Methods, devices, equipment, media, and programs for field search based on business information
By calculating the business importance score of field values and optimizing the sorting strategy, the problem that field value sorting in existing technologies cannot adapt to dynamic business contexts is solved, and the query efficiency and accuracy of quickly locating key field values are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING YOUTEJIE INFORMATION TECH
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-26
AI Technical Summary
In existing technologies, the sorting methods for field values cannot adapt to dynamically changing business contexts, and cannot automatically respond to different times and different analysis scenarios. This results in important new values not being quickly identified, high maintenance costs, and poor scalability.
By obtaining business data association information for the target field, the business importance score of each field value is calculated, and the values are sorted according to the score. The business importance dimension is introduced to optimize the sorting strategy.
It improves the efficiency and accuracy of field value queries, enabling quick location of field values that have a critical impact on business operations, and overcomes the limitations of traditional sorting methods.
Smart Images

Figure CN122086967A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the fields of computer software application and data processing technology, and in particular to a field search method, apparatus, electronic device, storage medium and program based on business information. Background Technology
[0002] In the field of data query, search, and analysis, such as log query and analysis, especially for professional scenarios such as operation and maintenance, security, and auditing, users often need to quickly locate key entities from drop-down lists of fields containing massive heterogeneous values.
[0003] Currently, there are two main methods for sorting field values in dropdown lists: basic dictionary sorting and frequency-based sorting. Basic dictionary sorting arranges field values in simple alphabetical (AZ) or reverse (ZA) order. Frequency-based sorting, on the other hand, sorts field values in descending order based on their frequency of occurrence within the current query time range. Some advanced data management platforms are experimenting with introducing "tags" or "categories" for field values, allowing administrators to manually label certain field values as "important" and highlight them during display.
[0004] In the process of developing this invention, the inventors discovered the following shortcomings in existing technologies: The sorting results of basic dictionary sorting methods are completely detached from the business semantics of the data and the current analysis context. While frequency-based statistical sorting methods can reflect popular data, they cannot distinguish between high-frequency but insignificant operations and low-frequency but crucial security events. For example, high-frequency heartbeat logs may be ranked highly, while low-frequency unauthorized access events may be buried in the list. Current sorting methods that label field values or use classification functions are essentially static, manual, and non-quantitative. They rely on pre-configured static labels or rules, making them unable to adapt to dynamically changing business contexts, such as different times and different analysis scenarios. They also cannot automatically assess importance based on real-time data, nor can they handle massive amounts of new values that are not pre-labeled, resulting in high maintenance costs and poor scalability. Furthermore, sorting methods that label field values or use classification functions cannot automatically respond to business changes, such as the launch of new core services and sudden security threats, causing the rule base to quickly become outdated and important new values to be unable to be quickly identified. Summary of the Invention
[0005] This invention provides a method, apparatus, electronic device, storage medium, and program for searching fields based on business information, which can improve the efficiency and accuracy of querying and searching key business field values.
[0006] According to one aspect of the present invention, a field search method based on business information is provided, comprising: In response to a dropdown query list trigger request for the target field, obtain the business data association information of the target field; Calculate the business importance score of each field value of the target field based on the business data association information of the target field; The values of each field in the target field are sorted according to their business importance scores. The drop-down query list of the target field displays the sorting results of the values of each field.
[0007] According to another aspect of the present invention, a field search device based on business information is provided, comprising: The business data association information acquisition module is used to acquire the business data association information of the target field in response to a drop-down query list trigger request of the target field. The business importance score calculation module is used to calculate the business importance score of each field value of the target field based on the business data association information of the target field; The field value sorting module is used to sort the field values of the target field according to the business importance score of each field value of the target field; The field value sorting and display module is used to display the sorting result information of each field value in the drop-down query list of the target field.
[0008] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the field search method based on business information as described in any embodiment of the present invention.
[0009] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the field search method based on business information as described in any embodiment of the present invention.
[0010] According to another aspect of the present invention, a computer program product is also provided, comprising a computer program that, when executed by a processor, implements the field search method based on business information as described in any embodiment of the present invention.
[0011] This invention, in response to a dropdown query list trigger request for a target field, obtains business data association information for the target field. Based on this association information, it calculates the business importance score of each value in the target field. Then, it sorts the values in the target field according to these scores, displaying the sorted results in the dropdown query list. This technical solution uses business importance as the core sorting dimension, enabling rapid location of fields with critical business impact when querying a list of field values. It addresses the problem that existing methods of sorting field values alphabetically or by indiscriminate frequency often fail to quickly locate critically impactful values, thus improving the efficiency and accuracy of searching for key business field values.
[0012] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a flowchart of a field search method based on business information provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of a field search method based on business information provided in Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of a field search device based on business information provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0015] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0016] It should be noted that the terms "first," "second," and "third," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0017] Example 1 Figure 1 This is a flowchart of a field search method based on business information provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where the values of each field are sorted and queried based on the business importance assessment information of the field. This method can be executed by a field search device based on business information. This device can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can execute the field search method based on business information. The present invention does not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations: S110. In response to the drop-down query list trigger request of the target field, obtain the business data association information of the target field.
[0018] The target field can be the field from which the user needs to query a value. The target field is also a field within the target system platform that provides a list of field values for querying. Optionally, the target system platform can be a data management system platform capable of providing field value query and retrieval functions, such as, but not limited to, log management systems, database systems, and device security management systems. Correspondingly, different types of target system platforms may offer different types of fields for querying field values. For example, when the target system platform is a log management platform, the fields included in the dropdown query list could be source IP (Internet Protocol Address), destination IP address, operation type, error code, and host, etc. When the target system platform is a database system platform, the fields included in the dropdown query list could be number, region, and device, etc. Business data association information can be business information related to the target field. The dropdown query list can be a list of all field values corresponding to the target field, and may include all field values of the target field. For example, when the target field is an IP address, its corresponding field value can be detailed IP address information; when the target field is a hostname, its corresponding field value can be detailed hostname or host identifier information; when the target field is a device, its corresponding field value can be detailed device name or device identifier information.
[0019] In professional scenarios such as operations and maintenance, security, and auditing, users often focus on search results for entities highly relevant to business information when querying field values. For example, in a log management system, these highly relevant entities might include host IP addresses (Internet Protocol addresses) with SLA (Service Level Agreement) levels or usernames with sensitive permissions. Because traditional alphabetical or frequency-based sorting methods cannot correlate and sort field values with associated business information, they fail to directly reflect the relationship between field values and business information. Therefore, users struggle to quickly locate entities with critical business impact from a vast amount of field values, requiring manual filtering, which is time-consuming, labor-intensive, and has low accuracy.
[0020] To overcome the limitations of traditional field value sorting methods that only sort by letter or simple frequency, and to better meet the query and search needs of quickly locating field values that have a critical impact on business, this embodiment of the invention introduces a business importance dimension into the field value sorting strategy, and optimizes the sorting of the list of field values that users need to query.
[0021] When a user needs to query the value of a target field in a target system platform, they can select to trigger a drop-down query list for the target field in the current field value query interface of the target system platform. Correspondingly, the target system platform can respond to the drop-down query list trigger request for the target field, obtain the business data association information of the target field, and optimize the sorting method of each field value of the target field based on the business data association information. For example, the business data association information may include, but is not limited to, pre-configured static rule bases, real-time data streams related to field values, and data stored in associated external business systems, as long as it can provide referable business information for the field value query and search process. This embodiment of the invention does not limit the specific information type and content of the business data association information.
[0022] S120. Calculate the business importance score of each field value of the target field based on the business data association information of the target field.
[0023] Among them, the business importance score can assess the importance of field values from the perspective of the degree of business relevance.
[0024] Understandably, target fields may include multi-dimensional business information. For example, there may be business relationships between static rules (such as blacklists) of IP addresses and alarm information, real-time data streams, and external business data. Therefore, to more comprehensively reflect the business relationships of each field value, a business importance score can be calculated for each field value of the target field based on the multi-dimensional business data relationship information. This will allow the calculated business importance score to comprehensively reflect the degree of association between the field value and various related business information.
[0025] For example, business importance scoring can include, but is not limited to, importance scores calculated based on static rule bases, importance scores calculated based on real-time data streams, and importance scores calculated based on externally related knowledge bases. Among these, importance scores calculated based on static rule bases reflect the degree of correlation between field values and static rules. Importance scores calculated based on real-time data streams reflect the degree of correlation between field values and real-time information of concern. For example, real-time information of concern can include, but is not limited to, real-time risk assessment information or other indicator information. Importance scores calculated based on externally related knowledge bases reflect the degree of correlation between field values and external business information. Therefore, by utilizing the business data correlation information of the target field to calculate the business importance score of each field value, it can serve as the analysis result of the business importance of the field value analysis, comprehensively assessing the business importance of each field value of the target field, thereby improving the accuracy of business-critical information assessment.
[0026] S130. Sort the values of each field of the target field according to the business importance score of each field value of the target field.
[0027] Accordingly, after calculating the business importance score of each field value of the target field based on the business data association information of the target field, the field values of the target field can be sorted according to the business importance score. For example, the field values of the target field can be sorted in descending order of business importance score. The higher the business importance score of a field value, the higher the query search value reflected by that field value in the business dimension, and the more quickly a response is required. The lower the business importance score of a field value, the lower the query search value reflected by that field value in the business dimension, and the lower the urgency of its response.
[0028] S140. Display the sorting results of the values of each field in the drop-down query list of the target field.
[0029] After sorting the values of each field in the dropdown list of the target field based on business importance assessment information, the sorted results can be displayed in the dropdown list of the target field. For example, assuming the target field is an IP address, the business importance assessment information can be used to sort the specific IP addresses in the IP address dropdown list, prioritizing and displaying IP addresses on the blacklist for faster user queries and responses. Similarly, assuming the target field is a username, the business importance assessment information can be used to sort the specific usernames in the username dropdown list, prioritizing and displaying usernames with special access permissions for faster user queries and responses.
[0030] Therefore, the above technical solution breaks through the limitations of traditional field value query methods that only sort by letter or simple frequency, by introducing business importance assessment information into the field value sorting strategy. This allows users to directly obtain entity information (such as IPs and users) that has a key impact on the business dimension from the top of the field value list without having to scroll through lengthy lists or make subjective guesses when performing field queries. This greatly improves the efficiency of locating field values with a key impact on the business and the accuracy of analysis, realizing a transformation of field value query methods from passive screening to proactive risk guidance.
[0031] This invention, in response to a dropdown query list trigger request for a target field, obtains business data association information for the target field. Based on this association information, it calculates the business importance score of each value in the target field. Then, it sorts the values in the target field according to these scores, displaying the sorted results in the dropdown query list. This technical solution uses business importance as the core sorting dimension, enabling rapid location of fields with critical business impact when querying a list of field values. It addresses the problem that existing methods of sorting field values alphabetically or by indiscriminate frequency often fail to quickly locate critically impactful values, thus improving the efficiency and accuracy of searching for key business field values.
[0032] Example 2 Figure 2 This is a flowchart of a field search method based on business information provided in Embodiment 2 of the present invention. This embodiment is a specific embodiment based on the above embodiment. In this embodiment, various specific optional implementation methods are given for obtaining business data association information of the target field, calculating the business importance score of each field value of the target field, and sorting the field values of the target field. Correspondingly, as Figure 2 As shown, the method in this embodiment may include: S210. In response to the drop-down query list trigger request of the target field, obtain the context information of the associated fields of the target field.
[0033] Among them, the context information of the associated field can be the context information related to the target field.
[0034] In this embodiment of the invention, when a user needs to query the value of a target field in a target system platform, they can select to trigger a drop-down query list for the target field in the current field value query interface of the target system platform. Correspondingly, the target system platform can respond to the drop-down query list trigger request for the target field, obtain the context information associated with the target field as the associated field context information, and analyze the query intent for the field value based on the associated field context information.
[0035] S220. Generate the current recommended field value sorting strategy for the target field based on the context information of the associated fields of the target field.
[0036] The field value sorting strategy refers to the strategy used to sort the field values. The currently recommended field value sorting strategy is the recommended field value sorting strategy currently provided for the target field.
[0037] Because different users and / or different fields have different query intentions for field values, various optional field value sorting strategies can be provided for different query intentions. For example, field value sorting strategies may include, but are not limited to, default field value sorting strategies, alarm correlation sorting strategies, rarity sorting strategies, time trend pattern sorting strategies, and business importance sorting strategies. The default field value sorting strategy can be an existing, commonly used field value sorting strategy, such as alphabetical sorting or field value frequency sorting. The alarm correlation sorting strategy can be a strategy that sorts field values based on alarm information. The rarity sorting strategy can be a strategy that sorts field values based on information about the rarity of field values. The time trend pattern sorting strategy can be a strategy that sorts field values based on time and distribution pattern information. The business importance sorting strategy can be a strategy that sorts field values based on information about their business relevance. It is understood that different field value sorting strategies emphasize different information dimensions and content when sorting field values.
[0038] Current field value sorting methods are decoupled from the strong contextual information associated with the current field value query scenario, such as the specific analysis task, time range, and query interface information. For example, the "login failed" operation is crucial in a security investigation scenario, but may be irrelevant in a performance analysis scenario. Existing field value sorting methods cannot achieve this kind of dynamic, scenario-based evaluation of field values.
[0039] To achieve context awareness, a strong association is established between the field value sorting method and the specific analysis task, time range, and query interface information associated with the current field value query scenario. When a user queries the field value information of a target field based on the field query interface of the target system platform, after the target system platform detects the drop-down query list of the target field triggering a request, it obtains the multi-dimensional context information associated with the target field as the context information of the associated field of the target field, and generates the current recommended field value sorting strategy of the target field for display based on the context information of the associated field of the target field.
[0040] Optionally, multi-dimensional contextual information may include, but is not limited to, scenario information, query information, field feature information, and query object features. For example, when a user clicks on a dropdown list of a target field in the log query interface, the log management system captures this event and obtains the contextual information of the associated fields of the target field. It can then determine the application scenario for the current field value query based on this contextual information. For instance, if the user is currently in a security alert query interface, the current application scenario is an alert analysis scenario; if they are currently in a compliance audit report visualization interface, the current application scenario is a report analysis scenario; and if they are currently in an application performance monitoring interface, the current application scenario is a performance monitoring scenario. The log management system can also determine the query time range and field type specified in the current query interface, as well as obtain the filtering conditions specified for the target field based on the current interface, such as "Error type = ERROR1". Regarding field feature information, the log management system can parse the semantic type of the target field, such as user identifier, network address, operation type, and resource object. Regarding query object feature information, the log management system can obtain the role of the current querying user, such as a security analyst or operations engineer, and can also obtain the historical behavior information of the current querying user in this scenario.
[0041] Ultimately, the log management system can intelligently determine the current recommended field value sorting strategy (business importance sorting strategy or default field value sorting strategy) based on the aforementioned context information of the related fields, and recommend the current recommended field value sorting strategy to the user. Optionally, the default field value sorting strategy may include, but is not limited to, ascending order sorting strategy and descending order sorting strategy.
[0042] It should be noted that the target system platform can provide an authorization interface to users, prompting them whether they are allowed to access their user roles and record their historical behavior. If the user grants authorization based on the prompt and responds to the target system platform with permission to access their user roles and record their historical behavior, the target system platform can then record the user's historical behavior information and obtain the user's role information for use in the current field value query scenario.
[0043] S230. If it is determined that the business importance ranking strategy in the current recommended field value ranking strategy is triggered, obtain the business data association information of the target field.
[0044] When a user selects to trigger a business importance ranking strategy, the target system platform can retrieve all associated business data information and filter it to include the target field as associated business data information for that target field. Optionally, when the context information of the associated fields of the target field includes other limiting query conditions such as query time range and field type, the target system platform can combine these other limiting query conditions to filter business data information including the target field from the all associated business data information as associated business data information for that target field. For example, the target system platform can query all relevant business data information from the rule base, real-time data stream, and external business systems based on a limited query time range, and filter out business data involving the target field (such as IP address) within the limited query time range as associated business data information for the target field.
[0045] Optionally, business data association information includes static rule bases, real-time log data streams, and external related knowledge bases.
[0046] The static rule base stores pre-configured static rules. These rules are used to match and filter field values to obtain values that conform to specific rules. Real-time log data streams reflect the real-time flow characteristics and status changes of target fields. External knowledge bases can inject rich business semantic attributes into field values.
[0047] The existing field value sorting methods rely solely on manually preset rules or simple frequencies, failing to integrate multi-dimensional information from the associated real-time data stream itself, external authoritative data sources such as external authoritative risk databases, and user behavior feedback to comprehensively and quantitatively assess the business importance of field values. This results in a lack of accurate assessment data on the business importance of field values.
[0048] To address the aforementioned technical issues, this invention provides a comprehensive quantitative assessment of the business importance of field values from multiple dimensions, including self-static rules, real-time log streams, and external knowledge systems. Multiple business importance score calculation pipelines are activated in parallel, with each pipeline responsible for calculating the business importance score of the field values from different sources, ensuring the accuracy of the business importance assessment data for the field values.
[0049] Accordingly, the above method may also include the following operations: S240. Match the values of each field of the target field according to the static rule base of the target field to obtain the first business importance score.
[0050] The first business importance score can be data obtained by assessing the business importance of each field value of the target field based on a static rule base.
[0051] Specifically, one of the calculation pipelines determines the appropriate static rule base for the target field. Understandably, different target field types may result in different static rules stored in their respective static rule bases. Further, this calculation pipeline matches the list of target field values against the pre-configured static rule base to calculate the first business importance score for each field value. Optionally, the first business importance score can be normalized to obtain a score within the 0-1 range.
[0052] In an optional embodiment of the present invention, the step of matching the values of each field of the target field according to the static rule base of the target field to obtain a first business importance score may include: determining the field query scenario of the target field according to the context information of the associated fields of the target field; determining the field query weight of the field query scenario of the target field; obtaining an initial matching result of matching the values of each field of the target field according to the static rule base of the target field; adjusting the initial matching result of matching the values of each field of the target field according to the field query weight of the field query scenario of the target field to obtain the first business importance score.
[0053] Among them, the field query weight can be used to adjust the business importance score obtained based on static rule base matching.
[0054] Considering that the reference value of the first business importance score calculated based on a static rule base varies across different scenarios, context-sensitive rule matching can be introduced when calculating the first business importance score of each field value of the target field. Specifically, the field query scenario of the target field can first be determined based on the context information of its associated fields. For example, the field query scenario can include, but is not limited to, security investigation scenarios, report analysis scenarios, and performance monitoring scenarios. Further, the matching field query weights are determined based on the type of the target field's field query scenario. Then, the values of each field of the target field can be matched based on the static rule base of the target field to obtain an initial matching result, which serves as the initial first business importance score. Further, the initial matching result obtained by matching the values of each field of the target field using the determined field query weights is adjusted to obtain the final processed first business importance score.
[0055] For example, the same rule "IP address belongs to the core network segment" may have a field query weight of 1.0 in a security investigation scenario, but only 0.3 in a performance monitoring scenario. The static rule base supports dynamic activation based on context and dynamic adjustment of field query weights.
[0056] S250. Match the values of each field of the target field according to the real-time log data stream of the target field to obtain a second business importance score.
[0057] The second business importance score can be data obtained by assessing the business importance of each field value of the target field based on the real-time log data stream.
[0058] Specifically, one of the calculation pipelines can also analyze the real-time log data stream within the current query time range of the target field. Using the real-time log data stream within the current query time range of the target field as the data source, it analyzes multiple real-time performance indicators and distribution patterns corresponding to each field value of the target field. Then, based on the analyzed real-time performance indicators and distribution patterns, it comprehensively evaluates and calculates the second business importance score of each field value of the target field. Optionally, the second business importance score can be normalized to obtain a score belonging to the 0-1 range.
[0059] In an optional embodiment of the present invention, the step of matching the values of each field of the target field according to the real-time log data stream of the target field to obtain a second business importance score may include: calculating real-time statistical indicators of each field value of the target field according to the real-time log data stream of the target field, and calculating an indicator correlation score based on the real-time statistical indicators of each field value of the target field; detecting the sudden increase in the value of each field of the target field within a target time window using a sliding window algorithm according to the real-time log data stream of the target field, and calculating a sudden increase score based on the sudden increase in the value of each field value of the target field within the target time window; determining the frequency of occurrence of each field value of the target field in historical distribution information according to the real-time log data stream of the target field, and calculating a pattern scarcity score based on the frequency of occurrence of each field value of the target field in historical distribution information; and performing a weighted calculation of the indicator correlation score, the sudden increase score, and the pattern scarcity score to obtain the second business importance score.
[0060] The real-time statistical metrics can be various metrics that are statistically analyzed in real time for the field values within the current query time range. For example, real-time statistical metrics may include, but are not limited to, at least one of the following: the co-occurrence frequency of target alarm events, resource utilization, failure rate, and real-time energy consumption. The metric correlation score can be a score calculated based on the real-time statistical metrics for each field value of the target field. The surge magnitude score can be used to assess the surge in field values within a certain time window. The pattern scarcity score can be used to assess the frequency of occurrence within the current query time range.
[0061] Specifically, when calculating the second business importance score for each field value of the target field, real-time statistical indicators corresponding to each field value of the target field can be statistically analyzed based on the real-time log data stream of the target field. It is understandable that different types of target fields will result in different types and numbers of real-time statistical indicators corresponding to their field values. Different numbers of real-time statistical indicators will lead to different methods for calculating the indicator correlation score. For example, if the target field is a device, real-time statistical indicators such as resource utilization, failure rate, and real-time energy consumption corresponding to each device can be statistically analyzed based on the device's real-time log data stream. Multiple indicator scores are then calculated based on these multiple real-time statistical indicators, and a weighted average is applied to obtain the final indicator correlation score. These indicator scores can include: a resource utilization score calculated based on resource utilization (the lower the resource utilization, the higher the score); a failure rate score calculated based on failure rate (the higher the failure rate, the higher the score); and an energy consumption score calculated based on real-time energy consumption (the higher the real-time energy consumption, the higher the score). If the target field is an IP address, the co-occurrence frequency of each specific IP address and the target alarm event can be statistically analyzed based on the real-time log data stream of the IP address. For example, the target alarm event could be a high-level alarm event. Furthermore, an alarm correlation score can be calculated based on the co-occurrence frequency of each value of the target field and the target alarm event. This alarm correlation score is used to assess the correlation density between the field value and the target alarm event and is directly used as the indicator correlation score. The higher the co-occurrence frequency of the field value and the target alarm event, the higher the alarm correlation score, i.e., the higher the indicator correlation score.
[0062] Specifically, when calculating the second business importance score for each value of the target field, the surge in the values of each target field can also be assessed based on the real-time log data stream of the target field. First, the current query time range can be divided into multiple time windows, and a time window requiring focused attention, such as the most recent time window, can be selected as the target time window. This target time window can be a partial or complete time window. Further, a sliding window algorithm can be used to analyze the real-time log data stream of the target field within the current query time range to calculate the surge magnitude of each value of the target field within the target time window. This determines whether a significant surge in field values occurs within the target time window, and a surge magnitude score is calculated based on the surge magnitude of each value of the target field within the target time window. The higher the surge magnitude, the higher the calculated surge magnitude score.
[0063] Specifically, when calculating the second business importance score for each value of the target field, the scarcity of each value can also be assessed based on the real-time log data stream of the target field. First, the frequency of each value in the historical distribution information of the target field can be analyzed based on the real-time log data stream. Then, a pattern scarcity score can be calculated based on the frequency of each value in the historical distribution information. The pattern scarcity score can assign higher novelty or scarcity scores to field values that are newly appearing in the current query or have extremely low frequency (e.g., below 1% of the historical baseline) to identify potential risks.
[0064] After calculating the indicator correlation score, surge magnitude score, and pattern scarcity score, a weighted average can be applied to these scores based on the weights corresponding to each dimension to obtain the second business importance score. Optionally, the weights corresponding to each dimension score can be dynamically configured based on the field query scenario of the target field; this embodiment of the invention does not impose any limitations on this.
[0065] S260. Match the values of each field of the target field according to the external related knowledge base of the target field to obtain the third business importance score.
[0066] The third business importance score can be data obtained by assessing the business importance of each field value of the target field based on an external knowledge base.
[0067] Specifically, one of the calculation pipelines can also collaborate with external business systems to analyze the business semantic attributes corresponding to each field value of the target field, in order to obtain semantic information about the core characteristics or properties of the business entity. Then, based on the comprehensive evaluation of the business semantic attributes corresponding to each field value, a third business importance score for each field value of the target field is calculated. Optionally, the third business importance score can be normalized to obtain a score within the 0-1 range.
[0068] In an optional embodiment of the present invention, the step of matching the values of each field of the target field according to the external associated knowledge base of the target field to obtain a third business importance score may include: matching the values of each field of the target field according to the management data information of the target field to obtain a management attribute score; matching the values of each field of the target field according to the risk record information of the target field to obtain a risk attribute score; matching the values of each field of the target field according to the human resources information of the target field to obtain a human resources attribute score; and performing a weighted calculation on the management attribute score, the risk attribute score, and the human resources attribute score to obtain the third business importance score.
[0069] Specifically, the management attribute score can be used to assess the importance of each field value of the target field in the management dimension based on external management data. The risk attribute score can be used to assess the importance of each field value of the target field in the risk control dimension based on external risk record data. The human resources attribute score can be used to assess the importance of each field value of the target field in the human resources management dimension based on human resources data.
[0070] Optionally, a third business importance score can also be calculated for each field value of the target field from multiple dimensions. Specifically, when the external knowledge base associated with the target field includes a management database, the field values of the target field can be matched based on the management data information of the target field to obtain a management attribute score. For example, the configuration management database can be queried via API (Application Programming Interface) to obtain information such as the "business system" type, "service level agreement (SLA)", and "responsible person" corresponding to the field value (e.g., host IP). The more important the "business system" type corresponding to the field value, the higher its management attribute score; the higher the SLA level corresponding to the field value, the higher its management attribute score; the higher the "responsible person" level corresponding to the field value, the higher its management attribute score. If multiple management attribute scores from different dimensions are involved, the management attribute scores of each dimension can be weighted and calculated to obtain the final management attribute score. When the external knowledge base associated with the target field includes a threat intelligence database, the field values of the target field can be matched based on the risk record information of the target field stored in the threat intelligence database to obtain a risk attribute score. For example, a threat intelligence database can be queried to check if an IP address or username appears in a malicious IP list or a leaked credential database. If so, its risk attribute score is significantly improved. When the external knowledge base associated with the target field includes a human resources system, the values of each field in the target field can be matched based on the human resources information of the target field to obtain a human resources attribute score. For example, if the target field is a user, the human resources system can be queried to determine whether the user belongs to a sensitive role such as "administrator group" or "finance department," and to determine the user's permission information. The higher the sensitivity and / or permissions of the user's role, the higher its human resources attribute score.
[0071] Finally, the management attribute score, risk attribute score, and human resource attribute score are weighted and calculated to obtain the third business importance score. Similarly, the weights corresponding to the management attribute score, risk attribute score, and human resource attribute score can be dynamically configured according to the field query scenario of the target field, and this embodiment of the invention does not limit this.
[0072] S270. Dynamically determine the weights of the static rule base, the real-time log data stream, and the external associated knowledge base.
[0073] Optionally, a lightweight decision model, such as a rule-based or simple neural network, can be used to output a weight vector of a static rule base, a real-time log data stream, and an externally related knowledge base, based on the context. Where W_rule represents the weight of the static rule base, W_realtime represents the weight of the real-time log data stream, and W_knowledge represents the weight of the external associated knowledge base. For example, in an emergency response scenario, W_realtime has the highest weight; in a compliance preparation scenario, W_rule and W_knowledge have the highest weights.
[0074] S280. Based on the weights of the static rule base, the real-time log data stream, and the external associated knowledge base, the first business importance score, the second business importance score, and the third business importance score are weighted and calculated to obtain the business importance score of each field value of the target field.
[0075] Finally, based on the dynamically determined weights of the static rule base, real-time log data stream, and external related knowledge base, the first business importance score, the second business importance score, and the third business importance score are weighted and calculated to obtain the business importance score of each field value of the target field.
[0076] S290. Sort the values of each field of the target field according to the business importance score of each field value, and display the sorting result information of each field value in the drop-down query list of the target field.
[0077] In an optional embodiment of the present invention, sorting the field values of the target field according to the multidimensional alarm correlation score of each field value of the target field may include: sorting the field values of the target field in descending order according to the business importance score of each field value of the target field; and sorting each target field value according to field identification information when it is determined that the multidimensional alarm correlation scores of multiple target field values are the same.
[0078] The target field value can be multiple field values with the same business importance score.
[0079] When sorting the values of a target field based on their business importance scores, if the scores are different, the values can be sorted in descending order of importance. If multiple target field values have the same score, they can be further sorted by field identifier information, in addition to the initial sorting by score. For example, the target field values can be sorted alphabetically in descending or ascending order. This embodiment of the invention does not limit the secondary sorting method for the target field values. The advantage of this setup is that the values are first sorted in descending order based on their calculated business importance scores, placing the field value with the highest business importance at the top of the drop-down list. For field values with the same or similar business importance scores, a secondary sorting using traditional ascending or descending alphabetical order can be applied, ensuring a clear and orderly drop-down list.
[0080] To further improve the efficiency of querying field values, the dropdown query list can not only display sorted field values, but also display different colors or corresponding icon markers next to the field values based on the score range corresponding to the business importance score. For example, red indicates key field values, yellow indicates important field values, and green indicates ordinary field values. Alternatively, the target system platform can automatically generate explanatory labels for field values, such as "Core Service (SLA1)," "Associated with 3 High-Risk Alerts," and "Added Suspicious IP," which are directly displayed next to the dropdown field values. When the mouse hovers over a corresponding field value, the target system platform can also respond to the hover operation by displaying a brief analysis of the business importance score composition of the corresponding field value, such as "Rule Score: 0.8, Real-Time Score: 0.9, External Knowledge Score: 0.6."
[0081] Simultaneously, an authorization interface can be provided to users, allowing them to provide feedback on the field value sorting results, such as "This sorting is helpful," enabling the target system platform to achieve interaction and iterative learning. With user authorization, the target system platform can also record user preferences for field values to optimize subsequent field value sorting strategies. Specifically, the target system platform can provide an authorization interface to prompt users whether they wish to record field value selection preferences. If a user grants authorization based on this prompt and provides feedback to the target system platform allowing the recording of field value selection preferences, the platform can record the user's field value selection preferences. For example, if a user frequently skips top-ranked options with a single, high-scoring rule (e.g., high rule score) and selects lower-ranked options with high real-time scores, the target system platform will automatically fine-tune the weight of W_realtime in the weight decision model within similar contexts. For field values frequently selected by users but not covered by any static rules, the target system platform can prompt the administrator with "It is recommended to add a business rule for value [XXX]." For new field values, when historical data is lacking, external knowledge scoring and static rule matching are used first to assess business importance. This avoids situations where the business importance score is zero or the default value is not covered by the static rule library, preventing the field from being discovered first in critical scenarios and helping it to quickly get through the cold start phase.
[0082] The above technical solution provides a field search method based on alarm information. Upon responding to a dropdown query list trigger request for a target field, this method obtains the context information of related fields of the target field. Based on this context information, it generates a current recommended field value ranking strategy for the target field. If the alarm correlation ranking strategy within the current recommended field value ranking strategy is triggered, it filters alarm information including the target field from the full alarm information to obtain the alarm field correlation information for the target field. Further, based on the alarm field correlation information, it calculates the alarm frequency score, alarm severity score, and time decay score for each field value of the target field. This is then weighted to obtain a multi-dimensional alarm correlation score for each field value of the target field. After obtaining the multi-dimensional alarm correlation scores for each field value of the target field, the field values of the target field can be ranked according to these scores, and the ranking results are displayed in the dropdown query list of the target field. The above-mentioned field search method based on alarm information can effectively improve the efficiency and accuracy of querying and searching abnormal field values.
[0083] This invention constructs a dynamic, intelligent, and learnable business importance assessment framework. It not only relies on static rules but also emphasizes dynamically perceiving the context during queries and integrating multi-source information to perform real-time calculation and ranking of field value business importance assessment results. This business information-based field search method achieves a transformation from static to dynamic intelligence. Through context awareness and multi-source real-time calculation, it ensures that business importance assessment closely aligns with the specific context of each field value query, significantly improving accuracy. Simultaneously, this business information-based field search method overcomes the limitations of relying solely on manual rules or simple frequency. By integrating information from three dimensions—static rules, real-time data, and external knowledge—it constructs a more comprehensive and reliable business importance assessment model with broader coverage, mitigating the cold start problem. Furthermore, this business information-based field search method possesses adaptive evolution capabilities. By introducing a feedback learning loop, it can continuously learn from user behavior, optimize scoring strategies, and possess self-evolution capabilities, reducing long-term maintenance costs. The field ranking results provided by the business information-based field search method are interpretable and interactive. They not only provide the ranking results of field values but also reveal the logic behind the field value ranking (such as scoring composition and key tags), enhancing user trust. Meanwhile, user interaction behavior, in turn, trains the system, forming a virtuous cycle. The above technical solution integrates various mechanisms such as temporal surge detection, context-sensitive rule matching, and dynamic weight decision-making, upgrading simple business rule matching into a complex event processing and decision-making system, significantly improving the accuracy and intelligence of field value queries.
[0084] It should be noted that, Figure 2 This is merely a schematic diagram of one implementation method. There is no sequential relationship between steps S240 and S260. Step S240 can be implemented first, followed by step S250, and finally S260. Alternatively, step S260 can be implemented first, followed by step S250, and finally S240. All three can also be implemented simultaneously in parallel.
[0085] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) disclosed herein are information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of such data comply with the relevant laws, regulations, and standards of the relevant regions. Furthermore, users may be provided with corresponding access points to choose whether to agree to or reject the automated decision-making results; if the user chooses to reject, the process will proceed to the expert decision-making stage.
[0086] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.
[0087] Example 3 Figure 3 This is a schematic diagram of a field search device based on business information provided in Embodiment 3 of the present invention, as shown below. Figure 3 As shown, the device includes: a business data association information acquisition module 310, a business importance score calculation module 320, a field value sorting module 330, and a field value sorting display module 340, wherein: The business data association information acquisition module 310 is used to acquire the business data association information of the target field in response to a drop-down query list trigger request of the target field. The business importance score calculation module 320 is used to calculate the business importance score of each field value of the target field based on the business data association information of the target field; The field value sorting module 330 is used to sort the field values of the target field according to the business importance score of each field value of the target field; The field value sorting and display module 340 is used to display the sorting result information of each field value in the drop-down query list of the target field.
[0088] This invention, in response to a dropdown query list trigger request for a target field, obtains business data association information for the target field. Based on this association information, it calculates the business importance score of each value in the target field. Then, it sorts the values in the target field according to these scores, displaying the sorted results in the dropdown query list. This technical solution uses business importance as the core sorting dimension, enabling rapid location of fields with critical business impact when querying a list of field values. It addresses the problem that existing methods of sorting field values alphabetically or by indiscriminate frequency often fail to quickly locate critically impactful values, thus improving the efficiency and accuracy of searching for key business field values.
[0089] Optionally, the business data association information acquisition module 310 is further configured to: in response to a drop-down query list trigger request of the target field, acquire the associated field context information of the target field; generate a current recommended field value sorting strategy for the target field based on the associated field context information of the target field; and acquire the business data association information of the target field when it is determined that the business importance sorting strategy in the current recommended field value sorting strategy is triggered.
[0090] Optionally, the business data association information includes a static rule base, a real-time log data stream, and an external association knowledge base. The business importance score calculation module 320 is further configured to: match the values of each field of the target field according to the static rule base of the target field to obtain a first business importance score; match the values of each field of the target field according to the real-time log data stream of the target field to obtain a second business importance score; match the values of each field of the target field according to the external association knowledge base of the target field to obtain a third business importance score; dynamically determine the weights of the static rule base, the real-time log data stream, and the external association knowledge base; and perform a weighted calculation on the first business importance score, the second business importance score, and the third business importance score according to the weights of the static rule base, the real-time log data stream, and the external association knowledge base to obtain the business importance score of each field value of the target field.
[0091] Optionally, the business importance score calculation module 320 is further configured to: determine the field query scenario of the target field based on the context information of the associated fields of the target field; determine the field query weight of the field query scenario of the target field; obtain the initial matching result of matching each field value of the target field according to the static rule base of the target field; adjust the initial matching result of matching each field value of the target field according to the field query weight of the field query scenario of the target field to obtain the first business importance score.
[0092] Optionally, the business importance score calculation module 320 is further configured to: statistically analyze real-time indicators of each field value of the target field based on the real-time log data stream of the target field, and calculate an indicator correlation score based on the real-time statistical indicators of each field value of the target field; detect the sudden increase in the value of each field value of the target field within a target time window using a sliding window algorithm based on the real-time log data stream of the target field, and calculate a sudden increase score based on the sudden increase in the value of each field value of the target field within the target time window; determine the frequency of occurrence of each field value of the target field in historical distribution information based on the real-time log data stream of the target field, and calculate a pattern scarcity score based on the frequency of occurrence of each field value of the target field in historical distribution information; and perform a weighted calculation on the indicator correlation score, the sudden increase score, and the pattern scarcity score to obtain the second business importance score.
[0093] Optionally, the business importance score calculation module 320 is further configured to: match the values of each field of the target field with the management data information of the target field to obtain a management attribute score; match the values of each field of the target field with the risk record information of the target field to obtain a risk attribute score; match the values of each field of the target field with the human resources information of the target field to obtain a human resources attribute score; and perform a weighted calculation on the management attribute score, the risk attribute score, and the human resources attribute score to obtain the third business importance score.
[0094] Optionally, the field value sorting module 330 is further configured to: sort the field values of the target field in descending order according to the business importance score of each field value of the target field; and sort the target field values according to the field identification information when it is determined that the multidimensional alarm correlation scores of multiple target field values are the same.
[0095] The above-described field search device based on business information can execute the field search method based on business information provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method. Technical details not described in detail in this embodiment can be found in the field search method based on business information provided in any embodiment of the present invention.
[0096] Since the above-described field search device based on business information is an apparatus capable of executing the field search method based on business information in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the field search device based on business information in this embodiment based on the field search method based on business information described in the embodiments of the present invention. Therefore, how the field search device based on business information implements the field search method based on business information in the embodiments of the present invention will not be described in detail here. Any apparatus used by those skilled in the art to implement the field search method based on business information in the embodiments of the present invention falls within the scope of protection of this application.
[0097] Example 4 Figure 4A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0098] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0099] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0100] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as field search methods based on business information.
[0101] Optionally, the field search method based on business information may include: in response to a drop-down query list trigger request for a target field, obtaining business data association information of the target field; calculating the business importance score of each field value of the target field based on the business data association information of the target field; sorting each field value of the target field based on the business importance score of each field value of the target field; and displaying the sorting result information of each field value in the drop-down query list of the target field.
[0102] In some embodiments, the business information-based field search method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the business information-based field search method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the business information-based field search method by any other suitable means (e.g., by means of firmware).
[0103] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0104] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0105] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0106] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0107] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0108] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0109] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0110] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A field search method based on business information, characterized in that, include: In response to a dropdown query list trigger request for the target field, obtain the business data association information of the target field; Calculate the business importance score of each field value of the target field based on the business data association information of the target field; The values of each field in the target field are sorted according to their business importance scores. The drop-down query list of the target field displays the sorting results of the values of each field.
2. The method according to claim 1, characterized in that, The process of responding to a dropdown query list trigger request for the target field and obtaining the business data association information of the target field includes: In response to a dropdown query list trigger request for the target field, obtain the context information of the associated fields of the target field; The current recommended field value sorting strategy for the target field is generated based on the context information of the associated fields of the target field; If it is determined that the business importance ranking strategy in the current recommended field value ranking strategy has been triggered, the business data association information of the target field is obtained.
3. The method according to claim 1, characterized in that, The business data association information includes a static rule base, real-time log data streams, and an external association knowledge base. The step of calculating the business importance score of each field value of the target field based on the business data association information of the target field includes: The values of each field of the target field are matched according to the static rule base of the target field to obtain the first business importance score; The values of each field of the target field are matched based on the real-time log data stream of the target field to obtain a second business importance score; The values of each field of the target field are matched with the external related knowledge base of the target field to obtain a third business importance score; The weights of the static rule base, the real-time log data stream, and the external associated knowledge base are dynamically determined; Based on the weights of the static rule base, the real-time log data stream, and the external associated knowledge base, the first business importance score, the second business importance score, and the third business importance score are weighted and calculated to obtain the business importance score of each field value of the target field.
4. The method according to claim 3, characterized in that, The step of matching the values of each field of the target field according to the static rule base of the target field to obtain the first business importance score includes: The field query scenario for the target field is determined based on the context information of the associated fields of the target field; Determine the field query weight for the target field in the field query scenario; Obtain the initial matching results by matching the values of each field of the target field according to the static rule base of the target field; The initial matching results of matching each field value of the target field according to the field query weight of the field query scenario of the target field are adjusted to obtain the first business importance score.
5. The method according to claim 3, characterized in that, The step of matching the values of each field of the target field according to the real-time log data stream of the target field to obtain a second business importance score includes: Based on the real-time log data stream of the target field, the real-time statistical indicators of each field value of the target field are statistically analyzed, and the indicator correlation score is calculated based on the real-time statistical indicators of each field value of the target field. Based on the real-time log data stream of the target field, a sliding window algorithm is used to detect the sudden increase in the value of each field of the target field within the target time window, and a sudden increase score is calculated based on the sudden increase in the value of each field of the target field within the target time window. The frequency of occurrence of each field value of the target field in the historical distribution information is determined based on the real-time log data stream of the target field, and the pattern scarcity score is calculated based on the frequency of occurrence of each field value of the target field in the historical distribution information. The second business importance score is obtained by weighting the correlation score of the indicator, the surge magnitude score, and the pattern scarcity score.
6. The method according to claim 3, characterized in that, The step of matching the values of each field of the target field with the external related knowledge base of the target field to obtain a third business importance score includes: The management attribute score is obtained by matching the values of each field of the target field with the management data information of the target field. The risk attribute score is obtained by matching the values of each field of the target field with the risk record information of the target field. The human resources attribute scores are obtained by matching the values of each field in the target field with the human resources information in the target field. The third business importance score is obtained by weighting the management attribute score, the risk attribute score, and the human resources attribute score.
7. A field search device based on business information, characterized in that, include: The business data association information acquisition module is used to acquire the business data association information of the target field in response to a drop-down query list trigger request of the target field. The business importance score calculation module is used to calculate the business importance score of each field value of the target field based on the business data association information of the target field; The field value sorting module is used to sort the field values of the target field according to the business importance score of each field value of the target field; The field value sorting and display module is used to display the sorting result information of each field value in the drop-down query list of the target field.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor, such that the at least one processor is able to perform the field search method based on business information as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the field search method based on business information as described in any one of claims 1-6.
10. A computer program product, characterized in that, It includes a computer program / instruction, wherein the computer program / instruction, when executed by a processor, implements the field search method based on business information as described in any one of claims 1-6.