Multi-dimensional intelligent alarm compression method based on time series

Through a multi-dimensional intelligent alarm compression method based on time series, root cause analysis and resource/professional group compression technology are used to solve the problem of being unable to quickly locate the root cause of the alarm and effectively compress the alarm in the existing technology, and the effect of quickly identifying the root cause of the fault and reducing the processing cost is achieved.

CN114090319BActive Publication Date: 2025-06-27SHANGHAI SNC NET INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111388842.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-22
Publication Date
2025-06-27
Estimated Expiration
2041-11-22

AI Technical Summary

Technical Problem

The prior art is difficult to quickly locate the root cause relationship between multiple alarms, and cannot effectively compress and reduce noise alarms, resulting in high fault processing time cost.

Method used

The multi-dimensional intelligent alarm compression method based on time series is adopted to perform multi-dimensional compression through root cause analysis, resource type and professional groups, mark the root cause results of the alarm, and merge or generate new events to reduce the amount of alarms.

Benefits of technology

By displaying the correlation between alarms, operation and maintenance personnel can quickly identify the root cause of the fault, reduce the amount of alarms, reduce the processing time cost, and improve the alarm recovery efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114090319B_ABST
    Figure CN114090319B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-dimensional intelligent alarm compression method based on time series, which includes the following steps: when a new alarm is generated, read all alarm data within a set time period; obtain the correlation relationship between alarms through root cause analysis, and locate the root cause triggered by the related alarms; according to the root cause analysis result, merge and compress the alarms or generate new events; compress the alarms that cannot be compressed according to the root cause analysis result according to the resource type; for the alarms lacking the resource type or not meeting the resource type compression, compress them according to the professional group; repeat the above steps to compress and merge the subsequent generated alarms into relevant events or generate new events. The present invention identifies the root cause result of the alarm through the root cause algorithm, and displays the correlation relationship between alarms, which is convenient for the operation and maintenance personnel to quickly identify the root cause of the fault; compresses the alarms through multiple dimensions, reduces the alarm volume, reduces the time cost of alarm processing, and improves the efficiency of alarm recovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an alarm compression method, and particularly to a multi-dimensional intelligent alarm compression method based on time series. Background Art

[0002] With the increasing popularity of cloud computing and big data technologies, the rapid development of distributed technologies, the call levels between business systems are getting deeper and the call relationships are becoming increasingly complex. When a business system fails, it is impossible to quickly and accurately locate the root cause of the failure from a large number of alarms.

[0003] Most of the current solutions on the market perform intelligent compression on alarms according to technical parameters such as device association relationships, alarm times, and durations. The current technical solutions have the following problems: 1. It is impossible to find the root cause relationship between multiple alarms, unable to quickly locate the cause of the failure, and unable to achieve the purpose of intelligent compression and intelligent noise reduction; 2. It is impossible to effectively ensure the smooth progress of the business process through the alarm scheduling process, increasing the time cost loss of personnel analyzing alarms and restoring alarms. Therefore, an alarm compression method that can locate the root cause of the failure and ensure the business processing process is needed. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a multi-dimensional intelligent alarm compression method based on time series, which performs multi-dimensional intelligent compression on alarms through root cause analysis, resource types or professional groups, reducing the number of alarms and facilitating the operation and maintenance personnel to quickly identify the root cause of the failure.

[0005] The technical solution adopted by the present invention to solve the above technical problem is to provide a multi-dimensional intelligent alarm compression method based on time series, including the following steps: S1: When an alarm is generated, read all alarm data within a set time period; S2: Obtain the association relationship between each alarm through root cause analysis, locate the root cause of the alarms with an association relationship; and mark the alarm root cause analysis result on each alarm; S3: According to the root cause analysis result, merge and compress the alarms or generate a new event; S4: Compress the alarms that cannot be compressed according to the root cause analysis result according to the resource type; S5: For the alarms lacking resource types or not meeting the resource type compression, compress them according to the professional group; S6: Repeat steps S1-S5 to compress and merge the subsequent generated alarms into relevant events or generate new events.

[0006] Further, the step S2 includes: S21: Obtain the root cause link between alarms through root cause analysis of the fault knowledge graph and root cause analysis of curve waveform similarity; S22: Define alarm roles according to the root cause link, including suspect alarms, victim alarms, independent alarms, and mass alarms; The suspect alarm is the root cause alarm of the alarm or fault; The victim alarm is the alarm generated by the influence of the root cause alarm; The independent alarm is the alarm that cannot be determined as a suspect alarm or a victim alarm through root cause analysis; The mass alarm is an independent alarm that exists for a long time due to a fault in the application system.

[0007] Further, the alarm compression according to the root cause analysis result in the step S3 includes: S31: Immediately create a suspect event when a suspect alarm occurs; S32: Merge the victim alarm into the associated suspect event after the victim alarm occurs; S33: After the victim alarm has been incorporated into the suspect event, if there are other associated suspect events, the victim alarm will be automatically associated with the other suspect events at the same time; S34: When an independent alarm occurs, generate a new event or wait for subsequent compression processing.

[0008] Further, for the independent alarms that cannot be compressed according to the root cause analysis result in the step S4, an event is generated when the first independent alarm occurs. When subsequent independent alarms occur, the alarm will be incorporated into the independent alarm event of the same resource if the following conditions are met at the same time, otherwise a new event will be generated or wait for subsequent compression processing: S41: The occurrence time of the independent alarm of the same resource type is within the delay time T1 from the occurrence time of the previous alarm; S42: The occurrence time of the independent alarm of the same resource type is within the time range T2 from the occurrence time of the first alarm.

[0009] Further, when the equivalent resource type rule is configured for the identification of the same resource type, alarms with different actual resource types can be equated to the same resource type and identified as the same resource type; If the equivalent resource type rule is not configured, the identification is performed according to the actual resource type of itself.

[0010] Further, the alarms lacking the resource type or not meeting the resource type compression conditions in the step S5 are defined as difficult-to-compress alarms. A new event is generated when the first difficult-to-compress alarm occurs. When subsequent difficult-to-compress alarms occur, the difficult-to-compress alarms will be incorporated into the event of the same professional group if the following conditions are met at the same time, otherwise a new event will be generated: S51: The occurrence time of the difficult-to-compress alarm of the same professional group is within the delay time T3 from the occurrence time of the previous alarm; S52: The occurrence time of the difficult-to-compress alarm of the same professional group is within the time range T4 from the occurrence time of the first alarm.

[0011] Further, the root cause analysis of the fault knowledge graph includes: creating an impact model based on the CMDB configuration model, defining the influencing factors of each configuration item in the CMDB configuration model through AND / OR relationships, setting the trigger conditions for the influencing factors, where the trigger conditions include not triggering, all unavailable, and at least one unavailable; and deriving and calculating the root cause relationship through the influencing factors between alarms.

[0012] Further, the root cause analysis of the curve waveform similarity identifies the root cause role by analyzing the waveform similarity of the performance data of two alarm metrics, including obtaining the performance data of two alarm metrics within a time period, calculating the waveform similarity of the two performance curves, and when the similarity reaches or exceeds the preset similarity standard, it is considered that there is a potential influence relationship between the two metrics. Then, according to the alarm occurrence priority principle, the earlier-occurring alarm is identified as the suspect alarm, and the later-occurring alarm is identified as the victim alarm.

[0013] The present invention has the following beneficial effects compared with the prior art: The multi-dimensional intelligent alarm compression method based on time series provided by the present invention identifies the root cause results of alarms through the root cause algorithm, displays the association relationships between alarms, which is convenient for operation and maintenance personnel to quickly identify the root cause of faults; compresses alarms through multiple dimensions, reduces the number of alarms, reduces the time cost of alarm processing, and improves the efficiency of alarm recovery. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 is a flowchart of the multi-dimensional intelligent alarm compression method based on time series in an embodiment of the present invention;

[0015] Figure 2 is a schematic diagram of resource role analysis for root cause analysis of the fault knowledge graph in an embodiment of the present invention;

[0016] Figure 3 is a waveform diagram of the performance data of alarm metrics for root cause analysis of curve waveform similarity in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The present invention will be further described below with reference to the drawings and embodiments.

[0018] Figure 1 is the process of the multi-dimensional intelligent alarm compression method based on time series in an embodiment of the present invention.

[0019] Please refer to Figure 1 , the multi-dimensional intelligent alarm compression method based on time series in an embodiment of the present invention includes the following steps:

[0020] S1: When an alarm is generated, read all alarm data within a set time period; the initial time setting is 10 minutes, which can be changed according to needs.

[0021] S2: Obtain the correlation relationships between various alarms through root cause analysis, locate the root causes triggered by the correlated alarms; and mark the alarm root cause analysis results on each alarm.

[0022] S21: Obtain the root cause link between alarms through root cause analysis of the fault knowledge graph and root cause analysis of curve waveform similarity.

[0023] The root cause analysis of the fault knowledge graph includes: creating an impact model based on the CMDB (Configuration Management Database) configuration model, defining the influencing factors of each configuration item in the CMDB configuration model through AND / OR relationships, setting the trigger conditions for the influencing factors, where the trigger conditions include no trigger, all unavailable, and at least one unavailable; and deducing and calculating the root cause relationship through the influencing factors between alarms.

[0024] According to the configuration model, create an impact model of resources. Use the impact model to take a certain resource as the impact source, traverse the resource objects associated with this resource to determine whether this resource has an impact on its associated resource objects. When this resource is unavailable, if all or at least one of its associated resource objects are unavailable, it means there is an impact; classify the associated resource objects according to the judgment results. Those with no impact are classified into the mass data set Q1; those with impact and being the cause of the impact are classified into the suspect data set P1; those with impact and being the affected are classified into the victim data set S1; as Figure 2 shown.

[0025] Through the above analysis of the resource impact relationship, assign roles to resources to obtain suspect, victim, and mass data. In the result of a single fault root cause analysis, a single resource will only have one role; then, according to the association between alarms and resources, convert the impact relationship between resources into the impact relationship between alarms; define the alarm roles.

[0026] The root cause analysis of curve waveform similarity identifies the root cause role by analyzing the waveform similarity of the performance data of two alarm indicators, including taking the performance data of two alarm indicators within a time period, calculating the waveform similarity of the two performance curves, and when the similarity reaches or exceeds the preset similarity standard, it is considered that there is a potential impact relationship between these two indicators. Then, according to the alarm occurrence priority principle, the earlier-occurring alarm is identified as the suspect alarm, and the later-occurring alarm is identified as the victim alarm. As Figure 3 shown, Curve 1 represents the CPU usage rate, Curve 2 represents the memory usage rate, then the CPU alarm is the suspect alarm, and the memory alarm is the victim alarm.

[0027] S22: Define alarm roles according to the root cause link, including suspect alarms, victim alarms, independent alarms, and mass alarms; suspect alarms are the root alarms for alarms or faults; victim alarms are the alarms generated due to the influence of root alarms; independent alarms are alarms that cannot be determined as suspect alarms or victim alarms through root cause analysis; mass alarms are independent alarms that exist for a long time due to application system failures.

[0028] S3: According to the root cause analysis results, merge and compress alarms or generate new events;

[0029] Alarm compression according to the root cause analysis results includes:

[0030] S31: Immediately create a suspect event when a suspect alarm occurs;

[0031] S32: Merge the victim alarm into the associated suspect event after it is generated;

[0032] After the victim alarm has been incorporated into the suspect event, if there are other associated suspect events generated, the victim alarm will be automatically associated with the other suspect events at the same time;

[0033] S34: When an independent alarm occurs, generate a new event or wait for subsequent compression processing.

[0034] When the event status is pending processing, pending escalation, processed, or suspended, the above incorporation and association rules are supported.

[0035] For alarms that cannot be compressed based on the root cause analysis results, compress them according to the resource type; for independent alarms that cannot be compressed based on the root cause analysis results, generate an event when the first independent alarm occurs. When subsequent independent alarms occur, if the following conditions are met at the same time, incorporate the alarms into the independent alarm event of the same resource, otherwise generate a new event or wait for subsequent compression processing:

[0036] S41: The occurrence time of independent alarms of the same resource type is within the delay time T1 from the previous alarm;

[0037] S42: The occurrence time of independent alarms of the same resource type is within the time range T2 from the occurrence time of the first alarm.

[0038] For the identification of the above same resource types, when the equivalent resource type rule is configured, alarms with different actual resource types can be equated to the same resource type and identified as the same resource type; if the equivalent resource type rule is not configured, identify them according to their actual resource types.

[0039] The delay time T1 and the time range T2 can be set according to requirements. When the event status is pending processing, pending escalation, processed, or suspended, the above incorporation rules are supported.

[0040] S5: For alarms lacking resource types or not meeting the resource type compression requirements, compress them according to professional groups; there is an attribution relationship between alarm data and professional groups, and according to this attribution relationship, each alarm has an attributed professional group; define alarms lacking resource types or not meeting the resource type compression conditions as difficult-to-compress alarms. Generate a new event when the first difficult-to-compress alarm occurs. When subsequent difficult-to-compress alarms occur and the following conditions are met simultaneously, incorporate the difficult-to-compress alarms into the event of the same professional group, otherwise generate a new event:

[0041] S51: The time between the occurrence of difficult-to-compress alarms in the same professional group and the previous alarm is within the delay time T3;

[0042] S52: The time between the occurrence of difficult-to-compress alarms in the same professional group and the first alarm is within the time range T4.

[0043] The delay time T3 and the time range T4 can be set according to requirements. When the event status is pending processing, pending escalation, processed, or suspended, the above incorporation rules are supported.

[0044] S6: Repeat steps S1 - S5 to compress and merge subsequent alarms into relevant events or generate new events.

[0045] In summary, the multi-dimensional intelligent alarm compression method based on time series in the embodiments of the present invention identifies the root cause results of alarms through the root cause algorithm, displays the association relationships between alarms, facilitating the operation and maintenance personnel to quickly identify the root cause of faults; compresses alarms through multiple dimensions, reduces the number of alarms, reduces the time cost of alarm processing, and improves the efficiency of alarm recovery.

[0046] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications and improvements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be defined by the claims.

Claims

1. A multi-dimensional intelligent alarm compression method based on time series, characterized in that, It includes the following steps: S1: When a new alarm is generated, read all alarm data within a set time period; S2: Obtain the correlation relationships between various alarms through root cause analysis, locate the root causes triggered by the correlated alarms; and mark the alarm root cause analysis results on each alarm; S3: According to the root cause analysis results, merge and compress the alarms or generate new events; S4: Compress the alarms that cannot be compressed according to the root cause analysis results by resource type; S5: Compress the alarms lacking resource type or not meeting the resource type compression by professional group; S6: Repeat steps S1 - S5 to merge and compress the subsequent generated alarms into relevant events or generate new events; The step S2 includes: S21: Obtain the root cause link between alarms through root cause analysis of the fault knowledge graph and root cause analysis of curve waveform similarity; S22: Define alarm roles according to the root cause link, including suspect alarms, victim alarms, independent alarms, and mass alarms; A suspect alarm is the root cause alarm of an alarm or a fault; A victim alarm is an alarm generated due to the influence of the root cause alarm; An independent alarm is an alarm that cannot be determined as a suspect alarm or a victim alarm through root cause analysis; A mass alarm is an independent alarm that exists for a long time due to a fault in the application system; The root cause analysis of the fault knowledge graph includes: creating an impact model according to the CMDB configuration model, defining the influencing factors of each configuration item in the CMDB configuration model through AND / OR relationships, setting the trigger conditions of the influencing factors, and the trigger conditions include not triggering, all unavailable, and at least one unavailable; deriving and calculating the root cause relationship through the influencing factors between alarms; The root cause analysis of curve waveform similarity identifies the root cause role by analyzing the waveform similarity of the performance data of two alarm indicators, including obtaining the performance data of two alarm indicators within a time period, calculating the waveform similarity of the two performance curves, and when the similarity reaches or exceeds the preset similarity standard, it is considered that there is a potential influence relationship between the two indicators, and then according to the alarm occurrence priority principle, the earlier occurring alarm is identified as the suspect alarm and the later occurring alarm is identified as the victim alarm.

2. The multi-dimensional intelligent alarm compression method based on time series according to claim 1, characterized in that The alarm compression in step S3 according to the root cause analysis results includes: S31: Immediately create a suspect event when a suspect alarm is generated; S32: Merge the victim alarm into the associated suspect event after it is generated; S33: After the victim alarm has been incorporated into the suspect event, if there are other associated suspect events generated, the victim alarm will be automatically associated with the other suspect events at the same time; S34: When an independent alarm is generated, generate a new event or wait for subsequent compression processing.

3. The multi-dimensional intelligent alarm compression method based on time series according to claim 2, wherein For the independent alarms that cannot be compressed according to the root cause analysis results in step S4, an event is generated when the first independent alarm is generated, and when subsequent independent alarms are generated, the alarms will be incorporated into the independent alarm event of the same resource if the following conditions are met at the same time, otherwise a new event is generated or wait for subsequent compression processing: S41: The occurrence time of the independent alarm of the same resource type is within the delay time T1 from the previous alarm; S42: The occurrence time of the independent alarm of the same resource type is within the time range T2 from the occurrence time of the first alarm.

4. The multi-dimensional intelligent alarm compression method based on time series according to claim 3, characterized in that, When the rule of equivalent resource types is configured, the alarm with a different actual resource type can be equated to the same resource type and recognized as the same resource type; if the rule of equivalent resource types is not configured, it is recognized according to its actual resource type.

5. The multi-dimensional intelligent alarm compression method based on time series according to claim 3, wherein In step S5, the alarm lacking a resource type or not meeting the resource type compression condition is defined as a difficult-to-compress alarm. When the first difficult-to-compress alarm occurs, a new event is generated. When subsequent difficult-to-compress alarms occur, the difficult-to-compress alarms are incorporated into the event of the same professional group when the following conditions are met simultaneously, otherwise a new event is generated: S51: The occurrence time of the difficult-to-compress alarm of the same professional group is within the delay time T3 from the occurrence time of the previous alarm; S52: The occurrence time of the difficult-to-compress alarm of the same professional group is within the time range T4 from the occurrence time of the first alarm.

Citation Information

Patent Citations

  • Root alarm analysis and recognition method based on data mining

    CN106250288A