Data Processing Method and Device
By obtaining monitoring information at all levels in the hierarchical architecture and performing abnormal detection, the problem of poor early warning accuracy in the existing technology is solved, and more efficient monitoring and early warning is achieved.
Patent Information
- Application Number
- CN202210415794.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-20
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-04-20
AI Technical Summary
The early warning accuracy of existing monitoring equipment is poor, and it is prone to false warnings, resulting in artificial identification and inefficient monitoring efficiency.
By obtaining monitoring information at each level in the hierarchical architecture, and performing abnormal detection based on the relationship between each level, business alarm information is generated to reflect the operating status of the target software.
It reduces the probability of error warning of monitoring equipment, improves warning accuracy and monitoring efficiency.
Smart Images

Figure CN114911672B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a data processing method and apparatus. Background Art
[0002] In order to ensure the stable operation of the server, currently, monitoring devices are usually used to monitor the operation status of the service layer of the server online, so as to issue early warnings according to the monitored operation status of the service layer. The service layer is used to provide a variety of business services based on the resources provided by the infrastructure layer of the server.
[0003] However, the inventor found that the current early warning method may have false early warnings. For example, false early warnings caused by incorrect operation status of the monitored service layer, or false early warnings caused by the lack of the need for early warning when the downstream of the service layer already has fault tolerance capabilities. Therefore, it is necessary to manually identify whether the early warning belongs to a false early warning, so as to notify relevant maintenance personnel to perform exception handling when it is determined that the early warning does not belong to a false early warning. Therefore, the current early warning accuracy of the monitoring device is poor and the monitoring efficiency is low. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a data processing method and apparatus, which reduces the probability of false early warnings of the monitoring device to a certain extent, improves the early warning accuracy, and enhances the monitoring efficiency. The specific technical solutions are as follows:
[0005] In the first aspect of the present invention, a data processing method is first provided, which is applied to a monitoring device for monitoring the operation status of a target software, and the target software is designed based on a layered architecture; the method includes:
[0006] Obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the layered architecture, where the monitoring information reflects the operation status of the monitoring objects;
[0007] When there is abnormal information in the monitoring information of other layers except the user layer, perform anomaly detection on the first monitoring information of the monitoring objects of the user layer associated with the abnormal monitoring object according to the association relationship of the monitoring objects of each layer, where the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each layer associated in the association relationship respond to the same service request;
[0008] When it is determined that the first monitoring information is abnormal information, generate a service alarm information and display the service alarm information, where the service alarm information is used to reflect that the target software runs abnormally;
[0009] When there is no abnormal information in the monitoring information of the other levels and there is abnormal information in the monitoring information of the user layer, generate the service alarm information and display the service alarm information.
[0010] In a second aspect of the implementation of the present invention, there is also provided a data processing device, which is applied to a monitoring device for monitoring the running state of a target software, and the target software is designed based on a hierarchical architecture; the device includes:
[0011] An acquisition module, configured to acquire the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the hierarchical architecture, and the monitoring information reflects the running state of the monitoring objects;
[0012] A detection module, configured to, when there is abnormal information in the monitoring information of other levels that do not belong to the user layer, perform abnormal detection on the first monitoring information of the monitoring objects of the user layer associated with the abnormal monitoring objects according to the association relationship of the monitoring objects of each level, where the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each level associated in the association relationship respond to the same service request;
[0013] A generation module, configured to generate and display the service alarm information when determining that the first monitoring information is abnormal information, and the service alarm information is used to reflect that the target software runs abnormally; and is also configured to generate and display the service alarm information when there is no abnormal information in the monitoring information of the other levels and there is abnormal information in the monitoring information of the user layer.
[0014] In a third aspect of the implementation of the present invention, there is also provided an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus;
[0015] The memory is used to store a computer program;
[0016] The processor is configured to implement the method steps of any one of the above first aspects when executing the program stored on the memory.
[0017] In a fourth aspect of the implementation of the present invention, there is also provided a computer-readable storage medium, in which instructions are stored, and when it runs on a computer, it causes the computer to execute the data processing method of any one of the above first aspects.
[0018] In a fifth aspect of the implementation of the present invention, there is also provided a computer program product containing instructions, which, when running on a computer, causes the computer to execute the data processing method described in any one of the above first aspects.
[0019] A data processing method and device provided by an embodiment of the present application are applied to a monitoring device for monitoring the running state of a target software. The target software is designed based on a hierarchical architecture, and the hierarchical architecture includes: a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, abnormal detection is performed on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated level respond to the same service request. When it is determined that the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running anomaly, and a service warning message is generated and displayed. When there is no abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running anomaly, and a service warning message is generated and displayed. In this technical solution, since there is a high probability that the target software has a real fault problem when there is an anomaly in the user layer. Therefore, when there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the target software, by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information, the accuracy of anomaly determination for the target software can be improved. Compared with the related art, the probability of false warnings of the monitoring device is reduced, the warning accuracy is improved, and the monitoring efficiency is enhanced. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art.
[0021] Figure 1 It is a schematic diagram of the implementation environment for a data processing method provided by an embodiment of the present application;
[0022] Figure 2 It is a flowchart of a data processing method provided by an embodiment of the present application;
[0023] Figure 3 It is a flowchart of another data processing method provided by an embodiment of the present application;
[0024] Figure 4 It is a flowchart of a method for determining source abnormal information provided by an embodiment of the present application;
[0025] Figure 5 It is a schematic diagram of a data processing platform provided by an embodiment of the present application;
[0026] Figure 6 Schematic diagram of another data processing platform provided by an embodiment of the present application
[0027] Figure 7 Structural diagram of a data processing device provided by an embodiment of the present application;
[0028] Figure 8 Structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0029] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.
[0030] Please refer to Figure 1 , which shows a schematic diagram of an implementation environment of a data processing method provided by an embodiment of the present application. As Figure 1 shown, the implementation environment may include: a monitoring device 101 and a monitored system 102 running a target software. The monitoring device 101 is connected to the monitored system 102 through a network. Optionally, the network may be a wireless network. The wireless network may include: a Wi-Fi network, a 3rd-generation (3G) mobile communication technology network, or a general packet radio service (GPRS), etc.
[0031] Among them, the monitoring device 101 is used to monitor the running status of the target software running in the monitored system, so as to perform early warning and / or fault analysis (also known as anomaly analysis) according to the monitored running situation of the target software. Optionally, the monitoring device 101 may include a display device to display the monitored running situation of the target software. Exemplarily, the monitoring device 101 may be a server externally connected with a display device, a server cluster including multiple servers, or a cloud server, etc.
[0032] The target software is designed based on a layered architecture. The layered architecture includes three levels: a user layer, a service layer, and an infrastructure layer. The infrastructure layer in the layered architecture provides computing and storage resources. The service layer provides various services based on the resources provided by the infrastructure layer. The user layer displays the results of various services. Based on this, the monitoring device 101 can be used to monitor the monitoring objects belonging to the infrastructure layer, the monitoring objects belonging to the service layer, and the monitoring objects belonging to the user layer, so as to realize the monitoring of each level of the target software.
[0033] In an application scenario, the target software can be software running in a cloud computing environment. The target software can run in a distributed system, and at least two of the user layer, service layer, and infrastructure layer of the target software can be deployed on different electronic devices. By way of example, as Figure 1 shown, the monitored system 102 can include a terminal 1021 and a server 1022 running the target software. The server 1022 provides various services supported by the target software for the terminal 1021. The terminal 1021 is used to display the operation results of various services supported by the target software. The part of the server that provides hardware resources such as computing and storage belongs to the infrastructure layer. The part of the server that provides various services based on the hardware resources provided in the infrastructure layer belongs to the service layer. The terminal belongs to the user layer. By way of example, the terminal can be a mobile phone, a computer, or a wearable device, etc. The server can be a single server, a server cluster including multiple servers, or a cloud server, etc.
[0034] Optionally, the server can include one or more electronic devices. Among them, the electronic devices belonging to the service layer are used to provide resource service capabilities for the target software. The resource service capabilities can include computing services, storage services, network services, security monitoring services, etc. The electronic devices belonging to the infrastructure layer are used to provide basic hardware for the target software. For example, the electronic devices belonging to the infrastructure layer can be computing servers, storage servers, and / or network devices such as switches and routers.
[0035] Optionally, for the target software that can be software running in a cloud computing environment. The monitoring objects of the monitoring device for the infrastructure layer can include: the computing unit and / or storage unit in the server of the monitored system. For example, the computing unit and / or storage unit can include: memory, central processing unit (CPU), disk space, and network IO. The monitoring objects of the monitoring device for the service layer can include: the interfaces in the server of the monitored system that are used to provide the services required by the target software, also known as application programming interfaces (APIs). The monitoring objects of the monitoring device for the user layer can include: the terminals that send service requests in the monitored system. For example, the monitoring objects of the user layer are the terminal display page, terminal page interaction operations, etc. In an optional implementation manner, the monitoring objects of each layer of the monitored device can be determined based on the user's business usage mode of the monitored system.
[0036] For example, a user can query the content of the first column of the first table stored in the server through a terminal and perform a summation operation on the content of the first column. The user sends a target service request through the terminal, and the target service request is used to request the sum of the content of the first column of the first table. After receiving the target service request, the server obtains the content of the first column of the first table stored in the storage unit in the infrastructure layer through the first interface of the service layer. The content of the first column of the first table obtained is called through the second interface of the service layer, and a summation operation is performed on the content to obtain a summation result. The summation result is then sent to the terminal. The terminal displays the summation result. Based on this, for the service of querying the first table and performing operations on the content of the first table, the monitoring object in the infrastructure layer can be the target storage unit storing the first table. The monitoring objects in the service layer can be the first interface and the second interface. The monitoring object in the user layer can be the target interface of the terminal for displaying the summation result.
[0037] In another application scenario, the target software can be software that runs independently on a single machine. The target software can run on an electronic device. Exemplarily, the monitored system includes a terminal running the target software. The basic hardware components that provide resources such as computing and storage in the terminal belong to the infrastructure layer. The components running in the terminal that provide the services supported by the target software belong to the service layer. The relevant interfaces of the target software displayed on the terminal belong to the application layer. Exemplarily, the terminal can be a mobile phone, a computer, or a wearable device, etc.
[0038] Optionally, for the target software that can be software running independently on a single machine. The monitoring objects of the monitoring device for the infrastructure layer can include: the computing unit and / or storage unit in the terminal. For example, the computing unit and / or storage unit can include: memory, Central Processing Unit (CPU), and disk space. The monitoring objects of the monitoring device for the service layer can include: the running logs of the components that provide the services supported by the target software. For example, the monitoring object in the service layer can be the running logs of the target code, and the terminal runs the target code to implement the services supported by the target software. The monitoring objects of the monitoring device for the user layer can include: the interfaces for providing the display data of the relevant interfaces of the target software.
[0039] Please refer to Figure 2 which shows a flowchart of a data processing method provided by an embodiment of the present application. The data processing method can be applied to Figure 1 the implementation environment shown, and is executed by the monitoring device in the implementation environment. As Figure 2 shown, the method includes:
[0040] Step 201, obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the hierarchical architecture.
[0041] In the embodiments of the present application, the monitoring information reflects the operating status of the monitored object. In an alternative manner, the monitoring information may include: the monitored object identifier and the operating status. The monitored object identifier is used to uniquely indicate the monitored object. The operating status may be a healthy status or an abnormal status. When the monitored object is in a healthy status, it indicates that the monitored object is operating normally. When the monitored object is in an abnormal status, it indicates that the monitored object is operating abnormally and there is a fault.
[0042] In another alternative manner, the monitoring information may include: the monitored object identifier and the monitoring metrics. The content of the monitoring metrics can reflect the operating status of the monitored object. In one case, the target software may be a software running on a single machine. The monitoring information of the monitored object in the infrastructure layer includes: the operating data of the monitored object. The monitoring information of the monitored object in the service layer includes: the content of the supervision object (i.e., the operation log of the component providing the service supported by the target software). The monitoring metrics of the monitored object in the user layer include: the information displayed on the terminal.
[0043] In another case, the target software may be a software running in a cloud computing environment. The monitoring metrics of the monitored object in the user layer may include: the information displayed on the terminal that sends the service request. The monitoring information of the monitored object in the service layer may include: the HyperText Transfer Protocol (HTTP) response code of the interface. The HTTP response code is used to indicate whether the service request is successfully completed. The monitoring information of the monitored object in the infrastructure layer includes: the operating data of the monitored object. It should be noted that the monitoring information may further include at least one of the following information: the response time of the monitored object, the response content of the monitored object.
[0044] Exemplarily, taking the service of querying the first table and performing operations on the content of the first table as an example. The monitoring metrics of the monitored object in the user layer are the summation results displayed on the terminal. The monitoring information of the first interface in the service layer is the HTTP response code generated by the first interface. The monitoring information of the second interface in the service layer is the HTTP response code generated by the second interface. The monitoring information of the monitored object in the infrastructure layer is the stored data of the storage unit storing the first table.
[0045] Optionally, the monitoring device may periodically obtain the monitoring information of the monitored objects at each level. Alternatively, the monitoring device may also obtain the monitoring information of the monitored objects at each level in real time.
[0046] Among them, for monitoring objects at different levels, the process by which the monitoring device obtains the monitoring information of the monitoring object can be the same or different. In an alternative implementation, the process by which the monitoring device obtains the monitoring information of the monitoring object at the user layer, the monitoring information of the monitoring object at the service layer, and the monitoring information of the infrastructure layer may all include: the monitoring device sends a monitoring information request to the monitoring object. In response to the monitoring information request, the monitoring device receives the monitoring information sent by the monitoring object. After determining the monitoring objects at each level, the monitoring device may store the addresses of the monitoring objects at each level. To send a monitoring information request to the monitoring object through the address, and the monitoring information request is an HTTP request. After receiving the monitoring information request, the monitoring object sends a monitoring response to the monitoring device for the monitoring information, and the monitoring response includes the monitoring information of the monitoring object. Thus, the monitoring device receives the monitoring information sent by the monitoring object.
[0047] Alternatively, the monitoring object may also periodically send the monitoring information of the monitoring object to the monitoring device, so that the monitoring device can obtain the monitoring information of the monitoring objects at each level.
[0048] In another alternative implementation, for the monitoring object at the user layer, the process by which the monitoring device obtains the monitoring information of the monitoring object at the user layer may include: the monitoring device automatically obtains the monitoring information of the monitoring object through a User Interface (UI) automation module. Alternatively, the monitoring device obtains the monitoring information of the monitoring object through a Web service interface. Alternatively, the monitoring device obtains the monitoring information through an interface that provides the display data of the relevant interface of the target software. For the monitoring object at the service layer, the process by which the monitoring device obtains the monitoring information of the monitoring object at the service layer may include: invoking the monitoring object at the service layer to obtain the monitoring information of the monitoring object. For the monitoring object at the infrastructure layer, the process by which the monitoring device obtains the monitoring information of the monitoring object at the infrastructure layer may include: for the storage unit, reading the storage file information of the monitoring object at the infrastructure layer to obtain the monitoring information of the monitoring object, and the storage file information may be used to indicate the local file storage situation of the monitoring object. For the computing unit, reading the running file information of the monitoring object at the infrastructure layer to obtain the monitoring information of the monitoring object, and the running file information may be used to indicate the computing operation situation of the monitoring object.
[0049] Step 202, when there is abnormal information in the monitoring information of other levels except the user layer, according to the association relationship of the monitoring objects at each level, perform abnormal detection on the first monitoring information of the monitoring object at the user layer associated with the abnormal monitoring object, where the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects at each level associated in the association relationship respond to the same service request.
[0050] In the embodiments of the present application, the abnormal information may refer to the information used to reflect the abnormal operation of the monitored object. The abnormal information may reflect that there is an abnormal operation in the target software, or there is an operation failure. After the monitoring device obtains the monitoring information of the monitored objects at each level, it may determine whether there is abnormal information in the obtained monitoring information at each level to determine whether the target software may have an abnormal operation.
[0051] When it is determined that there is abnormal information in the monitoring information of other levels that do not belong to the user layer, it indicates that the target software may have an abnormal operation. Since there will be abnormal reflections in the user layer when there is a real abnormal operation problem in the target software. Therefore, the monitoring device may determine the monitored object in the user layer associated with the abnormal monitored object according to the association relationship of the monitored objects at each level. Furthermore, obtain the first monitoring information of the monitored object in the associated user layer, and perform abnormal detection on the first monitoring information to further verify whether the target software has a failure according to the first monitoring information of the user layer associated with the abnormal monitored object. Optionally, the process of the monitoring device performing abnormal detection on the first monitoring information may include: the monitoring device determines whether the first monitoring information of the monitored object in the user layer associated with the abnormal monitored object is abnormal information.
[0052] In an alternative implementation, if the monitoring information includes the monitored object identifier and the running state. Then the process for the monitoring device to determine whether there is abnormal information in the obtained monitoring information at each level includes: the monitoring device traverses the running states included in each monitoring information to determine whether there is abnormal information in each monitoring information according to whether the running state is an abnormal state. For example, when it is determined that the monitoring information including the abnormal state exists in the monitoring information of other levels that do not belong to the user layer, it is determined that there is abnormal information in the monitoring information of this other level. When it is determined that the monitoring information of other levels that do not belong to the user layer does not include the monitoring information of the abnormal state, it is determined that there is no abnormal information in the monitoring information of this other level.
[0053] In another alternative implementation, if the monitoring information may include the monitored object identifier and the monitoring index. Then the process for the monitoring device to determine whether there is abnormal information in the obtained monitoring information at each level includes: the monitoring device may determine whether the monitoring index of each monitoring information is abnormal data. The monitoring information with the abnormal data of the monitoring index indicates that the monitored object of this monitoring information has an abnormal operation. For example, when it is determined that the monitoring index of the monitoring information of other levels that do not belong to the user layer has abnormal data, it is determined that there is abnormal information in the monitoring information of this other level. When it is determined that the monitoring data of the monitoring information of other levels that do not belong to the user layer does not have abnormal data, it is determined that there is no abnormal information in the monitoring information of this other level.
[0054] Among them, the abnormal data of the monitoring index can refer to values different from the normal data of the monitoring index. Optionally, the monitoring device can pre-store the normal data of the monitoring index of the monitored object. Or, the monitoring device can determine the normal data of the monitoring index by means of calculation, etc. Of course, the monitoring device can also pre-store the abnormal data of the monitored object.
[0055] Exemplarily, for the monitored object at the user layer, the monitoring device can store the abnormal data displayed by the terminal sending the service request. For example, the abnormal data is an error code. For the monitored object at the service layer, the monitoring device stores the HTTP response code indicating that the service request has not been successfully completed. Or, for the monitored object at the service layer, the monitoring device stores the error information in the running log of the target code. For the monitored object at the infrastructure layer, the monitoring device can store the normal operation data of the monitored object. The monitoring device can compare the actual data of the monitoring index in the monitoring information with the abnormal data / normal data of the target monitored object for any target monitored object in each monitored object. Determine whether the monitoring index of the monitoring information is abnormal data according to the comparison result.
[0056] In the embodiments of the present application, the monitoring device can store the association relationships of the monitored objects at each level, and the associated monitored objects at each level in the association relationship respond to the same service request. The association relationships of the monitored objects at each level can be determined manually according to the monitored objects involved in responding to the same service request after determining the monitored objects at each level. Or, the association relationship can also be collected and determined by a tool according to the monitored objects involved in responding to the same service request after determining the monitored objects at each level.
[0057] It should be noted that the target software can be software running in a cloud computing environment. The monitored objects at the service layer can include multiple microservice nodes. The association relationship of each microservice node at the service layer can be based on the call relationship of each microservice node. For example, for service request A, after the first microservice node receives service request A, it calls the second microservice node to respond to service request A according to the response information of the second microservice node. Then, if the monitored objects at the service layer include the first microservice node and the second microservice node, the first microservice node and the second microservice node are associated in the association relationship.
[0058] Exemplarily, taking the service of querying the first table and performing operations on the content of the first table as an example. The monitored object at the infrastructure layer is the target storage unit storing the first table. The monitored objects at the service layer can be the first interface and the second interface. The monitored object at the user layer can be the target interface on the terminal that displays the summation result. Then, in the association relationships of the monitored objects at each level, the target storage unit at the infrastructure layer, the first interface at the service layer, the second interface at the service layer, and the target interface at the user layer are associated.
[0059] Step 203, when it is determined that the first monitoring information is abnormal information, generate service alarm information and display the service alarm information, where the service alarm information is used to reflect the abnormal operation of the target software.
[0060] In the embodiment of the present application, after performing anomaly detection on the first monitoring information of the monitoring objects in the user layer associated with the anomaly monitoring object, if it is determined that the first monitoring information is not abnormal information, it indicates that the probability of false anomalies in the target software is relatively high, and the monitoring device may not take any action. Alternatively, the monitoring device may mark the monitoring information of each monitoring object of the abnormal information as possibly abnormal to remind the staff that there may be anomalies in the monitoring objects of the abnormal information. If it is determined that the first monitoring information is abnormal information, it indicates that the target software is definitely operating abnormally. Then the monitoring device may generate service alarm information and display the service alarm information. Optionally, the monitoring device may also send the service alarm information to the terminals of relevant staff to remind the relevant staff that the target software is operating abnormally and there are fault problems.
[0061] Step 204, when there is no abnormal information in the monitoring information of other levels that do not belong to the user layer and there is abnormal information in the monitoring information of the user layer, generate service alarm information and display the service alarm information.
[0062] In the embodiment of the present application, when there is no abnormal information in the monitoring information of other levels that do not belong to the user layer and there is abnormal information in the monitoring information of the user layer, it indicates that the target software is definitely operating abnormally. Then the monitoring device may generate service alarm information and display the service alarm information. Optionally, the monitoring device may also send the service alarm information to the terminals of relevant staff to remind the relevant staff that the target software is operating abnormally and there are fault problems.
[0063] It should be noted that when the monitoring device determines that the monitoring information of the monitoring objects at each level is not abnormal information, it indicates that the target software has no faults. The monitoring device may store the current judgment result for the convenience of staff query.
[0064] In summary, a data processing method and apparatus provided by an embodiment of the present application are applied to a monitoring device for monitoring the running state of a target software. The target software is designed based on a hierarchical architecture, which includes a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, abnormal detection is performed on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated level respond to the same service request. When it is determined that the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running abnormality, and a service alarm message is generated and the service alarm message is displayed. When there is no abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running abnormality, and a service alarm message is generated and the service alarm message is displayed. In this technical solution, since there is a high probability that the target software has a real fault problem when there is an abnormality in the user layer. Therefore, when there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the target software, by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information, the accuracy of abnormal determination for the target software can be improved. Compared with the related technology, the probability of false alarms of the monitoring device is reduced, the early warning accuracy is improved, and the monitoring efficiency is enhanced.
[0065] Please refer to Figure 3 , which shows a flowchart of another data processing method provided by an embodiment of the present application. The data processing method can be applied to Figure 1 the implementation environment shown, and is executed by the monitoring device in the implementation environment. As Figure 3 shown, the method includes:
[0066] Step 301, obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the hierarchical architecture. The monitoring information reflects the running state of the monitoring objects.
[0067] Step 302, when there is abnormal information in the monitoring information of other levels that do not belong to the user layer, according to the association relationship of the monitoring objects of each level, perform abnormal detection on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and in the association relationship, the monitoring objects of each associated level respond to the same service request.
[0068] Step 303, when it is determined that the first monitoring information is abnormal information, generate a service alarm message and display the service alarm message. The service alarm message is used to reflect the running abnormality of the target software.
[0069] Step 304: When there is no abnormal information in the monitoring information of other levels that do not belong to the user layer, and there is abnormal information in the monitoring information of the user layer, generate a service alarm message and display the service alarm message.
[0070] The explanations and implementation manners of steps 301 to 304 may refer to the explanations and implementation manners of the foregoing steps 201 to 204 in sequence, and the embodiments of the present application will not elaborate on this.
[0071] In the embodiments of the present application, the service alarm message may include: monitoring information belonging to abnormal information and / or a fault link diagram, etc., so that after receiving the service alarm message, the staff can obtain more fault abnormal information of the target software according to the service alarm message, thereby improving the fault troubleshooting and maintenance efficiency. Taking the content that the service alarm message may include in the embodiments of the present application as the following several cases as examples, the generation process of the service alarm message will be further described.
[0072] The first optional implementation manner, the process of generating a service alarm message includes: generating a service alarm message including source abnormal information. That is, the service alarm message includes source abnormal information. Then, before generating the service alarm message, the method may further include steps 401 to 402. As Figure 4 shown, the method further includes:
[0073] Step 401: According to the association relationship of the monitoring objects at each level, obtain the second monitoring information of the monitoring objects associated with the abnormal monitoring object, and the second monitoring information is abnormal information.
[0074] In the embodiments of the present application, the monitoring device may determine the monitoring objects associated with the abnormal monitoring object according to the association relationship of the monitoring objects at each level. The monitoring objects associated with the abnormal monitoring object refer to the monitoring objects at each level associated with the abnormal monitoring object. Obtain all the monitoring information of the monitoring objects associated with the abnormal monitoring object, and screen out the second monitoring information belonging to abnormal information from all the monitoring information. Among them, the implementation manner of the monitoring device screening out the second monitoring information belonging to abnormal information from all the monitoring information may refer to the implementation manner of the monitoring device determining whether there is abnormal information in the monitoring information obtained at each level described above, and the embodiments of the present application will not elaborate on this here.
[0075] Step 402: According to the response order of each monitoring object to the service request in the association relationship, select the monitoring information of the first monitoring object from the second monitoring information and the monitoring information of the abnormal monitoring object as the source abnormal information.
[0076] In an embodiment of the present application, the monitoring device may select the monitoring information of the first monitoring object as the source abnormal information from the second monitoring information and the monitoring information of the abnormal monitoring object, that is, from the monitoring objects belonging to the abnormal information among the monitoring information of all monitoring objects associated with the abnormal monitoring object.
[0077] For example, taking the service of querying the first table and performing operations on the content of the first table as an example. The monitoring object at the infrastructure layer is the target storage unit storing the first table. The monitoring objects at the service layer may be the first interface and the second interface. The monitoring object at the user layer may be the target interface for displaying the summation result on the terminal. In the association relationship of the monitoring objects at each layer, the target storage unit at the infrastructure layer, the first interface at the service layer, the second interface at the service layer, and the target interface at the user layer are associated.
[0078] Assume that the monitoring information of the monitoring objects at each layer is abnormal information, then the abnormal monitoring objects are the monitoring objects at each layer. The monitoring device selects the target storage unit at the infrastructure layer (i.e., the first monitoring object) as the source abnormal information from the monitoring information of the monitoring objects at each layer according to the response order of each monitoring object to the service: the target storage unit at the infrastructure layer, the second interface at the service layer, the first interface at the service layer, and the target interface at the user layer.
[0079] In this way, each monitoring object is sorted according to the response order to the service request. In terms of layers, this sorting order is usually the monitoring object at the infrastructure layer, the monitoring object at the service layer, and the monitoring object at the user layer. Since the impact of abnormal operation of the user layer, service layer, and infrastructure layer on the normal operation of the target software deepens in turn, and the abnormal operation of the user layer, service layer, and infrastructure layer is correlated, the abnormal operation of the infrastructure layer will affect the service layer and user layer in turn. Therefore, selecting the monitoring information of the first monitoring object as the source abnormal information according to the response order of each monitoring object to the service request in the association relationship can realize the backtracking of the abnormal conditions of each monitoring object according to the impact order of the abnormal operation of the monitoring object on the normal operation of the target software, so as to find the monitoring object with the earliest abnormal operation, determine the monitoring object with the initial abnormal operation, and realize the accurate positioning of the faulty monitoring object. This is beneficial to the fault analysis and fault repair of the target software. And, compared with the related technology, it solves the problem of inaccurate fault location caused by fault spread, improves the accuracy of abnormal determination of the target software. Furthermore, it further reduces the probability of false alarms of the monitoring device, improves the early warning accuracy, and enhances the monitoring efficiency.
[0080] In an embodiment of the present application, the monitoring device may also select the source abnormal information from the second monitoring information and the monitoring information of the abnormal monitoring object according to other conditions.
[0081] Exemplarily, the monitored objects at each level may have a maintenance priority. The maintenance priority of the monitored objects may be determined according to the influence degree of each monitored object on the normal operation of the target software during abnormal operation. The higher the maintenance priority, the greater the influence degree. The monitoring device may select the monitoring information of the monitored objects with a maintenance priority greater than the priority threshold from the second monitoring information and the monitoring information of the abnormal monitored objects as the source abnormal information. Among them, the maintenance priority may be determined according to the actual situation.
[0082] The second optional implementation manner, the process of generating the service alarm information includes: generating the service alarm information including the fault link diagram. That is, the service alarm information includes the fault link diagram. Then, before generating the service alarm information, the method may further include step S11. The method further includes:
[0083] Step S11: Generate a fault link diagram according to the response order of each monitored object in the association relationship of the monitored objects at each level to the service request, the monitoring information of the abnormal monitored objects, and the monitoring information of the monitored objects associated with the abnormal monitored objects. The monitoring information in the fault link diagram is connected and displayed according to the response order of each monitored object in the association relationship to the service request.
[0084] In the embodiments of the present application, that the monitoring information in the fault link diagram can be connected and displayed according to the response order may include: each monitoring information can be connected and displayed in the form of a connection line according to the response order. Or, each monitoring information can be connected and displayed in the form of a multi-level menu according to the response order.
[0085] Exemplarily, assume that the abnormal monitored object is the second monitored object in the service layer. The monitored objects associated with the abnormal monitored object include: the first monitored object in the user layer and the third monitored object in the infrastructure layer. If in the association relationship, the first monitored object, the second monitored object, and the third monitored object are associated, and the response order of each monitored object to the same service request is: the third monitored object, the second monitored object, and the first monitored object. The monitoring device connects and displays the monitoring information of the first monitored object, the monitoring information of the second monitored object, and the monitoring information of the third monitored object in the response order, and generates a fault link diagram. The connection line identifies the association order and the corresponding order of the monitored objects of each monitoring information.
[0086] It should be noted that the monitoring device may also generate a fault link diagram according to the response order of the monitored objects at each level to the service request, and the monitoring information of the monitored objects at each level in the fault link diagram is connected and displayed according to the response order.
[0087] In this way, since the fault link diagram can visually display the monitoring results of the monitoring objects with associated relationships at each level in the vertical direction, that is, from the user layer, service layer to the infrastructure layer. Therefore, the service alarm information including the fault link diagram can more clearly remind relevant personnel of the abnormal operation of the target software, which is beneficial to the fault analysis of the target software.
[0088] The third optional implementation method. The process of generating service alarm information includes: generating service alarm information including source abnormal information and a fault link diagram. That is, the service alarm information includes source abnormal information and a fault link diagram. Then, before generating the service alarm information, the method may further include step S21. The method further includes:
[0089] Step S21: According to the associated relationships of the monitoring objects at each level, obtain the second monitoring information of the monitoring objects associated with the abnormal monitoring object, and the second monitoring information is abnormal information.
[0090] Step S22: According to the response order of each monitoring object to the service request in the associated relationship, select the monitoring information of the first monitoring object from the second monitoring information and the monitoring information of the abnormal monitoring object as the source abnormal information.
[0091] Step S23: Generate a fault link diagram according to the response order of each monitoring object to the service request in the associated relationship of the monitoring objects at each level, the monitoring information of the abnormal monitoring object, and the monitoring information of the monitoring objects associated with the abnormal monitoring object. The monitoring information in the fault link diagram is connected and displayed according to the response order of each monitoring object to the service request in the associated relationship.
[0092] For the explanations and implementation methods of steps S21, S22, and S23, reference can be made to the explanations and implementation methods of the foregoing steps 401, step 402, and step S11 in sequence, and the embodiments of the present application will not elaborate on this.
[0093] It should be noted that the source abnormal information in the fault link diagram can be marked and displayed. This marked display can mean that the source abnormal information is marked and displayed in forms such as highlighting and bolding. In this way, compared with the fault link diagram generated by the second optional implementation method, the fault link diagram generated by the third optional implementation method. Since the source abnormal information included in the fault link diagram is marked and displayed, it is more beneficial for the service alarm information including the fault link diagram to clearly remind relevant personnel of the abnormal operation of the target software, and further beneficial to the fault analysis of the target software.
[0094] Step 305: Send the service alarm information to the alarm terminal corresponding to the level to which the abnormal monitoring object belongs.
[0095] In the embodiments of the present application, among the user layer, the service layer, and the infrastructure layer, the monitoring personnel corresponding to any level can be different. That is to say, different levels of monitoring tasks can be assigned to different role personnel in the system R & D team. For example, the operation and maintenance team is assigned the monitoring tasks of the infrastructure layer. The development team is assigned the monitoring tasks of the service layer. The Quality Assurance (QA) team or the customer operation and maintenance team is assigned the monitoring tasks of the user layer. The monitoring device can send service alarm information to the monitoring personnel in the form of emails, instant messaging software, or telephones, etc.
[0096] Optionally, the monitoring device can store the correspondence between the identity identifiers of the monitoring personnel and the levels, as well as the correspondence between the identity identifiers and the relevant information of the monitoring personnel indicated by them. At least included in the relevant information corresponding to the identity identifier are: the terminal identifier of the alarm terminal held by the monitoring personnel indicated by the identity identifier. The monitoring personnel indicated by the identity identifier have the permission to view the monitoring information of the corresponding level. The monitoring device can query the correspondence according to the level to which the abnormal monitoring object of the abnormal information in the monitoring information of each level belongs. The service alarm information is sent to the alarm terminal corresponding to the identity identifier corresponding to this level. Of course, the granularity of the viewing permission of the monitoring personnel can also be the monitoring object. That is to say, the monitoring personnel can correspond to the monitoring object.
[0097] In this way, different monitoring personnel can be responsible for part of the abnormal analysis and maintenance work, improving the work efficiency of the abnormal fault analysis and maintenance of the target software. For example, it improves the work efficiency in abnormal fault analysis such as fault reproduction, and in fault maintenance such as fault resolution and error confirmation after fault resolution. Further, for the single-level abnormal information caused by reasons such as the downstream calling party has entered the fault tolerance processing, etc., at this time, all the downstream monitoring objects are operating normally. The monitoring device can send the service alarm information to the monitoring personnel corresponding to the single-level abnormal information. On the basis of ensuring the fault analysis and maintenance efficiency, it reduces the manpower input and analysis time cost of fault analysis, and improves the fault analysis efficiency and monitoring efficiency.
[0098] It should be noted that the monitoring device can also perform summary analysis on the monitoring information of the monitoring objects at any level to obtain a summary result. The summary result is sent to the alarm terminal corresponding to this level. In this way, it can visually display the monitoring results of the monitoring objects at each level in the horizontal direction, that is, in each single direction of the user layer, the service layer, and the infrastructure layer.
[0099] Optionally, the monitoring device may perform an operation health analysis on the monitoring information of the monitoring objects at any level based on the monitoring information of the monitoring objects at that level to obtain an operation health degree. The operation health degree is used to reflect the overall operation condition of that level. By way of example, the operation health degree may be the ratio of the monitoring objects with abnormal operation to the monitoring objects with normal operation. It may also be the proportion of the number of monitoring objects with abnormal operation to the total number of monitoring objects at that level, etc.
[0100] In the embodiments of the present application, the monitoring device may store the monitoring information of the monitoring objects at each level, source exception information, fault link diagrams, alarm information, and other information generated during the operation of the monitoring device, so as to facilitate relevant staff to call and view. Optionally, the method further includes:
[0101] Step 306: In response to a display instruction for the monitoring information query page, display the monitoring information query page.
[0102] In the embodiments of the present application, if a query person wants to view the monitoring information of a target software, the query person may perform a trigger operation on the monitoring information query page, so that the monitoring device receives the trigger operation on the monitoring information query page, and in response to the trigger operation, generates a display instruction for the monitoring information query page. Then, in response to this display instruction, the monitoring information query page is displayed. Among them, the monitoring device may receive the query object that the query person wants to view the monitoring information on the monitoring information query page.
[0103] By way of example, the trigger operation on the monitoring information query page may be a setting operation on the trigger control for the monitoring information query page. The query person may perform a setting operation on the trigger control, so that the monitoring device can receive the setting operation on the trigger control, and in response to the setting operation, generate a display instruction for the monitoring information query page. Then, in response to this display instruction, the monitoring information query page is displayed. The query person may write the query object on the monitoring information query page. Among them, the trigger control may be used to trigger the display of the monitoring information query page. The setting operation on the trigger control may include operations in forms such as click operation, long press operation, or slide operation.
[0104] Step 307: In response to an information query instruction, obtain the query object and the identity identifier of the query person on the monitoring information query page. The query object may include: a target monitoring object and / or a target level.
[0105] Among them, the identity identifier of the query person corresponds to at least one level. The query person indicated by the identity identifier has the permission to view the monitoring information of the corresponding level. In the embodiments of the present application, the query person may be the aforementioned monitoring person.
[0106] Optionally, the monitoring information query page may include an input area for the query object that the query person wants to view the monitoring information. The query person can trigger an input operation for the query object in the input area. For example, the input area may include an input box for the query person to write the query object. Then, the query person triggering an input operation for the query object in the input area may include: the query person writing the query object in the input box. Alternatively, the input area may include selection controls. One selection control corresponds to one query object. The query person triggering an input operation for the query object in the input area may include: the query person performing a triggering operation on the selection control corresponding to the query object in the input area. Among them, the triggering operation on the selection control corresponding to the query object may include operations in forms such as click operation, long press operation, or swipe operation.
[0107] Exemplarily, the monitoring device may receive an input operation for the query object in the input area of the monitoring information query page, and in response to the input operation, generate an information query instruction and obtain the identity identifier of the query person and the query object corresponding to the selection operation. Another exemplarily, the monitoring information query page may further include a confirmation query control. After the query person triggers an input operation for the query object in the input area, the query person may perform an input operation on the confirmation query control. The monitoring device may receive the input operation for the confirmation query control, and in response to the input operation, generate an information query instruction. And obtain the identity identifier of the query person and the query object corresponding to the selection operation in the input area.
[0108] Step 308, when the level corresponding to the identity identifier of the query person is consistent with the level of the query object, display a query result page, where the query result page includes: the monitoring information of the query object and / or the monitoring information of each monitoring object associated with the query object in the association relationship.
[0109] In the embodiments of the present application, the monitoring device may perform a consistency check on the level corresponding to the identity identifier of the query person and the level of the query object. If the level corresponding to the identity identifier is consistent with the level of the query object, it indicates that the query person indicated by the identity identifier has the permission to view the monitoring information of the query object, then the monitoring device displays the query result page on the monitoring device. If the level corresponding to the identity identifier is inconsistent with the level of the query object, it indicates that the query person indicated by the identity identifier does not have the permission to view the monitoring information of the monitoring object, then the monitoring device may display a no-permission prompt message, and the no-permission prompt message is used to prompt the query person that they do not have the permission to view the written monitoring object.
[0110] Among them, when the query object is the target monitoring object, the query result page may include: the monitoring information of the target monitoring object, and / or in the association relationships of monitoring objects at all levels, the monitoring information of each monitoring object associated with the target monitoring object. When the query object is the target level, the query result page may include: the monitoring information of the monitoring objects included in the target level, and / or the monitoring information of the monitoring objects associated with each monitoring object in the target level.
[0111] Exemplarily, the input area of the monitoring information query page may include: selection controls corresponding to monitoring objects at all levels, and selection controls corresponding to each level. If the query person wants to view the monitoring information of the target monitoring object belonging to the service layer, they can click on the selection control corresponding to the target monitoring object, that is, perform a click operation on the selection control corresponding to the target monitoring object. The monitoring device receives this click operation, and in response to the click operation, generates an information query instruction and uses the target monitoring object corresponding to the click operation as the query object. The monitoring device determines whether the level corresponding to the identity identifier of the query person is consistent with the level of the query object. If so, it displays the query result page, which includes the monitoring information of the target monitoring object and the monitoring information of each monitoring object associated with the target monitoring object. If not, it displays a no-permission prompt message.
[0112] If the query person wants to view the monitoring information of each monitoring object belonging to the service layer, they can click on the selection control corresponding to the service layer, that is, perform a click operation on the selection control corresponding to the service layer. The monitoring device receives this click operation, and in response to the click operation, generates an information query instruction and uses the service layer corresponding to the click operation as the query object. The monitoring device determines whether the level corresponding to the identity identifier of the query person is consistent with the level of the query object. If so, it displays the query result page, which includes the monitoring information of the monitoring objects included in the service layer. If not, it displays a no-permission prompt message.
[0113] In summary, a data processing method and apparatus provided by an embodiment of the present application are applied to a monitoring device for monitoring the running state of a target software. The target software is designed based on a layered architecture, which includes a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, abnormal detection is performed on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated layer respond to the same service request. When it is determined that the first monitoring information of the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running abnormality, and a service alarm information is generated and the service alarm information is displayed. When there is no abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running abnormality, and a service alarm information is generated and the service alarm information is displayed. In this technical solution, since there is a high probability that the target software has a real fault problem when there is an abnormal reflection in the user layer. Therefore, when there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the target software, by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information, the accuracy of abnormal determination for the target software can be improved. Compared with the related art, the probability of false alarms of the monitoring device is reduced, the early warning accuracy is improved, and the monitoring efficiency is enhanced.
[0114] An embodiment of the present application further provides a data processing platform. The data processing platform is a web system constructed using a Model-View-Controller (MVC) architecture. The data processing platform may include an information display layer, an information service layer, and an information access layer.
[0115] Among them, the information display layer is used for different monitoring personnel to use functions such as platform function setting and monitoring information query through the data processing platform. The information service layer is used to analyze monitoring data such as the monitoring information of monitoring objects and the association relationships of monitoring objects at each layer to generate service alarm information. The information service layer provides a monitoring information query interface, a platform function setting interface, etc. for the information display layer. The information access layer is used to collect the monitoring information of monitoring objects at each layer, preprocess the monitoring information, and control the storage of the monitoring information in the database. Among them, preprocessing the monitoring information may include performing noise reduction and cleaning processing on the monitoring information. The database may be the database included in the data processing platform, or a database connected to the data processing platform, etc.
[0116] Please refer to Figure 5 which shows a block diagram of a data processing platform provided by an embodiment of the present application. The data processing platform is built on Figure 1On the monitoring device shown, the data processing platform can implement any data processing method provided in the embodiments of the present application. For example, Figure 5 As shown, the data processing platform 500 includes: an information display layer 501, an information service layer 502, and an information access layer 503.
[0117] The information access layer 503 is used to obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer. The monitoring information reflects the operating status of the monitoring objects.
[0118] When there is abnormal information in the monitoring information of other levels except the user layer, the information service layer 502 is used to perform anomaly detection on the first monitoring information of the monitoring objects of the user layer associated with the abnormal monitoring object according to the association relationship of the monitoring objects of each level. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each level associated in the association relationship respond to the same service request; when it is determined that the first monitoring information is abnormal information, a service alarm message is generated, and the service alarm message is used to reflect that the target software runs abnormally; when there is no abnormal information in the monitoring information of other levels except the user layer, and there is abnormal information in the monitoring information of the user layer, a service alarm message is generated.
[0119] The information display layer 501 is used to display the monitoring information and / or service alarm messages of each level.
[0120] Optionally, the information service layer 502 is further used to: obtain the second monitoring information of the monitoring objects associated with the abnormal monitoring object according to the association relationship, and the second monitoring information is abnormal information; select the monitoring information of the first monitoring object among the second monitoring information and the monitoring information of the abnormal monitoring object as the source abnormal information according to the response order of each monitoring object to the service request in the association relationship; generate a service alarm message including the source abnormal information.
[0121] Optionally, the information service layer 502 is further used to: generate a fault link diagram according to the response order of each monitoring object to the service request in the association relationship, the monitoring information of the abnormal monitoring object, and the monitoring information of the monitoring objects associated with the abnormal monitoring object, and the monitoring information in the fault link diagram is connected and displayed according to the response order; generate a service alarm message including the fault link diagram.
[0122] Optionally, the information service layer 502 is further used to: send the service alarm message to the alarm terminal corresponding to the level to which the abnormal monitoring object belongs.
[0123] Optionally, the information service layer 502 is further configured to: in response to a display instruction for a monitoring information query page, display the monitoring information query page; in response to an information query instruction, obtain a query object and an identity identifier of a query person in the monitoring information query page, the identity identifier corresponding to at least one level, and the person indicated by the identity identifier has the permission to view the monitoring information of the corresponding level, and the query object includes: a target monitoring object and / or a target level;
[0124] The information display layer 503 is further configured to: when the level corresponding to the identity identifier is the same as the level of the query object, display a query result page, and the query result page includes: the monitoring information of the query object and / or the monitoring information of each monitoring object associated with the query object in the association relationship.
[0125] Optionally, the data processing platform 500 further includes: a log recording module and a permission control module. The log module is at least used to record the behavior logs of the data processing platform. The permission control module is at least used to verify the permissions of the monitoring objects.
[0126] In the embodiments shown by the data processing platform provided by the embodiments of the present application, the explanations and implementation processes of the methods executed by each level or module can refer to the relevant explanations and implementation processes provided by the foregoing method-side embodiments of the data processing method. To avoid repetition, they will not be elaborated here.
[0127] In the embodiments of the present application, a data processing platform provided by the embodiments of the present application is used to monitor the running state of a target software. The target software is designed based on a hierarchical architecture, and the hierarchical architecture includes: a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, by performing abnormal detection on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object, the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated level respond to the same service request. To determine that the first monitoring information of the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running abnormality, generate a service alarm message, and display the service alarm message. When there is no abnormal information in the monitoring information of other levels that do not belong to the user layer in the hierarchical architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running abnormality, generate a service alarm message, and display the service alarm message. In this technical solution, since there is a high probability that there is a real fault problem in the target software when there is an abnormality in the user layer. Therefore, when there is abnormal information in the monitoring information of other levels that do not belong to the user layer in the target software, by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information, the accuracy of abnormal determination for the target software can be improved. Compared with the related art, the probability of false alarms of the monitoring device is reduced, the warning accuracy is improved, and the monitoring efficiency is enhanced.
[0128] For example, please refer to Figure 6 , which shows a schematic diagram of another data processing platform provided by an embodiment of the present application. An embodiment of the present application uses the data processing platform as shown in Figure 6 to further illustrate the data processing method and data processing platform provided by the present invention. As shown in Figure 6 , the data processing platform 600 includes: an information display layer 601, an information service layer 602, an information access layer 603, a log recording module 604, and a permission control module 605.
[0129] Among them, the information display layer 601 includes: a user layer 6011 and an interaction layer 6012. The user layer 6011 is used to display monitoring information and / or business alarm information of each level to monitoring personnel (developers, operation and maintenance personnel, testers, and managers) on the monitoring system page, and is also used to display setting pages such as monitoring object setting pages, business alarm information setting pages, monitoring information query pages, and query result pages.
[0130] The interaction layer 6012 includes a page interaction module 60121 and an alarm push module 601212. The page interaction module 60121 is used to obtain monitoring information to be displayed from the information service layer 602 and push it to the user layer 6011. The page interaction module 60121 can also be used to transmit information obtained from the setting page to the information service layer 602. The alarm push module 601212 is used to obtain business alarm information from the information service layer 602 and push it to the user layer 6011.
[0131] The information service layer 602, also known as the business layer 602. The information service layer 602 includes: a monitoring information viewing module 6021, an alarm setting module 6022, a monitoring information analysis module 6023, a monitoring object setting module 6024, and a monitoring index setting module 6025. Among them, the monitoring information viewing module 6021 provides monitoring information to the interaction layer. The alarm setting module 6022 is used to set the content that the business alarm information may include and / or the business alarm information generation rule. For example, the alarm setting module 6022 is used to set that when the first monitoring information of the monitoring object in the user layer associated with the abnormal monitoring object is abnormal information, business alarm information is generated. The monitoring information analysis module 6023 is used to implement the functions of the information service layer of the data processing platform provided in the foregoing embodiment where it is located. The monitoring object setting module 6024 is used to manually set the monitoring objects of each level. The monitoring index setting module 6025 is used to manually set the monitoring indexes in the monitoring information. Figure 5
[0132] The information access layer 603 includes: a monitoring information collection layer 6031, a data processing layer 6032, and a data storage layer 6033. Among them, the monitoring information collection layer 6031 includes: a database synchronization module 60311, a request push module 60312, a data file parsing module 60313, and a data reading interface 60314. Among them, the request push module 60312 is used to send monitoring information requests to monitoring objects at each level and receive monitoring information responses including monitoring information sent by the monitoring objects. The data file parsing module 60313 is used to parse the monitoring information response to obtain the monitoring information. The database synchronization module 60311 is used to transmit the monitoring information to the data processing layer 6032 through the data reading interface 60314.
[0133] The data processing layer 6032 includes: a monitoring data reading module 60321 and a monitoring data writing module 60322. The monitoring data reading module 60321 is used for the service layer to obtain the monitoring information collected by the information access layer 603 from the data storage layer through the monitoring data reading module 60321. The monitoring data writing module 60322 is used to store the monitoring information transmitted by the data processing layer 6032 into the data storage layer.
[0134] The data storage layer 6033 includes: a mySQL database, a log database, and other file databases. The mySQL database, the log database, and other file databases are all used to store information of the data processing platform. Among them, the log database can be used to store the behavior logs of the data processing platform. The mySQL database is also called the original monitoring data storage database and can be used to store the monitoring information of monitoring objects at each level.
[0135] The log module 604 can be used to record the behavior logs of the data processing platform, and the permission control module 605 can be used to verify the permissions of monitoring objects.
[0136] In summary, a data processing platform provided by an embodiment of the present application is used to monitor the running state of a target software. The target software is designed based on a layered architecture, and the layered architecture includes: a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, abnormal detection is performed on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated layer respond to the same service request. When it is determined that the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running abnormality, and service warning information is generated and displayed. When there is no abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running abnormality, and service warning information is generated and displayed. In this technical solution, since there is a high probability that the target software has a real fault problem when there is an abnormality in the user layer. Therefore, when there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the target software, the accuracy of abnormal determination for the target software can be improved by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information. Compared with the related technology, the probability of false warnings of monitoring devices is reduced, the warning accuracy is improved, and the monitoring efficiency is enhanced.
[0137] Please refer to Figure 7 , which shows a block diagram of a data processing device provided by an embodiment of the present application. The data processing device is applied to a monitoring device, and the monitoring device is used to monitor a target software. The target software includes: a user layer, a service layer, and an infrastructure layer; as Figure 7 shown, the data processing device 700 includes: an acquisition module 701, a detection module 702, and a generation module 703.
[0138] The acquisition module 701 is configured to obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the layered architecture. The monitoring information reflects the running state of the monitoring objects;
[0139] The detection module 702 is configured to perform abnormal detection on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object according to the association relationship of the monitoring objects of each layer when there is abnormal information in the monitoring information of other layers that do not belong to the user layer. The abnormal monitoring object is the monitoring object of the abnormal information, and in the association relationship, the monitoring objects of each associated layer respond to the same service request;
[0140] A generating module 703, configured to generate a service alarm message and display the service alarm message when it is determined that the first monitoring information is abnormal information, where the service alarm message is used to reflect that the target software runs abnormally; and is further configured to generate and display the service alarm message when there is no abnormal information in the monitoring information of other levels that do not belong to the user layer and there is abnormal information in the monitoring information of the user layer.
[0141] Optionally, the obtaining module 701 is further configured to obtain second monitoring information of a monitoring object associated with the abnormal monitoring object according to the association relationship, where the second monitoring information is abnormal information.
[0142] The data processing device 700 further includes: a selecting module, configured to select the monitoring information of the first monitoring object among the second monitoring information and the monitoring information of the abnormal monitoring object as source abnormal information according to the response order of each monitoring object in the association relationship for the service request.
[0143] The generating module 703 is further configured to generate a service alarm message including the source abnormal information.
[0144] Optionally, the generating module 703 is further configured to generate a fault link diagram according to the response order of each monitoring object in the association relationship for the service request, the monitoring information of the abnormal monitoring object, and the monitoring information of the monitoring object associated with the abnormal monitoring object, where each piece of monitoring information in the fault link diagram is connected and displayed according to the response order; and is further configured to generate a service alarm message including the fault link diagram.
[0145] Optionally, the data processing device 700 further includes: a sending module, configured to send the service alarm message to an alarm terminal corresponding to the level to which the abnormal monitoring object belongs.
[0146] Optionally, the data processing device 700 further includes: a display module, configured to display the monitoring information query page in response to a display instruction for the monitoring information query page.
[0147] The obtaining module 701 is further configured to: in response to an information query instruction, obtain a query object and an identity identifier of a query person in the monitoring information query page, where the identity identifier corresponds to at least one level, and the person indicated by the identity identifier has the permission to view the monitoring information of the corresponding level, and the query object includes: a target monitoring object and / or a target level.
[0148] The display module is further configured to display a query result page when the level corresponding to the identity identifier is the same as the level of the query object. The query result page includes: monitoring information of the query object and / or monitoring information of each monitoring object associated with the query object in the association relationship.
[0149] Optionally, the monitoring objects in the user layer include: the terminal that sends the service request; the monitoring objects in the service layer include: the interfaces in the server that provide the services required by the target software; the monitoring objects in the infrastructure layer include: the computing unit and / or storage unit in the server. The monitoring information includes: a monitoring object identifier and a monitoring metric. Among them, the monitoring metric of the monitoring object in the user layer includes: the information displayed by the terminal that sends the service request. The monitoring information of the monitoring object in the service layer includes: the Hypertext Transfer Protocol (HTTP) response code of the interface. The monitoring information of the monitoring object in the infrastructure layer includes: the running data of the monitoring object.
[0150] Optionally, the monitoring objects in the service layer include multiple microservice nodes, and the association relationship of each microservice node in the service layer is determined based on the call relationship of each microservice node.
[0151] In summary, a data processing device provided in an embodiment of the present application is applied to a monitoring device for monitoring the running state of a target software. The target software is designed based on a layered architecture, and the layered architecture includes: a user layer, a service layer, and an infrastructure layer. When there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, abnormal detection is performed on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each associated layer respond to the same service request. When it is determined that the first monitoring information of the user layer associated with the abnormal monitoring object is abnormal information, it is determined that the target software has a running abnormality, and a service alarm information is generated and the service alarm information is displayed. When there is no abnormal information in the monitoring information of other layers that do not belong to the user layer in the layered architecture, and there is abnormal information in the monitoring information of the user layer, it is determined that the target software has a running abnormality, and a service alarm information is generated and the service alarm information is displayed. In this technical solution, since there is a high probability that the target software has a real fault problem when there is an abnormal reflection in the user layer. Therefore, when there is abnormal information in the monitoring information of other layers that do not belong to the user layer in the target software, by verifying whether the monitoring information of the monitoring objects in the user layer is abnormal information, the accuracy of abnormal determination for the target software can be improved. Compared with the related technology, the probability of false alarms of the monitoring device is reduced, the warning accuracy is improved, and the monitoring efficiency is enhanced.
[0152] An embodiment of the present application further provides an electronic device, which may be the above-mentioned terminal or server. As Figure 8 shown, it includes a processor 801, a communication interface 802, a memory 803, and a communication bus 804. Among them, the processor 801, the communication interface 802, and the memory 803 communicate with each other through the communication bus 804.
[0153] The memory 803 is used to store a computer program.
[0154] When the processor 801 is used to execute the program stored in the memory 803, the following steps are implemented: obtaining monitoring information of monitoring objects belonging to the user layer, monitoring information of monitoring objects belonging to the service layer, and monitoring information of monitoring objects belonging to the infrastructure layer from the hierarchical architecture, where the monitoring information reflects the operating status of the monitoring objects; when there is abnormal information in the monitoring information of other levels that do not belong to the user layer, performing abnormal detection on the first monitoring information of the monitoring objects of the user layer associated with the abnormal monitoring object according to the association relationship of the monitoring objects of each level, where the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects of each level associated in the association relationship respond to the same service request; when it is determined that the first monitoring information is abnormal information, generating a service alarm information and displaying the service alarm information, where the service alarm information is used to reflect that the target software runs abnormally; when there is no abnormal information in the monitoring information of other levels that do not belong to the user layer and the monitoring information of the user layer has abnormal information, generating the service alarm information and displaying the service alarm information.
[0155] The communication bus mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0156] The communication interface is used for communication between the above electronic device and other devices.
[0157] The memory may include a Random Access Memory (RAM), or may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0158] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU for short), a Network Processor (NP for short), etc.; it may also be a Digital Signal Processor (DSP for short), an Application Specific Integrated Circuit (ASIC for short), a Field-Programmable Gate Array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0159] In another embodiment provided by the present invention, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it performs the steps of any one of the data processing methods described in the above embodiments.
[0160] In another embodiment provided by the present invention, a computer program product containing instructions is further provided. When it runs on a computer, it causes the computer to perform the steps of any one of the data processing methods described in the above embodiments.
[0161] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, a computer, a server, or a data center to another website, a computer, a server, or a data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a Solid State Disk (SSD)).
[0162] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "and / or" means and as well as or. For example, "A and / or B" means: A, B, and the case of both A and B. The terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0163] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for the relevant content.
[0164] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included within the protection scope of the present invention.
Claims
1. A data processing method, characterized in that, Applied to a monitoring device, the monitoring device is used to monitor the running state of a target software, and the target software is designed based on a hierarchical architecture; the method includes: Obtain the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer from the hierarchical architecture, and the monitoring information reflects the running state of the monitoring objects; When there is abnormal information in the monitoring information of other levels that do not belong to the user layer, according to the association relationship of the monitoring objects at each level, perform abnormal detection on the first monitoring information of the monitoring objects in the user layer associated with the abnormal monitoring object, where the abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects at each level associated in the association relationship respond to the same service request; When it is determined that the first monitoring information is abnormal information, generate a service alarm message and display the service alarm message, and the service alarm message is used to reflect that the target software runs abnormally; When there is no abnormal information in the monitoring information of the other levels and there is abnormal information in the monitoring information of the user layer, generate the service alarm message and display the service alarm message.
2. The method according to claim 1, characterized in that, The method further includes: According to the association relationship, obtain the second monitoring information of the monitoring objects associated with the abnormal monitoring object, and the second monitoring information is abnormal information; According to the response order of each monitoring object to the service request in the association relationship, select the monitoring information of the first monitoring object from the second monitoring information and the monitoring information of the abnormal monitoring object as the source abnormal information; The generating of the service alarm message includes: generating a service alarm message including the source abnormal information.
3. The method according to claim 1, characterized in that, The method further includes: According to the response order of each monitoring object to the service request in the association relationship, the monitoring information of the abnormal monitoring object, and the monitoring information of the monitoring objects associated with the abnormal monitoring object, generate a fault link diagram, and the monitoring information in the fault link diagram is connected and displayed according to the response order; The generating of the service alarm message includes: generating a service alarm message including the fault link diagram.
4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Send the service alarm message to the alarm terminal corresponding to the level to which the abnormal monitoring object belongs.
5. The method according to claim 4, characterized in that, The method further includes: In response to a display instruction for a monitoring information query page, display the monitoring information query page; In response to an information query instruction, obtain a query object and the identity identifier of a query person in the monitoring information query page, the identity identifier corresponds to at least one level, and the person indicated by the identity identifier has the permission to view the monitoring information of the corresponding level, and the query object includes: a target monitoring object and / or a target level; When the level corresponding to the identity identifier is consistent with the level of the query object, display a query result page, and the query result page includes: the monitoring information of the query object and / or the monitoring information of each monitoring object associated with the query object in the association relationship.
6. The method according to any one of claims 1 to 3, characterized in that, The monitoring objects at the user layer include: the terminal that sends the service request; the monitoring objects at the service layer include: the interfaces in the server that provide the services required by the target software; the monitoring objects at the infrastructure layer include: the computing unit and / or storage unit in the server, and the monitoring information includes: the monitoring object identifier and the monitoring metrics. Among them, the monitoring metrics of the monitoring objects at the user layer include: the information displayed by the terminal that sends the service request, the monitoring information of the monitoring objects at the service layer includes: the Hypertext Transfer Protocol (HTTP) response code of the interfaces, and the monitoring information of the monitoring objects at the infrastructure layer includes: the running data of the monitoring objects.
7. The method according to any one of claims 1 to 3, characterized in that, The monitoring objects at the service layer include multiple microservice nodes, and the association relationship between the microservice nodes at the service layer is determined based on the call relationship between the microservice nodes.
8. A data processing device, characterized in that, Applied to a monitoring device, the monitoring device is used to monitor the running status of a target software, and the target software is designed based on a layered architecture; the device includes: An acquisition module, configured to obtain, from the layered architecture, the monitoring information of the monitoring objects belonging to the user layer, the monitoring information of the monitoring objects belonging to the service layer, and the monitoring information of the monitoring objects belonging to the infrastructure layer, where the monitoring information reflects the running status of the monitoring objects; A detection module, configured to, when there is abnormal information in the monitoring information of other layers that do not belong to the user layer, perform abnormal detection on the first monitoring information of the monitoring objects at the user layer associated with the abnormal monitoring objects according to the association relationship between the monitoring objects at each layer. The abnormal monitoring object is the monitoring object of the abnormal information, and the monitoring objects at each layer associated in the association relationship respond to the same service request; A generation module, configured to generate a service alarm message and display the service alarm message when it is determined that the first monitoring information is abnormal information, where the service alarm message is used to indicate that the target software is running abnormally; and is also configured to generate and display the service alarm message when there is no abnormal information in the monitoring information of the other layers and there is abnormal information in the monitoring information of the user layer.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store a computer program; The processor, when executing the program stored on the memory, implements the method steps described in any one of claims 1 to 7.
10. A computer-readable storage medium, on which a computer program is stored, characterized in that, The program, when executed by the processor, implements the method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Method and apparatus for monitoring cloud platform
CN108337100A
Abnormality detection method, device and equipment of business system and storage medium
CN114296984A