed server cluster log processing method and device

    CN120123184A