Alarm information processing method and device, storage medium and electronic equipment
By determining the monitoring area to which the network equipment belongs in the system and using event analyzer to process the alarm information, generating formatted data and alarm types, the problem that traditional alarm information processing methods cannot adapt to the needs of different regions is solved, and the system expansion and management efficiency is improved.
Patent Information
- Application Number
- CN202111614869.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2041-12-27
AI Technical Summary
The traditional alarm information processing method cannot meet the processing needs of different regions. As the system expands, management efficiency is inefficient and cannot adapt to the diverse alarm information processing needs.
By obtaining the alarm information of the network device, determining the monitoring area it belongs to, and sending it to the corresponding event analyzer, the trigger event analyzer processes it based on the pre-configured alarm processing rules, generates formatted data and alarm types, and sends it to the corresponding message queue and alarm device.
It realizes that different alarm processing rules are used in different monitoring areas to meet the needs of system expansion, improve management efficiency and adaptability, and supports diversified alarm information processing.
Smart Images

Figure CN114265751B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of alarm technology, and in particular to an alarm information processing method and device, a storage medium and an electronic device. Background Art
[0002] With the development of 5G, software-defined access networks, and core network technologies, more and more companies are shifting their businesses and related work from offline to online. Monitoring the performance and faults of network equipment in the system, sending alarms to operations and maintenance personnel, and enabling them to maintain the network equipment in the system in a timely manner are one of the necessary means to ensure the stable operation of enterprise systems.
[0003] Currently, when processing the system's alarm information, the entire system usually uses the same processing rules. However, as the system continues to expand and the system covers a wider range, the traditional alarm information processing method cannot meet the processing needs of different regions. Therefore, there is an urgent need for an alarm information processing method that meets the needs of different regions. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide an alarm information processing method and apparatus, a storage medium, and an electronic device. The present invention supports applying different alarm information processing methods to multiple areas in a system to achieve diversified message processing.
[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:
[0006] A first aspect of the present invention discloses a method for processing alarm information, comprising:
[0007] Obtain alarm information sent by network devices;
[0008] Determining the monitoring area to which the network device belongs, and sending the alarm information to an event analyzer corresponding to the monitoring area;
[0009] Triggering the event analyzer to process the alarm information based on pre-configured alarm processing rules, obtain formatted data of the alarm information and the alarm type, and send the formatted data to a message queue paired with the event analyzer;
[0010] The message queue is triggered to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation.
[0011] In the above method, optionally, determining the monitoring area to which the network device belongs includes:
[0012] Parsing the warning information to obtain the area identifier in the warning information;
[0013] The area identifier is compared with the area identification code of each monitoring area, and the monitoring area with the same area identification code as the area identifier is used as the monitoring area to which the network device belongs.
[0014] Optionally, in the above method, the triggering of the event analyzer to process the alarm information based on a pre-configured alarm processing rule to obtain formatted data of the alarm information and the alarm type includes:
[0015] Parsing the alarm information based on the parsing rules in the alarm processing rules to obtain parsed information;
[0016] Based on the data format requirements in the parsing rules, the parsed information is formatted to obtain formatted data of the alarm information;
[0017] Based on the alarm classification information in the alarm processing rule, the formatted data is analyzed to determine the alarm type of the alarm information.
[0018] The above method optionally includes configuring alarm processing rules for each event analyzer, including:
[0019] Identify each event analyzer;
[0020] Allocating a message queue to each of the event analyzers;
[0021] Determining an alarm processing rule for each event analyzer based on the alarm requirements of the monitoring area to which each event analyzer belongs;
[0022] The alarm processing rules of each event analyzer are configured to each event analyzer through the message queue of each event analyzer.
[0023] The above method may optionally further include:
[0024] Determining a region code and a rule identification code for each of the event analyzers;
[0025] generating a queue name of a message queue of each event analyzer based on the region code and rule identification code of each event analyzer;
[0026] Generate a mapping dictionary table based on each queue name.
[0027] A second aspect of the present invention discloses an alarm information processing device, comprising:
[0028] An acquisition unit, configured to acquire alarm information sent by a network device;
[0029] a first determining unit, configured to determine a monitoring area to which the network device belongs, and send the alarm information to an event analyzer corresponding to the monitoring area;
[0030] a triggering unit, configured to trigger the event analyzer to process the alarm information based on a pre-configured alarm processing rule, obtain formatted data of the alarm information and an alarm type, and send the formatted data to a message queue paired with the event analyzer;
[0031] The sending unit is configured to trigger the message queue to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation.
[0032] In the above device, optionally, the first determining unit includes:
[0033] an acquiring subunit, configured to parse the alarm information and acquire the area identifier in the alarm information;
[0034] The comparison subunit is configured to compare the area identifier with an area identification code of each monitoring area, and use the monitoring area with the same area identification code as the area identifier as the monitoring area to which the network device belongs.
[0035] In the above device, optionally, the trigger unit includes:
[0036] a parsing subunit, configured to parse the alarm information based on the parsing rules in the alarm processing rules to obtain parsed information;
[0037] a processing subunit, configured to format the parsed information based on the data format requirements in the parsing rules to obtain formatted data of the alarm information;
[0038] The analyzing subunit is configured to analyze the formatted data based on the alarm classification information in the alarm processing rule to determine the alarm type of the alarm information.
[0039] The above device may optionally further include:
[0040] A second determining unit, configured to determine each event analyzer;
[0041] an allocating unit, configured to allocate a message queue to each of the event analyzers;
[0042] a third determining unit, configured to determine an alarm processing rule for each of the event analyzers based on an alarm requirement of a monitoring area to which each of the event analyzers belongs;
[0043] A configuration unit is used to configure the alarm processing rules of each event analyzer to each event analyzer through the message queue of each event analyzer.
[0044] The above device may optionally further include:
[0045] a fourth determining unit, configured to determine a region code and a rule identification code of each of the event analyzers;
[0046] a first generating unit, configured to generate a queue name of a message queue of each event analyzer based on a region code and a rule identification code of each event analyzer;
[0047] The second generating unit is configured to generate a mapping dictionary table based on each queue name.
[0048] A third aspect of the present invention discloses a storage medium, which includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the alarm information processing method as described above.
[0049] A fourth aspect of the present invention discloses an electronic device comprising a memory and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to execute the alarm information processing method as described above.
[0050] Compared with the prior art, the present invention has the following advantages:
[0051] The present invention provides an alarm information processing method and device, a storage medium, and an electronic device. The method includes: obtaining alarm information sent by a network device; determining the monitoring area to which the network device belongs, and sending the alarm information to an event analyzer corresponding to the monitoring area; triggering the event analyzer to process the alarm information based on an alarm processing rule, obtain formatted data of the alarm information and the alarm type, and send the formatted data to a message queue paired with the event analyzer; triggering the message queue to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation. After receiving the alarm information sent by the network device, the monitoring area to which the alarm device belongs is determined, and the alarm information is sent to the event analyzer in the monitoring area, so that the event analyzer processes the alarm information, obtains formatted data and the alarm type, and sends the formatted data to the message queue corresponding to the event analyzer, so that the message queue sends the formatted data to the alarm device corresponding to the alarm type. By using the alarm processing rules in the event processor to process the alarm information, different alarm processing rules can be configured in different event processors, so that different monitoring areas can use different information processing methods, thereby meeting the needs of continuous expansion of the system and using different processing methods in different areas. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0053] Figure 1 A flowchart of a method for processing alarm information provided by an embodiment of the present invention;
[0054] Figure 2 A flow chart of a method for determining a monitoring area to which a network device belongs provided by an embodiment of the present invention;
[0055] Figure 3 A flow chart of a method for processing alarm information by an event analyzer provided in an embodiment of the present invention;
[0056] Figure 4 A flow chart of a method for configuring alarm processing rules for each event analyzer provided in an embodiment of the present invention;
[0057] Figure 5 A schematic diagram of the structure of an alarm information processing device provided by an embodiment of the present invention;
[0058] Figure 6 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0059] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0060] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0061] With the development of 5G, software-defined access networks, and core network technologies, large enterprises are increasingly deploying a growing number of network devices with increasing complexity and variety. Monitoring network infrastructure is becoming increasingly crucial. Traditionally, IBM NetCool products have been used for network device performance and fault monitoring. However, as IT scale has expanded, NetCool has encountered numerous issues in terms of product functionality, technical support, and business operations. For example, NetCool only supports the issuance of alarm rules for a single region, which, in the long term, lacks scalability and reduces management efficiency.
[0062] This invention primarily addresses the network equipment monitoring business for large enterprises. This involves monitoring various types of network equipment, ensuring the secure and stable operation of enterprise systems, and assisting operations personnel in promptly identifying and resolving network failures and restoring production. Through modules such as message queues and event analyzers, this invention supports multi-region alarm rule isolation and corresponding alarm generation.
[0063] The present invention can be used in a variety of general-purpose or special-purpose computing device environments or configurations, such as personal computers, server computers, handheld or portable devices, tablet devices, multi-processor devices, and distributed computing environments including any of the above.
[0064] An embodiment of the present invention provides an alarm information processing method, which can be applied to an alarm processing system. The alarm processing system can be constructed by a plurality of general or special computing devices.
[0065] Reference Figure 1 , is a flowchart of a method for processing alarm information provided by an embodiment of the present invention, and is specifically described as follows:
[0066] S101. Acquire alarm information sent by a network device.
[0067] The alarm system receives alarm information sent by network devices. It should be noted that the alarm system can receive alarm information sent by multiple network devices. The alarm system is used to monitor the performance of network devices.
[0068] The alarm system of the present invention can monitor network devices in different areas, and the network devices include but are not limited to computer terminals and devices that provide business support to users.
[0069] After generating the alarm information, the network device sends the alarm information to the alarm protocol based on the pre-configured communication data, where the communication data may include the communication protocol used and the communication address of the alarm system, such as the TCP / IP protocol, NetBEUI protocol, and folded IPX / SPX protocol.
[0070] Alarm information can be information generated when a network device fails to operate, or it can be information generated when a network device makes an error in processing a service.
[0071] S102: Determine the monitoring area to which the network device belongs, and send alarm information to an event analyzer corresponding to the monitoring area.
[0072] After receiving the alarm information sent by the network device, you need to determine the monitoring area to which the network device belongs. Figure 2 , which is a flow chart of a method for determining the monitoring area to which a network device belongs, is specifically described as follows:
[0073] S201: Analyze the alarm information to obtain the area identifier in the alarm information.
[0074] The area identifier in the alarm information is used to indicate the monitoring area to which the network device belongs. It should be noted that the area identifiers of the network devices in the same monitoring area are the same.
[0075] The alarm information includes but is not limited to the area identifier and the specific data for the alarm.
[0076] S202: Compare the area identifier with the area identification code of each monitoring area, and use the monitoring area with the same area identification code as the area identifier as the monitoring area to which the network device belongs.
[0077] The obtained area identification is compared with the area identification code of each monitoring area in the area identification list to obtain the area identification code that is the same as the area identification. The monitoring area corresponding to the area identification code that is the same as the area identification is the monitoring area to which the network device belongs.
[0078] In the method provided in an embodiment of the present invention, the monitoring area to which the network device belongs is determined by using the area identifier in the alarm information, and the area identifier in the alarm information is compared with the area identification code of each monitoring area, so that the monitoring area to which the network device belongs can be accurately determined, so as to facilitate subsequent processing of the alarm information.
[0079] After determining the monitoring area to which the network device belongs, the alarm information is sent to the event analyzer corresponding to the monitoring area. It should be noted that the event analyzer is a device that processes alarm information. Each monitoring area has a corresponding event analyzer. Therefore, the alarm devices in different monitoring areas can be processed and analyzed by different event analyzers, and different event analyzers can be set with different information processing methods, thereby realizing the use of different information processing methods in different areas and realizing the supervision of networks in multiple areas.
[0080] S103 : Trigger the event analyzer to process the alarm information based on pre-configured alarm processing rules, obtain formatted data of the alarm information and the alarm type, and send the formatted data to a message queue paired with the event analyzer.
[0081] Reference Figure 3 , which is a flow chart of a method for processing alarm information by an event analyzer provided in an embodiment of the present invention, and is specifically described as follows:
[0082] S301. Analyze alarm information based on analysis rules in alarm processing rules to obtain analysis information.
[0083] The event analyzer is pre-configured with alarm processing rules. The alarm information is parsed according to the data parsing rules in the alarm processing rules, and the alarm data in the alarm information is used as parsing information. The parsing information includes but is not limited to the specific alarm cause, alarm time, and various device parameters when the network device generates the alarm information.
[0084] It should be noted that the parsing rules in different alarm processing rules may be different. Specifically, for example, some parsing rules require decryption, while some parsing rules do not require decryption.
[0085] S302: Format the parsed information based on the data format requirements in the parsing rules to obtain formatted data of the alarm information.
[0086] The data format requirements in different parsing rules may be different. For example, some parsing rules require that the data be converted into binary, JSON, XML, etc.
[0087] After formatting the parsed information according to the data format requirements, formatted data that meets the data format requirements can be obtained.
[0088] By formatting the parsed information, data that meets the data format requirements is obtained to facilitate subsequent processing.
[0089] S303: Analyze the formatted data based on the alarm classification information in the alarm processing rule to determine the alarm type of the alarm information.
[0090] The alarm classification information includes the specific contents of various alarm types. Based on the alarm classification information, the formatted data is analyzed to determine the alarm type of the alarm information.
[0091] Furthermore, different alarm types require different alarm operations. Some alarm types do not meet the maintenance requirements, while some alarm types require maintenance by operation and maintenance personnel, and some alarm types can be automatically repaired.
[0092] After determining the alarm type of the alarm information, the formatted data is sent to the message queue paired with the event analyzer. It should be noted that each event analyzer has a paired message queue, and the message queues of each event analyzer are paired in advance.
[0093] S104: The trigger message queue sends the formatted data to the alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation.
[0094] After the formatted data is sent to the message queue, the message queue is triggered to send the formatted data to the alarm device corresponding to the alarm type based on the alarm type of the alarm information, so that the alarm device performs the corresponding alarm operation. For example, when the alarm type is a high-risk alarm, the formatted data can be sent to the corresponding alarm device for notifying the operation and maintenance personnel, so that the alarm device notifies the corresponding operation and maintenance personnel, so that the operation and maintenance personnel can repair the network equipment; for example, when the alarm type is a business error alarm, the formatted data can be sent to the corresponding alarm device for initialization, so that the alarm device initializes the automatic repair operation of the network equipment. At the same time, the corresponding operation record can also be generated, and the operation record can be fed back to the management personnel.
[0095] In the method provided by the embodiment of the present invention, the alarm information sent by the network device is obtained; the monitoring area to which the network device belongs is determined, and the alarm information is sent to the event analyzer corresponding to the monitoring area; the event analyzer is triggered to process the alarm information based on the alarm processing rules, obtain the formatted data of the alarm information and the alarm type, and send the formatted data to the message queue paired with the event analyzer; the message queue is triggered to send the formatted data to the alarm device corresponding to the alarm type, so that the alarm device performs the corresponding alarm operation. After receiving the alarm information sent by the network device, the monitoring area to which the alarm device belongs is determined, and the alarm information is sent to the event analyzer of the monitoring area, so that the event analyzer processes the alarm information, obtains the formatted data and the alarm type, and sends the formatted data to the message queue corresponding to the event analyzer, so that the message queue sends the formatted data to the alarm device corresponding to the alarm type. When processing alarm information, the present invention uses different event analyzers for network devices in different monitoring areas. Each event analyzer is pre-set with alarm processing rules and message queues. The alarm processing rules in different event analyzers can be different. Thus, different areas can use different message processing methods, thereby meeting the needs of continuous expansion of the system and the use of different processing methods in different areas.
[0096] The embodiment of the present invention also provides an example of configuring alarm processing rules for each event analysis, specifically referring to Figure 4, the specific instructions are as follows:
[0097] S401: Determine each event analyzer.
[0098] After determining each monitoring area, each event analyzer can be determined, and the monitoring area and the event analyzer correspond one to one. Further, each monitoring area that needs to be monitored can be determined, and an event analyzer is allocated to each monitoring area, thereby determining each event analyzer.
[0099] S402: Allocate a message queue to each event analyzer.
[0100] After determining each event analyzer, a message queue is allocated to each event analyzer. Preferably, the event analyzers correspond to the message queues one to one.
[0101] S403: Determine an alarm processing rule for each event analyzer based on the alarm requirements of the monitoring area to which each event analyzer belongs.
[0102] The alarm requirements of the monitoring area to which each event analyzer belongs are obtained, and based on each alarm requirement, an alarm processing rule for each event analyzer is determined in a rule database.
[0103] The alarm processing rules of different event analyzers may be different or the same.
[0104] S404: Configure the alarm processing rules of each event analyzer to each event analyzer through the message queue of each event analyzer.
[0105] After the message queue of each event analyzer is determined, the alarm processing rule is sent to each event analyzer using the message queue of each event analyzer, so as to complete the configuration of the alarm processing rule for each event analyzer.
[0106] In the method provided by the embodiment of the present invention, the alarm processing rules of the event analyzer of each monitoring area are determined according to the alarm requirements of each monitoring area, so that corresponding alarm processing rules can be configured for each monitoring area according to the requirements, thereby meeting the different processing requirements of different monitoring areas and increasing the diversity of system monitoring. The alarm information processing method provided by the embodiment of the present invention is more suitable for continuously expanding systems, meets the different requirements of different areas of the system, and realizes multiple message processing methods for the same system.
[0107] Furthermore, after configuring the alarm processing rules for each event analyzer, a mapping dictionary table containing the mapping relationship between each event analyzer and each message queue can be generated. The specific process is as follows:
[0108] Determining a region code and a rule identification code for each of the event analyzers;
[0109] generating a queue name of a message queue of each event analyzer based on the region code and rule identification code of each event analyzer;
[0110] Generate a mapping dictionary table based on each queue name.
[0111] It should be noted that the area code of the event analyzer can represent the monitoring area to which the event analyzer belongs. The area code here can be understood as the above-mentioned area identifier or area identification code; the rule identification code can be obtained by parsing the alarm processing rules. The rule identification code can be understood as the identification identifier of the alarm processing rules.
[0112] The queue name of the event analyzer's message queue is composed of the region code and the rule identification code, specifically: queue name = region code + rule identification code. Based on each queue name, a mapping dictionary table between the event analyzer and the message queue is generated. For example, the mapping dictionary table can refer to Table 1, as shown below:
[0113]
[0114] Table 1
[0115] It should be noted that the keys in the table can be understood as the region codes of the aforementioned content, with different region codes representing different monitoring areas, and the values can be understood as the rule identification codes of the aforementioned content. The mapping dictionary table can be freely expanded on the web, which is convenient and simple, while also achieving regional isolation.
[0116] It should be noted that the mapping dictionary table also includes descriptions of rule identification codes, as shown in Table 2. The contents of Table 2 are as follows:
[0117] Serial number key value type describe 1 101 Nanhu Data Center even_rule_quara_sign Isolation marks for each row 2 102 Yangqiao Data Center even_rule_quara_sign Isolation marks for each row 3 103 Daoxiang Lake Data Center even_rule_quara_sign Isolation marks for each row 4 104 Public Cloud even_rule_quara_sign Public cloud rules and regulations
[0118] Table 2
[0119] It should be noted that the values in Table 2 can be understood as the rule identification codes mentioned above. For example, 101 indicates that the event processor uses the processing rules of the Nanhu Data Center, 102 indicates that the event processor uses the processing rules of the Yangqiao Data Center, 103 indicates that the event processor uses the processing rules of the Daoxiang Lake Data Center, and 104 indicates that the event processor uses the processing rules of the public cloud.
[0120] In the method provided herein, a mapping dictionary table can be displayed to management personnel, allowing them to understand the mapping relationship between event processors and message queues based on the mapping dictionary table. The present invention utilizes event processors and message queues to construct a network device alarm system that supports multi-region alarm rule isolation. The system proposes using a mapping dictionary table to provide mapping relationships when alarm rules are distributed to event analyzers. Alarm rules for different regions are distributed to event analyzers in different monitoring areas, enabling step-by-step, zone-by-zone, and simultaneous distribution of alarm rules, thereby reducing the correlation between alarm rules in different regions.
[0121] and Figure 1 Corresponding to the method shown in FIG. 1 , an embodiment of the present invention further provides an alarm information processing device, which can be set in an alarm processing system. The structural diagram of the device is shown in FIG. Figure 5 The specific instructions are as follows:
[0122] An acquisition unit 501 is configured to acquire alarm information sent by a network device;
[0123] A first determining unit 502 is configured to determine a monitoring area to which the network device belongs, and send the alarm information to an event analyzer corresponding to the monitoring area;
[0124] A triggering unit 503 is configured to trigger the event analyzer to process the alarm information based on a pre-configured alarm processing rule, obtain formatted data of the alarm information and the alarm type, and send the formatted data to a message queue paired with the event analyzer;
[0125] The sending unit 504 is configured to trigger the message queue to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation.
[0126] In the device provided by the embodiment of the present invention, the alarm information sent by the network device is obtained; the monitoring area to which the network device belongs is determined, and the alarm information is sent to the event analyzer corresponding to the monitoring area; the event analyzer is triggered to process the alarm information based on the alarm processing rules, obtain the formatted data of the alarm information and the alarm type, and send the formatted data to the message queue paired with the event analyzer; the message queue is triggered to send the formatted data to the alarm device corresponding to the alarm type, so that the alarm device performs the corresponding alarm operation. After receiving the alarm information sent by the network device, the monitoring area to which the alarm device belongs is determined, and the alarm information is sent to the event analyzer of the monitoring area, so that the event analyzer processes the alarm information, obtains the formatted data and the alarm type, and sends the formatted data to the message queue corresponding to the event analyzer, so that the message queue sends the formatted data to the alarm device corresponding to the alarm type. When processing alarm information, the present invention uses different event analyzers for network devices in different monitoring areas. Each event analyzer is pre-set with alarm processing rules and message queues. The alarm processing rules in different event analyzers can be different. Thus, different areas can use different message processing methods, thereby meeting the needs of continuous expansion of the system and the use of different processing methods in different areas.
[0127] In the apparatus provided by the embodiment of the present invention, the first determining unit 502 may be configured as follows:
[0128] an acquiring subunit, configured to parse the alarm information and acquire the area identifier in the alarm information;
[0129] The comparison subunit is configured to compare the area identifier with an area identification code of each monitoring area, and use the monitoring area with the same area identification code as the area identifier as the monitoring area to which the network device belongs.
[0130] In the apparatus provided by the embodiment of the present invention, the trigger unit 503 may be configured as follows:
[0131] a parsing subunit, configured to parse the alarm information based on the parsing rules in the alarm processing rules to obtain parsed information;
[0132] a processing subunit, configured to format the parsed information based on the data format requirements in the parsing rules to obtain formatted data of the alarm information;
[0133] The analyzing subunit is configured to analyze the formatted data based on the alarm classification information in the alarm processing rule to determine the alarm type of the alarm information.
[0134] The device provided in the embodiment of the present invention may also be configured as follows:
[0135] A second determining unit, configured to determine each event analyzer;
[0136] an allocating unit, configured to allocate a message queue to each of the event analyzers;
[0137] a third determining unit, configured to determine an alarm processing rule for each of the event analyzers based on an alarm requirement of a monitoring area to which each of the event analyzers belongs;
[0138] A configuration unit is used to configure the alarm processing rules of each event analyzer to each event analyzer through the message queue of each event analyzer.
[0139] The device provided in the embodiment of the present invention may also be configured as follows:
[0140] a fourth determining unit, configured to determine a region code and a rule identification code of each of the event analyzers;
[0141] a first generating unit, configured to generate a queue name of a message queue of each event analyzer based on a region code and a rule identification code of each event analyzer;
[0142] The second generating unit is configured to generate a mapping dictionary table based on each queue name.
[0143] An embodiment of the present invention further provides a storage medium, which includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the above-mentioned alarm information processing method.
[0144] The embodiment of the present invention further provides an electronic device, the structural diagram of which is shown in FIG. Figure 6 As shown, it specifically includes a memory 601 and one or more instructions 602, wherein the one or more instructions 602 are stored in the memory 601 and are configured to be executed by one or more processors 603 to perform the above-mentioned alarm information processing method.
[0145] The specific implementation processes and derivative methods of the above embodiments are all within the protection scope of the present invention.
[0146] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without expending creative work.
[0147] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0148] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for processing alarm information, characterized in that: include: Obtain alarm information sent by network devices; Determining the monitoring area to which the network device belongs, and sending the alarm information to an event analyzer corresponding to the monitoring area; Parsing the alarm information based on the parsing rules in the alarm processing rules to obtain parsed information, where the parsing rules in different alarm processing rules are different; Based on the data format requirements in the parsing rules, the parsed information is formatted to obtain formatted data of the alarm information, where different parsing rules have different data format requirements; Analyzing the formatted data based on the alarm classification information in the alarm processing rule, determining the alarm type of the alarm information, and sending the formatted data to a message queue paired with the event analyzer; triggering the message queue to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation; The process of configuring alarm processing rules for each event analyzer includes: Determine each event analyzer, wherein the monitoring area corresponds to the event analyzer in a one-to-one manner; Allocating a message queue to each of the event analyzers; Determining an alarm processing rule for each event analyzer based on the alarm requirements of the monitoring area to which each event analyzer belongs; The alarm processing rules of each event analyzer are configured to each event analyzer through the message queue of each event analyzer.
2. The method according to claim 1, characterized in that Determining the monitoring area to which the network device belongs includes: Parsing the warning information to obtain the area identifier in the warning information; The area identifier is compared with the area identification code of each monitoring area, and the monitoring area with the same area identification code as the area identifier is used as the monitoring area to which the network device belongs.
3. The method according to claim 1, characterized in that Also includes: Determining a region code and a rule identification code for each of the event analyzers; generating a queue name of a message queue of each event analyzer based on the region code and rule identification code of each event analyzer; Generate a mapping dictionary table based on each queue name.
4. An alarm information processing device, characterized in that: include: An acquisition unit, configured to acquire alarm information sent by a network device; a first determining unit, configured to determine a monitoring area to which the network device belongs, and send the alarm information to an event analyzer corresponding to the monitoring area; a triggering unit, configured to trigger the event analyzer to process the alarm information based on a pre-configured alarm processing rule, obtain formatted data of the alarm information and an alarm type, and send the formatted data to a message queue paired with the event analyzer; a sending unit, configured to trigger the message queue to send the formatted data to an alarm device corresponding to the alarm type, so that the alarm device performs a corresponding alarm operation; a second determining unit, configured to determine each event analyzer, wherein the monitoring areas correspond to the event analyzers in a one-to-one manner; an allocating unit, configured to allocate a message queue to each of the event analyzers; a third determining unit, configured to determine an alarm processing rule for each of the event analyzers based on an alarm requirement of a monitoring area to which each of the event analyzers belongs; a configuration unit, configured to configure the alarm processing rule of each event analyzer to each event analyzer through the message queue of each event analyzer; The trigger unit includes: a parsing subunit, configured to parse the alarm information based on a parsing rule in the alarm processing rule to obtain parsed information, wherein the parsing rules in different alarm processing rules are different; a processing subunit, configured to format the parsed information based on the data format requirements in the parsing rules to obtain formatted data of the alarm information, wherein different parsing rules have different data format requirements; The analyzing subunit is configured to analyze the formatted data based on the alarm classification information in the alarm processing rule to determine the alarm type of the alarm information.
5. The device according to claim 4, characterized in that The first determining unit includes: an acquiring subunit, configured to parse the alarm information and acquire the area identifier in the alarm information; The comparison subunit is configured to compare the area identifier with an area identification code of each monitoring area, and use the monitoring area with the same area identification code as the area identifier as the monitoring area to which the network device belongs.
6. A storage medium, characterized in that The storage medium includes stored instructions, wherein when the instructions are executed, the device where the storage medium is located is controlled to execute the alarm information processing method according to any one of claims 1 to 3.
7. An electronic device, characterized in that: The system comprises a memory and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be used by one or more processors to execute the alarm information processing method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Network equipment monitoring system and method
CN111200526A
Regional alarm message pushing method and system based on message queue
CN112702190A