Event priority evaluation method applied to IT service management and related equipment
By using word vectorization and machine learning models to extract and classify features from IT event data, and combining business rules and technical indicators, the system automatically assesses event priorities. This solves the problem of low efficiency in manual judgment in existing technologies, achieves fast and accurate priority assessment, and improves operational efficiency and system stability.
Patent Information
- Application Number
- CN202511396107.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-26
- Publication Date
- 2025-12-12
AI Technical Summary
In IT operations and maintenance management in the financial sector, existing technologies rely on human experience to determine event priorities, which is inefficient and prone to misjudgment.
The event data is feature extracted and classified using word vectorization and machine learning models. Event priority judgment rules are constructed by combining business rules and technical indicators to automatically evaluate the priority of events.
It enables learning from historical event data, quickly and accurately prioritizing tasks, improving operational efficiency, reducing the burden on operations and maintenance personnel, and enhancing the reliability and stability of IT systems.
Smart Images

Figure CN121117752A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and is applicable to the financial sector, particularly to an event priority assessment method and related equipment for IT service management. Background Technology
[0002] In the operation and maintenance management of the financial sector, there is a massive amount of historical event data. This data contains multi-dimensional information, including event description text, event classification tags, event grading results, business rules, and technical indicators. How to extract valuable information from this data and prioritize events based on this information is a pressing problem that needs to be solved.
[0003] Currently, most operations and maintenance personnel still rely on human experience and judgment to determine the priority of events. This approach is not only inefficient but also prone to misjudgment. Summary of the Invention
[0004] The purpose of this application is to propose an event priority assessment method and related equipment for IT service management, so as to solve the problems that traditional IT operation and maintenance management is not only inefficient, but also prone to misjudgment.
[0005] To address the aforementioned technical problems, this application provides an event priority assessment method for IT service management, employing the following technical solution:
[0006] Acquire historical event data, and extract event description text, event classification tags, event grading results, business rules, and technical indicators based on the historical event data;
[0007] The event description text is transformed into an event feature vector by a word vectorization method.
[0008] The initial support vector machine classification model is invoked, and the initial support vector machine classification model is trained according to the event classification label to obtain the target support vector machine classification model.
[0009] The event feature vector is input into the target support vector machine classification model for classification to obtain the event classification result.
[0010] The initial random forest regression model is invoked, and a prediction model training operation is performed on the initial random forest regression model based on the event classification results to obtain the target random forest regression model.
[0011] The event feature vector and the event classification result are input into the target random forest regression model for prediction to obtain the event severity score.
[0012] Construct event priority determination rules based on the aforementioned business rules and technical indicators;
[0013] The priority assessment result of the historical event data is determined based on the event classification results, the severity score, and the event priority judgment rules.
[0014] Furthermore, before the step of performing word vectorization on the event description text according to the word vectorization method to obtain the event feature vector, the following steps are also included:
[0015] The event description text is segmented using natural language processing techniques to remove stop words and redundant information, resulting in a cleaned event description text.
[0016] The step of performing word vectorization on the event description text to obtain the event feature vector specifically includes the following steps:
[0017] The cleaned event description text is transformed into event feature vectors using a word vectorization method.
[0018] Furthermore, after the step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule, the following step is also included:
[0019] Based on the event classification results and cluster analysis methods, the historical event data is grouped to obtain historical event groups;
[0020] Each of the historical event groups will be assigned a personalized event priority evaluation model.
[0021] The priority assessment results are adjusted according to the personalized event priority assessment model to obtain the final priority assessment result.
[0022] Furthermore, the step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule specifically includes the following steps:
[0023] An event priority evaluation model is constructed based on the event priority judgment rules, decision tree algorithm, and technical indicators.
[0024] The event classification results and the severity score are input into the event priority assessment model to perform a priority assessment operation, and the priority assessment results are obtained.
[0025] Furthermore, after the step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule, the following step is also included:
[0026] An event handling strategy is generated based on the priority evaluation results, wherein the generated event handling strategy includes a resource allocation strategy and a processing order strategy;
[0027] The historical event data is processed according to the event processing strategy.
[0028] To address the aforementioned technical problems, this application also provides an event priority assessment device for IT service management, employing the following technical solution:
[0029] The historical event data acquisition module is used to acquire historical event data and extract event description text, event classification tags, event grading results, business rules and technical indicators based on the historical event data.
[0030] The word vector conversion module is used to perform word vector conversion on the event description text according to the word vectorization method to obtain the event feature vector;
[0031] The classification model training module is used to call the initial support vector machine classification model and perform classification model training operations on the initial support vector machine classification model according to the event classification label to obtain the target support vector machine classification model.
[0032] The classification module is used to input the event feature vector into the target support vector machine classification model for classification operation to obtain the event classification result;
[0033] The prediction model training module is used to call the initial random forest regression model and perform prediction model training operations on the initial random forest regression model according to the event classification results to obtain the target random forest regression model.
[0034] The prediction module is used to input the event feature vector and the event classification result into the target random forest regression model to perform prediction operations and obtain an event severity score;
[0035] The rule building module is used to build event priority judgment rules based on the business rules and the technical indicators;
[0036] The evaluation result confirmation module is used to determine the priority evaluation result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule.
[0037] Furthermore, the device also includes: a word segmentation processing module, and the word vector conversion module includes: a word vector conversion submodule, wherein:
[0038] The word segmentation module is used to segment the event description text according to natural language processing technology, remove stop words and redundant information, and obtain the cleaned event description text.
[0039] The word vector conversion module is used to perform word vector conversion on the cleaned event description text according to the word vectorization method to obtain the event feature vector.
[0040] Furthermore, the device also includes:
[0041] The grouping module is used to group the historical event data according to the event classification results and cluster analysis methods to obtain historical event groups.
[0042] The personalized model acquisition module is used to acquire the personalized event priority evaluation model corresponding to the historical event group respectively;
[0043] The result adjustment module is used to adjust the priority assessment result according to the personalized event priority assessment model to obtain the final priority assessment result.
[0044] To address the aforementioned technical problems, this application also provides a computer device that employs the following technical solution:
[0045] It includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the event priority assessment method applied to IT service management as described above.
[0046] To address the aforementioned technical problems, this application also provides a computer-readable storage medium, employing the technical solution described below:
[0047] The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the event priority assessment method for IT service management as described above.
[0048] This application provides an event priority assessment method for IT service management, comprising: acquiring historical event data and extracting event description text, event classification tags, event grading results, business rules, and technical indicators based on the historical event data; performing word vectorization on the event description text to obtain event feature vectors; calling an initial support vector machine (SVM) classification model and training the initial SVM classification model based on the event classification tags to obtain a target SVM classification model; inputting the event feature vectors into the target SVM classification model for classification to obtain event classification results; calling an initial random forest regression model and training the initial random forest regression model for prediction based on the event grading results to obtain a target random forest regression model; inputting the event feature vectors and the event classification results into the target random forest regression model for prediction to obtain an event severity score; constructing event priority judgment rules based on the business rules and the technical indicators; and determining the priority assessment result of the historical event data based on the event classification results, the severity score, and the event priority judgment rules. Compared to existing technologies, this application can automatically learn and summarize experience from historical event data, and quickly and accurately prioritize new events based on the learned knowledge. This can not only greatly improve operation and maintenance efficiency and reduce the workload of operation and maintenance personnel, but also make operation and maintenance work more intelligent and standardized, and improve the reliability and stability of the entire IT system. Attached Figure Description
[0049] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0050] Figure 1 This is an exemplary system architecture diagram to which this application can be applied;
[0051] Figure 2 This is a flowchart illustrating the implementation of the event priority assessment method for IT service management provided in the embodiments of this application.
[0052] Figure 3 This is a flowchart illustrating an embodiment of an IT service management system provided in this application.
[0053] Figure 4 This is a schematic diagram of the structure of an event priority assessment device for IT service management provided in an embodiment of this application;
[0054] Figure 5 This is a schematic diagram of the structure of one embodiment of the computer device according to this application. Detailed Implementation
[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings of this application, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings of this application are used to distinguish different objects, not to describe a particular order.
[0056] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0057] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0058] like Figure 1 As shown, system architecture 100 may include terminal device 101, network 102, and server 103. Terminal device 101 may be a laptop 1011, tablet 1012, or mobile phone 1013. Network 102 is used as a medium to provide a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0059] Users can use terminal device 101 to interact with server 103 via network 102 to receive or send messages, etc. Various communication client applications can be installed on terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social media platform software, etc.
[0060] Terminal device 101 can be various electronic devices with a display screen and support web browsing. In addition to laptops 1011, tablets 1012, or mobile phones 1013, terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer, and a desktop computer, etc.
[0061] Server 103 can be a server that provides various services, such as a backend server that provides support for the pages displayed on terminal device 101.
[0062] It should be noted that the event priority assessment method for IT service management provided in this application embodiment is generally executed by a server / terminal device, and correspondingly, the event priority assessment device for IT service management is generally installed in the server / terminal device.
[0063] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0064] Continue to refer to Figure 2 The diagram illustrates a flowchart of an embodiment of an event priority assessment method for IT service management according to this application. The event priority assessment method for IT service management includes steps S201, S202, S203, S204, S205, S206, S207, and S208.
[0065] In step S201, historical event data is obtained, and event description text, event classification tags, event grading results, business rules, and technical indicators are extracted based on the historical event data. The historical event data may be "transaction data, payment data, business data, or purchase data" related to financial institutions (such as banks). It should be understood that the examples of historical event data here are for convenience of understanding only and are not intended to limit this application.
[0066] In the embodiments of this application, historical event data can be collected from various sources (such as databases, log files, news reports, etc.).
[0067] In this embodiment of the application, the event description text refers to the textual description of the event, which provides the background, process and result of the event.
[0068] In this application embodiment, the event classification label refers to a label used to identify the type of event, such as natural disaster, safety accident, economic event, etc.
[0069] In the embodiments of this application, the event classification result refers to the classification of the event according to its severity or scope of impact, such as minor, moderate, severe, etc.
[0070] In this application embodiment, business rules refer to rules or standards regarding event handling within a specific field or organization.
[0071] In the embodiments of this application, technical indicators refer to technical data related to the event, such as the time of occurrence, location, and scope of impact.
[0072] In step S202, the event description text is transformed into a word vector using a word vectorization method to obtain the event feature vector.
[0073] In this embodiment of the application, word vectorization methods (such as Word2Vec, TF-IDF, etc.) are used to convert the event description text into numerical feature vectors so that machine learning models can process them.
[0074] In step S203, the initial support vector machine classification model is invoked, and the initial support vector machine classification model is trained according to the event classification label to obtain the target support vector machine classification model.
[0075] In this embodiment of the application, the initial support vector machine (SVM) classification model and event classification labels are used to train the model to obtain a target SVM classification model that can accurately classify events.
[0076] In step S204, the event feature vector is input into the target support vector machine classification model for classification to obtain the event classification result.
[0077] In this embodiment of the application, the event feature vector is input into the target SVM classification model to obtain the event classification result.
[0078] In step S205, the initial random forest regression model is invoked, and the prediction model training operation is performed on the initial random forest regression model according to the event classification results to obtain the target random forest regression model.
[0079] In this embodiment of the application, the model is trained using an initial random forest regression model and event classification results to obtain a target random forest regression model that can predict the severity of events.
[0080] In step S206, the event feature vector and the event classification result are input into the target random forest regression model for prediction to obtain the event severity score.
[0081] In this embodiment of the application, the event feature vector and the event classification result are input into the target random forest regression model to obtain the severity score of the event.
[0082] In step S207, event priority judgment rules are constructed based on business rules and technical indicators.
[0083] In this application embodiment, a set of rules or standards for determining event priority is formulated based on business rules and technical indicators.
[0084] In step S208, the priority evaluation results of historical event data are determined based on the event classification results, severity scores, and event priority judgment rules.
[0085] In this embodiment of the application, the priority of historical events is comprehensively evaluated by combining the event classification results, severity scores, and event priority judgment rules.
[0086] In this application, multiple technologies, including Natural Language Processing (NLP), Machine Learning (ML), and rule engines, are combined to learn from historical data and predict the classification and severity of future events, thereby providing decision support for event management and emergency response. This approach has broad application prospects in risk management, disaster early warning, and cybersecurity.
[0087] In practical applications, such as Figure 3 The flowchart shown is for an IT service management system, including unified event integration management and determining event processing priorities. Specifically:
[0088] 1. Unified and integrated event management:
[0089] Actively reported and passively discovered IT events are synchronized, dispatched, and integrated from various systems into Oncall event management.
[0090] (1) Proactive discovery: This includes monitoring alerts that operations and maintenance determine require handling (alarms are converted into events), and events proactively reported by R&D (before users perceive them).
[0091] (2) User reporting: This includes IT incidents reported through the Group's ITSM work order system, the Happy and Safe Event Account (a public WeChat account, mainly for mobile reporting), and the customer service system for C-end customers.
[0092] *Assignment method: Oncall processing team members are responsible for their own main systems. In addition, in order to avoid too many problems being reported by the same system in a short period of time, and the same Oncall personnel being unable to respond and handle them in a timely manner, when an Oncall personnel has more than 10 unfinished work orders, they are automatically assigned to other Oncall personnel to ensure that production events can be handled within the time limit (8 working hours).
[0093] 2. Determine the priority of event handling:
[0094] Events are pre-classified and pre-graded to determine their priority: major events > system problems > consultation / operational issues;
[0095] (1) Event Classification:
[0096] Consultation procedures: business rules, data verification, and operation guidelines;
[0097] System issues: code defects, data problems, requirement issues (major events);
[0098] (2) Event level: P1>P2>P3>P4>P5.
[0099] The rating is primarily based on financial losses, the impact of regulatory / customer complaints, the number of user data breaches, and the duration of system outages. Events rated P3 and above are considered major incidents.
[0100] This application provides a method for event priority assessment in IT service management, comprising: acquiring historical event data and extracting event description text, event classification tags, event grading results, business rules, and technical indicators from the historical event data; performing word vectorization on the event description text to obtain event feature vectors; calling an initial support vector machine (SVM) classification model and training the initial SVM classification model based on the event classification tags to obtain a target SVM classification model; inputting the event feature vectors into the target SVM classification model for classification to obtain event classification results; calling an initial random forest regression model and training the initial random forest regression model for prediction based on the event grading results to obtain a target random forest regression model; inputting the event feature vectors and event classification results into the target random forest regression model for prediction to obtain an event severity score; constructing event priority judgment rules based on business rules and technical indicators; and determining the priority assessment results of historical event data based on the event classification results, severity scores, and event priority judgment rules. Compared with existing technologies, this application can automatically learn and summarize experience from historical event data and quickly and accurately judge the priority of new events based on the learned knowledge. This can not only greatly improve operation and maintenance efficiency and reduce the workload of operation and maintenance personnel, but also make operation and maintenance work more intelligent and standardized, and improve the reliability and stability of the entire IT system.
[0101] In some optional implementations of the embodiments of this application, before the step of performing word vector transformation on the event description text according to the word vectorization method to obtain the event feature vector, the following steps are also included:
[0102] The event description text is segmented using natural language processing techniques to remove stop words and redundant information, resulting in a cleaned event description text.
[0103] The steps involved in transforming the event description text into word vectors using word vectorization methods to obtain event feature vectors include the following:
[0104] The cleaned event description text is transformed into event feature vectors using word vectorization methods.
[0105] In this embodiment, word segmentation is a fundamental task in NLP, referring to the division of a continuous text string into individual words or phrases. For Chinese text, since there are no obvious spaces separating words, word segmentation becomes an important preprocessing step. Specifically:
[0106] Word Segmentation Methods: Common Chinese word segmentation methods include dictionary-based word segmentation, statistics-based word segmentation, and deep learning-based word segmentation. Dictionary-based word segmentation methods determine word boundaries by looking up predefined dictionaries; statistics-based word segmentation methods use the frequency of word occurrences and context information in the text for word segmentation; deep learning-based word segmentation methods automatically learn word segmentation rules by training neural network models;
[0107] Word Segmentation Results: After word segmentation, the text is segmented into individual words or phrases, which serve as the basis for subsequent processing.
[0108] In the embodiments of this application, stop words refer to words that frequently appear in the text but contribute little to the text semantics, such as "de", "le", "zai", etc. Removing stop words can reduce the noise in the text data and improve the effect of subsequent processing. Among them:
[0109] Stop Word List: Usually, NLP tools provide a predefined stop word list for removing these words during text processing;
[0110] Removing Method: In the segmented text, by looking up the stop word list and deleting these words, the text after removing stop words can be obtained.
[0111] In the embodiments of this application, redundant information refers to information that appears repeatedly in the text or contributes little to the text semantics. Removing redundant information can further streamline the text data and improve the efficiency of subsequent processing. Among them:
[0112] Types of Redundant Information: Redundant information includes repeatedly occurring words, sentences or paragraphs, as well as insignificant detailed descriptions, etc.;
[0113] Removing Method: The method of removing redundant information varies depending on the specific application scenario. For repeatedly occurring words or sentences, they can be identified and deleted by counting word frequencies or sentence similarities; for insignificant detailed descriptions, it is necessary to judge in combination with context information and semantic understanding.
[0114] In the embodiments of this application, after word segmentation, removing stop words and redundant information, the original event description text is cleaned into a more concise and clear form. This cleaned text data is more suitable for subsequent text analysis, sentiment analysis, topic extraction and other tasks.
[0115] In the embodiments of this application, by preprocessing the text data, a more reliable data foundation is provided for subsequent analysis and mining.
[0116] In some optional implementations of the embodiments of this application, after the step of determining the priority evaluation result of historical event data based on event classification results, severity scores, and event priority judgment rules, the following steps are further included:
[0117] Based on the event classification results and cluster analysis methods, the historical event data is grouped to obtain historical event groups;
[0118] Each personalized event priority assessment model corresponding to a historical event group is obtained.
[0119] The priority assessment results are adjusted based on the personalized event priority assessment model to obtain the final priority assessment result.
[0120] In this embodiment of the application, text data preprocessing is a crucial step in the data analysis and data mining process. Text data typically contains a large amount of noise, redundant information, and inconsistent formatting, which directly affect the accuracy and reliability of subsequent analysis results. Therefore, by preprocessing text data, these adverse factors can be removed, providing a clearer, more accurate, and consistent data foundation for subsequent analysis and mining.
[0121] In this embodiment, preprocessing text data can significantly improve data quality, standardize data format, enhance data interpretability, and improve analysis efficiency. These preprocessing steps provide a more reliable data foundation for subsequent analysis and mining, helping to reveal key information and potential patterns in the text data, and providing strong support for decision support and knowledge discovery.
[0122] In some optional implementations of the embodiments of this application, the step of determining the priority evaluation result of historical event data based on event classification results, severity scores, and event priority judgment rules specifically includes the following steps:
[0123] An event priority evaluation model is constructed based on event priority judgment rules, decision tree algorithm, and technical indicators.
[0124] The event classification results and severity scores are input into the event priority assessment model to perform priority assessment operations, and the priority assessment results are obtained.
[0125] In this embodiment, the event priority determination rules are formulated based on business needs and domain knowledge, and are used to guide how to determine the priority of events according to factors such as their nature, scope of impact, and urgency. These rules may include:
[0126] The impact of event classification (such as natural disasters, safety accidents, system failures, etc.) on priority;
[0127] The correspondence between the severity rating of an event (e.g., minor, moderate, severe) and its priority.
[0128] The priority is weighted by specific technical indicators (such as the number of people affected, economic losses, system downtime, etc.).
[0129] In this embodiment, the decision tree algorithm partitions the dataset through a series of questions (i.e., decision nodes) and ultimately forms a tree structure. In event priority evaluation, the decision tree algorithm can build a model based on various attributes of events (such as classification results, severity scores, technical indicators, etc.) to automatically determine event priorities.
[0130] In this embodiment, technical indicators are quantitative metrics that reflect information such as event characteristics, scope of impact, and urgency. When constructing an event priority assessment model, technical indicators can be used as one of the input features to evaluate the event's priority. These indicators may include:
[0131] Scope of impact (e.g., number of people, regions, or systems affected);
[0132] Economic losses (such as direct economic losses, indirect economic losses, etc.);
[0133] System downtime (e.g., system unavailability time, recovery time, etc.);
[0134] The frequency and trends of events, etc.
[0135] In this embodiment of the application, by inputting the event classification results and severity scores into the model for priority evaluation, accurate priority evaluation results can be obtained, providing strong support for event handling decisions.
[0136] In some optional implementations of the embodiments of this application, after the step of determining the priority evaluation result of historical event data based on event classification results, severity scores, and event priority judgment rules, the following steps are further included:
[0137] An event handling strategy is generated based on the priority evaluation results. The generated event handling strategy includes a resource allocation strategy and a processing order strategy.
[0138] Perform event processing operations on historical event data according to the event processing strategy.
[0139] In this embodiment, priority evaluation results are a crucial basis for generating event handling strategies. By evaluating the priorities of events, we can determine which events need to be processed first and which can be processed later. Based on this evaluation result, we can formulate corresponding event handling strategies to ensure that resources are allocated reasonably and the processing order is optimized.
[0140] In this embodiment, the resource allocation strategy refers to allocating corresponding processing resources based on the priority of events. These resources may include human resources (such as emergency response teams, technical support personnel, etc.), material resources (such as relief supplies, equipment and tools, etc.), and time resources (such as processing time windows, response times, etc.). Specifically:
[0141] Human resource allocation: For high-priority events, experienced and skilled personnel should be assigned to handle them first; for low-priority events, relatively fewer personnel can be assigned or automated tools can be used to handle them.
[0142] Resource allocation: Based on the nature and priority of the event, necessary relief supplies and equipment should be allocated rationally. For example, for high-priority events such as natural disasters, relief supplies and equipment should be quickly dispatched to the disaster area; for low-priority events such as system failures, existing inventory or backup equipment can be used for repairs.
[0143] Time resource allocation: For high-priority events, more processing time windows and faster response times should be given to ensure that the problems are resolved in a timely manner; for low-priority events, the processing time can be appropriately extended or the processing can be scheduled during off-peak hours.
[0144] In this embodiment, the processing order strategy refers to determining the order of processing events based on their priority. This strategy aims to optimize the processing flow and improve processing efficiency. Specifically:
[0145] Prioritize high-priority events: High-priority events should be handled first to ensure that problems are resolved in a timely manner and to minimize the impact on business or systems.
[0146] Low-priority events can be delayed in processing, so that more resources and energy can be devoted to the processing of high-priority events.
[0147] Combining parallel and serial processing: When resources permit, parallel processing of multiple events can be attempted to improve efficiency. However, it should be noted that parallel processing may increase resource consumption and complexity, so careful evaluation is necessary.
[0148] In the embodiments of this application, by allocating resources reasonably and optimizing the processing sequence, we can improve the efficiency and quality of event processing and ensure the stable operation of business or system.
[0149] In some optional implementations of the embodiments of this application, combined with Figure 3 The flowchart shown is applied to the IT service management system. This application also includes a major incident emergency response mechanism and an incident review and task tracking mechanism, specifically:
[0150] 1. Emergency Response Mechanism for Major Incidents:
[0151] (1) Generate a major event order (new / forward) and start recording the duration of the abnormality. The Oncall robot automatically creates a group based on the system's personnel structure.
[0152] Pull in development, testing, product, and operations teams from related systems; send event cards: event name, level, discovery method, reporter, reporting time, event description, and affected systems;
[0153] Notify everyone that the emergency response process has been activated and that everyone gathers in a dedicated conference room; inform them of the SLA indicators associated with the pre-classified event.
[0154] As an example: the event is predicted to be P3, and a stop loss should be implemented within 30 minutes to resolve the issue on the same day.
[0155] (2) Critical status of handling major incidents:
[0156] Start, stop the bleeding, resolve the issue, review;
[0157] The processing flow is updated in real time via the @Oncall robot in a dedicated processing group, with a focus on key items;
[0158] As an example: @Health Insurance OnCall Robot - ul oc: Missing code -> Update Critical Events Page: Problem Location: Missing code;
[0159] Key areas of focus: Abnormal systems (initiating system, related systems), business impact (financial losses, number of regulatory / customer complaints, amount of user data corruption);
[0160] Problem identification, hemostasis plan, application / data repair plan (the plan includes three stages: identification, execution, and verification), and time of occurrence;
[0161] (3) Notification of Major Events:
[0162] Notification methods include incremental notifications and scheduled notifications; the notification recipients include R&D leaders (in a fixed R&D management group) and business stakeholders (via email).
[0163] Taking P3 events as an example, when the notification method is set to update critical handling nodes, if there is no status update within 10 minutes after the last update, the processing progress will be sent again automatically.
[0164] (4) Emergency response status lifted: Hemostasis protocol validated.
[0165] Special group notification: The emergency process has been closed. Please restore the application and data as soon as possible, and conduct analysis and review.
[0166] Stop recording abnormal durations and stop notifications for critical events;
[0167] One-click batch automatic feedback of related event work order processing opinions;
[0168] 2. Event review and task follow-up mechanism:
[0169] (1) One-click pre-generation of reports after major incidents are resolved:
[0170] After system repair is completed, a major event report is pre-generated with one click, and timeline data is processed synchronously, with key items of concern highlighted and other data supplemented by the responsible system.
[0171] (2) Supplementary analysis, classification and responsibility assignment, identification of pending tasks and follow-up:
[0172] Define the responsibility system, conduct a three-tiered quality network analysis of business impact (final classification based on business impact), and write down to-do items (clearly identify the follow-up person, estimated completion date, and regular reminders); finalize the report at the debriefing meeting, and update and close the major event process upon completion of the debriefing.
[0173] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0174] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0175] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0176] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0177] Further reference Figure 4 As a response to the above Figure 2 The implementation of the method shown in this application provides an embodiment of an event priority assessment device for IT service management, which is similar to... Figure 2 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0178] like Figure 4 As shown, the event priority assessment device 200 for IT service management according to an embodiment of this application includes:
[0179] The historical event data acquisition module 210 is used to acquire historical event data and extract event description text, event classification tags, event grading results, business rules and technical indicators based on the historical event data.
[0180] The word vector conversion module 220 is used to perform word vector conversion on the event description text according to the word vectorization method to obtain the event feature vector;
[0181] The classification model training module 230 is used to call the initial support vector machine classification model and perform classification model training operations on the initial support vector machine classification model according to the event classification label to obtain the target support vector machine classification model.
[0182] The classification module 240 is used to input the event feature vector into the target support vector machine classification model for classification operations to obtain the event classification result;
[0183] The prediction model training module 250 is used to call the initial random forest regression model and perform prediction model training operations on the initial random forest regression model according to the event classification results to obtain the target random forest regression model.
[0184] Prediction module 260 is used to input the event feature vector and event classification results into the target random forest regression model for prediction to obtain the event severity score;
[0185] Rule building module 270 is used to build event priority judgment rules based on business rules and technical indicators;
[0186] The assessment result confirmation module 280 is used to determine the priority assessment results of historical event data based on the event classification results, severity scores, and event priority judgment rules.
[0187] In this embodiment, an event priority assessment device 200 for IT service management is provided, comprising: a historical event data acquisition module 210, used to acquire historical event data and extract event description text, event classification tags, event grading results, business rules, and technical indicators based on the historical event data; a word vector conversion module 220, used to perform word vector conversion on the event description text according to a word vectorization method to obtain event feature vectors; a classification model training module 230, used to call an initial support vector machine classification model and perform classification model training on the initial support vector machine classification model according to the event classification tags to obtain a target support vector machine classification model; and a classification module 240, used to input the event feature vectors. The system performs classification operations on the target support vector machine (SVM) classification model to obtain the event classification result. A prediction model training module 250 calls the initial random forest regression model and trains it based on the event classification result to obtain the target random forest regression model. A prediction module 260 inputs the event feature vector and event classification result into the target random forest regression model for prediction to obtain the event severity score. A rule construction module 270 constructs event priority judgment rules based on business rules and technical indicators. An evaluation result confirmation module 280 determines the priority evaluation result of historical event data based on the event classification result, severity score, and event priority judgment rules. Compared with existing technologies, this application can automatically learn and summarize experience from historical event data and quickly and accurately judge the priority of new events based on the learned knowledge. This can not only greatly improve operation and maintenance efficiency and reduce the workload of operation and maintenance personnel, but also make operation and maintenance work more intelligent and standardized, and improve the reliability and stability of the entire IT system.
[0188] In some optional implementations of the embodiments of this application, the event priority assessment device 200 applied to IT service management further includes: a word segmentation processing module, and the word vector conversion module includes: a word vector conversion submodule, wherein:
[0189] The word segmentation module is used to segment the event description text according to natural language processing technology, remove stop words and redundant information, and obtain the cleaned event description text.
[0190] The word vector conversion module is used to perform word vector conversion on the cleaned event description text according to the word vectorization method to obtain event feature vectors.
[0191] In some optional implementations of the embodiments of this application, the event priority assessment device 200 applied to IT service management further includes:
[0192] The grouping module is used to group historical event data according to event classification results and cluster analysis methods to obtain historical event groups;
[0193] The personalized model acquisition module is used to acquire personalized event priority evaluation models corresponding to historical event groups.
[0194] The results adjustment module is used to adjust the priority assessment results according to the personalized event priority assessment model to obtain the final priority assessment result.
[0195] To address the aforementioned technical problems, embodiments of this application also provide a computer device. Please refer to [link / reference needed]. Figure 5 , Figure 5 This is a basic structural block diagram of a computer device according to an embodiment of this application.
[0196] The computer device 300 includes a memory 310, a processor 320, and a network interface 330 that are interconnected via a system bus. It should be noted that only the computer device 300 with components 310-330 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0197] The computer device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device can interact with the user via a keyboard, mouse, remote control, touchpad, or voice control.
[0198] The memory 310 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 310 may be an internal storage unit of the computer device 300, such as the hard disk or memory of the computer device 300. In other embodiments, the memory 310 may also be an external storage device of the computer device 300, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. Of course, the memory 310 may also include both internal storage units and external storage devices of the computer device 300. In this embodiment, the memory 310 is typically used to store the operating system and various application software installed on the computer device 300, such as computer-readable instructions for event priority assessment methods applied to IT service management. Furthermore, the memory 310 can also be used to temporarily store various types of data that have been output or will be output.
[0199] In some embodiments, the processor 320 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 320 is typically used to control the overall operation of the computer device 300. In this embodiment, the processor 320 is used to execute computer-readable instructions stored in the memory 310 or to process data, for example, to execute computer-readable instructions for the event priority assessment method applied to IT service management.
[0200] The network interface 330 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the computer device 300 and other electronic devices.
[0201] The computer equipment provided in this application can automatically learn and summarize experience from historical event data, and quickly and accurately prioritize new events based on the learned knowledge. This can not only greatly improve operation and maintenance efficiency and reduce the workload of operation and maintenance personnel, but also make operation and maintenance work more intelligent and standardized, and improve the reliability and stability of the entire IT system.
[0202] This application also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the event priority assessment method applied to IT service management as described above.
[0203] The computer-readable storage medium provided in this application can automatically learn and summarize experience from historical event data, and quickly and accurately prioritize new events based on the learned knowledge. This can not only greatly improve operation and maintenance efficiency and reduce the workload of operation and maintenance personnel, but also make operation and maintenance work more intelligent and standardized, and improve the reliability and stability of the entire IT system.
[0204] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0205] Obviously, the embodiments described above are only some embodiments of this application, not all embodiments. The accompanying drawings show preferred embodiments of this application, but do not limit the patent scope of this application. This application can be implemented in many different forms; rather, the purpose of providing these embodiments is to provide a more thorough and comprehensive understanding of the disclosure of this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this application's specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the scope of patent protection of this application.
Claims
1. An event priority assessment method applied to IT service management, characterized in that, Includes the following steps: Acquire historical event data, and extract event description text, event classification tags, event grading results, business rules, and technical indicators based on the historical event data; The event description text is transformed into an event feature vector by a word vectorization method. The initial support vector machine classification model is invoked, and the initial support vector machine classification model is trained according to the event classification label to obtain the target support vector machine classification model. The event feature vector is input into the target support vector machine classification model for classification to obtain the event classification result. The initial random forest regression model is invoked, and a prediction model training operation is performed on the initial random forest regression model based on the event classification results to obtain the target random forest regression model. The event feature vector and the event classification result are input into the target random forest regression model for prediction to obtain the event severity score. Construct event priority determination rules based on the aforementioned business rules and technical indicators; The priority assessment result of the historical event data is determined based on the event classification results, the severity score, and the event priority judgment rules.
2. The event priority assessment method for IT service management according to claim 1, characterized in that, Before the step of performing word vectorization on the event description text according to the word vectorization method to obtain the event feature vector, the following steps are also included: The event description text is segmented using natural language processing techniques to remove stop words and redundant information, resulting in a cleaned event description text. The step of performing word vectorization on the event description text to obtain the event feature vector specifically includes the following steps: The cleaned event description text is transformed into event feature vectors using a word vectorization method.
3. The event priority assessment method for IT service management according to claim 1, characterized in that, After the step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule, the following step is also included: Based on the event classification results and cluster analysis methods, the historical event data is grouped to obtain historical event groups; Each of the historical event groups will be assigned a personalized event priority evaluation model. The priority assessment results are adjusted according to the personalized event priority assessment model to obtain the final priority assessment result.
4. The event priority assessment method for IT service management according to claim 1, characterized in that, The step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule specifically includes the following steps: An event priority evaluation model is constructed based on the event priority judgment rules, decision tree algorithm, and technical indicators. The event classification results and the severity score are input into the event priority assessment model to perform a priority assessment operation, and the priority assessment results are obtained.
5. The event priority assessment method for IT service management according to claim 1, characterized in that, After the step of determining the priority assessment result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule, the following step is also included: An event handling strategy is generated based on the priority evaluation results, wherein the generated event handling strategy includes a resource allocation strategy and a processing order strategy; The historical event data is processed according to the event processing strategy.
6. An event priority assessment device for IT service management, characterized in that, include: The historical event data acquisition module is used to acquire historical event data and extract event description text, event classification tags, event grading results, business rules and technical indicators based on the historical event data. The word vector conversion module is used to perform word vector conversion on the event description text according to the word vectorization method to obtain the event feature vector; The classification model training module is used to call the initial support vector machine classification model and perform classification model training operations on the initial support vector machine classification model according to the event classification label to obtain the target support vector machine classification model. The classification module is used to input the event feature vector into the target support vector machine classification model for classification operation to obtain the event classification result; The prediction model training module is used to call the initial random forest regression model and perform prediction model training operations on the initial random forest regression model according to the event classification results to obtain the target random forest regression model. The prediction module is used to input the event feature vector and the event classification result into the target random forest regression model to perform prediction operations and obtain an event severity score; The rule building module is used to build event priority judgment rules based on the business rules and the technical indicators; The evaluation result confirmation module is used to determine the priority evaluation result of the historical event data based on the event classification result, the severity score, and the event priority judgment rule.
7. The event priority assessment device for IT service management according to claim 6, characterized in that, The device further includes: a word segmentation processing module, wherein the word vector conversion module includes: a word vector conversion submodule, wherein: The word segmentation module is used to segment the event description text according to natural language processing technology, remove stop words and redundant information, and obtain the cleaned event description text. The word vector conversion module is used to perform word vector conversion on the cleaned event description text according to the word vectorization method to obtain the event feature vector.
8. The event priority assessment device for IT service management according to claim 6, characterized in that, The device further includes: The grouping module is used to group the historical event data according to the event classification results and cluster analysis methods to obtain historical event groups. The personalized model acquisition module is used to acquire the personalized event priority evaluation model corresponding to the historical event group respectively; The result adjustment module is used to adjust the priority assessment result according to the personalized event priority assessment model to obtain the final priority assessment result.
9. A computer device, comprising a memory and a processor, characterized in that, The memory stores computer-readable instructions, and when the processor executes the computer-readable instructions, it implements the steps of the event priority assessment method for IT service management as described in any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the event priority assessment method for IT service management as described in any one of claims 1 to 5.