An alarm information processing method and device
By automatically processing alarm information of online production services, identifying the source of alarms and performing corresponding actions, the problems of low efficiency and high cost of alarm processing in the existing technology are solved, and safe and standardized alarm processing is achieved.
Patent Information
- Application Number
- CN202011118151.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-10-19
AI Technical Summary
In the prior art, after an alarm occurs in online production services, the processing efficiency is low, the cost is high, and manual processing is prone to errors, which may cause secondary accidents.
By receiving business performance alarm information, identifying the source of the alarm, calling the alarm analysis model to generate event objects, querying the associated alarm rule configuration, obtaining execution programs, and performing corresponding actions on the business system to automatically process alarms.
Automatic and standardized alarm processing is realized, reducing manual errors, avoiding secondary accidents, and reducing processing costs.
Smart Images

Figure CN114090397B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method and apparatus for processing warning information. Background Art
[0002] When a warning occurs in an online production service, developers are notified through instant messages, and then the developers analyze the warning information and process it according to personal experience.
[0003] In the process of implementing the present invention, the inventors found that there are at least the following problems in the prior art:
[0004] Currently, all services in the online production service are monitored for warnings manually in real time all day long, resulting in high personnel costs. Even if manual attention can be timely, from analyzing the warning, troubleshooting the warning to processing the warning according to experience, the time consumption varies from person to person, and the processing process is also different, resulting in untimely warning handling and thus causing the problem to expand. At the same time, manual processing is prone to errors, and under the urgent high pressure of online warnings, manual operations are more likely to make mistakes, thus causing secondary accidents. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method and apparatus for processing warning information, which can solve the problems of low processing efficiency and high cost after a warning occurs in the existing online production service.
[0006] To achieve the above object, according to one aspect of the embodiments of the present invention, there is provided a method for processing warning information, including receiving business performance warning information, identifying the source of the business performance warning information, and then calling a corresponding warning parsing model to generate an event object; according to the event object, querying the associated warning rule configuration, obtaining the execution program corresponding to the warning rule configuration, and then performing corresponding actions on the business system to complete the processing of the business performance warning information.
[0007] Optionally, receiving business performance warning information includes:
[0008] Accessing different monitoring systems through corresponding preset protocol interfaces to receive business performance warning information from different sources.
[0009] Optionally, calling a corresponding warning parsing model to generate an event object includes:
[0010] Calling a corresponding warning parsing model, obtaining the target attribute value in the business performance warning information; and then encapsulating the target attribute value to generate an event object.
[0011] Optionally, according to the event object, querying the associated warning rule configuration, obtaining the execution program corresponding to the warning rule configuration includes:
[0012] Parse the event object, obtain the monitoring system identifier in the target attribute value, and query to obtain the alarm rule configuration associated with the event object;
[0013] Parse the alarm rule configuration, obtain the execution rule configuration that matches the alarm rule configuration, so as to obtain the corresponding execution program.
[0014] Optionally, after parsing the alarm rule configuration, it includes:
[0015] Based on the preset alarm configuration, extract the target attribute value encapsulated in the event object;
[0016] Judge whether the relationship between the extracted target attribute values conforms to the alarm rule configuration. If so, obtain the execution rule configuration that matches the alarm rule configuration. If not, generate a message indicating that the alarm rule configuration trigger fails.
[0017] Among them, the alarm rule configuration refers to the relationship between multiple alarm configurations.
[0018] Optionally, after obtaining the execution rule configuration that matches the alarm rule configuration, it includes:
[0019] Obtain the execution actions included in the execution rule configuration;
[0020] Judge whether the trigger switch of the execution action is in the on state. If so, obtain the corresponding execution program. If not, generate a message indicating that the execution program trigger fails.
[0021] Optionally, after obtaining the execution program corresponding to the alarm rule configuration, and then performing corresponding actions on the business system, it includes:
[0022] Obtain the execution program corresponding to the alarm rule configuration, and call the corresponding interface of the development platform to perform corresponding actions on the business system.
[0023] In addition, the present invention also provides an alarm information processing device, including:
[0024] An alarm parsing module, configured to receive business performance alarm information, identify the source of the business performance alarm information, and then call the corresponding alarm parsing model to generate an event object;
[0025] A rule parser, configured to query the associated alarm rule configuration according to the event object, and obtain the execution program corresponding to the alarm rule configuration;
[0026] An executor, configured to perform corresponding actions on the business system to complete the processing of the business performance alarm information.
[0027] One embodiment of the above invention has the following advantages or beneficial effects: By adapting to access the monitoring system (such as UMP, MDC, Raytheon, etc.), when a notification is triggered on the alarm platform, the system automatically parses the alarm and quickly executes actions such as offline and downgrade according to the prefabricated handling actions, so as to solve the problems in the prior art that manual attention to alarms is required all day long in real time, the traffic of alarm information processing varies from person to person and there is no unified standard, manual processing is not timely, and there are manual misoperations. Thus, the present invention realizes automated and standardized alarm processing, avoids manual handling errors, and avoids secondary accidents.
[0028] The further effects of the above non-conventional optional methods will be described below in combination with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings are used to better understand the present invention and do not constitute an improper limitation of the present invention. Among them:
[0030] Figure 1 is a schematic diagram of the main process of the alarm information processing method according to the first embodiment of the present invention;
[0031] Figure 2 is a schematic diagram of the main process of the alarm information processing method according to the second embodiment of the present invention;
[0032] Figure 3 is a schematic diagram of the framework of the alarm information processing method according to the embodiment of the present invention;
[0033] Figure 4 is a schematic diagram of the main modules of the alarm information processing device according to the first embodiment of the present invention;
[0034] Figure 5 is a schematic diagram of the main modules of the alarm information processing device according to the second embodiment of the present invention;
[0035] Figure 6 is a schematic diagram of the rule configuration module according to the embodiment of the present invention;
[0036] Figure 7 is a schematic diagram of the alarm parsing module according to the embodiment of the present invention;
[0037] Figure 8 is a schematic diagram of the rule parser according to the embodiment of the present invention;
[0038] Figure 9 is a schematic diagram of the actuator according to the embodiment of the present invention;
[0039] Figure 10 is an exemplary system architecture diagram to which the embodiment of the present invention can be applied;
[0040] Figure 11 It is a schematic structural diagram of a computer system of a terminal device or a server suitable for implementing the embodiments of the present invention. Detailed implementation manners
[0041] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.
[0042] Figure 1 It is a schematic diagram of the main process of the alarm information processing method according to the first embodiment of the present invention, as Figure 1 shown. The alarm information processing method includes:
[0043] Step S101, receive service performance alarm information, identify the source of the service performance alarm information, and then call the corresponding alarm parsing model to generate an event object.
[0044] In some embodiments, different monitoring systems are accessed through corresponding preset protocol interfaces to receive service performance alarm information from different sources. For example: access the Ump monitoring system by providing an Http protocol interface to receive service performance alarm information of the Ump monitoring system. Therefore, it can be seen that this embodiment enables the present invention to integrate different monitoring systems, that is, to be applied to different monitoring systems, receive service performance alarm information from different sources, and thus greatly improves the adaptability and usability of the alarm information processing method.
[0045] In some other embodiments, calling the corresponding alarm parsing model to generate an event object, the specific implementation process includes: calling the corresponding alarm parsing model, obtaining the target attribute value in the service performance alarm information, and then encapsulating the target attribute value to generate an event object. For example: encapsulate target attribute values such as application name, monitoring system identification key, specified IP, contact person, etc. in the service performance alarm information into the Event event object.
[0046] That is to say, the present invention can receive alarm information from different monitoring system sources, and at the same time, for the alarm parsing service, it is customized separately according to different source types, that is, different parsing is implemented for alarm information from different monitoring system sources, realizing the high compatibility and flexibility of the present invention.
[0047] Step S102: Query the associated alarm rule configuration according to the event object, obtain the execution program corresponding to the alarm rule configuration, and then perform corresponding actions on the business system to complete the processing of the business performance alarm information.
[0048] In some embodiments, querying the associated alarm rule configuration according to the event object and obtaining the execution program corresponding to the alarm rule configuration, the specific implementation process includes:
[0049] Parse the event object to obtain the monitoring system identifier in the target attribute value, and query the alarm rule configuration associated with the event object. Then, parse the alarm rule configuration to obtain the execution rule configuration that matches the alarm rule configuration to obtain the corresponding execution program. For example: query the associated alarm rule configuration through the monitoring system identifier Key in the Event event object, and then obtain the corresponding execution rule configuration through the alarm rule configuration, that is, obtain a set of multiple executors with an execution order. Different executors correspond to different execution actions, and the execution rule configuration includes a set of actions to be executed in sequence.
[0050] It can be seen that the unique identifier included in the event object can be associated with the corresponding alarm rule configuration, that is, different events can adopt different alarm rule configurations to execute the event, thereby realizing the configurability of execution, and maximizing the flexibility and execution effect.
[0051] In a further embodiment, after parsing the alarm rule configuration, the target attribute value encapsulated in the event object can be extracted based on a preset alarm configuration. Then, determine whether the relationship between the extracted target attribute values conforms to the alarm rule configuration. If so, obtain the execution rule configuration that matches the alarm rule configuration. If not, generate a message indicating that the alarm rule configuration trigger fails. Among them, the alarm rule configuration refers to the relationship between multiple alarm configurations. Therefore, a message can also be sent for notification when the alarm rule configuration association of the event fails.
[0052] In another further embodiment, after obtaining the execution rule configuration that matches the alarm rule configuration, the execution actions included in the execution rule configuration can be obtained. Then, determine whether the trigger switch of the execution action is in the on state. If so, obtain the corresponding execution program. If not, generate a message indicating that the execution program trigger fails.
[0053] It can be seen that in this embodiment of the present invention, a trigger switch is set for the execution actions in the execution rule configuration, and the execution actions can be adjusted according to the application scenario and usage conditions to meet different execution needs.
[0054] It should be noted that to obtain the execution program corresponding to the alarm rule configuration, the corresponding interface of the development platform can be called to perform corresponding actions on the business system. For example: by accessing the offline action interface of the JSF development platform and passing in the specified IP in the Event event object, the offline action is performed on the business system. Among them, JavaServer Faces (JSF) is a standard framework for building Java Web applications.
[0055] Figure 2 It is a schematic diagram of the main process of the alarm information processing method according to the second embodiment of the present invention. The alarm information processing method may include:
[0056] Step S201, access different monitoring systems through corresponding preset protocol interfaces to receive business performance alarm information from different sources.
[0057] Step S202, call the corresponding alarm parsing model to obtain the target attribute value in the business performance alarm information, and then encapsulate the target attribute value to generate an event object.
[0058] Step S203, parse the event object, obtain the monitoring system identifier in the target attribute value, and query the alarm rule configuration associated with the event object.
[0059] Step S204, parse the alarm rule configuration, and extract the target attribute value encapsulated in the event object based on the preset alarm configuration.
[0060] Step S205, determine whether the relationship between the extracted target attribute values conforms to the alarm rule configuration. If so, go to step S206; if not, go to step S207.
[0061] Step S206, obtain the execution rule configuration matching the alarm rule configuration, obtain the execution action included in the execution rule configuration, and go to step S208.
[0062] Step S207, generate a message indicating that the alarm rule configuration trigger fails, and exit this process.
[0063] Step S208, determine whether the trigger switch of the execution action is in the on state. If so, go to step S209; if not, go to step S210.
[0064] Step S209, obtain the execution program corresponding to the alarm rule configuration, call the corresponding interface of the development platform, and perform corresponding actions on the business system.
[0065] Step S210, generate a message indicating that the execution program trigger fails, and exit this process.
[0066] Figure 3It is a schematic structural diagram of an alarm information processing method according to an embodiment of the present invention. The monitoring platform integrates various monitoring systems, such as the UMP monitoring system, the MDC monitoring system, and the thor monitoring system. Different monitoring systems are accessed through corresponding preset protocol interfaces to receive business performance alarm information from different sources. For the business performance alarm information of different monitoring systems, the corresponding alarm parsing model is called to obtain the target attribute values in the business performance alarm information, and then the target attribute values are encapsulated to generate an event object. For example, the target attributes parsed from the business performance alarm information of the UMP monitoring system include performance, availability, call count, etc. Of course, the target attributes can also be customized.
[0067] The event object is parsed by a rule parser to obtain the monitoring system identifier in the target attribute value, and the alarm rule configuration associated with the event object is queried. The alarm rule configuration is parsed to obtain the execution rule configuration that matches the alarm rule configuration, so as to obtain the corresponding execution program. The execution rule configuration includes a set of action sets that are executed in sequence, that is, a set of executors with an execution order is obtained, and different executors correspond to different execution actions. The configuration center of the executor can set the trigger switch and some configurable settings, and can customize the interface API with the development platform and the message queue MQ for transmitting execution instructions through the interface API. Preferably, the execution instructions are transmitted in the form of Cookies. And the business system corresponding to the business performance alarm information can be built on top of the development platform.
[0068] Figure 4 It is a schematic diagram of the main modules of an alarm information processing device according to an embodiment of the present invention, as Figure 4 shown, the alarm information processing device 400 includes an alarm parsing module 401, a rule parser 402, and an executor 403. Among them, the alarm parsing module 401 receives business performance alarm information, identifies the source of the business performance alarm information, and then calls the corresponding alarm parsing model to generate an event object; the rule parser 402 queries the associated alarm rule configuration according to the event object to obtain the execution program corresponding to the alarm rule configuration; the executor 403 performs corresponding actions on the business system to complete the processing of the business performance alarm information.
[0069] As other embodiments, as Figure 5 shown, the alarm information processing device 400 further includes a rule configuration module 404. Among them, the rule configuration module 404 can perform preset settings on the alarm configuration, the alarm rule configuration, and the execution rule configuration. As Figure 6 shown, the rule configuration module 404 includes an alarm configuration, an alarm rule configuration, and an execution rule configuration.
[0070] Among them, the alarm configuration includes information such as alarm type, alarm data, alarm cycle frequency, etc. Preferably, the alarm baseline rule can be configured through the page, that is, only when the target attribute value encapsulated in the event object matches the corresponding alarm configuration (that is, meets the corresponding alarm configuration), can it be recognized as an alarm. And the rule configuration refers to configuring the relationship between multiple alarm configurations and matching the corresponding execution rule configuration. The relationship between the target attribute values encapsulated in the event object needs to conform to the rule configuration to be recognized as an alarm. The execution rule configuration includes a set of action sets executed in sequence (for example: take down the specified JSF instance and send a downgrade instruction to MQ), that is, the relationship configuration of multiple executors. That is, each execution action corresponds to an executor, and the execution rule configuration includes a set of multiple executors with an execution order.
[0071] It should be noted that subsequently, by quickly expanding alarms (such as CPU, memory, performance, etc.) and executors (such as taking down the line, GC, current limiting, downgrading, etc.), during the operation process, when alarms or problems such as increased CPU, increased memory, and poor performance occur, corresponding rules can be configured to trigger execution actions such as taking down the device, GC, current limiting, and downgrading, ensuring that the service is instantly restored or avoiding greater problems from occurring, so as to achieve the preprocessing effect.
[0072] In some embodiments, the alarm parsing module 401 receives service performance alarm information, including: accessing different monitoring systems through corresponding preset protocol interfaces to receive service performance alarm information from different sources.
[0073] In some embodiments, the alarm parsing module 401 calls the corresponding alarm parsing model to generate an event object, including: calling the corresponding alarm parsing model to obtain the target attribute value in the service performance alarm information; and then encapsulating the target attribute value to generate an event object.
[0074] Preferably, as Figure 7 shown, the alarm parsing module 401 can provide functions such as alarm monitoring, receiving, parsing, and triggering the rule parser 402 to execute. By accessing the monitoring system (such as the UMP) platform, detection of preset metrics (such as detection of server usage rate) can be performed. Additionally, alarm listening can be used to receive alarm information from the monitoring system. And call the alarm parsing model corresponding to the monitoring system, parse based on the alarm configuration to obtain the target attribute value in the service performance alarm information, and then encapsulate the target attribute value to generate an event object.
[0075] In some embodiments, the rule parser 402 queries the associated alarm rule configuration according to the event object, and obtains the execution program corresponding to the alarm rule configuration, including: parsing the event object, obtaining the monitoring system identifier in the target attribute value, and querying to obtain the alarm rule configuration associated with the event object; parsing the alarm rule configuration, obtaining the execution rule configuration matching the alarm rule configuration, so as to obtain the corresponding execution program.
[0076] In some embodiments, after the rule parser 402 parses the alarm rule configuration, it includes: extracting the target attribute value encapsulated in the event object based on the preset alarm configuration; determining whether the relationship between the extracted target attribute values conforms to the alarm rule configuration, if so, obtaining the execution rule configuration matching the alarm rule configuration, if not, generating a message indicating that the alarm rule configuration trigger fails; wherein, the alarm rule configuration refers to the relationship between multiple alarm configurations.
[0077] In some embodiments, after the rule parser 402 obtains the execution rule configuration matching the alarm rule configuration, it includes: obtaining the actuator included in the execution rule configuration; determining whether the trigger switch of the actuator is in the on state, if so, obtaining the execution program corresponding to the execution rule configuration, if not, generating a message indicating that the execution program trigger fails.
[0078] That is to say, as Figure 8 shown, the rule parser 402 can provide the parsing and matching capabilities of alarm configuration, alarm rule configuration, and execution rule configuration.
[0079] In some embodiments, the actuator 403 can call the corresponding interface of the development platform to perform corresponding actions on the business system.
[0080] Preferably, as Figure 9 shown, the actuator 403 includes action management such as parsing and offline of execution rules, GC, flow limiting, restarting, or degradation. By accessing the corresponding interface API for offline of the instance of the development platform (such as the JSF development platform), the actuator is enabled to have the ability to offline the specified IP instance. And through the API of the internal action management, the service integration (JSF service integration) of calling the action management to offline the specified IP instance is realized.
[0081] It should be noted that there is a corresponding relationship in the specific implementation content between the alarm information processing method and the alarm information processing device of the present invention, so the repeated content will not be described again.
[0082] Figure 10 An exemplary system architecture 1000 is shown to which the alarm information processing method or the alarm information processing device of the embodiments of the present invention can be applied.
[0083] AsFigure 10 As shown, the system architecture 1000 may include terminal devices 1001, 1002, 1003, a network 1004, and a server 1005. The network 1004 is used to provide a medium for communication links between the terminal devices 1001, 1002, 1003 and the server 1005. The network 1004 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0084] Users can use the terminal devices 1001, 1002, 1003 to interact with the server 1005 through the network 1004 to receive or send messages, etc. Various communication client applications may be installed on the terminal devices 1001, 1002, 1003.
[0085] The terminal devices 1001, 1002, 1003 may be various electronic devices having an alarm information processing screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop portable computers, and desktop computers, etc.
[0086] The server 1005 may be a server that provides various services, such as a background management server (only for example) that supports users using the terminal devices 1001, 1002, 1003. The background management server may analyze and process data such as product information query requests received, and feedback the processing results (such as target push information, product information - only for example) to the terminal devices.
[0087] It should be noted that the alarm information processing method provided by the embodiments of the present invention is generally executed by the server 1005. Correspondingly, the computing device is generally disposed in the server 1005.
[0088] It should be understood that Figure 10 the numbers of terminal devices, networks, and servers in
[0089] are merely illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers.
[0089] Next, refer to Figure 11 , which shows a schematic structural diagram of a computer system 1100 of a terminal device suitable for implementing the embodiments of the present invention. Figure 11 The terminal device shown is merely an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present invention.
[0090] As Figure 11As shown, computer system 1100 includes a central processing unit (CPU) 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage section 1108 into a random access memory (RAM) 1103. In the RAM 1103, various programs and data required for the operation of the computer system 1100 are also stored. The CPU 1101, ROM 1102, and RAM 1103 are connected to each other via a bus 1104. An input / output (I / O) interface 1105 is also connected to the bus 1104.
[0091] The following components are connected to the I / O interface 1105: an input section 1106 including a keyboard, a mouse, etc.; an output section 1107 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1108 including a hard disk, etc.; and a communication section 1109 including a network interface card such as a LAN card, a modem, etc. The communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the I / O interface 1105 as needed. A removable medium 1111, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1110 as needed so that a computer program read from it can be installed into the storage section 1108 as needed.
[0092] Specifically, according to an embodiment disclosed by the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment disclosed by the present invention includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1109, and / or installed from the removable medium 1111. When the computer program is executed by a central processing unit (CPU) 1101, the above functions defined in the system of the present invention are executed.
[0093] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0095] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an alarm parsing module, a rule parser, and an executor. Among them, the names of these modules do not constitute a limitation to the module itself in some cases.
[0096] As another aspect, the present invention further provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist alone without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device is caused to include receiving service performance alarm information, identifying the source of the service performance alarm information, and then invoking a corresponding alarm parsing model to generate an event object; according to the event object, querying the associated alarm rule configuration, obtaining the execution program corresponding to the alarm rule configuration, and then performing corresponding actions on the service system to complete the processing of the service performance alarm information.
[0097] According to the technical solution of the embodiments of the present invention, the problems of low processing efficiency and high cost after an alarm occurs in the existing online production service can be solved.
[0098] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for processing alarm information, characterized in that, it includes: Receiving service performance alarm information, identifying the source of the service performance alarm information, and then invoking the corresponding alarm parsing model to obtain the target attribute value in the service performance alarm information to generate an event object; According to the event object, querying the associated alarm rule configuration, obtaining the execution program corresponding to the alarm rule configuration, and then performing corresponding actions on the service system to complete the processing of the service performance alarm information; wherein, the alarm rule configuration refers to the relationship between multiple alarm configurations, and obtaining the execution program corresponding to the alarm rule configuration includes: Parsing the alarm rule configuration, extracting the target attribute value encapsulated in the event object based on the preset alarm configuration; judging whether the relationship between the extracted target attribute values conforms to the alarm rule configuration, if so, obtaining the execution rule configuration matching the alarm rule configuration to obtain the corresponding execution program, if not, generating a message indicating that the alarm rule configuration trigger fails.
2. The method according to claim 1, characterized in that, Receiving service performance alarm information includes: Accessing different monitoring systems through corresponding preset protocol interfaces to receive service performance alarm information from different sources.
3. The method according to claim 1, characterized in that, Generating the event object includes: Generating an event object by encapsulating the target attribute value.
4. The method according to claim 3, characterized in that, According to the event object, querying the associated alarm rule configuration includes: Parsing the event object, obtaining the monitoring system identifier in the target attribute value, and querying to obtain the alarm rule configuration associated with the event object.
5. The method according to claim 1, characterized in that, After obtaining the execution rule configuration matching the alarm rule configuration, it includes: Obtaining the execution actions included in the execution rule configuration; Judging whether the trigger switch of the execution action is in the on state, if so, obtaining the corresponding execution program, if not, generating a message indicating that the execution program trigger fails.
6. The method according to any one of claims 1-5, characterized in that, Obtaining the execution program corresponding to the alarm rule configuration and then performing corresponding actions on the service system includes: Obtaining the execution program corresponding to the alarm rule configuration, and invoking the corresponding interface of the development platform to perform corresponding actions on the service system.
7. An alarm information processing device, characterized in that, it includes: An alarm parsing module for receiving service performance alarm information, identifying the source of the service performance alarm information, and then invoking the corresponding alarm parsing model to obtain the target attribute value in the service performance alarm information to generate an event object; A rule parser for querying associated alarm rule configurations according to the event object and obtaining the execution program corresponding to the alarm rule configuration; wherein, the alarm rule configuration refers to the relationship between multiple alarm configurations, and obtaining the execution program corresponding to the alarm rule configuration includes: parsing the alarm rule configuration, extracting the target attribute values encapsulated in the event object based on the preset alarm configuration; determining whether the relationship between the extracted target attribute values conforms to the alarm rule configuration, if so, obtaining the execution rule configuration matching the alarm rule configuration to obtain the corresponding execution program, if not, generating a message indicating that the alarm rule configuration trigger fails; An executor for performing corresponding actions on the business system to complete the processing of the business performance alarm information.
8. An electronic device, Characterized in that, Comprising: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-6.
9. A computer-readable medium having a computer program stored thereon, Characterized in that, The program, when executed by a processor, implements the method according to any one of claims 1-6.
Citation Information
Patent Citations
Alarm information processing method and system, computer device and readable storage medium
CN110096410A
Fault processing method and device based on network alarm association
CN110247792A