Label obtaining method, device and electronic device
By utilizing the information of alarm events and pre-established label class dependencies, combined with the streaming computing framework, the problem of lack of label acquisition methods in the alarm system is solved, and the classification and efficient processing of alarm events are achieved.
Patent Information
- Application Number
- CN201711434367.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2017-12-26
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2037-12-26
AI Technical Summary
Existing alarm systems lack effective methods to obtain labels for alarm events, resulting in the inability to classify alarm events.
The label of the alarm event is obtained through the dependency relationship between the target alarm event information and the pre-established label class, and a streaming computing framework such as the Flink framework is used to perform real-time calculation and classification of the label.
It achieves effective classification of alarm events, provides a basis for subsequent alarm subscription, aggregation and analysis, and improves processing efficiency and accuracy.
Smart Images

Figure CN108171265B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of alarm technology, and in particular to a tag acquisition method, device and electronic equipment. Background Art
[0002] An alarm system processes received alarm events. Specifically, it sends alarm event information to operations and maintenance personnel. With the increasing number of alarms and growing user demands, the alarm system needs to implement various functions, such as alarm subscription, alarm aggregation, and analysis. A prerequisite for implementing these functions is the classification of alarm events. Classifying alarm events involves adding tags to the alarm events and using these tags to categorize them. An alarm event can have multiple tags, allowing for classification across different dimensions. For example, alarm event 1 has three tags: Project A, Cluster B, and Zabbix. Classifying the alarm event based on the Project dimension means that the alarm event belongs to Project A. Classifying the alarm event based on the Cluster dimension means that the alarm event belongs to Cluster B. Classifying the alarm event based on the Data Source dimension means that the alarm event belongs to Zabbix. Project, Cluster, and Data Source are all tag classes. Zabbix is an enterprise-class, open-source solution that provides distributed system and network monitoring capabilities based on a Web (World Wide Web) interface.
[0003] However, in the process of implementing the present invention, the inventors found that the existing technology has at least the following problems: to classify alarm events, it is necessary to first obtain the labels of the alarm events, but there is no method to obtain the labels of alarm events in the existing alarm system, and thus the alarm events cannot be classified by labels. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a tag acquisition method, device, and electronic device to classify alarm events. The specific technical solution is as follows:
[0005] In one aspect of the present invention, in order to achieve the above-mentioned purpose, an embodiment of the present invention provides a label acquisition method, the method comprising:
[0006] Obtaining a target alarm event, wherein the target alarm event includes target information;
[0007] Based on the dependency relationship between the target information and the pre-established tag class, the tag of the target alarm event is obtained, wherein one tag corresponds to one tag class, and one dependency relationship includes a first tag class and a second tag class. The acquisition of the tag corresponding to the first tag class depends on the tag corresponding to the second tag class. The first tag class is the tag class in a dependent position in the dependency relationship, and the second tag class is the tag class in a dependent position in the dependency relationship.
[0008] Optionally, obtaining the label of the target alarm event based on the dependency relationship between the target information and a pre-established label class includes:
[0009] Based on the target information, obtaining a target tag of the target alarm event, wherein the tag class corresponding to the target tag is not the first tag class in each of the dependency relationships;
[0010] For each first tag class in the pre-established dependency relationship between tag classes, when the dependent tags of the first tag class have been obtained, the tag of the target alarm event corresponding to the first tag class is obtained based on the dependent tags of the first tag class, wherein the dependent tag is the tag of the target alarm event corresponding to the second tag class that has a dependency relationship with the first tag class.
[0011] Optionally, obtaining a target tag of the target alarm event based on the target information includes:
[0012] Using the target information as the target label of the target alarm event;
[0013] or
[0014] According to the association relationship between the tag corresponding to the preset reference tag class and the information, the tag associated with the target information is used as the target tag of the target alarm event, wherein the reference tag class is the tag class corresponding to the target tag.
[0015] Optionally, obtaining the label of the target alarm event corresponding to the first label class based on the dependent label of the first label class includes:
[0016] Based on the dependent tag of the first tag class, calling a predetermined external program interface to obtain the tag of the target alarm event corresponding to the first tag class;
[0017] or
[0018] The label of the target alarm event corresponding to the first label class is obtained according to the preset association relationship between the dependent label of the first label class and the label corresponding to the first label class.
[0019] Optionally, obtaining a target tag of the target alarm event based on the target information includes:
[0020] The target information is used as input of a preset stream computing framework to obtain a target label of the target alarm event; wherein the stream computing framework outputs the target label according to the target information;
[0021] For each first tag class in the pre-established dependency relationship between tag classes, obtaining a tag corresponding to the second tag class based on the dependency tags of the first tag class when the dependency tags of the first tag class have been obtained includes:
[0022] The target tag is used as the input of the streaming computing framework to obtain the tag of the target alarm event other than the target tag; wherein, the streaming computing framework uses the target and a preset tag class topology structure to output the tag of the target alarm event other than the target tag, and the tag class topology structure is generated based on the dependency relationship between pre-established tag classes.
[0023] Optionally, the streaming computing framework is the Flink streaming computing framework.
[0024] Optionally, after obtaining the label of the target alarm event based on the dependency relationship between the target information and the pre-established label class, the method includes:
[0025] Determine whether the tag corresponding to the obtained tag is a tag in the pre-recorded association relationship between the user and the tag;
[0026] If yes, determine the user associated with the tag in the association relationship;
[0027] The target alarm event is sent to the determined user.
[0028] In another aspect of the present invention, in order to achieve the above-mentioned purpose, an embodiment of the present invention further provides a label obtaining device, the device comprising:
[0029] A first obtaining module is used to obtain a target alarm event, wherein the target alarm event includes target information;
[0030] The second acquisition module is used to obtain the label of the target alarm event based on the dependency relationship between the target information and the pre-established label class, wherein one label corresponds to one label class, and one dependency relationship includes a first label class and a second label class. The acquisition of the label corresponding to the first label class depends on the label corresponding to the second label class. The first label class is the label class in a dependent position in the dependency relationship, and the second label class is the label class in a dependent position in the dependency relationship.
[0031] Optionally, the second obtaining module includes:
[0032] A first obtaining submodule is configured to obtain a target tag of the target alarm event based on the target information, wherein the tag class corresponding to the target tag is not the first tag class in each of the dependency relationships;
[0033] The second acquisition submodule is used to obtain, for each first tag class in the dependency relationship between pre-established tag classes, the label of the target alarm event corresponding to the first tag class based on the dependency label of the first tag class, when the dependency label of the first tag class has been obtained, wherein the dependency label is the label of the target alarm event corresponding to the second tag class that has a dependency relationship with the first tag class.
[0034] Optionally, the first obtaining submodule is specifically configured to:
[0035] Using the target information as the target label of the target alarm event;
[0036] or
[0037] According to the association relationship between the tag corresponding to the preset reference tag class and the information, the tag associated with the target information is used as the target tag of the target alarm event, wherein the reference tag class is the tag class corresponding to the target tag.
[0038] Optionally, the second obtaining submodule is specifically configured to:
[0039] Based on the dependent tag of the first tag class, a predetermined external program interface is called to obtain the tag of the target alarm event corresponding to the second tag class;
[0040] or
[0041] According to the preset association relationship between the dependent tag of the first tag class and the tag corresponding to the second tag class, the tag of the target alarm event corresponding to the second tag class is obtained.
[0042] Optionally, the first obtaining submodule is specifically configured to:
[0043] The target information is used as input of a preset stream computing framework to obtain a target label of the target alarm event; wherein the stream computing framework outputs the target label according to the target information;
[0044] The second obtaining submodule is specifically used to:
[0045] The target tag is used as the input of the streaming computing framework to obtain the tag of the target alarm event other than the target tag; wherein, the streaming computing framework uses the target and a preset tag class topology structure to output the tag of the target alarm event other than the target tag, and the tag class topology structure is generated based on the dependency relationship between pre-established tag classes.
[0046] Optionally, the streaming computing framework is the Flink streaming computing framework.
[0047] Optionally, the device includes:
[0048] A judging module, configured to judge whether the obtained tags contain tags in a pre-recorded association relationship between users and tags;
[0049] a determination module, configured to determine the user associated with the tag in the association relationship if the determination result of the determination module is yes;
[0050] The sending module is used to send the target alarm event to the determined user.
[0051] In another aspect of the present invention, an electronic device is provided, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0052] Memory for storing computer programs;
[0053] The processor is configured to implement any of the above-mentioned label obtaining methods when executing the program stored in the memory.
[0054] In another aspect of the present invention, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium. When the computer-readable storage medium is run on a computer, the computer executes any of the above-mentioned label obtaining methods.
[0055] In another aspect of the implementation of the present invention, an embodiment of the present invention further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any of the above-mentioned label obtaining methods.
[0056] The label acquisition method, apparatus, and electronic device provided by the embodiments of the present invention can obtain labels for alarm events by using the dependency relationship between the information carried by the alarm event and pre-established label classes, thereby achieving classification of the alarm events. Of course, any product or method implementing the present invention does not necessarily need to simultaneously achieve all of the advantages described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for describing the embodiments or the prior art.
[0058] Figure 1 A first flow chart of a label acquisition method is provided for an embodiment of the present invention;
[0059] Figure 2 A second flow chart of a label acquisition method is provided for an embodiment of the present invention;
[0060] Figure 3 A third flow chart of a label acquisition method is provided for an embodiment of the present invention;
[0061] Figure 4 A schematic diagram of a tag-based topology structure generated in an embodiment of the present invention;
[0062] Figure 5 A fourth flow chart of a label acquisition method is provided for an embodiment of the present invention;
[0063] Figure 6 A schematic diagram of the structure of a label obtaining device is provided for an embodiment of the present invention;
[0064] Figure 7 A structural diagram of an electronic device is provided for an embodiment of the present invention. DETAILED DESCRIPTION
[0065] The technical solutions in the embodiments of the present invention will be described below with reference to the accompanying drawings in the embodiments of the present invention.
[0066] To address the problems of the prior art, embodiments of the present invention provide a label acquisition method, device, and electronic device. These methods can obtain labels for alarm events based on the dependency between the information carried by the alarm event and pre-established label classes, thereby enabling classification of the alarm events. This provides the necessary preparation for implementing various functions such as alarm subscription, alarm aggregation, and analysis. The label acquisition method provided by embodiments of the present invention will be first described below.
[0067] The tag acquisition method provided in the embodiment of the present invention can be applied to an alarm system. Furthermore, the alarm system is an alarm system that processes alarm events according to tags. Specifically, the alarm system can be an alarm system of a cloud platform-service cloud.
[0068] Figure 1 A first flowchart of a label acquisition method is provided for an embodiment of the present invention. The method includes:
[0069] S101: Obtain a target alarm event, wherein the target alarm event includes target information.
[0070] The target alarm event is the alarm event that needs to be tagged. This target alarm event can be obtained from the alarm system itself. Specifically, it can be pulled from a message queue. The message queue can be Kafka. Kafka is a distributed, partitionable, redundant, and persistent log service primarily used for processing active streaming data. Target alarm events can also be obtained from other systems.
[0071] Target information is the information carried by the target alarm event. For example, target information can include alarm indicators and information about the server that generated the alarm. Alarm indicators are indicators of the server's alarm, such as CPU (Central Processing Unit), memory, disk, etc.
[0072] S102: Based on the dependency relationship between the target information and the pre-established tag class, obtain the tag of the target alarm event, wherein one tag corresponds to one tag class, and one dependency relationship includes a first tag class and a second tag class. The acquisition of the tag corresponding to the first tag class depends on the tag corresponding to the second tag class. The first tag class is the tag class in a dependent position in the dependency relationship, and the second tag class is the tag class in a dependent position in the dependency relationship.
[0073] Tags are used to identify the classification or content of a target. In this embodiment of the present invention, the target is the target alarm event. Each tag corresponds to a tag class, but a tag class can correspond to many tags. A tag class refers to the type of tag to which a tag corresponds. For example, the tag "Cluster A" corresponds to the tag class "Cluster," and the tag "192.168.45.9" corresponds to the tag class "IP (Internet Protocol) address."
[0074] The dependency relationship between tag classes is pre-defined and established based on the relationship between tag classes. A dependency relationship includes a first tag class and a second tag class. To obtain the tag corresponding to the first tag class of the alarm event, one must rely on the tag corresponding to the second tag class of the alarm event obtained previously. For example, one tag class is a cluster, and the other tag class is an IP address. Only by knowing the IP address of the server can we determine which cluster the server belongs to. In the pre-established dependency relationship between the cluster and the IP address, the cluster is in a dependent position and is the first tag class, and the IP address is in a dependent address and is the second tag class. It should be noted that dependence and dependence are relative, not absolute. A tag class is in a dependent position in one dependency relationship, that is, the first tag class, and can also be in a dependent address in another dependency relationship, that is, the second tag class.
[0075] In a dependency relationship, the first tag class can have only one tag class or multiple tag classes. In the case of multiple tag classes, it means that after obtaining the tag corresponding to the second tag class in the dependency relationship, the tags corresponding to the tag classes contained in the first tag class can be obtained based on the tags corresponding to the obtained second tag class, that is, multiple tags of the alarm event can be obtained. For example, in dependency relationship A, the first tag class includes the host name and MAC (Media Access Control) address, and the second tag class is the IP address. After obtaining the server's IP address tag, the server's host name and MAC address can be determined based on the server's IP address.
[0076] In a dependency relationship, the second tag class can have only one tag class or multiple tag classes. When it contains multiple tag classes, it means that the tag corresponding to each tag class in the second tag class in the dependency relationship needs to be obtained in order to obtain the tag corresponding to the first tag class in the dependency relationship.
[0077] In all dependency relationships, there must be a tag class that is only in a dependent position, not in a dependent position in any dependency relationship. The acquisition of the tag corresponding to this tag class depends on the target information. After determining a tag based on the target information, other tags for the target alarm event can be determined based on the determined tag and pre-established dependency relationships.
[0078] For an alarm event, it is possible to obtain the label corresponding to each label class in the established dependency relationship, or it is possible to obtain the labels corresponding to some label classes in the established dependency relationship. Specifically, the number of labels that can be obtained for an alarm event is determined by the alarm event.
[0079] The tag acquisition method provided in the embodiment of the present invention can be run in the alarm system in the form of a plug-in.
[0080] In the embodiment of the present invention, the label of the target event is obtained through the dependency relationship between the target information contained in the target alarm event and the pre-established label class, thereby achieving classification of the alarm event.
[0081] Figure 2 A second flowchart of a label acquisition method is provided for an embodiment of the present invention, the method comprising:
[0082] S201: Obtain a target alarm event, wherein the target alarm event includes target information.
[0083] S202: Based on the target information, a target tag of the target alarm event is obtained, wherein the tag class corresponding to the target tag is not the first tag class in each dependency relationship.
[0084] The tag class corresponding to the target tag is not a dependent class in any of the established dependency relationships. Determining the tag corresponding to a tag class does not depend on the tags corresponding to other tag classes. Therefore, obtaining the tag corresponding to that tag class depends on the information contained in the alarm event. Only after obtaining the target tag can the other tags of the target alarm event be obtained.
[0085] In an embodiment of the present invention, one way to obtain a target label of a target alarm event based on target information may be to use the target information as the target label of the target alarm event.
[0086] If the target information contained in the target alarm event is a tag corresponding to a tag class that is not in a dependent position in any dependency relationship, the target information can be used as the target tag of the target alarm event. For example, if the target information is zabbix and the tag class that is not in a dependent position in any dependency relationship is the data source, then the tag corresponding to the data source of the target alarm event is zabbix. When there is more than one tag class that is not in a dependent position in any dependency relationship, the information contained in the target information is used as the tag corresponding to the corresponding tag class.
[0087] In an embodiment of the present invention, one way to obtain the target label of the target alarm event based on the target information may be: according to the association relationship between the label corresponding to the preset reference label class and the information, the label that has an association relationship with the target information is used as the target label of the target alarm event, wherein the reference label class is the label class corresponding to the target label.
[0088] The association relationship between the tag corresponding to the reference tag class and the information can be understood as the association relationship between each tag in the reference tag class and the information. When the information is determined to be target information, the tag associated with the target information can be determined to be the target tag of the target alarm event. When more than one target tag needs to be obtained, and the target information contains only one piece of information, these target tags correspond to a reference tag class respectively. Based on the association relationship between the tag corresponding to the reference tag class established for each reference tag class and the information, the target tag can be determined. When more than one target tag needs to be obtained, and the target information contains more than one piece of information, for each reference tag class, a relationship between the tag corresponding to the reference tag class and the information is pre-established, and the target tag can be obtained based on the information contained in the target information.
[0089] The method used to obtain the target tag is determined by factors such as the information contained in the alarm event and the established dependencies. Using either method can quickly obtain the target tag, and the method for obtaining the target tag can be flexibly selected based on the situation of the alarm system.
[0090] S203: For each first tag class in the dependency relationship between pre-established tag classes, when the dependent tags of the first tag class have been obtained, the tag of the target alarm event corresponding to the first tag class is obtained based on the dependent tags of the first tag class, wherein the dependent tag is the tag of the target alarm event corresponding to the second tag class that has a dependency relationship with the first tag class.
[0091] The acquisition of the label corresponding to the first label class needs to rely on the label corresponding to the second label class that has a dependency relationship with the first label class. When the dependent labels of the first label class are not all obtained, the label corresponding to the first label class cannot be obtained. When the labels corresponding to the first label class are all obtained, the label of the target alarm event corresponding to the first label class can be obtained based on the obtained dependent labels. When the label corresponding to the first label class cannot be obtained, the label corresponding to the first label class in the dependency relationship in which the first label class is dependent cannot be obtained. For example, label class 3 depends on label class 1 and label class 2. Currently, only the label corresponding to label class 1 is obtained, and the label corresponding to label class 2 is not obtained. That is, the dependent labels of label class 3 are not all obtained, and the alarm event corresponding to label class 3 of the alarm event cannot be obtained.
[0092] In an embodiment of the present invention, one way to obtain the label of the target alarm event corresponding to the first label class based on the dependent label of the first label class may be: based on the dependent label of the first label class, call a predetermined external program interface to obtain the label of the target alarm event corresponding to the first label class.
[0093] In the alarm system, the acquisition of some tags needs to rely on external program interfaces. The specific tags that need to be obtained by relying on external interfaces are pre-set. When it is determined that an external interface needs to be scheduled to obtain a tag corresponding to a tag class, the external interface corresponding to the tag class can be called. The external interface outputs the tag corresponding to the tag class based on the obtained dependent tag and the pre-set tag acquisition method, and feeds the tag back to the alarm system.
[0094] In an embodiment of the present invention, another way to obtain the label of the target alarm event corresponding to the first label class based on the dependent label of the first label class may be: obtaining the label of the target alarm event corresponding to the first label class based on the pre-set association relationship between the dependent label of the first label class and the label corresponding to the first label class.
[0095] In an alarm system, some tags can be obtained based on pre-established associations. Once all dependent tags of a first tag class have been obtained, the tag corresponding to the first tag class can be determined based on the association between the dependent tags of the first tag class and the tags corresponding to the first tag class. For example, the dependent tags of the first tag class are: Project A, Network Error; the first tag class is Severity. A pre-established association between the project, error type, and severity can be used to determine the severity of the alarm event, i.e., the tag corresponding to the first tag class.
[0096] The tag acquisition method for each tag class is predefined, and the corresponding tag can be obtained according to the pre-determined acquisition method. Using the same method to obtain tags for different alarm events can unify the tag acquisition standards and make the subsequent alarm event processing based on the tags more accurate.
[0097] In an embodiment of the present invention, the target label of the target alarm event is obtained through the target information. When the dependent labels of the first label class have been obtained, other labels are obtained based on the dependent labels of the first label class. In this way, labels of different dimensions of the alarm event can be obtained, thereby realizing the classification of the alarm event.
[0098] Figure 3 A third flowchart of a label acquisition method is provided for an embodiment of the present invention. The method includes:
[0099] S301: Obtain a target alarm event, wherein the target alarm event includes target information.
[0100] S302: Using the target information as input to a preset stream computing framework to obtain a target label for the target alarm event; wherein the stream computing framework outputs the target label according to the target information.
[0101] A streaming computing framework processes large data streams in real time or near real time. The streaming computing framework in the embodiments of the present invention is a preconfigured streaming computing framework. After obtaining target information, the streaming computing framework performs calculations based on a preset target label acquisition method and outputs a target label. Specifically, the preset target label acquisition method can be the target label acquisition method described above.
[0102] The streaming computing framework can obtain the labels of alarm events in real time. The streaming computing framework can obtain the labels of different alarm events in parallel. In this way, when a large number of alarm events are generated, the labels of alarm events can be obtained in batches, and the alarm events can be processed flexibly with low latency.
[0103] S303: Use the target tag as the input of the streaming computing framework to obtain the tags of the target alarm event other than the target tag; wherein, the streaming computing framework uses the target and the preset tag class topology structure to output the tags of the target alarm event other than the target tag, and the tag class topology structure is generated based on the dependency relationship between pre-established tag classes.
[0104] The tag class topology is generated based on the dependency relationship. The tag class topology will only be regenerated when the dependency relationship between the established tag classes changes. Using the tag class topology to organize the relationship between tag classes can facilitate the organization and subsequent expansion of tag classes. For example, the established dependency relationship can be shown in Table 1:
[0105] Table 1
[0106] First label class Second label class Dependency 1 Tag Class 2, Tag Class 3, Tag Class 4 Tag Class 1 Dependency 2 Tag Class 5 Tag Class 2, Tag Class 3 Dependency 3 Tag Class 6 Tag Class 4, Tag Class 5
[0107] The generated topology is as follows Figure 4 As shown, Figure 4 The tag classes with dependency relationships are connected by lines, and the direction of the connection line is from the second tag class to the first tag class. Each tag class corresponds to a tag class node.
[0108] The streaming framework can be used to obtain labels: when a new alarm event arrives, the label class nodes that the alarm event needs to flow through are assigned based on the pre-obtained label class topology. Each time the alarm event passes through a label class node, if a label corresponding to that label class is obtained, the obtained label is stored in the shared memory of the streaming computing framework for use by other label class nodes. It should be noted that just because an alarm event passes through a label class node does not guarantee that the label corresponding to that label class will be obtained. Allowing the alarm event to pass through every label class node is to avoid missing labels. Once the alarm event passes through all label class nodes, the alarm event's label is fully obtained. When the alarm event passes through a label class node corresponding to a label class that is not the first label class in any dependency relationship, the target label can be obtained using target information. When the alarm event passes through a label class node that requires a dependent label, the dependent label is obtained from shared memory. If the obtained dependent label is not all the dependent labels of the label class node, the corresponding label cannot be output. If all the dependent labels have been obtained, the corresponding label can be output using the above-mentioned method of obtaining labels based on dependent labels.
[0109] The streaming computing framework in this embodiment of the present invention can be the Flink streaming computing framework. Flink is an open-source computing platform for distributed data stream processing and batch data processing, supporting high-throughput, low-latency, and high-performance stream processing. Using the Flink streaming computing framework, alarm event labels can be calculated in real time, enabling flexible and low-latency processing of alarm events.
[0110] In the embodiment of the present invention, the labels of the alarm events are calculated in real time through a preset stream computing framework and a pre-generated label class topology structure, thereby realizing the classification of the alarm events.
[0111] Figure 5 A fourth flow chart of a label acquisition method is provided for an embodiment of the present invention. The method includes:
[0112] S501: Obtain a target alarm event, wherein the target alarm event includes target information.
[0113] S502: Based on the dependency relationship between the target information and the pre-established tag class, obtain the tag of the target alarm event, wherein one tag corresponds to one tag class, and one dependency relationship includes a first tag class and a second tag class. The acquisition of the tag corresponding to the first tag class depends on the tag corresponding to the second tag class. The first tag class is the tag class in a dependent position in the dependency relationship, and the second tag class is the tag class in a dependent position in the dependency relationship.
[0114] S503: Determine whether the tag corresponding to the obtained tag is a tag in the pre-recorded association relationship between the user and the tag. If yes, execute S504; if not, end.
[0115] In this embodiment of the present invention, after obtaining the alarm event tag, alarm subscription can be implemented. Operations personnel can send the subscribed tags to the alarm system. The alarm system will record the association between users and tags, that is, which user subscribes to which tag. For example, if operations personnel A only wants to pay attention to alarms for Project 1, they can send a message to the alarm system to subscribe to Project 1. The alarm system will record the association as: Operation personnel ID: Project 1. The operation personnel ID can be the operation personnel's name, account number, email address, mobile phone number, etc.
[0116] S504: Determine the user associated with the tag class in the association relationship.
[0117] After obtaining all tags for an alarm event, the system determines whether any of the tags are included in the pre-recorded associations between users and tags. If so, this indicates that a user has subscribed to the tag. The user associated with the tag can then be determined from the recorded associations. If the recorded associations contain more than one tag for the target alarm event, the system can determine the users who have subscribed to the tags in the associations for the target alarm event.
[0118] S505: Send the target alarm event to the determined user.
[0119] After the user confirms, the target alarm event is sent to the determined user. The specific sending form can be pre-set. For example, it can be pushed to the user in the form of a message notification, or sent to the user in the form of an email or text message.
[0120] In an embodiment of the present invention, when the tag of the alarm event is a tag subscribed by the user, the alarm event is sent to the user, which can promptly remind the user that there is an abnormality in the running service, and specifically notify users who need to know the abnormality, thereby improving the user experience.
[0121] Figure 6 A schematic structural diagram of a label acquisition device is provided for an embodiment of the present invention, the device comprising:
[0122] A first obtaining module 601 is configured to obtain a target alarm event, wherein the target alarm event includes target information;
[0123] The second acquisition module 602 is used to obtain the label of the target alarm event based on the dependency relationship between the target information and the pre-established label class, wherein one label corresponds to one label class, one dependency relationship includes a first label class and a second label class, the acquisition of the label corresponding to the first label class depends on the label corresponding to the second label class, the first label class is the label class in a dependent position in the dependency relationship, and the second label class is the label class in a dependent position in the dependency relationship.
[0124] In the embodiment of the present invention, the label of the target event is obtained through the dependency relationship between the target information contained in the target alarm event and the pre-established label class, thereby achieving classification of the alarm event.
[0125] In one embodiment of the present invention, the second obtaining module 602 may include:
[0126] A first obtaining submodule is configured to obtain a target label of a target alarm event based on the target information, wherein the label class corresponding to the target label is a non-first label class in each dependency relationship;
[0127] The second acquisition submodule is used to obtain the label of the target alarm event corresponding to the first label class based on the dependent label of the first label class for each first label class in the dependency relationship between pre-established label classes, when the dependent labels of the first label class have been obtained, wherein the dependent label is the label of the target alarm event corresponding to the second label class that has a dependency relationship with the first label class.
[0128] In one embodiment of the present invention, the first obtaining submodule is specifically configured to:
[0129] Use the target information as the target label of the target alarm event;
[0130] or
[0131] According to the association relationship between the tag corresponding to the preset reference tag class and the information, the tag associated with the target information is used as the target tag of the target alarm event, wherein the reference tag class is the tag class corresponding to the target tag.
[0132] In one embodiment of the present invention, the second obtaining submodule is specifically configured to:
[0133] Based on the dependent tag of the first tag class, a predetermined external program interface is called to obtain a tag of the target alarm event corresponding to the second tag class;
[0134] or
[0135] The label of the target alarm event corresponding to the second label class is obtained according to the preset association relationship between the dependent label of the first label class and the label corresponding to the second label class.
[0136] In one embodiment of the present invention, the first obtaining submodule is specifically configured to:
[0137] The target information is used as input of a preset stream computing framework to obtain a target label of the target alarm event; wherein the stream computing framework outputs the target label according to the target information;
[0138] The second submodule is used to:
[0139] The target label is used as the input of the streaming computing framework to obtain the label of the target alarm event other than the target label; wherein, the streaming computing framework uses the target and the preset label class topology structure to output the label of the target alarm event other than the target label, and the label class topology structure is generated based on the dependency relationship between pre-established label classes.
[0140] In one embodiment of the present invention, the streaming computing framework is the Flink streaming computing framework.
[0141] In one embodiment of the present invention, the device may further include:
[0142] A judging module, configured to judge whether the obtained tags contain tags in a pre-recorded association relationship between users and tags;
[0143] A determination module, configured to determine the user associated with the tag in the association relationship when the judgment structure of the judgment module is yes;
[0144] The sending module is used to send the target alarm event to the determined user.
[0145] The embodiment of the present invention further provides an electronic device, such as Figure 7 As shown, it includes a processor 701, a communication interface 702, a memory 703 and a communication bus 704, wherein the processor 701, the communication interface 702, and the memory 703 communicate with each other through the communication bus 704.
[0146] Memory 703, used for storing computer programs;
[0147] The processor 701 is configured to execute the program stored in the memory 703, and implement the following steps:
[0148] Obtaining a target alarm event, wherein the target alarm event includes target information;
[0149] Based on the pre-established dependency relationship and target information between tag classes, the tag of the target alarm event is obtained, wherein one tag corresponds to one tag class, one dependency relationship includes a first tag class and a second tag class, the acquisition of the tag corresponding to the first tag class depends on the tag corresponding to the second tag class, the first tag class is the tag class in a dependent position in the dependency relationship, and the second tag class is the tag class in a dependent position in the dependency relationship.
[0150] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0151] The communication interface is used for communication between the above electronic device and other devices.
[0152] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.
[0153] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0154] In the embodiment of the present invention, the label of the target event is obtained through the dependency relationship between the target information contained in the target alarm event and the pre-established label class, thereby achieving classification of the alarm event.
[0155] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, which, when executed on a computer, enable the computer to execute any of the label obtaining methods described in the above embodiments.
[0156] In the embodiment of the present invention, the label of the target event is obtained through the dependency relationship between the target information contained in the target alarm event and the pre-established label class, thereby achieving classification of the alarm event.
[0157] In another embodiment of the present invention, a computer program product including instructions is provided. When the computer program product is run on a computer, the computer is enabled to execute any of the label obtaining methods described in the above embodiments.
[0158] In the embodiment of the present invention, the label of the target event is obtained through the dependency relationship between the target information contained in the target alarm event and the pre-established label class, thereby achieving classification of the alarm event.
[0159] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0160] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0161] Each embodiment in this specification is described in a related manner. Similar portions between the various embodiments can be referenced to each other. Each embodiment focuses on the differences between the other embodiments. In particular, since the apparatus / electronic device / computer-readable storage medium / computer program product embodiments are generally similar to the method embodiments, their descriptions are relatively simple. For related portions, reference can be made to the descriptions of the method embodiments.
[0162] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.
Claims
1. A label acquisition method, characterized in that: Applied to an alarm system, the method comprises: Obtaining a target alarm event, wherein the target alarm event includes target information; Based on the pre-established dependency relationship between tag classes and the target information, the label of the target alarm event is obtained, wherein one label corresponds to one tag class, and one dependency relationship includes a first tag class and a second tag class. The acquisition of the label corresponding to the first tag class depends on the label corresponding to the second tag class. The first tag class is the tag class in a dependent position in the dependency relationship, and the second tag class is the tag class in a dependent position in the dependency relationship. The label of the target alarm event is used to classify the target alarm event.
2. The method according to claim 1, characterized in that The step of obtaining the label of the target alarm event based on the pre-established dependency relationship between the label classes and the target information includes: Based on the target information, obtaining a target tag of the target alarm event, wherein the tag class corresponding to the target tag is not the first tag class in each of the dependency relationships; For each first tag class in the pre-established dependency relationship between tag classes, when the dependent tags of the first tag class have been obtained, obtain the tag of the target alarm event corresponding to the first tag class based on the dependent tags of the first tag class, wherein the dependent tag is the tag of the target alarm event corresponding to the second tag class having a dependency relationship with the first tag class; Wherein, obtaining the target label of the target alarm event based on the target information includes: Using the target information as the target label of the target alarm event; Alternatively, based on the association relationship between the tag corresponding to a preset reference tag class and the information, a tag associated with the target information is used as the target tag of the target alarm event, wherein the reference tag class is the tag class corresponding to the target tag; The obtaining, based on the dependent tag of the first tag class, the tag of the target alarm event corresponding to the first tag class includes: Based on the dependent tag of the first tag class, a predetermined external program interface is called to obtain the tag of the target alarm event corresponding to the first tag class; Alternatively, the label of the target alarm event corresponding to the first label class is obtained according to a preset association relationship between the dependent label of the first label class and the label corresponding to the first label class.
3. The method according to claim 2, characterized in that The step of obtaining a target label of the target alarm event based on the target information includes: The target information is used as input of a preset stream computing framework to obtain a target label of the target alarm event; wherein the stream computing framework outputs the target label according to the target information; For each first tag class in the pre-established dependency relationship between tag classes, obtaining a tag corresponding to the first tag class based on the dependent tags of the first tag class when the dependent tags of the first tag class have been obtained includes: The target tag is used as the input of the streaming computing framework to obtain the tag of the target alarm event other than the target tag; wherein, the streaming computing framework uses the target and a preset tag class topology structure to output the tag of the target alarm event other than the target tag, and the tag class topology structure is generated based on the dependency relationship between pre-established tag classes.
4. The method according to claim 3, characterized in that The streaming computing framework is the Flink streaming computing framework.
5. The method according to claim 1, wherein After obtaining the label of the target alarm event based on the pre-established dependency relationship between label classes and the target information, the method includes: Determine whether the tag corresponding to the obtained tag is a tag in the pre-recorded association relationship between the user and the tag; If the tag corresponding to the obtained tag has a tag in a pre-recorded association relationship between a user and a tag, determining the user associated with the tag in the association relationship; The target alarm event is sent to the determined user.
6. A label obtaining device, characterized in that: Applied to an alarm system, the device comprises: A first obtaining module is used to obtain a target alarm event, wherein the target alarm event includes target information; The second acquisition module is used to obtain the label of the target alarm event based on the pre-established dependency relationship between label classes and the target information, wherein one label corresponds to one label class, and one dependency relationship includes a first label class and a second label class. The acquisition of the label corresponding to the first label class depends on the label corresponding to the second label class. The first label class is the label class in a dependent position in the dependency relationship, and the second label class is the label class in a dependent position in the dependency relationship. The label of the target alarm event is used to classify the target alarm event.
7. The device according to claim 6, characterized in that The second obtaining module includes: A first obtaining submodule is configured to obtain a target tag of the target alarm event based on the target information, wherein the tag class corresponding to the target tag is not the first tag class in each of the dependency relationships; A second obtaining submodule is configured to obtain, for each first tag class in the pre-established dependency relationship between tag classes, a tag of the target alarm event corresponding to the first tag class based on the dependent tags of the first tag class when all dependent tags of the first tag class have been obtained, wherein the dependent tag is a tag of the target alarm event corresponding to the second tag class having a dependency relationship with the first tag class; The first obtaining submodule is specifically configured to: Using the target information as the target label of the target alarm event; Alternatively, based on the association relationship between the tag corresponding to a preset reference tag class and the information, a tag associated with the target information is used as the target tag of the target alarm event, wherein the reference tag class is the tag class corresponding to the target tag; The second obtaining submodule is specifically used to: Based on the dependent tag of the first tag class, a predetermined external program interface is called to obtain the tag of the target alarm event corresponding to the second tag class; Alternatively, the label of the target alarm event corresponding to the second label class is obtained according to a preset association relationship between the dependent label of the first label class and the label corresponding to the second label class.
8. The device according to claim 7, characterized in that The first obtaining submodule is specifically configured to: The target information is used as input of a preset stream computing framework to obtain a target label of the target alarm event; wherein the stream computing framework outputs the target label according to the target information; The second obtaining submodule is specifically used to: The target tag is used as the input of the streaming computing framework to obtain the tag of the target alarm event other than the target tag; wherein, the streaming computing framework uses the target and a preset tag class topology structure to output the tag of the target alarm event other than the target tag, and the tag class topology structure is generated based on the dependency relationship between pre-established tag classes.
9. The device according to claim 8, characterized in that The streaming computing framework is the Flink streaming computing framework.
10. The device according to claim 6, characterized in that The device comprises: A judging module, configured to judge whether the obtained tags contain tags in a pre-recorded association relationship between users and tags; a determination module configured to, when there is a tag in a pre-recorded association relationship between a user and a tag among the obtained tags, determine the user associated with the tag in the association relationship; The sending module is used to send the target alarm event to the determined user.
11. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to implement the method steps described in any one of claims 1 to 5 when executing a program stored in a memory.
Citation Information
Patent Citations
Method for alarming electric power event
CN101625790A
Information pushing method and equipment
CN106209591A
Event processing method and device
CN106484595A
White list rule-based alarm information classification processing method and apparatus
CN106778873A
Device, method and computer program product for situation monitoring
US20070260569A1