A Method and System for Merging Operation and Maintenance Alarm Information in a Data Center

By using a combination of prefix tree and FP-growth correlation analysis algorithm in the data center, the operation and maintenance alarm information is extracted and merged, and the problem that massive operation and maintenance information cannot be effectively aggregated and analyzed is solved, efficient operation and maintenance alarm information management is achieved, and the operation stability of the data center is improved.

CN113849513BActive Publication Date: 2025-05-30CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111131935.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-26
Publication Date
2025-05-30
Estimated Expiration
2041-09-26

AI Technical Summary

Technical Problem

The existing technology cannot effectively aggregate and analyze massive operation and maintenance information, resulting in disordered operation and maintenance alarm information, which brings inconvenience to the daily maintenance work of operation and maintenance personnel and affects the operation stability of the data center.

Method used

The data center operation and maintenance alarm information merging method based on the prefix tree and FP-growth association analysis algorithm is adopted. The main alarm information and alarm details are extracted through the prefix tree, and the FP-growth algorithm is used to extract the association rules between alarm items, generate alarm merging rules, and the alarm details are compressed and merged based on these rules.

Benefits of technology

It effectively aggregates high-level operation and maintenance data representation, reduces low-level invalid operation and maintenance alarm information, improves the work efficiency of operation and maintenance staff, reduces unnecessary fault location and cross-department communication, and improves the stability of the data center.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113849513B_ABST
    Figure CN113849513B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for merging operation and maintenance warning information in a data center. The method includes: collecting various types of operation and maintenance information and uniformly importing them into the data center as original warning information; using a prefix tree to extract the main warning information and its corresponding warning detail data from the original warning information; using the FP-growth algorithm to extract the association rules between warning items in the original warning information to generate warning merging rules; compressing the warning detail data based on the warning merging rules to obtain the merged warning information; and pushing the merged warning information to the warning resending database according to a preset time interval and de-duplication strategy. The present invention conducts warning analysis based on a large amount of operation and maintenance information, aggregates the main information of warning data macroscopically, and compresses the detail data according to the association relationship microscopically, which not only aggregates the high-level operation and maintenance data representation but also reduces the low-level invalid operation and maintenance warning information, and can improve the work efficiency of operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer intelligent operation and maintenance, and particularly relates to a method and system for merging operation and maintenance alarm information in a data center based on a prefix tree and an FP-growth association analysis algorithm. Background Art

[0002] In traditional operation and maintenance scenarios, alarms play a very important role. Operation and maintenance personnel often obtain a series of system alarm information through means such as setting thresholds, historical data analysis, and sensor status acquisition. In actual operation and maintenance scenarios, due to different reasons for failures, different means of obtaining alarms, and different severity levels of alarm information, it directly leads to problems such as clutter, disorder, and structural chaos of operation and maintenance alarm information, bringing great inconvenience to the daily maintenance work of operation and maintenance personnel.

[0003] During the daily operation of a data center, a large amount of operation and maintenance information is generated, collected, and stored. However, there is currently no effective method for aggregating and analyzing operation and maintenance information. Operation and maintenance staff need to spend a lot of time following up and processing a large amount of repetitive, overlapping, or cumulative operation and maintenance information, which not only affects the operation stability of the data center but also poses a potential risk of fault avalanche. Summary of the Invention

[0004] In view of this, the present invention proposes a method and system for merging operation and maintenance alarm information in a data center based on a prefix tree and an FP-growth association analysis algorithm to solve the problem that a large amount of operation and maintenance information cannot be effectively aggregated and analyzed.

[0005] In the first aspect of the present invention, a method for merging operation and maintenance alarm information in a data center is disclosed. The method includes:

[0006] Collect various types of operation and maintenance information and uniformly import them into the data center as original alarm information;

[0007] Use a prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information;

[0008] Use the FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules;

[0009] Compress the alarm detail data based on the alarm merging rules to obtain the merged alarm information;

[0010] Push the merged alarm information to the alarm retransmission database according to a preset time interval and deduplication strategy.

[0011] Preferably, the use of a prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information specifically includes:

[0012] A monitoring tree is constructed in the form of a prefix tree based on all operation and maintenance alarm information of all monitoring items; the prefix tree is established based on the hierarchical division of the original alarm information, and each level represents a dimension;

[0013] Build an alarm tree in the form of a prefix tree based on the abnormal information of all monitoring items;

[0014] Compare the monitoring tree of the prefix tree with the alarm tree, and extract the main alarm information based on the specification results;

[0015] Intelligent merging of alarms based on prefix tree.

[0016] Preferably, the comparison between the monitoring tree based on the prefix tree and the alarm tree and extracting the trunk alarm information specifically includes:

[0017] Compare the monitoring tree with the alarm tree, recursively push upward from the bottom layer to find the source node of each alarm, and save the path information from the root node of the alarm tree to the source node as the reduction result;

[0018] The monitoring tree is calculated from bottom to top layer by layer, with the ratio of normal monitoring items to abnormal monitoring items in the lower nodes under the current node being managed. The nodes whose abnormal ratio exceeds the preset threshold are regarded as historical abnormal alarm information.

[0019] The reduction is performed again from the bottom up until the farthest ancestor node path containing only the root node to the historical abnormal alarm information is obtained;

[0020] The farthest ancestor node path containing only the root node to the historical abnormal alarm information is used as the main alarm information.

[0021] Preferably, the prefix tree-based intelligent merging of alarms specifically includes:

[0022] Prune the alarm tree in the time dimension to complete the initial weight reduction;

[0023] Based on an extensible rule base, the alarm information at each level is counted and merged with the same source to generate a new alarm tree;

[0024] According to the new alarm tree, the main alarm information and the corresponding alarm detail data are obtained.

[0025] Preferably, the extracting association rules between alarm items in the original alarm information using the FP-growth algorithm to generate alarm merging rules specifically includes:

[0026] Use a sliding time window to treat the alarm data that appear in the same time window as a co-occurrence relationship;

[0027] Use the FP-growth algorithm to calculate frequent item sets for object data with co-occurrence relationships and mine association rules between frequent items;

[0028] A directed graph is constructed with alarm items as nodes and association rules as directed and authorized edges, and the connected subgraphs in the directed graph are used as an alarm merging rule.

[0029] Preferably, compressing the detailed data based on the alarm merging rule specifically includes:

[0030] If an original alarm message appears in a node of an alarm merging rule, it is considered that the original alarm message triggers the corresponding alarm merging rule;

[0031] The node with the largest sum of out-degree weights under the corresponding alarm merging rule is used as the representative alarm item of the original alarm information, and the alarm detail data is compressed according to the representative alarm item to obtain the merged alarm data, and the alarm count is accumulated at the same time;

[0032] All compressed alarm detail data are connected to the protocol alarm record by field association and written back to the alarm detail table;

[0033] For alarm items that do not trigger the alarm merging rules, they are directly written back to the alarm detail table and marked with a separate field.

[0034] Preferably, the step of pushing the merged alarm information to the alarm retransmission database according to the preset time interval and deduplication strategy specifically includes:

[0035] A prefix tree is constructed based on the merged alarm data, the historical alarm data that has been pushed but not read by the data center, and the historical alarm data that has been pushed within a certain period of time;

[0036] The alarm data with the same prefix is ​​pruned and deduplicated, the trunk alarm information in the prefix tree is associated with the compressed detailed alarm information, and they are divided into primary and secondary tables and written back into the alarm resending database.

[0037] In a second aspect of the present invention, a data center operation and maintenance alarm information merging system is disclosed, the system comprising:

[0038] Original data import module: collects various operation and maintenance information and imports them into the data center as original alarm information;

[0039] Intermediate data analysis module: Use prefix tree to extract the main alarm information and its corresponding alarm detail data in the original alarm information; use FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules;

[0040] Alarm intelligent merging module: compresses the alarm detail data based on the alarm merging rules to obtain the merged alarm information; pushes the merged alarm information to the alarm retransmission database according to the preset time interval and deduplication strategy.

[0041] In a third aspect of the present invention, an electronic device is disclosed, comprising: at least one processor, at least one memory, a communication interface and a bus; wherein the processor, memory and communication interface communicate with each other via the bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to implement the method described in the first aspect of the present invention.

[0042] According to a fourth aspect of the present invention, a computer-readable storage medium is disclosed, wherein the computer-readable storage medium stores computer instructions, and the computer instructions enable a computer to implement the method described in the first aspect of the present invention.

[0043] Compared with the prior art, the present invention has the following beneficial effects:

[0044] 1) The present invention analyzes and processes alarm information based on massive operation and maintenance information, mines the implicit aggregation and correlation information in the alarm information, extracts the alarm trunk information and alarm detail data, aggregates the trunk information of the alarm data through the prefix tree from a macro perspective, and compresses the correlation relationship mined out by the FP-growth algorithm from a micro perspective. It not only aggregates high-level operation and maintenance data representations, but also reduces low-level invalid operation and maintenance alarm information. It can improve the work efficiency of operation and maintenance staff, reduce unnecessary fault location, fault tracking, cross-departmental personnel communication and other work, and build a new paradigm of digital management of data center operation and maintenance, thereby improving the stability of data centers and surrounding IT infrastructure.

[0045] 2) Based on the existing alarm information, the present invention is based on the OLAP roll-up operation concept of the data cube model. By constructing a prefix tree, the implicit aggregation and association information in the alarm information is mined, and this is used as the basis for merging hierarchical features. For multi-dimensional alarm data, the alarm information with repeated information is merged to realize the layer-by-layer roll-up of the alarm information, ultimately achieving the effect of eliminating useless information, minimizing key alarm information, and not losing valid alarm information.

[0046] 3) In order to tap the potential value of operation and maintenance alarm information and improve the work efficiency of operation and maintenance personnel, the present invention implements an engineered alarm information data analysis method from three angles: alarm merging, alarm deduplication and alarm retransmission, which is used to reduce the amount of invalid information in alarm information, improve information readability and ease of use, and realize a closed loop of alarm information data analysis in all scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0048] Figure 1 Schematic diagram of a method for merging operation and maintenance alarm information in a data center proposed by the present invention;

[0049] Figure 2 Schematic diagram of an alarm tree of the present invention;

[0050] Figure 3 For the present invention Figure 2 Schematic diagram of comparison between the alarm tree and the monitoring tree of the present invention;

[0051] Figure 4 Schematic diagram of extracting alarm merging rules of the present invention;

[0052] Figure 5 Schematic diagram of alarm merging of the present invention;

[0053] Figure 6 Schematic diagram of alarm retransmission of the present invention. Detailed implementation manners

[0054] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in combination with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0055] As Figure 1 shown, the present invention proposes a method for merging operation and maintenance alarm information in a data center, and the method includes:

[0056] S1. Collect various operation and maintenance information and uniformly import it into the data center as the original alarm information;

[0057] Specifically, the operation and maintenance information from different regions, different devices, different software and hardware, etc. is uniformly imported into the data center, and the present invention analyzes and processes the imported information based on this data source;

[0058] S2. Use a prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information;

[0059] Step S2 specifically includes the following sub-steps:

[0060] S21, extracting trunk alarm information by using a monitoring tree and alarm tree comparison algorithm based on a prefix tree;

[0061] For details, please refer to Figure 3 The comparison diagram of the alarm tree and the monitoring tree is shown in FIG. 1 , and step S21 includes the following sub-steps:

[0062] S211. A monitoring tree is constructed in the form of a prefix tree based on all operation and maintenance alarm information of all monitoring items in a certain time window, and an alarm tree is constructed in the form of a prefix tree based on the abnormal information of all monitoring items; the prefix tree is established based on the hierarchical division of the original alarm information, and each level represents a dimension; all operation and maintenance alarm information of all monitoring items includes normal and abnormal alarm information.

[0063] In the data center, operation and maintenance alarm information is often differentiated based on six levels: domain layer, province layer, system layer, system module layer, node layer, and indicator layer. In the most basic indicator layer, the alarm information presents different characteristics, such as abnormal alarms representing whether the terminal is online, middleware offline alarms, and some indicators that can be used for alarm prompts, such as CPU utilization, disk utilization, etc. The present invention is based on the roll-up idea. First, an alarm tree is established for all alarm information based on the above six levels. The alarm tree is easy to manage and can trace the source of the alarm and the corresponding initiating indicator to facilitate subsequent processing. Specifically, the monitoring tree and the alarm tree are constructed in the form of a prefix tree, and each level is a data dimension, such as provinces, cities, districts and counties, software and hardware types, IP addresses, etc. Figure 2 The figure shows a schematic diagram of an alarm tree, where white represents normal alarms and gray represents abnormal alarms.

[0064] S212, compare the monitoring tree of the prefix tree with the alarm tree, recursively deduce from the bottom layer upwards, find the source nodes that generate the respective alarms, and save the path information from the root node of the alarm tree to the source node as the reduction result;

[0065] S213, calculating the ratio of normal monitoring items to abnormal monitoring items in the lower nodes under the current node from the bottom to the top of the monitoring tree, and treating the nodes whose abnormal ratio exceeds the preset threshold as historical abnormal alarm information; and performing reduction again from the bottom to the top until obtaining the farthest ancestor node path containing only the root node to the historical abnormal alarm information;

[0066] S214: Use the farthest ancestor node path that only includes the root node to the historical abnormal alarm information as the main alarm information.

[0067] S22, using an alarm intelligent merging algorithm based on a prefix tree to obtain trunk alarm information and corresponding alarm detail data;

[0068] Specifically, step S22 includes the following sub-steps:

[0069] S221. Prune the alarm tree in the time dimension to complete the initial weight reduction; specifically, "prune" the repeated alarm information within a period of time to simplify the number of alarms and improve the value of the alarm information.

[0070] S222. Based on an extensible rule base, the alarm information of each level is counted and merged with the same source to generate a new alarm tree; the extensible rule base can be different threshold specifications, similar to the specification based on the preset threshold in step S213.

[0071] S223. Obtain the main alarm information and corresponding alarm detail data according to the new alarm tree.

[0072] The new alarm tree contains all the alarms merged at each level, as well as the basic information after the alarms are compressed. Through this intelligent alarm merging algorithm, on the one hand, the number of alarms sent can be greatly reduced, the number of alarms can be reduced, and the operation and maintenance costs can be reduced. On the other hand, it can focus on key node information. For example, if the custom configuration merge level is IP, the merged alarm information can quickly locate the faulty IP and its fault items, making it easier for operation and maintenance personnel to conduct subsequent fault analysis and processing.

[0073] Based on the existing alarm information, the present invention is based on the OLAP roll-up operation concept of the data cube model, and based on the existing alarm information, it mines the implicit aggregation and correlation information in the alarm information, and then uses this as the basis for merging hierarchical features. For multi-dimensional alarm data, such as time, IP, module, region and other dimensions, the alarm information with repeated information volume is merged to realize the layer-by-layer roll-up of the alarm information, and finally achieves the effect of reducing useless information, minimizing key alarm information and not losing effective alarm information.

[0074] S3. Use the FP-growth-based alarm merging rule extraction algorithm to extract alarm merging rules.

[0075] This step uses the FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules. For time series alarm data, the co-occurrence relationship between alarm items can be captured through a dynamic sliding time window, that is, when a certain monitoring item generates an alarm, if other monitoring items also generate alarms within a certain time window, then there may be a potential association relationship between these monitoring items. By analyzing the time series alarm data through the association analysis algorithm, the association rules between alarm items can be extracted from the massive original alarm data to provide support for subsequent analysis.

[0076] Specifically, step S3 includes the following sub-steps:

[0077] S31. Use a sliding time window to consider the alarm data that appears within the same time window as a co-occurrence relationship;

[0078] Specifically, in order to perform correlation analysis on time-series alarm data, the original data needs to be converted into co-occurrence data first, that is, under a certain statistical dimension, different alarm items co-occur under the same statistical caliber. In order to better analyze the correlation relationship between data, the present invention uses a sliding time window to consider the data that appears within the same time window as co-occurrence.

[0079] S32. Use the FP-growth algorithm to calculate the frequent item sets for the object data with co-occurrence relationships, and mine the association rules between the frequent items;

[0080] S33. Construct a directed graph with alarm items as nodes and association rules as directed weighted edges, and use the connected subgraphs in the directed graph as an alarm merging rule.

[0081] Specifically, please refer to the Figure 4 schematic diagram for extracting alarm merging rules as shown. After calculating the association rules between alarm items, construct a directed graph with alarm items as nodes and association rules as directed weighted edges. The degree of association represents the weight, and the connected subgraphs in the directed graph are an alarm merging rule. Figure 4 In the figure are two examples of connected subgraphs, representing two alarm merging rules. Multiple different alarm merging rules form an alarm merging rule group. For a connected subgraph, there is a pointing relationship based on the association rule between all nodes inside the connected subgraph. Calculate the node with the largest sum of out-degree weights as the most representative alarm item under this alarm merging rule, that is, the most fundamental cause of the fault. For example, Figure 4 in the first of the alarm merging rules in the figure, alarm item A is the node with the largest sum of out-degree weights, so alarm item A is the representative alarm item under the first alarm merging rule, that is, the merged item.

[0082] S4. Use an alarm compression algorithm based on the alarm merging rule to compress the alarm detail data to obtain the merged alarm information;

[0083] Specifically, for the alarm merging rules calculated by the above correlation analysis algorithm, for the alarm data after reduction, since the data after reduction represents the indicators of the overall data, each piece of alarm information after reduction contains a large amount of detail data, and it is necessary to compress the details while ensuring that the amount of information is as high as possible. Therefore, this step compresses the alarm detail data based on the alarm merging rule to obtain the merged alarm information.

[0084] Please refer to the Figure 5 schematic diagram of alarm merging. Step S4 specifically includes the following sub-steps:

[0085] S41. If a certain original alarm information has appeared in a node of a certain alarm merging rule, it is considered that the original alarm information has triggered the corresponding alarm merging rule; the node with the largest sum of out-degree weights under the corresponding alarm merging rule is used as the representative alarm item of the original alarm information, and the alarm detail data is compressed according to the representative alarm item to obtain the merged alarm data, and the alarm count is accumulated at the same time;

[0086] S42, connecting all compressed alarm detail data to the protocol alarm record by field association and writing back to the alarm detail table;

[0087] S43. For the alarm items that do not trigger the alarm merging rule, they are directly written back to the alarm detail table and marked with a separate field.

[0088] S5. Use the prefix tree-based alarm retransmission algorithm to retransmit the alarm.

[0089] For a single merged alarm message, if it has been pushed but not read and processed by the data center within a certain period of time, the alarm message needs to be pushed again. Therefore, this step pushes the merged alarm message to the alarm resending database according to the preset time interval and deduplication strategy. Figure 6 Schematic diagram of alarm retransmission, step S5 specifically includes the following sub-steps:

[0090] S51, constructing a prefix tree based on the merged alarm data, the historical alarm data that has been pushed but not read by the data center, and the historical alarm data that has been pushed within a certain period of time;

[0091] S52: Prune and remove duplicates of alarm data with the same prefix, associate the trunk alarm information in the prefix tree with the compressed detailed alarm information, divide them into primary and secondary tables, and write them back into the alarm retransmission database.

[0092] In order to tap the potential value of operation and maintenance alarm information and improve the work efficiency of operation and maintenance personnel, this project has implemented an engineered alarm information data analysis method from three angles: alarm merging, alarm resending and alarm deduplication. It is used to reduce the amount of invalid information in alarm information, improve information readability and ease of use, and realize a closed loop of alarm information data analysis in all scenarios.

[0093] The present invention provides a method and system for merging data center operation and maintenance alarm information based on prefix tree and FP-growth association analysis algorithm. The method and system aggregate the main information of alarm data from a macro perspective, and compress the detailed data according to the association relationship from a micro perspective. It not only aggregates high-level operation and maintenance data representations, but also reduces low-level invalid operation and maintenance alarm information, empowers data center managers and front-line operation and maintenance staff, and builds a new paradigm for digital management of data center operation and maintenance.

[0094] Corresponding to the above method embodiments, the present invention also discloses a system for merging operation and maintenance alarm information in a data center, which includes:

[0095] An original data import module: collecting various operation and maintenance information and uniformly importing it into the data center as original alarm information;

[0096] An intermediate data analysis module: using a prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information; using the FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules;

[0097] An alarm intelligent merging module: compressing the alarm detail data based on the alarm merging rules to obtain the merged alarm information; pushing the merged alarm information to the alarm retransmission database according to a preset time interval and deduplication strategy.

[0098] The above method embodiments and system embodiments correspond one by one. For the brief description of the system embodiments, please refer to the method embodiments, and details will not be repeated here.

[0099] The present invention also discloses an electronic device, which includes: at least one processor, at least one memory, a communication interface, and a bus; wherein, the processor, the memory, and the communication interface complete mutual communication through the bus; the memory stores program instructions executable by the processor, and the processor calls the program instructions to implement the method described above in the present invention.

[0100] The present invention also discloses a computer-readable storage medium, which stores computer instructions, and the computer instructions enable the computer to implement all or part of the steps of the method described in the embodiments of the present invention. The storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories ROM, random access memories RAM, magnetic disks, or optical discs that can store program codes.

[0101] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be distributed to multiple network units. Those of ordinary skill in the art can, without creative efforts, select some or all of the modules according to actual needs to achieve the purpose of the solution of this embodiment.

[0102] The above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for merging data center operation and maintenance alarm information. It is characterized in that The method comprises: Collect various operation and maintenance information and import them into the data center as original alarm information; Use the prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information, including: A monitoring tree is constructed in the form of a prefix tree based on all operation and maintenance alarm information of all monitoring items; the prefix tree is established based on the hierarchical division of the original alarm information, and each level represents a dimension; Build an alarm tree in the form of a prefix tree based on the abnormal information of all monitoring items; Compare the monitoring tree of the prefix tree with the alarm tree, and extract the main alarm information based on the specification results; Intelligent merging of alarms based on prefix tree; Use the FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules; Compress the alarm detail data based on the alarm merging rule to obtain the merged alarm information; The merged alarm information is pushed to the alarm resending database according to the preset time interval and deduplication strategy.

2. According to the data center operation and maintenance alarm information merging method according to claim 1, It is characterized in that The monitoring tree based on the prefix tree is compared with the alarm tree, and the extraction of the main alarm information specifically includes: Compare the monitoring tree with the alarm tree, recursively push upward from the bottom layer to find the source node of each alarm, and save the path information from the root node of the alarm tree to the source node as the reduction result; The monitoring tree is calculated from bottom to top layer by layer, with the ratio of normal monitoring items to abnormal monitoring items in the lower nodes under the current node being managed. The nodes whose abnormal ratio exceeds the preset threshold are regarded as historical abnormal alarm information. The reduction is performed again from the bottom up until the farthest ancestor node path containing only the root node to the historical abnormal alarm information is obtained; The farthest ancestor node path containing only the root node to the historical abnormal alarm information is used as the main alarm information.

3. According to the data center operation and maintenance alarm information merging method according to claim 2, It is characterized in that The prefix tree-based intelligent merging of alarms specifically includes: Prune the alarm tree in the time dimension to complete the initial weight reduction; Based on an extensible rule base, the alarm information at each level is counted and merged with the same source to generate a new alarm tree; According to the new alarm tree, the main alarm information and the corresponding alarm detail data are obtained.

4. According to the data center operation and maintenance alarm information merging method according to claim 1, It is characterized in that The extracting association rules between alarm items in the original alarm information by using the FP-growth algorithm and generating alarm merging rules specifically includes: Use a sliding time window to treat the alarm data that appear in the same time window as a co-occurrence relationship; Use the FP-growth algorithm to calculate frequent item sets for object data with co-occurrence relationships and mine association rules between frequent items; A directed graph is constructed with alarm items as nodes and association rules as directed and authorized edges, and the connected subgraphs in the directed graph are used as an alarm merging rule.

5. According to the data center operation and maintenance alarm information merging method according to claim 4, It is characterized in that The compressing of detailed data based on the alarm merging rule specifically includes: If an original alarm message appears in a node of an alarm merging rule, it is considered that the original alarm message triggers the corresponding alarm merging rule; The node with the largest sum of out-degree weights under the corresponding alarm merging rule is used as the representative alarm item of the original alarm information, and the alarm detail data is compressed according to the representative alarm item to obtain the merged alarm data, and the alarm count is accumulated at the same time; All compressed alarm detail data are connected to the protocol alarm record by field association and written back to the alarm detail table; For alarm items that do not trigger the alarm merging rules, they are directly written back to the alarm detail table and marked with a separate field.

6. According to the data center operation and maintenance alarm information merging method according to claim 5, It is characterized in that The step of pushing the merged alarm information to the alarm retransmission database according to the preset time interval and deduplication strategy specifically includes: A prefix tree is constructed based on the merged alarm data, the historical alarm data that has been pushed but not read by the data center, and the historical alarm data that has been pushed within a certain period of time; The alarm data with the same prefix is ​​pruned and deduplicated, the trunk alarm information in the prefix tree is associated with the compressed detailed alarm information, and they are divided into primary and secondary tables and written back into the alarm resending database.

7. A data center operation and maintenance alarm information merging system, It is characterized in that The system comprises: Original data import module: collects various operation and maintenance information and imports them into the data center as original alarm information; Intermediate data analysis module: Use prefix tree to extract the main alarm information and its corresponding alarm detail data in the original alarm information; use FP-growth algorithm to extract the association rules between alarm items in the original alarm information and generate alarm merging rules; The use of the prefix tree to extract the main alarm information and its corresponding alarm detail data from the original alarm information specifically includes: A monitoring tree is constructed in the form of a prefix tree based on all operation and maintenance alarm information of all monitoring items; the prefix tree is established based on the hierarchical division of the original alarm information, and each level represents a dimension; Build an alarm tree in the form of a prefix tree based on the abnormal information of all monitoring items; Compare the monitoring tree of the prefix tree with the alarm tree, and extract the main alarm information based on the specification results; Intelligent merging of alarms based on prefix tree; Alarm intelligent merging module: compresses the alarm detail data based on the alarm merging rules to obtain the merged alarm information; pushes the merged alarm information to the alarm retransmission database according to the preset time interval and deduplication strategy.

8. An electronic device, It is characterized in that include: at least one processor, at least one memory, a communication interface, and a bus; Wherein, the processor, memory, and communication interface communicate with each other via the bus; The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to implement the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions enable a computer to implement the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Alarm processing method and device, equipment and medium

    CN109951306A

  • Alarm fusion system and method based on data center anomaly monitoring

    CN110399278A