A method and apparatus for alarm aggregation
By generating alarm feature vectors and continuously updating aggregation groups under the streaming processing framework, the problem of low alarm aggregation efficiency in the existing technology is solved, and fast and efficient alarm data stream aggregation is achieved, meeting the real-time requirements of the current network.
Patent Information
- Application Number
- CN202010128022.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-02-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2040-02-28
AI Technical Summary
In the process of alarm aggregation, the existing technology processes a fixed number of alarm data streams, resulting in large calculations and long waiting time, which affects the alarm rate due to positioning speed and subsequent repair, which cannot meet the real-time requirements of the current network.
By generating an alarm feature vector under the streaming processing framework, determining the aggregation group to which it belongs, and continuously updating the alarm data stream in the aggregation group until the preset conditions are met, the aggregation group is output. This method allows real-time processing of alarm data streams, reducing latency and calculating data volume.
It improves the efficiency of alarm aggregation, shortens the time for the alarm aggregation module to aggregate data streams, enhances the efficiency of the network management system in root cause analysis, and meets the real-time requirements of the current network.
Smart Images

Figure CN113328869B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information technology, and more particularly, to a method and apparatus for alarm aggregation. Background Art
[0002] With the continuous expansion of the scale of telecommunication networks, the number of alarms reported by devices has increased explosively, and the network structure has become increasingly complex. Therefore, quickly and accurately locating the root cause of alarms is beneficial to the rapid repair of the network. In the process of locating the root cause of alarms, alarm aggregation is crucial and is one of the key links for quick location.
[0003] However, existing alarm aggregation methods usually need to process a fixed number (such as a batch) of alarm data. This may result in a large amount of calculation and a long waiting time for alarm aggregation, thus leading to low efficiency of alarm aggregation, and further affecting the location speed of the root cause of alarms and subsequent repair, and cannot meet the real-time requirements of the current network. Summary of the Invention
[0004] This application provides a method and apparatus for alarm aggregation, aiming to improve the efficiency of alarm aggregation, thereby facilitating the quick location of the root cause of alarms and subsequent repair, and further meeting the real-time requirements of the current network.
[0005] In a first aspect, a method for alarm aggregation is provided. The method includes: generating an alarm feature vector based on the obtained alarm data stream; determining, based on each alarm feature vector, the aggregation group to which the corresponding alarm data stream belongs, where the aggregation group includes a first aggregation group; updating the alarm data streams in the first aggregation group based on each alarm data stream determined to belong to the first aggregation group until the update of the alarm data streams in the first aggregation group meets a preset condition; and outputting the first aggregation group.
[0006] It should be understood that this method can be executed, for example, by an alarm aggregation module, specifically by an alarm aggregation module in a network management system.
[0007] The embodiments of this application propose the processing of alarm data streams in a streaming processing framework. The alarm aggregation module can determine, based on each generated alarm feature vector, which aggregation group the corresponding alarm data stream belongs to, and then update the alarm data streams in the aggregation group based on the determination of the aggregation group to which each alarm data stream belongs, so as to achieve continuous calculation and update. The above steps can be implemented, for example, by a streaming clustering algorithm.
[0008] Based on the above technical solution, the alarm aggregation module does not have to wait for a batch or a larger number of alarm data streams to arrive before performing alarm aggregation. It can perform the current aggregation calculation while waiting for the generation of the next alarm feature vector. On the other hand, since the determination of the aggregation group is performed for each alarm feature vector, compared with a batch or a larger number of alarm data streams, the amount of data calculated each time is smaller, so the calculation time is also shorter. In this way, the time for the alarm aggregation module to aggregate the data stream can be greatly shortened, which is beneficial to improving the efficiency of root cause analysis of the entire network management system.
[0009] The following exemplarily lists several possible preset conditions. When the update of a certain aggregation group meets the preset conditions, the alarm aggregation module can output the aggregation group for subsequent analysis of the root cause of the alarm.
[0010] Optionally, the update of the alarm data stream in the first aggregation group meeting the preset conditions includes: the update frequency of the alarm data stream in the first aggregation group is less than the first preset threshold.
[0011] Optionally, the update of the alarm data stream in the first aggregation group meeting the preset conditions includes: the update time of the alarm data stream in the first aggregation group reaches the second preset threshold.
[0012] Optionally, the update of the alarm data stream in the first aggregation group meeting the preset conditions includes: the update times of the alarm data stream in the first aggregation group reach the third preset threshold.
[0013] Among them, the update times can be counted starting from the creation of the aggregation group; the update time can be timed starting from the creation time of the aggregation group; the update frequency can be determined according to the update times and the update time.
[0014] Generally, there is one or more existing aggregation groups in the alarm aggregation module. When a new alarm feature vector is generated, the alarm aggregation module can first determine whether the alarm data stream corresponding to the alarm feature vector belongs to one of the existing aggregation groups. Here, the first alarm data stream in the obtained alarm data stream is taken as an example for illustration.
[0015] Combined with the first aspect, in some possible implementation manners, the method further includes: determining that the first alarm data stream in the obtained alarm data stream belongs to an existing aggregation group, where the existing aggregation group is an aggregation group created before the generation of the first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; adding the first alarm data stream to the existing aggregation group to which it belongs.
[0016] That is, in a possible situation, the first alarm data stream belongs to an existing aggregation group. In this case, the alarm aggregation module can add the alarm data stream to the aggregation group to complete the update of the alarm data stream in the aggregation group. Thus, the number of alarm data streams in the aggregation group increases by one.
[0017] Optionally, determining that the first alarm data stream in the acquired alarm data streams belongs to an existing aggregation group includes: determining the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation groups; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; if the distance between the first alarm data stream and the class center vectors of at least one existing aggregation group is less than or equal to a fourth preset threshold, determining that the first alarm data stream belongs to the existing aggregation group.
[0018] Among them, there is a one-to-one correspondence between the class center vector and the aggregation group. Each class center vector is determined by the alarm feature vectors of the alarm data streams in its corresponding aggregation group.
[0019] The aggregation group to which the alarm data stream belongs can be determined according to the distance between the corresponding alarm feature vector and the class center vector. Taking the first alarm data stream as an example, if the distance between the corresponding first alarm feature vector and the class center vectors of one or more existing aggregation groups is less than or equal to the fourth preset threshold, it can be determined that the first alarm data stream belongs to the existing aggregation group.
[0020] Among them, the fourth preset threshold can be stored in the alarm aggregation module in advance, for example. Based on different types of distances, the value of the fourth preset threshold is also different. The present application does not limit the specific value of the fourth preset threshold.
[0021] Further, the existing aggregation group includes a first aggregation group, and the method further includes: if the distance between the class center vector of the first aggregation group and the first alarm feature vector is less than the distances between the class center vectors of any other existing aggregation group and the first alarm feature vector, determining that the first alarm data stream belongs to the first aggregation group. Among them, adding the first alarm data stream to the existing aggregation group to which it belongs includes: adding the first alarm data stream to the first aggregation group.
[0022] In the case of determining that the first alarm data stream belongs to an existing aggregation group, it can be further determined which existing aggregation group the first alarm data stream belongs to. Assuming that the above-mentioned first aggregation group is an existing aggregation group, and the distance between the class center vector of the first aggregation group and the first alarm feature vector is the minimum among the distances between the class center vectors of the existing aggregation groups and the first alarm feature vector, it can be determined that the first alarm data stream belongs to the first aggregation group. In other words, the aggregation group corresponding to the class center vector with the closest distance to the first alarm feature vector is determined as the aggregation group to which the first alarm data stream belongs.
[0023] Further, the method further includes: updating the class center vector of the first aggregation group according to the first alarm feature vector.
[0024] Based on the update of the first aggregation group, the alarm aggregation module can further update the class center vector of the first aggregation group according to the first alarm feature vector, so as to calculate the distance between the subsequently generated alarm feature vector and the class center vector of the first aggregation group.
[0025] Among them, there are many ways to update the class center vector of the first aggregation group according to the first alarm feature vector. For example, the average value, weighted sum, etc. of the alarm feature vectors corresponding to all alarm data streams of the first aggregation group can be calculated. This application does not limit this.
[0026] In a possible design, the updated class center vector c' and the class center vector c before update satisfy: c'=(c×n + v) / (n + 1); where, v represents the first alarm feature vector, and n represents the number of other alarm data streams that are determined to be the first aggregation group before the first alarm data stream is determined to belong to the first aggregation group, and n is a positive integer.
[0027] Those skilled in the art can understand that the above update of the class center vector can also be implemented by means of taking the average value or other equivalent means. This application does not limit this.
[0028] Combined with the first aspect, in some possible implementation manners, the method further includes: determining that the first alarm data stream in the obtained alarm data stream does not belong to the existing aggregation group; the existing aggregation group is an aggregation group created before generating the first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; creating a second aggregation group, and the second aggregation group includes the first alarm data stream.
[0029] That is, another possible situation is that the first alarm data stream does not belong to the existing aggregation group. In this case, the alarm aggregation module can create a second aggregation group and add the first alarm data stream to the second aggregation group.
[0030] Optionally, determining that the first alarm data stream in the obtained alarm data stream does not belong to the existing aggregation group includes: determining the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation group; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; if the distances between the first alarm data stream and the class center vectors corresponding to each aggregation group in the existing aggregation group are all greater than the fourth preset threshold, it is determined that the first alarm data stream does not belong to the existing aggregation group.
[0031] As described above, the aggregation group to which the alarm data stream belongs can be determined based on the distance between the corresponding alarm feature vector and the class center vector. If the distance between the first alarm feature vector and any class center vector is greater than the fourth preset threshold, it can be determined that the first alarm data stream does not belong to the existing aggregation group.
[0032] Further, the method further includes: determining the first alarm feature vector as the class center vector of the second aggregation group.
[0033] After creating the second aggregation group based on the first alarm data stream, the first alarm feature vector can be further determined as the class center vector of the second aggregation group, so as to facilitate judging the distance between the subsequently generated alarm feature vectors and the class center vector of the second aggregation group.
[0034] After that, the second aggregation group also becomes an existing aggregation group. As the alarm feature streams added to the second aggregation group increase, the class center vector of the second aggregation group is continuously updated.
[0035] Combined with the first aspect, in some possible implementation manners, the above distance includes Euclidean distance, Mahalanobis distance or cosine distance.
[0036] This application does not limit the specific manner of calculating the distance between the alarm feature vector and the class center vector. The calculation of various types of distances can refer to the prior art, and this application does not limit it. It can be understood that based on different types of distances, the value of the above fourth preset threshold will be different.
[0037] Combined with the first aspect, in some possible implementation manners, each alarm data stream includes at least one of the following dimensions of features: topology, alarm name, alarm level, alarm event type, alarm time, and current time.
[0038] By providing features of multiple dimensions for the alarm data stream, it is beneficial to obtain alarm feature vectors of more dimensions, to accurately judge which aggregation group the alarm data stream belongs to from more dimensions, and also to improve the accuracy of subsequent root cause analysis.
[0039] Combined with the first aspect, in some possible implementation manners, the method further includes: determining the alarm root cause according to the alarm data streams in the first aggregation group.
[0040] It should be understood that when the alarm aggregation module outputs the first aggregation group, the root cause analysis module in the network management system can perform root cause analysis on the alarm data streams in the first aggregation group, thereby determining the alarm root cause and repairing it for the alarm root cause.
[0041] Since the method provided by this application can improve the efficiency of alarm aggregation, it is conducive to quickly finding the root cause and fixing it, and is conducive to quickly restoring the normal operation of the communication network.
[0042] In a second aspect, an apparatus for alarm aggregation is provided. The apparatus may include various modules or units for executing the methods in the first aspect and any possible implementation manner in the first aspect.
[0043] In a third aspect, an apparatus for alarm aggregation is provided. The apparatus may include a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the first aspect and any possible implementation manner in the first aspect. Optionally, the communication apparatus further includes a memory. Optionally, the communication apparatus further includes a communication interface, and the processor is coupled to the communication interface.
[0044] Optionally, the processor is one or more.
[0045] Optionally, the apparatus includes the above-mentioned memory. Optionally, the memory is one or more.
[0046] Optionally, the memory may be integrated with the processor, or the memory is separately provided from the processor.
[0047] In one implementation manner, the apparatus is a chip.
[0048] In a fourth aspect, a network management system is provided, including the apparatus for alarm aggregation as described in the second aspect or the third aspect. The network management system may further include an alarm collection module, an alarm noise reduction module, a root cause analysis module, and an online feedback module.
[0049] In a fifth aspect, a computer program product is provided. The computer program product includes: a computer program (which may also be referred to as code, or instruction), when the computer program is run, it causes the computer to execute the methods in any possible implementation manner in the first aspect.
[0050] In a sixth aspect, a computer-readable medium is provided. The computer-readable medium stores a computer program (which may also be referred to as code, or instruction), when it runs on a computer, it causes the computer to execute the methods in any possible implementation manner in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 and Figure 2 is a schematic diagram applicable to the system provided by the embodiments of the present application;
[0052] Figure 3 is a schematic diagram of the working process of the network management system provided by the embodiments of the present application;
[0053] Figure 4 It is a schematic flowchart of the alarm aggregation method provided by an embodiment of the present application;
[0054] Figure 5 It is a schematic diagram of churn clustering provided by an embodiment of the present application;
[0055] Figure 6 It is a schematic block diagram of the alarm aggregation device provided by an embodiment of the present application;
[0056] Figure 7 It is another schematic block diagram of the alarm aggregation device provided by an embodiment of the present application. Detailed implementation manners
[0057] Next, the technical solutions in the present application will be described in conjunction with the accompanying drawings.
[0058] The technical solutions of the embodiments of the present application can be applied to various communication networks, such as including but not limited to: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication systems, 5th Generation (5G) mobile communication systems or New Radio Access Technology (NR), or next-generation communications, such as 6G. Among them, the 5G mobile communication system can be non-standalone (NSA) or standalone (SA).
[0059] The technical solution provided by this application can also be applied to machine type communication (MTC), Long Term Evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, the IoT network can include, for example, the vehicle networking. Among them, the communication methods in the vehicle networking system are collectively referred to as vehicle to X (V2X, where X can represent anything). For example, the V2X can include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, communication between vehicle and pedestrian (V2P), or vehicle to network (V2N) communication, etc.
[0060] The method provided by the embodiments of this application can be used in a communication system to collect alarm information in the network, perform root cause analysis based on the alarm information, and then repair the root cause.
[0061] For ease of understanding, the following combines Figure 1 to elaborate in detail the system architecture of the embodiments of this application. Figure 1 is a schematic diagram of the system architecture applicable to the method provided by the embodiments of this application. It should be understood that Figure 1 the system architecture shown is only an example for ease of understanding and should not limit the scope applicable to this application.
[0062] As Figure 1 shown, the system includes a communication network 110 and a network management system 120. Among them, the communication network 110 can include at least one network device 111 to 118, and each network device may generate alarms during operation. A network device can be understood as an object to be managed in a communication network. A network device can be implemented by software, for example, it can be a virtual machine, a container, an application, etc.; it can also be implemented by hardware, for example, a server, a base station, a switch, a router, a relay, a mobile terminal, a personal computer, a disk, a solid-state drive, etc.; it can also be implemented in a combination of software and hardware. This application does not limit the specific form of the network device.
[0063] The network management system 120 may include an alarm collection device 121 and an alarm processing device 122. Among them, the alarm collection device 121 can be used to collect and manage the alarms of each network device in the communication network 110. For example, the alarm collection device 121 can be communicatively connected to the communication network 110. When any network device in the communication network generates alarm data, the network device can send the alarm to the alarm collection device 121. The alarm collection device 121 can provide the received alarms to the subsequent alarm processing device 122, so as to perform root cause analysis based on the alarms, and then perform repairs according to the root cause.
[0064] Optionally, the alarm processing device 122 may include an alarm noise reduction module 1221, an alarm aggregation module 1222, a root cause analysis module 1223, an online feedback module 1224, etc.
[0065] Among them, the alarm noise reduction module 1221 can be used to eliminate duplicate or invalid alarms obtained from the alarm collection device 121 through pre-set filtering rules (such as shielding, flash interruption, oscillation rules, etc.) to achieve the effect of noise reduction.
[0066] However, due to the continuous expansion of the scale of the communication network, the number of alarms reported by network devices has increased explosively. Even after noise reduction of the alarms, there are still many remaining valid alarms. If the on-site operation and maintenance personnel are required to perform manual root cause analysis of the alarms, the workload is huge, and problems such as root cause omission and inaccurate positioning are likely to occur, seriously affecting subsequent rapid fault diagnosis and timely repair. Therefore, before root cause analysis, the valid alarms can be effectively clustered. This can be achieved by the alarm aggregation module 1222. The alarm aggregation module 1222 can cluster the alarms from the alarm noise reduction module 1221 based on existing clustering algorithms or existing clustering engines. After clustering, the alarms are divided into multiple aggregation groups, or multiple classes.
[0067] The root cause analysis module 1223 can perform root cause analysis based on the clustering results of the alarms by the alarm aggregation module 1222. For example, the root cause analysis module 1223 can perform root cause analysis based on each aggregation group to analyze the suspicion degree of the root cause alarms of each aggregation group. The root cause analysis module 1223 can determine the alarm data stream with the highest suspicion degree as the alarm root cause of the aggregation group.
[0068] The operation and maintenance personnel can manually identify the root cause alarms and enter the processing methods of the alarms into the experience database, and perform online feedback through the online feedback module 1224 to form a root cause alarm processing experience database.
[0069] It should be understood that the above is only for easy understanding, and the network management system 120 is divided based on different functions. However, this should not constitute any limitation to this application. For example, as Figure 2As shown, the network management system 120 may also include an alarm collection module 1201, an alarm noise reduction module 1202, an alarm aggregation module 1203, a root cause analysis module 1204, an online feedback module 1205, etc. It can be understood that although the division methods are different, the functions implemented by the network management system 120 are still the same or similar. For the convenience of understanding and explanation in the following text, all examples will be described with the network management system 120 shown in Figure 2 as an example of the network management system 120 in
[0070] In one design, the above-mentioned network management system 120 may be deployed on a physical device, for example. The physical device may include one or more processors and one or more memories. Among them, instructions may be stored in the memory. When the instructions are loaded and executed by the processor, the functions performed by the above-mentioned network management system 120 can be realized. For example, the functions of each device and each module listed above can be realized by the processor executing corresponding instructions respectively. Of course, the physical device may also include an input / output interface (or communication interface), such as a wired or wireless network interface, for communicating with the outside world. The physical device may also include components that can be used to implement other functions. For the sake of brevity, details are not described here.
[0071] In another design, the above-mentioned network management system 120 may also be distributedly deployed on multiple physical devices. The multiple physical devices may form a device cluster. The device cluster may include one or more processors and one or more memories. Among them, instructions may be stored in the memory. When the instructions are loaded and executed by the processor, the functions performed by the above-mentioned network management system 120 can be realized.
[0072] For example, the alarm collection device 121 and the alarm processing device 122 listed above may be independently deployed on two physical devices. The functions of each device can be realized by the processor in each physical device executing corresponding instructions. The functions of each module in the alarm processing device 122 can be further realized by the processor executing corresponding instructions. Or, the functions of each module in the alarm processing device 122 can be realized by independent multiple physical devices, and each module is deployed on one physical device. This is equivalent to the alarm collection module 1201, the alarm noise reduction module 1202, the alarm aggregation module 1203, the root cause analysis module 1204, and the online feedback module 1205 listed above being independently deployed on different physical devices. The present application does not make any limitations in this regard.
[0073] In addition, each physical device may also include an input / output interface for communication between physical devices and communication with the outside world. The device cluster may also include components that can be used to implement other functions. For the sake of brevity, details are not described here.
[0074] To better understand the functions of each module in the network management system, the following will be combined withFigure 3 will be elaborated in more detail. It should be understood that the description below in combination with Figure 3 the description made is only a possible implementation manner for the network management system to implement the above functions, and should not constitute any limitation to this application.
[0075] Figure 3 shows the specific process of the network management system working.
[0076] In step 310, the alarm collection module collects alarm data streams from the communication network.
[0077] When a fault or error occurs in the communication network, the network device can generate an alarm data stream and send the alarm data stream to the alarm collection module. For example, the network device can immediately send the alarm data stream to the alarm collection module when a fault or error occurs, or it can wait for a period of time after a fault or error occurs. If the fault or error has not been recovered during this waiting period, it will generate an alarm data stream and send it to the alarm collection module.
[0078] It can be understood that the communication network can include multiple network devices. Moreover, this network management system may also provide services for multiple communication networks at the same time. Therefore, the alarm collection module may receive alarm data streams sent by multiple network devices in parallel. Usually, the number of alarm data streams received by the alarm collection device is huge.
[0079] In step 320, the alarm collection module sends the collected alarm data stream to the alarm noise reduction module.
[0080] The alarm collection module sends the alarm data stream collected from the communication network to the alarm noise reduction module to perform noise reduction processing on the massive alarm data streams.
[0081] In step 330, the alarm noise reduction module performs noise reduction processing on the alarm data stream.
[0082] The alarm noise reduction module can, for example, remove more duplicate or invalid alarm data streams through pre-configured filtering rules (such as including correlation rules or other rules, such as shielding, flashing, and oscillation rules, etc.), and filter out the valid alarm data streams.
[0083] In step 340, the alarm noise reduction module sends the valid alarm data stream to the alarm aggregation module.
[0084] After the above massive alarm data is processed by the alarm noise reduction module, there are still many valid alarm data streams remaining. If the remaining valid alarm data streams are directly handed over to the operation and maintenance personnel for alarm root cause analysis, there will be a huge workload and capacity bottleneck, which may lead to root cause omission or inaccurate root cause location, and thus seriously affect the subsequent rapid fault diagnosis and timely repair.
[0085] Therefore, the above-mentioned effective alarm data stream after noise reduction processing can be sent to the alarm aggregation module first.
[0086] In a possible implementation, a cache can be set in the alarm noise reduction module, and the cache can be used to save the newly collected alarm data stream. The alarm noise reduction module can continuously collect the newly reported alarm data stream, and can perform noise reduction processing on the alarm data stream collected within a predefined time window, and output the remaining effective alarm data stream after noise reduction processing to the alarm aggregation module.
[0087] In step 350, the alarm aggregation module aggregates the effective alarm data stream.
[0088] The alarm aggregation module can aggregate the alarm data stream based on a variety of different algorithms to distribute the effective alarm data stream into different aggregation groups.
[0089] In one implementation, the alarm aggregation module can push the received alarm data stream into the rule engine for rule-based aggregation to divide these alarm data into different aggregation groups. For example, an aggregation group related to service interruption, an aggregation group related to performance failure, an aggregation group related to environmental impact, etc.
[0090] In another implementation, the alarm aggregation module can also push the received alarm data to the alarm intelligent analysis engine. The engine can first use the time bucket technology to accumulate the alarm data within a certain time window, and then use the hierarchical clustering algorithm to cluster the alarm data accumulated within this time window to divide the alarm data into different aggregation groups. The remaining alarm data that has not been accumulated in the previous time window can continue to be accumulated and wait for the next root cause analysis.
[0091] There are many methods for the alarm aggregation module to aggregate the alarm data. For the sake of simplicity, they will not be listed one by one here.
[0092] Through alarm aggregation, alarm data of the same category can be grouped into one aggregation group. As shown in the figure, multiple alarm data streams are aggregated to obtain three aggregation groups, namely Aggregation Group #1: an aggregation group for service interruption; Aggregation Group #2: an aggregation group for performance failure; and Aggregation Group #3: an aggregation group for environmental impact. Each aggregation group includes one or more alarm data streams.
[0093] In order to distinguish the aggregation groups to which each alarm data stream belongs, in one implementation, tags can be added when the alarm aggregation module outputs each alarm data stream to identify the category corresponding to each alarm data stream. Since each aggregation group corresponds to a category, the process of the alarm aggregation module outputting each alarm data stream is also the process of outputting the aggregation group. Each aggregation group may include one or more alarm data streams belonging to the same category.
[0094] In step 360, the alarm noise reduction module sends the aggregated alarm data stream to the root cause analysis module.
[0095] As mentioned above, the alarm aggregation module can identify the category corresponding to each alarm data stream. The root cause analysis module can perform root cause analysis based on the alarm data streams in each aggregation group.
[0096] In step 370, the root cause analysis module performs root cause analysis on the alarm data streams in the aggregation group and performs repair based on the analysis results.
[0097] In one implementation, artificial intelligence-based alarm analysis technology can be used to perform root cause analysis. The alarm data streams in each aggregation group can be input into a pre-trained root cause recognition model to determine whether each alarm data stream is a root cause, and finally the alarm root causes of each category are output.
[0098] For each aggregation group, such as Figure 3 the aggregation group #1 shown in, that is, the alarm data stream of the service interruption category, determine the suspicion degree of the root cause alarm for each alarm data stream therein, and determine the alarm data stream with the highest suspicion degree as the root cause of the alarm data stream of this aggregation group.
[0099] There can be many specific ways for the root cause analysis module to perform root cause analysis on the alarm data stream. For the sake of simplicity, they are not listed one by one here. This application does not make any limitations in this regard.
[0100] The operation and maintenance personnel can adopt corresponding repair strategies based on the alarm root cause output by the root cause analysis module to repair the network.
[0101] In step 380, the alarm data, the alarm root cause, and the corresponding processing experience are entered into the experience database through the online feedback module.
[0102] The root cause alarms corresponding to the alarm data streams in each aggregation group and their processing experiences can be entered into the experience database. When a similar scenario is encountered next time, the processing experiences stored in this experience database can be referred to for processing. Thus, unnecessary ineffective repairs can be avoided, which is beneficial to reducing the repair duration. Thus, it is beneficial to quickly restore the normal operation of the communication network.
[0103] It should be understood that the above steps for online feedback of alarm root causes and handling experience can be completed by the operation and maintenance personnel on the online feedback module, or can also be automatically completed by the network management system. This application does not limit this.
[0104] It should also be understood that each module in the network management system described above in combination with Figures 1 to 3 is not necessarily required to exist. For example, the network management system does not include an alarm noise reduction module; or, for another example, the network management system does not include an online feedback module, etc. This application does not limit this.
[0105] The above in combination with Figure 3 briefly introduced the specific working process of the network management system. It can be seen that the alarm data stream needs to go through multiple steps of processing from generation to repair, and the waiting time is relatively long. For example, the time-consuming of noise reduction processing, the time-consuming of clustering, the time-consuming of root cause analysis, and the time-consuming of repair, etc. In the modern communication network operation and maintenance scenario, it is very important to quickly find the root cause and quickly repair. And the clustering of the alarm data stream is one of the key environments for rapid fault location. If the alarm data stream cannot be aggregated quickly, the root cause cannot be quickly located, and thus the faults or errors in the communication network cannot be repaired in time, and the real-time requirements of the existing network cannot be met. Therefore, it is hoped to provide a method that can achieve rapid clustering of the alarm data stream and reduce the waiting time for root cause analysis.
[0106] Generally, the clustering of alarm data by the alarm aggregation module, for example, includes rule-based clustering, clustering based on hierarchical clustering algorithms, etc. However, these methods usually need to aggregate a fixed number of alarm data streams. For example, a batch within a predetermined time window, or all the alarm data currently obtained, etc. However, when clustering for a fixed number of alarm data, usually the number of alarms is large, the amount of data to be calculated is large, and the calculation is time-consuming. In some implementation manners, it is also necessary to wait for the generation of alarm feature vectors based on the alarm data stream, and the waiting time is also relatively long. Therefore, generally speaking, the time-consuming for the alarm aggregation module to aggregate alarm data is relatively long.
[0107] In view of this, this application provides a method for alarm aggregation, in order to improve the efficiency of alarm aggregation, thereby facilitating the reduction of the waiting time for root cause analysis and meeting the real-time requirements of the existing network.
[0108] The method and device for alarm aggregation provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0109] It should be understood that the method for alarm aggregation described below can be executed by one or more processors. The one or more processors can be configured in the network management system, for example, to implement the functions of the alarm aggregation module.
[0110] Figure 4It is a schematic flowchart of the alarm aggregation method 400 provided by an embodiment of the present application. As Figure 4 shown, the method 400 may include steps 410 to 450. The following will describe in detail Figure 4 each step in it.
[0111] In step 410, an alarm data stream is obtained.
[0112] As described above, the alarm aggregation module may obtain the noise-reduced alarm data stream from the alarm noise reduction module, or obtain the alarm data stream from the alarm collection module. The present application does not make any limitation in this regard. The alarm aggregation module may obtain multiple alarm data streams simultaneously, for example, the alarm data streams collected within a time window.
[0113] It should be understood that the alarm data stream obtained by the alarm aggregation module may be the effective alarm data stream remaining after noise reduction processing, or may be the alarm data stream directly output by the alarm collection module without noise reduction processing. The present application does not make any limitation in this regard. For the convenience of description hereinafter, the alarm data stream obtained by the alarm aggregation module is collectively referred to as the alarm data stream, and no distinction or limitation is made on whether it has undergone noise reduction processing.
[0114] In an embodiment of the present application, the alarm data stream may include features of one or more of the following dimensions: topology, alarm name, alarm level, alarm event type, alarm time, and current time. The more dimensions of features included in the alarm data stream, the more information about this alarm can be obtained, which is beneficial for the subsequent root cause analysis module to make a more accurate judgment.
[0115] In a possible design, each alarm data stream includes features of the following multiple dimensions: topology, alarm name, and alarm time. Optionally, in addition to including the features of the above three dimensions of topology, alarm name, and alarm time, each alarm data stream may further include features of one or more of the dimensions of alarm level, alarm event type, and current time.
[0116] Of course, the alarm data stream may also include other dimensions of features other than those listed above. The present application does not make any limitation on the dimensions and the number of features included in the alarm data stream.
[0117] In step 420, an alarm feature vector is generated based on the obtained alarm data stream.
[0118] The alarm aggregation module may generate an alarm feature vector based on each alarm data stream in the obtained alarm data stream. Therefore, the alarm aggregation module may generate multiple corresponding alarm feature vectors based on the obtained multiple alarm data streams.
[0119] Exemplarily, it is assumed that the alarm data stream may include features in three dimensions: topology, alarm name, and alarm time. The alarm aggregation module may generate a topology feature vector, a name feature vector, and a time feature vector based on the features of each dimension. The alarm aggregation module may further generate an alarm feature vector based on the feature vectors of the three dimensions. For example, the topology feature vector, the name feature vector, and the time feature vector are concatenated to obtain the alarm feature vector. For another example, according to predefined weights, the topology feature vector, the name feature vector, and the time feature vector are concatenated to obtain the alarm feature vector.
[0120] Assume that the topology feature vector is denoted as a, the name feature vector is denoted as b, and the time feature vector is denoted as c. Then, the alarm feature vector v obtained after concatenation may be represented, for example, as Or, the alarm feature vector v obtained after concatenation according to the predefined weights may be represented, for example, as
[0121] It should be understood that the above is only for facilitating the understanding of the alarm feature vector, and the process of generating the alarm feature vector is illustrated by taking the three dimensions of topology, alarm name, and alarm time as examples. However, this should not constitute any limitation to this application. When the alarm data stream includes features in other more or fewer dimensions, the alarm feature vector can still be generated based on the above method. It can be understood that the generated alarm feature vector may also include features in more or fewer dimensions.
[0122] It should also be understood that the above-listed methods for generating the alarm feature vector are only examples and should not constitute any limitation to this application. This application does not limit the specific manner of generating the alarm feature vector based on the alarm data stream.
[0123] In step 430, based on the generated alarm feature vector, the aggregation group to which the corresponding alarm data stream belongs is determined.
[0124] In the embodiment of this application, the alarm aggregation module may achieve clustering of the alarm data stream based on streaming clustering, or rather, streaming aggregation. The so-called streaming clustering is to calculate based on each alarm data stream to determine the aggregation group to which it belongs. Whenever the alarm feature vector corresponding to an alarm data stream is generated, calculation can be directly performed based on the currently generated alarm feature vector without waiting for the generation of other alarm feature vectors. In other words, the alarm aggregation module does not have to wait for the generation of a fixed number of alarm feature vectors. For each generated alarm feature vector, one alarm data stream is processed. Thus, the waiting time and the amount of data to be calculated can be greatly reduced.
[0125] The above-mentioned streaming clustering can be understood as a streaming processing framework, and its specific implementation can be achieved through different algorithms, such as classic streaming clustering algorithms like CluStream, DenStream, etc. Of course, the aggregation process can also be customized. For example, the Euclidean distance, Mahalanobis distance, etc. can be used to calculate the distance between the alarm feature vector and the aggregation group class center vector, or a metric learning algorithm can be used to learn and calculate the distance between different alarm feature vectors. The present application does not limit the specific algorithm for streaming clustering.
[0126] It should be noted that the distance between the above vectors can also be referred to as the similarity between the vectors. The process of calculating the distance between the alarm feature vector and the vector in the aggregation group class described above can also be understood as the process of calculating the similarity between the alarm feature vector and the class center vector of the aggregation group. Those skilled in the art can understand that when the distance between vectors is small, their similarity is high. The following description of selecting the aggregation group corresponding to the class center vector with the smallest distance from the alarm feature vector to merge the alarm data stream is also to select the aggregation group corresponding to the class center vector with the largest similarity to the alarm feature vector to merge the alarm data stream.
[0127] For the convenience of understanding and explanation in the following text, the distance is used as an example to illustrate the specific implementation process.
[0128] Based on the alarm feature vectors generated from the above-mentioned multiple alarm data streams, the aggregation groups to which each alarm data stream belongs can be determined. Each aggregation group includes one or more alarm data streams. The alarm data streams in each aggregation group belong to the same category. Different aggregation groups correspond to different categories.
[0129] Figure 5 A schematic diagram of streaming clustering is shown.
[0130] As shown in the figure, after multiple alarm data streams are input into the alarm aggregation module, the alarm aggregation module generates multiple alarm feature vectors based on the multiple alarm data streams. Figure 5 It can be seen that the alarm aggregation module determines the aggregation groups to which each alarm data stream belongs based on each generated alarm feature vector.
[0131] Specifically, whenever the alarm aggregation module generates an alarm feature vector based on an alarm data stream, the alarm aggregation module can first determine whether the alarm feature vector belongs to an existing aggregation group.
[0132] Taking the first alarm data stream in the multiple alarm data streams obtained by the alarm aggregation module as an example for illustration. The first alarm data stream can be any one of the multiple alarm data streams obtained by the alarm aggregation module, and a first alarm feature vector can be generated from the first alarm data stream.
[0133] When it is determined that the first alarm data stream belongs to an existing aggregation group (for example, denoted as the first aggregation group), the alarm aggregation module may update the alarm data stream in the first aggregation group, and the updated first aggregation group includes the above-mentioned first alarm data stream; when it is determined that the first alarm data stream does not belong to an existing aggregation group, the alarm aggregation module may further create a new aggregation group (for example, denoted as the second aggregation group) and determine that the first alarm data stream belongs to the second aggregation group.
[0134] Among them, the existing aggregation group may refer to an aggregation group that has been created but not output before the generation of the first alarm feature vector. Usually, the network management system continuously collects alarm data streams for root cause analysis and repair. Therefore, when the alarm aggregation module aggregates the alarm data streams within a certain time window, one or more aggregation groups may have been created in the alarm aggregation module and these aggregation groups have not been output yet. These existing aggregation groups may be, for example, aggregation groups created based on the alarm data streams collected in the previous time window, or aggregation groups created based on the alarm data streams collected in the current time window, and so on. As Figure 5 shown, graphs of different shapes may represent different aggregation groups. Figure 5 The figure shows a situation where multiple existing clustering groups exist in the alarm aggregation module. Each existing aggregation group includes one or more alarm data streams.
[0135] In the embodiments of the present application, each aggregation group may correspond to a class center vector, whether it is an existing aggregation group or a newly created aggregation group. Each aggregation group and its corresponding class center vector may be saved in the alarm aggregation module. Each class center vector may be determined according to the alarm feature vectors corresponding to the alarm data streams of the aggregation group to which it belongs. For example, it may be the average value, weighted sum, etc. of the alarm feature vectors corresponding to the alarm data streams included in the aggregation group to which it belongs. The present application does not make any limitation on this.
[0136] In one implementation, the alarm aggregation module may determine whether the corresponding alarm data stream belongs to an existing aggregation group and which existing aggregation group it belongs to according to the magnitude relationship between the distance of each newly generated alarm feature vector and the class center vectors of the existing aggregation groups. For example, the alarm aggregation module may determine whether the first alarm data stream belongs to an existing aggregation group and which existing aggregation group it belongs to according to the magnitude relationship between the first alarm feature vector and the class center vectors of the existing aggregation groups.
[0137] Exemplarily, a fourth preset threshold is preset in the alarm aggregation module. In a possible situation, the distance between the first alarm feature vector and the class center vectors of one or more existing aggregation groups is less than or equal to the fourth preset threshold. In this case, the alarm aggregation module can determine that the first alarm data stream belongs to an existing aggregation group. If the distances between the class center vectors of multiple existing aggregation groups and the first alarm feature vector are less than or equal to the fourth preset threshold, the existing aggregation group corresponding to the class center vector with the smallest distance from the first alarm feature vector can be selected from the multiple existing aggregation groups as the aggregation group to which the first alarm data stream belongs. For example, the aggregation group to which the first alarm data stream belongs is the first aggregation group. That is, among the existing aggregation groups, the distance between the first alarm feature vector and the class center vector of the first aggregation group is the closest.
[0138] After the alarm aggregation module determines that the first alarm data stream belongs to the first aggregation group, it can further update the class center vector of the first aggregation group. The alarm aggregation module can update the class center vector according to the first alarm feature vector. For example, the average, weighted sum, etc. of the alarm feature vectors of all the alarm data streams (i.e., including the first alarm data stream) after the update of the first aggregation group can be calculated.
[0139] In one implementation, the updated class center vector (for example, denoted as c') and the class center vector before the update (for example, denoted as c) satisfy the following formula: c' = (c × n + v) / (n + 1); where v represents the above-mentioned first alarm feature vector, and n represents the number of other alarm data streams that have been determined to belong to the first aggregation group before the first alarm data stream is determined to belong to the first aggregation group, and n is a positive integer. Since the update of the class center vector will be illustrated with specific examples later, for the sake of brevity, it will not be elaborated here for the time being.
[0140] Another possible situation is that the distance between the first alarm feature vector and the class center vector of any one of the existing aggregation groups is greater than the fourth preset threshold. In this case, the alarm aggregation module can create a new aggregation group based on the generation of the first alarm feature vector, such as the second aggregation group mentioned above.
[0141] After the alarm aggregation module determines the second aggregation group to which the first alarm data stream belongs, it can further determine the class center vector of the second aggregation group. Since the second aggregation group only includes the first alarm data stream at this time, the class center vector of the second aggregation group can be the first alarm feature vector corresponding to the first alarm data stream.
[0142] Subsequently, if new alarm data streams are updated to the second aggregation group, the alarm aggregation module can update the class center vector of the second aggregation group based on the method described in the previous possible situation.
[0143] Among them, the above distance can be, for example, Euclidean distance, Mahalanobis distance, cosine distance, etc. This application does not limit this.
[0144] Based on different types of distances, the corresponding fourth preset threshold can also have different values. For example, when the above distance is Euclidean distance, the above fourth preset threshold can be an empirical value, for example, it can be determined according to the statistical value of historical data. When the above distance is cosine distance, the above fourth preset threshold can take the value of 0.7.
[0145] It should be understood that the above enumeration of distances and the corresponding enumeration of the fourth preset threshold are only examples and should not constitute any limitation to this application.
[0146] It should also be understood that the above method of determining the aggregation group to which the alarm data stream belongs based on the size relationship between the distance between the alarm feature vector and the class center vector and the fourth preset threshold is only an example. For example, it can also be considered by replacing the above greater than the fourth preset threshold and less than or equal to the fourth preset threshold with two cases of greater than or equal to the fourth preset threshold and less than the fourth preset threshold. This application does not limit this. Since the specific implementation process is the same as that described above, for the sake of brevity, it will not be elaborated here.
[0147] It should be noted that there may also be a time when all the aggregation groups of the alarm aggregation module are output. In this case, when generating an alarm feature vector from the alarm data stream obtained in the above step 410, since there is no existing aggregation group, the alarm aggregation module can create an aggregation group based on the first generated alarm feature vector, for example, denoted as the second alarm feature vector, such as the above first aggregation group. The newly created first aggregation group includes the second alarm data stream corresponding to the second alarm feature vector. It can be understood that the second alarm feature vector is generated before the above first alarm feature vector. Or rather, the first alarm feature vector is an alarm feature vector generated after the second alarm feature vector.
[0148] As described above, after the new alarm feature vector is generated and determined to belong to the first aggregation group, the first aggregation group may continue to be updated, and the corresponding class center vector is also updated accordingly. The update of the first aggregation group is: adding a new alarm data stream to the first aggregation group. The update of the class center vector can be: updating the class center vector of the first aggregation group according to the alarm feature vector of the newly added alarm data stream. Since it has been described above, for the sake of brevity, it will not be elaborated here.
[0149] In step 440, based on each alarm data stream determined to belong to the first aggregation group, update the alarm data stream in the first aggregation group until the update of the alarm data stream in the first aggregation group meets the preset conditions; in step 450, output the first aggregation group.
[0150] For ease of understanding and explanation, without loss of generality, the following describes the embodiments by taking the first aggregation group among multiple aggregation groups as an example. The first aggregation group may include one or more alarm data streams, and the category corresponding to the first aggregation group is denoted as the first category.
[0151] In the embodiments of the present application, whenever an alarm data stream is determined to belong to the first aggregation group, the alarm data streams in the first aggregation group are updated, that is, the newly determined alarm data stream belonging to the first aggregation group is added to the first aggregation group. Based on the description of step 430 above, it can be known that the alarm aggregation module determines the belonging aggregation group of each alarm data stream based on the streaming processing framework. With each time an alarm data stream is determined to belong to the first aggregation group, the first aggregation group can be updated once.
[0152] The alarm aggregation module can preset some conditions for outputting the aggregation group. When the update of the alarm data streams in the aggregation group meets the preset conditions, the aggregation group can be output.
[0153] Still taking the first aggregation group as an example below, it will be described in combination with different preset conditions.
[0154] For example, the preset condition is: the update frequency of the first aggregation group is less than a preset threshold (for example, denoted as the first preset threshold).
[0155] The alarm aggregation module can determine the update frequency according to the number of updates and the update duration of the first aggregation group. When the update frequency of the alarm data streams in the first aggregation group is less than the pre-set first preset threshold, the first aggregation group can be output.
[0156] Among them, the update duration can be timed, for example, starting from the creation time of the first aggregation group. For example, a timer can be set to start the timer when the first aggregation group is created. The number of updates can be counted, for example, starting from the time when the first aggregation group is created. For example, a counter can be set, and each time the alarm data streams in the first aggregation group are updated, the count of the counter is incremented by one. It should be understood that the above implementation manners are only examples and should not constitute any limitation to the present application.
[0157] Of course, the preset condition can also be: the update frequency of the first aggregation group is less than or equal to the first preset threshold.
[0158] As another example, the preset condition is: the update duration of the first aggregation group reaches a preset threshold (for example, denoted as the second preset threshold).
[0159] The alarm aggregation module can determine whether to output the first aggregation group according to the magnitude relationship between the update duration of the first aggregation group and the second preset threshold. When the update duration of the first aggregation group reaches the pre-set second preset threshold, the alarm aggregation module can output the first aggregation group.
[0160] The method for determining the update duration of the first aggregation group has been described in detail above. For the sake of brevity, it will not be repeated here.
[0161] As another example, the preset condition is that the number of updates to the first aggregation group reaches a preset threshold (for example, denoted as the third preset threshold).
[0162] The alarm aggregation module can also determine whether to output the first aggregation group based on the magnitude relationship between the number of updates of the first aggregation group and the third preset threshold. When the number of updates of the first aggregation group reaches the preset third preset threshold, the first aggregation group is output.
[0163] It should be understood that the above first preset threshold, second preset threshold, and third preset threshold can respectively set different values for different aggregation groups, or can set the same value for all aggregation groups. This application does not make any limitations in this regard.
[0164] It should also be understood that the alarm aggregation module can save the above output preset threshold, and can independently select a preset condition as the condition for outputting the aggregation group. After determining the preset condition, it can determine whether to update the aggregation group or output the aggregation group according to the corresponding preset threshold.
[0165] It should also be understood that the preset conditions listed above are only examples and should not constitute any limitation to this application. This application does not exclude using other possible preset conditions to determine in what circumstances to output the aggregation group. For example, the preset conditions obtained after transforming or equivalently replacing the preset conditions listed above. For the sake of brevity, they are not listed one by one here.
[0166] As described above, the first aggregation group can be one of at least one aggregation group. For each aggregation group, the alarm aggregation module can determine when to output the aggregation group based on the methods of the above step 440 and step 450.
[0167] To better understand this solution, the following will describe the specific implementation processes of step 430 to step 450 in combination with a specific example.
[0168] Suppose the alarm aggregation module obtains multiple alarm data streams. The multiple alarm data can be counted continuously starting from alarm data stream #1, for example, including alarm data stream #1 to alarm data stream #30. The alarm aggregation module can respectively generate multiple alarm feature vectors based on the multiple alarm data streams. Here, it is assumed that the serial numbers of the alarm feature vectors shown below are sorted in the order of generation of the alarm feature vectors. That is, the alarm feature vectors are in the order of generation: alarm feature vector #1, alarm feature vector #2, alarm feature vector #3 until alarm feature vector #30. For the sake of brevity, they are not listed one by one here.
[0169] First, the alarm aggregation module generates alarm feature vector #1 based on alarm data stream #1. Since this alarm feature vector #1 is the first alarm feature vector generated based on the alarm data stream obtained this time, there may not be any existing aggregation groups in the alarm aggregation module yet, or in other words, no aggregation groups have been created. The alarm aggregation module can create an aggregation group based on alarm feature vector #1, for example, denoted as aggregation group #1. This aggregation group #1 can include alarm data stream #1. The class center vector of this aggregation group #1 can be this alarm feature vector #1.
[0170] Meanwhile, the alarm aggregation module can continue to generate alarm feature vector #2 based on alarm data stream #2, generate alarm feature vector #3 based on alarm data stream #3, and so on, and so forth, which will not be listed one by one here.
[0171] With the generation of alarm feature vector #2, the alarm aggregation module can calculate the distance between alarm feature vector #2 and the class center vector of aggregation group #1. If the distance between the two is greater than the fourth preset threshold, a new aggregation group can be created based on alarm feature vector #2, for example, denoted as aggregation group #2. This aggregation group #2 can include alarm data stream #2. The class center vector of this aggregation group #2 can be this alarm feature vector #2.
[0172] With the generation of alarm feature vector #3, the alarm aggregation module can calculate the distances between alarm feature vector #3 and the class center vector of aggregation group #1 and the class center vector of aggregation group #2 respectively. Suppose the distance between alarm feature vector #3 and the class center vector of aggregation group #1 is greater than the fourth preset threshold, but the distance between alarm feature vector #3 and the class center vector of aggregation group #2 is less than the fourth preset threshold, then the alarm data stream #3 corresponding to this alarm feature vector #3 can belong to aggregation group #2. The alarm aggregation module can add alarm data stream #3 to aggregation group #2. The updated aggregation group #2 can include alarm data stream #2 and alarm data stream #3.
[0173] Since aggregation group #2 has been updated, the class center vector of this aggregation group #2 can also be updated accordingly. The class center vector of this aggregation group #2 was originally alarm feature vector #2. After adding alarm data stream #3 to this aggregation group #2, the class center vector of this aggregation group #2 can be updated to (alarm feature vector #2 + alarm feature vector #3) / 2.
[0174] With the generation of alarm feature vector #4, the alarm aggregation module can calculate the distances between alarm feature vector #4 and the class center vector of aggregation group #1 and the class center vector of aggregation group #2 respectively. It should be understood that the class center vector of aggregation group #2 at this time is the updated class center vector, that is, the above-mentioned (alarm feature vector #2 + alarm feature vector #3) / 2.
[0175] Suppose the distance between the alarm feature vector #4 and the class center vector of aggregation group #1 is less than the fourth preset threshold, and the distance between the alarm feature vector #4 and the class center vector of aggregation group #2 is also less than the fourth preset threshold, then the smaller value of the two can be taken. For example, if the distance between the alarm feature vector #4 and the class center vector of aggregation group #1 is greater than the distance between the alarm feature vector #4 and the class center vector of aggregation group #2, it can be determined that the alarm data stream #4 corresponding to the alarm feature vector #4 also belongs to aggregation group #2. The alarm aggregation module can add the alarm data stream #4 to aggregation group #2. The updated aggregation group #2 can include alarm data stream #2, alarm data stream #3, and alarm data stream #4.
[0176] Since aggregation group #2 has been updated, the class center vector of aggregation group #2 can also be updated accordingly. The original class center vector of aggregation group #2 was (alarm feature vector #2 + alarm feature vector #3) / 2. After adding the alarm data stream #4 to aggregation group #2, the class center vector of aggregation group #2 can be updated to (alarm feature vector #2 + alarm feature vector #3 + alarm feature vector #4) / 3.
[0177] With the generation of the alarm feature vector #5, the alarm aggregation module can calculate the distance between the alarm feature vector #5 and the class center vector of aggregation group #1 and the distance between the alarm feature vector #5 and the class center vector of aggregation group #2 respectively. It should be understood that the class center vector of aggregation group #2 at this time is the updated class center vector, that is, the above (alarm feature vector #2 + alarm feature vector #3 + alarm feature vector #4) / 3.
[0178] Suppose the distances between the alarm feature vector #5 and the class center vectors of both aggregation group #1 and aggregation group #2 are greater than the fourth preset threshold. The alarm aggregation module can newly create an aggregation group based on the alarm feature vector #5, for example, denoted as aggregation group #3. Aggregation group #3 can include alarm data stream #5. The class center vector of aggregation group #3 can be the alarm feature vector #5.
[0179] And so on, the alarm aggregation module can successively aggregate the above-mentioned alarm data streams #1 to #30.
[0180] When the update of the alarm data streams in a certain aggregation group meets the preset conditions, such as the update frequency is less than the first preset threshold, then the aggregation group can be output.
[0181] Based on the same method as above to aggregate multiple alarm data streams, the alarm aggregation module can output one or more aggregation groups.
[0182] The output aggregation group is further subjected to root cause analysis. The root cause analysis module can perform root cause analysis based on the previously output aggregation group to promptly determine the root cause and perform repairs. The subsequent processes of root cause analysis and repair can refer to the prior art and will not be elaborated here for the sake of brevity.
[0183] Based on the above technical solution, in the embodiment of the present application, by adopting a streaming processing framework, for each newly generated alarm feature vector, an aggregation group is determined, and the alarm data stream in the aggregation group is updated based on each determination of the aggregation group. On the one hand, the alarm aggregation module does not have to wait for a batch or a larger number of alarm data streams to arrive before performing alarm aggregation. It can perform the current aggregation calculation while waiting for the generation of the next alarm feature vector. On the other hand, since an aggregation group is determined for each alarm feature vector, compared with a batch or a larger number of alarm data streams, the amount of data calculated each time is smaller, so the calculation time is also shorter. In this way, the time for the alarm aggregation module to aggregate the data stream can be greatly shortened, which is beneficial to improving the efficiency of root cause analysis of the entire network management system.
[0184] In addition, since the alarm data stream includes features in multiple dimensions, it can provide more dimensional information for root cause analysis, which is beneficial to improving the accuracy of root cause analysis and the working effect of the network management system.
[0185] It should be understood that steps 410 to 450 in method 400 can be understood as a specific implementation manner for implementing Figure 3 step 350 in. Before step 410, the network management system can, for example, execute Figure 3 some or all of steps 310 to 340 in. After step 450, the network management system can, for example, execute Figure 3 some or all of steps 360 to 380 in.
[0186] It should also be understood that in the above embodiments, the first, second, and various numerical numbers are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. For example, they can be used to distinguish different alarm data streams, different alarm feature vectors, different aggregation groups, different preset thresholds, etc.
[0187] It should also be understood that in the embodiments of the present application, descriptions such as "in the case of...", "if", and "when" all refer to the situation where the device (such as the alarm aggregation module) will perform corresponding processing under a certain objective situation, and do not limit the time. Moreover, it is not required that the device (such as the alarm aggregation module) must have a judgment action when implementing, nor does it mean that there are other limitations.
[0188] Above, the method for alarm aggregation provided by the embodiments of the present application has been described in detail with reference to multiple accompanying drawings. Below, the apparatus for alarm aggregation provided by the embodiments of the present application will be described in detail with reference to the accompanying drawings.
[0189] Figure 6 FIG. 4 is a schematic block diagram of an alarm aggregation apparatus 600 provided by an embodiment of the present application. As Figure 6 shown, the apparatus 600 may include a processing module 610 and a communication module 620. Among them, the processing module 610 is used to generate an alarm feature vector based on the acquired alarm data stream; and is also used to determine the aggregation group to which the alarm data stream corresponding to each alarm feature vector belongs, where the aggregation group includes a first aggregation group; and is used to update the alarm data streams in the first aggregation group based on each alarm data stream determined to belong to the first aggregation group until the update of the alarm data streams in the first aggregation group meets a preset condition; the communication module 620 is used to output the first aggregation group.
[0190] Optionally, the update of the alarm data streams in the first aggregation group meeting the preset condition is: the update frequency of the alarm data streams in the first aggregation group is less than a first preset threshold.
[0191] Optionally, the update of the alarm data streams in the first aggregation group meeting the preset condition is: the update time of the alarm data streams in the first aggregation group reaches a second preset threshold.
[0192] Optionally, the update of the alarm data streams in the first aggregation group meeting the preset condition is: the update times of the alarm data streams in the first aggregation group reach a third preset threshold.
[0193] Optionally, the processing module 610 is further used to: determine that a first alarm data stream in the acquired alarm data stream belongs to an existing aggregation group, and the existing aggregation group is an aggregation group created before generating a first alarm feature vector based on the first alarm data stream; each existing aggregation group includes one or more alarm data streams; and add the first alarm data stream into the existing aggregation group to which it belongs.
[0194] Optionally, the processing module 610 is further used to: determine the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation group; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; if the distance between an alarm data stream and the class center vectors of at least one existing aggregation group is less than or equal to a fourth preset threshold, determine that the first alarm data stream belongs to the existing aggregation group.
[0195] Optionally, the existing aggregation group includes a first aggregation group; the processing module 610 is further configured to: if the distance between the class center vector of the first aggregation group and the first alarm feature vector is less than the distance between the class center vector of any other existing aggregation group and the first alarm feature vector, determine that the first alarm data stream belongs to the first aggregation group; add the first alarm data stream to the first aggregation group.
[0196] Optionally, the processing module 610 is further configured to update the class center vector of the first aggregation group according to the first alarm feature vector.
[0197] Optionally, the updated class center vector c' and the class center vector c before update satisfy: c' = (c×n + v) / (n + 1); where v represents the first alarm feature vector, and n represents the number of other alarm data streams determined to belong to the first aggregation group before the first alarm data stream is determined to belong to the first aggregation group, and n is a positive integer.
[0198] Optionally, the processing module 610 is further configured to determine that the first alarm data stream in the acquired alarm data streams does not belong to the existing aggregation group, where the existing aggregation group is an aggregation group created before the first alarm feature vector is generated based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; create a second aggregation group, and the second aggregation group includes the first alarm data stream.
[0199] Optionally, the processing module 610 is further configured to: determine the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation group; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; if the distances between the first alarm data stream and the class center vectors corresponding to the aggregation groups in the existing aggregation group are all greater than a fourth preset threshold, determine that the first alarm data stream does not belong to the existing aggregation group.
[0200] Optionally, the processing module 610 is further configured to determine the first alarm feature vector as the class center vector of the second aggregation group.
[0201] Optionally, each alarm data stream includes features of at least one of the following dimensions: topology, alarm name, alarm level, alarm event type, alarm time, and current time.
[0202] It should be understood that the device 600 may correspond to the alarm aggregation module of the alarm aggregation method 300 according to the embodiments of the present application, and the device 600 may include modules for executing the methods executed by the alarm aggregation module in the method 400. And, each module in the device 600 and the above other operations and / or functions are respectively for implementing Figure 4 in the method 400 executed by the alarm aggregation module. Figure 4The corresponding process executed by the alarm aggregation module in Method 400. Since the specific processes of each module executing the above corresponding steps have been described in detail in the method embodiments, for the sake of brevity, they will not be repeated here.
[0203] Figure 7 It is another schematic block diagram of the alarm aggregation device provided by the embodiments of the present application. As Figure 7 shown, the device 700 may include a processor 710, a memory 720, and a communication interface 730.
[0204] The memory 720 may be used to store program codes and data executed by the computer system. Therefore, the memory 720 may be an internal storage unit of the processor 710, an external storage unit independent of the processor 710, or a component including an internal storage unit of the processor 710 and an external storage unit independent of the processor 710.
[0205] The processor 710 may be composed of one or more general-purpose processors. For example, it may be a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in connection with the disclosure of the present application. The processor may also be a combination that implements computing functions, such as a combination of multiple microprocessors, a combination of a DSP and a microprocessor, and so on.
[0206] The processor 710 may be used to run the program codes for the processing functions. That is, the processor 710 executing the program codes can implement the functions of the determination module and the creation module. Among them, for the specific functions of the determination module and the creation module, reference may be made to the relevant descriptions in the foregoing embodiments.
[0207] In a possible implementation manner, the processor 710 is used to run the relevant program codes to implement the functions of the first server in the method embodiments of the present application above, or to implement the method described in steps 410 to 450 shown above in the present application, and / or to implement other steps of the technologies described herein. Details and limitations are not provided here in the present application. Figure 4 shown, and / or to implement other steps of the technologies described herein. Details and limitations are not provided here in the present application.
[0208] The communication interface 730 can be a wired interface (e.g., an Ethernet interface) or a wireless interface (e.g., a cellular network interface or a wireless local area network interface) for communicating with other modules / devices.
[0209] The memory 720 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DRRAM). The memory 720 can also include a combination of the above-mentioned types of memories. It should be noted that the memories of the systems and methods described herein are intended to include but are not limited to these and any other suitable types of memories.
[0210] The memory 720 can be used to store program code so that the processor 710 can call the program code stored in the memory 720 to implement the functions of the communication module and / or the processing module involved in the embodiments of the present invention. When the program code in the memory 720 is executed by the processor 710, the device 700 can be made to execute the method in the method embodiment 300 described above.
[0211] It should be understood that Figure 6 the processing module 610 shown, for example, can correspond to Figure 7 the processor 710 shown, Figure 6 and the communication module 620 shown, for example, can correspond to Figure 7 the communication interface 730 shown.
[0212] The embodiment of the present application also provides a network management system. The network management system may include, for example, the alarm aggregation device 600 shown above Figure 6 or the alarm aggregation device 700 shown Figure 7 above. The device 600 or 700 can be used to implement the functions of the alarm aggregation module shown, for example, Figure 3 above. The network management system may further include a root cause analysis module, which is used to determine the alarm root cause according to the alarm data stream in the first aggregation group output by the device 600 or 700.
[0213] Optionally, the network management system further includes one or more of an alarm collection module, an alarm noise reduction module, a root cause analysis module, and an online feedback module to implement the functions of the above network management system.
[0214] According to the method provided by the embodiment of the present application, the present application also provides a computer program product, which includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute Figure 3 the method executed by the network management system in the embodiment shown above or Figure 4 the method executed by the alarm aggregation module in the embodiment shown above.
[0215] According to the method provided by the embodiment of the present application, the present application also provides a computer-readable medium, which stores program code. When the program code runs on a computer, it causes the computer to execute Figure 3 the method executed by the network management system in the embodiment shown above or Figure 4 the method executed by the alarm aggregation module in the embodiment shown above.
[0216] The alarm aggregation device in each of the above device embodiments corresponds exactly to the alarm aggregation module in the method embodiment. The corresponding module or unit executes the corresponding steps. For example, the communication module (communication interface) executes the steps of receiving or sending in the method embodiment, and other steps except sending and receiving can be executed by the processing module (processor). The functions of specific units can refer to the corresponding method embodiments. Among them, the processor can be one or more.
[0217] As used in this specification, the terms "component", "module", "system", etc. are used to denote computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and the computing device can be components. One or more components can reside in a process and / or an execution thread, and a component can be located on one computer and / or distributed between two or more computers. In addition, these components can execute from various computer-readable media having various data structures stored thereon. A component can communicate, for example, by signals according to one or more data packets (e.g., data from two components interacting with another component local to a system, distributed system, and / or network, such as the Internet interacting with other systems via signals) through local and / or remote processes.
[0218] Those of ordinary skill in the art will appreciate that the various illustrative logical blocks and steps described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints of the technical solution. Skilled artisans may implement the described functionality in different ways for each particular application, but such implementation should not be considered to exceed the scope of this application.
[0219] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0220] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical functional division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0221] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0222] In addition, in each embodiment of the present application, each functional unit may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit.
[0223] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a high-density digital video disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0224] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0225] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A method for alarm aggregation, characterized in that, Including: Generating an alarm feature vector based on the acquired alarm data stream; Determining, based on each alarm feature vector, the aggregation group to which the corresponding alarm data stream belongs, where the aggregation group includes a first aggregation group; Updating the alarm data streams in the first aggregation group based on each alarm data stream determined to belong to the first aggregation group until the update of the alarm data streams in the first aggregation group meets a preset condition; Outputting the first aggregation group; The update of the alarm data streams in the first aggregation group meeting the preset condition includes: The update frequency of the alarm data streams in the first aggregation group is less than a first preset threshold; Or The update time of the alarm data streams in the first aggregation group reaches a second preset threshold; or The update times of the alarm data streams in the first aggregation group reach a third preset threshold.
2. The method according to claim 1, characterized in that, The method further includes: Determining that a first alarm data stream in the acquired alarm data stream belongs to an existing aggregation group, where the existing aggregation group is an aggregation group created before generating a first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; Adding the first alarm data stream to the existing aggregation group to which it belongs.
3. The method according to claim 2, characterized in that The determining that a first alarm data stream in the acquired alarm data stream belongs to an existing aggregation group includes: Determining the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation group; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; If the distance between the first alarm data stream and the class center vector of at least one existing aggregation group is less than or equal to a fourth preset threshold, determining that the first alarm data stream belongs to the existing aggregation group.
4. The method according to claim 3, characterized in that The existing aggregation group includes the first aggregation group, and the method further includes: If the distance between the class center vector of the first aggregation group and the first alarm feature vector is less than the distances between the class center vectors of any other existing aggregation group and the first alarm feature vector, determining that the first alarm data stream belongs to the first aggregation group; The adding the first alarm data stream to the existing aggregation group to which it belongs includes: Adding the first alarm data stream to the first aggregation group.
5. The method according to claim 4, characterized in that, The method further includes: Updating the class center vector of the first aggregation group according to the first alarm feature vector.
6. The method according to claim 5, wherein The updated class center vector c' and the class center vector c before update satisfy: c'=(c×n + v) / (n + 1); where v represents the first alarm feature vector, and n represents the number of other alarm data streams determined to be the first aggregation group before the first alarm data stream is determined to belong to the first aggregation group, and n is a positive integer.
7. The method according to claim 1, characterized in that, The method further includes: Determining that a first alarm data stream in the acquired alarm data stream does not belong to an existing aggregation group, where the existing aggregation group is an aggregation group created before generating a first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; Create a second aggregation group, where the second aggregation group includes the first alarm data stream.
8. The method according to claim 7, wherein The determining that the first alarm data stream in the obtained alarm data streams does not belong to an existing aggregation group includes: Determine the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation groups; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; If the distances between the first alarm data stream and the class center vectors corresponding to the respective aggregation groups in the existing aggregation groups are all greater than a fourth preset threshold, determine that the first alarm data stream does not belong to the existing aggregation groups.
9. The method according to claim 7 or 8, characterized in that, The method further includes: Determine the first alarm feature vector as the class center vector of the second aggregation group.
10. The method according to any one of claims 1 to 8, characterized in that, Each alarm data stream includes features of at least one of the following dimensions: topology, alarm name, alarm level, alarm event type, alarm time, and current time.
11. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Determine the root cause of the alarm according to the alarm data streams in the first aggregation group.
12. An apparatus for alarm aggregation, characterized in that, It includes: A processor, configured to generate an alarm feature vector based on the obtained alarm data streams; And configured to determine the aggregation group to which the corresponding alarm data stream belongs based on each alarm feature vector, where the aggregation group includes the first aggregation group; and is further configured to update the alarm data streams in the first aggregation group based on each alarm data stream determined to belong to the first aggregation group until the update of the alarm data streams in the first aggregation group meets a preset condition; A communication interface, configured to output the first aggregation group; The update of the alarm data streams in the first aggregation group meeting the preset condition includes: The update frequency of the alarm data streams in the first aggregation group is less than a first preset threshold; Or The update time of the alarm data streams in the first aggregation group reaches a second preset threshold; or The update times of the alarm data streams in the first aggregation group reach a third preset threshold.
13. The device according to claim 12, characterized in that, The processor is further configured to: Determine that the first alarm data stream in the obtained alarm data streams belongs to an existing aggregation group, where the existing aggregation group is an aggregation group created before the generation of the first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams Add the first alarm data stream to the existing aggregation group to which it belongs.
14. The device according to claim 13, characterized in that, The processor is further configured to: Determine the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation groups; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; If the distance between the first alarm data stream and the class center vector of at least one existing aggregation group is less than or equal to a fourth preset threshold, determine that the first alarm data stream belongs to the existing aggregation group.
15. The device according to claim 14, wherein The existing aggregation group includes the first aggregation group, and the processor is further configured to: If the distance between the class center vector of the first aggregation group and the first alarm feature vector is less than the distance between the class center vector of any other existing aggregation group and the first alarm feature vector, determine that the first alarm data stream belongs to the first aggregation group; Add the first alarm data stream to the first aggregation group.
16. The device according to claim 15, characterized in that, The processor is further configured to update the class center vector of the first aggregation group according to the first alarm feature vector.
17. The device according to claim 16, characterized in that, The updated class center vector c' and the class center vector c before update satisfy: c' = (c×n + v) / (n + 1); where v represents the first alarm feature vector, and n represents the number of other alarm data streams determined to be the first aggregation group before the first alarm data stream is determined to belong to the first aggregation group, and n is a positive integer.
18. The device according to claim 12, wherein The processor is further configured to: Determine that the first alarm data stream in the obtained alarm data streams does not belong to any existing aggregation group, where the existing aggregation groups are aggregation groups created before generating the first alarm feature vector based on the first alarm data stream, and each existing aggregation group includes one or more alarm data streams; Create a second aggregation group, where the second aggregation group includes the first alarm data stream.
19. The device according to claim 18, wherein The processor is further configured to: Determine the distances between the first alarm feature vector generated based on the first alarm data stream and the class center vectors of each aggregation group in the existing aggregation groups; the class center vector is determined by the alarm feature vectors of the alarm data streams included in the corresponding aggregation group; If the distances between the first alarm data stream and the class center vectors corresponding to the aggregation groups in the existing aggregation groups are all greater than a fourth preset threshold, determine that the first alarm data stream does not belong to the existing aggregation groups.
20. The device according to claim 18 or 19, characterized in that, The processor is further configured to determine the first alarm feature vector as the class center vector of the second aggregation group.
21. The device according to any one of claims 12 to 19, characterized in that, Each alarm data stream includes features of at least one of the following dimensions: topology, alarm name, alarm level, alarm event type, alarm time, and current time.
22. A network management system, including: The device according to any one of claims 12 to 21; And A root cause analysis module, configured to determine the alarm root cause according to the alarm data streams in the first aggregation group output by the device.
23. A computer-readable medium, characterized in that, Including a computer program, when the computer program runs on a computer, causing the computer to execute the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
Alarm classification method and device, electronic device and storage medium
CN110287316A
Alarm data processing method and device, computing device and medium
CN110401567A