A method, system, device and medium for processing intelligent early warning information

CN115098337BActive Publication Date: 2026-08-14KANG JIAN INFORMATION TECH (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-22
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

对于日志数据而言其通常是用于解决已知的技术问题,且难以根据错误日志数据进行信息的智能预警,进而导致错误日志数据的利用率降低

Benefits of technology

[0018] As described above, this invention discloses a method, system, device, and medium for processing intelligent early warning information. The early warning information is generated based on error log data and user-inputted data, effectively enhancing the utilization value of error log data. Simultaneously, it can extract relevant information from user-described events and identify the main characteristics of the current event, then determine potential errors at the current time through event type matching. Early warning information can save manpower and time costs and effectively mitigate error risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115098337B_ABST
    Figure CN115098337B_ABST
Patent Text Reader

Abstract

This invention provides a method, system, device, and medium for processing intelligent early warning information. The method includes acquiring basic data, which includes error log data automatically collected by the system and / or data manually entered by the user; tagging the basic data and storing the tagged basic data in a database; acquiring target data, which is data generated by the user during operation; comparing the target data with the basic data and obtaining comparison weight data; and generating early warning information based on the comparison weight data. This invention effectively improves the problem in existing technologies where it is difficult to perform intelligent early warning based on error log data, leading to a decrease in the utilization rate of error log data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing, and in particular to a method, system, device, and medium for processing intelligent early warning information. Background Technology

[0002] Log data records procedural events generated by IT systems. By viewing log data, one can obtain user information, time information, device information, operating system information, and specific operational information. In existing log systems, valuable data is typically extracted from log data to obtain user behavior information or to mine potential business value. However, log data is usually used to solve known technical problems, and it is difficult to provide intelligent early warnings based on error log data, leading to a decrease in the utilization rate of error log data. Summary of the Invention

[0003] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a method, system, device and medium for processing intelligent early warning information, so as to solve the problem of reduced utilization of error log data in the prior art.

[0004] To achieve the above and other related objectives, the present invention provides a method for processing intelligent early warning information, comprising:

[0005] Acquire basic data, which includes error log data automatically collected by the system and / or data manually entered by the user;

[0006] The basic data is tagged, and the tagged basic data is stored in the database;

[0007] Acquire target data, which is based on data generated by the user during the operation;

[0008] The target data is compared with the basic data, and the comparison weight data is obtained.

[0009] Based on the comparison weight data, an early warning message is generated.

[0010] The present invention also provides a device for processing intelligent early warning information, comprising:

[0011] The basic data acquisition module is used to acquire basic data, which includes error log data automatically collected by the system and / or data manually entered by the user.

[0012] A preprocessing module is used to tag the basic data and store the tagged basic data in a database;

[0013] The target data acquisition module is used to acquire target data, which is based on data generated by the user during the operation process;

[0014] A data comparison module is used to compare the target data with the basic data and obtain comparison weight data; and

[0015] The early warning information generation module is used to generate early warning information based on the comparison weight data.

[0016] The present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described intelligent early warning information processing method.

[0017] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described intelligent early warning information processing method.

[0018] As described above, this invention discloses a method, system, device, and medium for processing intelligent early warning information. The early warning information is generated based on error log data and user-inputted data, effectively enhancing the utilization value of error log data. Simultaneously, it can extract relevant information from user-described events and identify the main characteristics of the current event, then determine potential errors at the current time through event type matching. Early warning information can save manpower and time costs and effectively mitigate error risks. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a schematic diagram of an application environment for the intelligent early warning information processing method of the present invention;

[0021] Figure 2 This is a flowchart illustrating one embodiment of the intelligent early warning information processing method of the present invention;

[0022] Figure 3 This is a flowchart illustrating step S20 of the intelligent early warning information processing method of the present invention in one embodiment;

[0023] Figure 4This is a flowchart illustrating step S40 of the intelligent early warning information processing method of the present invention in one embodiment;

[0024] Figure 5 This is a schematic diagram of a module in one embodiment of the intelligent early warning information processing device of the present invention;

[0025] Figure 6 This is a schematic diagram of the preprocessing module in one embodiment of the intelligent early warning information processing device of the present invention;

[0026] Figure 7 This is a schematic diagram of the data comparison module in one embodiment of the intelligent early warning information processing device of the present invention;

[0027] Figure 8 This is a schematic diagram of another module of the intelligent early warning information processing device of the present invention in one embodiment;

[0028] Figure 9 This is a schematic diagram of a computer device according to one embodiment of the present invention.

[0029] Component designation explanation

[0030] 100. Intelligent early warning information processing device; 101. Electronic equipment; 102. Memory; 103. Processor;

[0031] 200. Basic Data Acquisition Module;

[0032] 300. Preprocessing module; 301. Initialization module; 302. Tag rule module; 303. Mapping module; 304. Storage module;

[0033] 400. Target Data Acquisition Module;

[0034] 500. Data Comparison Module; 501. Extraction Module; 502. Matching Module; 503. Comparison Module;

[0035] 600. Early warning information generation module; 700. Feedback module; 800. Display module. Detailed Implementation

[0036] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.

[0037] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0038] Please see Figure 1 As shown, the intelligent early warning information processing method provided by this invention can be executed by at least one of the following electronic devices: a server, a terminal, or other electronic devices that can be configured to execute the intelligent early warning information processing method. In other words, the intelligent early warning information processing method can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0039] Please see Figure 2 As shown in one embodiment, a method for processing intelligent early warning information is provided, which is applied to... Figure 1 The explanation and illustration will be based on the server-side example.

[0040] First, step S10 is executed to obtain basic data, wherein the basic data includes error log data automatically collected by the system and / or data manually entered by the user. It is understood that the basic data can be obtained automatically or manually. Specifically, for automatically obtained basic data, it includes error log data automatically collected by the system, and for manually entered basic data, it includes data actively entered by the user.

[0041] In one embodiment, the error log data is generated by applications deployed on different servers of the logging system, and the generated error log data is stored on the corresponding servers. Different servers can collect data such as system Info logs and Error logs generated by the service system at preset time nodes.

[0042] In one embodiment, error log data can be obtained in real time by a log collector monitoring error log files in specified directories on different servers. The log collector can be used to forward and aggregate logs and files, acquiring all log stream information. Specifically, in this embodiment, the log collector can be the Filebeat log collector, a lightweight log collector. However, it is not limited to this; the log collector can be determined according to actual needs. After the log collector obtains the log file, it can send the log file and corresponding error log data to a message queue for real-time publication of the error log data. Using a message queue to publish error log data ensures that logs monitored in real time are processed promptly. Furthermore, by using a message queue, it can support the transmission of massive amounts of data (TB-level) and avoid congestion and slow processing of error logs during transmission.

[0043] In one embodiment, user manual data input supplements the basic data through active user input. During this active data input process, users are allowed to input data via text. However, this is not limited to text input and can be determined according to actual needs. For example, users may also be allowed to input data via voice. When a user actively inputs data via voice, a voice recognition tool performs semantic recognition on the voice and converts the voice information into text information. Therefore, after obtaining the text information, it is necessary to extract the text information according to the corresponding extraction process to obtain the feature data corresponding to the current event. For example, the feature data of the current event may include multiple features such as the time, location, people involved, and actions of the current event.

[0044] Next, step S20 is executed to tag the basic data and store the tagged basic data in the database. After obtaining the basic data, it is classified and tagged to allow the basic data to have multiple tags, so that the basic data can be quickly extracted by tags.

[0045] Please see Figure 3 As shown, the process of tagging the basic data and storing the tagged basic data in the database includes the following steps:

[0046] S201. Initialize the classification training dataset and set multiple labels in the classification training dataset.

[0047] In one embodiment, firstly, the data in the dataset is clustered according to selected data features, and the data in the dataset is classified and labeled according to the clustering results, with multiple labels set. Secondly, an initial classification model is trained on the classified and labeled dataset to obtain a trained classification model. Finally, the trained classification model is tested, and a model dataset is established based on the test results.

[0048] In one embodiment, the entity executing the above steps can be a cloud server. The cloud server extracts features from the data in the dataset based on features in a preset feature library, clusters the extracted data features using a clustering algorithm, automatically classifies and labels the data corresponding to the clustering features based on the clustering results, trains a deep learning-based classification model based on the classified and labeled data, and tests the trained classification model. If the test result meets the judgment condition, it indicates that the classification of the dataset is successful, and the classified and labeled dataset is directly used as the model dataset for the deep learning-based classification model to achieve accurate data classification. If the test result does not meet the judgment condition, it indicates that the classification of the dataset has failed, and new features are obtained from the preset feature library, and the entire process is repeated until the test result meets the judgment condition, a model dataset is established, and accurate classification of the basic data is achieved.

[0049] In one embodiment, during the classification of basic data, the PCA data compression algorithm can be used to extract key features from the user-described event. For example, the extracted features may include the time, location, people involved, and actions of the event. After feature extraction from the basic data, the basic data is compared with the features in the initial classification training dataset, and the user-described event is classified using the k-nearest neighbor algorithm.

[0050] S202. Establish corresponding tag rules based on the tags.

[0051] The tags and tag rules can be set in advance. For example, the tags can include the time, place, people, and actions of the event, but are not limited to these. They can be determined according to actual needs and the application scenario of the event.

[0052] S203. According to the labeling rules, establish a mapping between the basic data and the labels.

[0053] In establishing the mapping relationship between the basic data and the tags, the basic data in the database is filtered according to different tag rules. A mapping relationship is then established between the basic data in the database that conforms to the corresponding tag rules and the corresponding tags.

[0054] S204. Store the mapped basic data in the database.

[0055] In this process, the basic data is labeled to ensure that each piece of data always corresponds to a label. Therefore, the mapped basic data is stored in a database.

[0056] Specifically, tagging the basic data is for the purpose of database sharding and table partitioning during storage, facilitating subsequent filtering, screening, and analysis. It's important to note that after acquiring the basic data but before tagging and creating the tag library, unified field addition and mapping operations can be performed on the basic data. These unified field addition and mapping operations facilitate subsequent storage, filtering, and statistical analysis of the basic data.

[0057] As an example, in one embodiment, after basic data is accessed into the database, a unified field addition operation is performed on the basic data accessed into the database. By adding fields, values ​​are assigned to the fields of the basic data accessed into the database, so that the basic data has the corresponding field information.

[0058] Then, a unified mapping operation is performed on the basic data. This unified mapping operation facilitates the storage and analysis of the basic data. Specifically, the unified mapping operation involves setting up a unified mapping rule and analyzing the basic data according to the rule to obtain important field information. For example, the important fields of the basic data include a specific problem field, a solution field, and a final result field, which are stored in a unified format. The specific problem field, solution field, and final result are interrelated; therefore, for the basic data to describe an event, it must simultaneously possess at least three important fields: a specific problem field, a solution field, and a final result.

[0059] In one embodiment, the solution method field is mapped to a level label, which includes positive, moderate, and extreme methods. Specifically, the level label represents the weight of the current solution method's influence on the final result. For example, a positive method indicates that the corresponding solution method has a positive effect on the final result of the current event, and a moderate method indicates that the corresponding solution method has a moderate effect on the final result of the current event. However, this is not the only possibility; the level label can be set according to actual needs.

[0060] In one embodiment, for the basic data, after classification and labeling, a decision tree can be constructed based on the basic data in the database, and caching and dataset indexing can be added. The decision tree can include multiple layers, and each layer includes nodes and rule nodes. Each attribute node has a corresponding rule node; for example, attribute nodes in the first layer have multiple corresponding rule nodes, and attribute nodes can include multiple error log data. Specifically, error log data located on an attribute node can have a corresponding rule node. Furthermore, caching and dataset indexing are also allowed to improve the data retrieval speed.

[0061] Furthermore, step S30 is executed to obtain target data, which is based on data generated by the user during the operation. It is understood that target data is data generated by the user during actual operation, such as the type of event actively described by the user. By analyzing the type of event actively described by the user, it is possible to determine the possible errors in the event. Specifically, for the user, active input of data is allowed via text input. However, this is not limited to this and can be determined according to actual needs; for example, the user may also be allowed to actively input via voice input. When the user actively inputs via voice, a voice recognition tool can be used to perform semantic recognition on the voice and convert the voice information into text information. Therefore, after obtaining the text information, it is necessary to extract the text information according to the corresponding extraction process to obtain the feature data included in the current event.

[0062] Furthermore, step S40 is executed, comparing the target data with the basic data to obtain comparison weight data. It is understood that the comparison weight data characterizes the degree of correlation between the target data and the basic data, and the comparison weight data may include multiple levels. For example, the comparison weight data may include three levels: mild, moderate, and severe, but it is not limited to this; the level distribution of the comparison weight data can be determined according to actual needs. It should be noted that different levels of comparison weight data characterize different degrees of correlation between the target data and the basic data. For example, when the comparison weight data level is mild, it indicates a low degree of correlation between the target data and the basic data; and when the comparison weight data level is severe, it indicates a high degree of correlation between the target data and the basic data.

[0063] Please see Figure 4 As shown, in one embodiment, the process of comparing the target data with the basic data and obtaining the comparison weight data includes the following steps:

[0064] S401. Extract the target feature parameters of the target data. It is understood that the main features of the user-described event can be extracted using the PCA data compression algorithm. For example, the extracted content may include features such as the time, location, people involved, and actions of the event. After feature extraction from the basic data, the basic data is compared with the features in the initial classification training dataset, and the user-described event is classified using the k-nearest neighbor algorithm.

[0065] S402, Perform label matching on the target feature parameters.

[0066] In one embodiment, firstly, labels are predefined, ensuring consistency with the labels in the base data and the label mapping rules. Then, a corresponding mapping relationship is established between the categorized target data and the labels. During this process, the base data in the database is filtered according to different label rules. Furthermore, base data in the database that conforms to the corresponding label rules is mapped to the corresponding labels. Therefore, label matching is performed using the target feature parameters, ensuring that the target data is mapped to the appropriate labels.

[0067] S403. Compare the target feature parameters with the basic data and obtain the comparison weight data.

[0068] In one embodiment, it is permissible to query the target data and basic data corresponding to the current label based on the label. Simultaneously, the target data and basic data under the current label are compared, and comparison weight data is obtained. It is important to note that during the comparison process, a comparison model is used to compare the key features of the target data and the key features of the basic data. For example, the key features may include the specific problem, the solution, and the final result. The comparison model may be obtained by training a feature parameter set using a machine learning algorithm. The feature parameter set is composed of preset feature parameters selected from a training set containing multiple different samples using a feature selection algorithm. For example, an optimal-first search algorithm can be used to select the feature parameters for training the target data, and then the selected feature parameters are imported into an SVM machine learning classifier for training. However, this is not the only possibility; the selection of the comparison model can be based on actual needs.

[0069] In one embodiment, the output of the comparison model is comparison weight data, which allows for different levels of results based on the similarity between the target data and the base data. For example, if the similarity between the target data and the base data is less than 20%, the level of the comparison weight data can be defined as mild. If the similarity between the target data and the base data is between 20% and 60%, the level of the comparison weight data can be defined as moderate. And if the similarity between the target data and the base data is between 60% and 100%, the level of the comparison weight data can be defined as severe. However, this is not the limitation; the similarity range between the target data and the base data can be determined according to actual needs.

[0070] S50. Generate early warning information based on the comparison weight data.

[0071] In one embodiment, after acquiring the comparison weight data, it is permissible to generate warning information based on different levels of the comparison weight data. It is understood that the warning information includes error information that may occur during the current user's operation. The warning information can be provided to the user via an information bar. Specifically, the number of warning messages corresponding to different levels of the comparison weight data varies. For example, if the comparison weight data level is severe, five warning messages are allowed. If the comparison weight data level is moderate, three warning messages are allowed. And if the comparison weight data level is mild, one warning message is allowed.

[0072] In one embodiment, it is possible to record the specific actions a user takes in response to the warning information and provide feedback on those actions to optimize the warning information.

[0073] As can be seen, the above solution improves the utilization rate of error log data by comparing and analyzing basic and target data. Furthermore, early warning information can further save manpower and time costs and mitigate corresponding risks.

[0074] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0075] Please see Figure 5 As shown, in one embodiment, an intelligent early warning information processing device 100 is provided, which corresponds one-to-one with the intelligent early warning information processing method in the above embodiment.

[0076] Please see Figure 5 As shown, the intelligent early warning information processing device 100 includes a basic data acquisition module 200, a preprocessing module 300, a target data acquisition module 400, a data comparison module 500, and an early warning information generation module 600. Here, a module, as referred to in this invention, is a series of computer program segments that can be executed by a processor and perform a fixed function, and is stored in a memory.

[0077] In one embodiment, the basic data acquisition module 200 is used to acquire basic data, wherein the basic data includes error log data automatically collected by the system and / or data manually entered by the user. It is understood that the basic data acquisition method can be either automatic or manual. Specifically, for automatically acquired basic data, it includes error log data automatically collected by the system, and for manually entered basic data, it includes data content actively entered by the user.

[0078] In one embodiment, error log data is generated by applications deployed on different servers of the logging system, and the generated error log data is stored on the corresponding servers. Different servers can collect system Info logs, Error logs, and other data generated by the service system at preset time nodes. User manual input supplements the basic data through active user input. Users are allowed to actively input data via text input, but this is not limited to this and can be determined according to actual needs. For example, users can also be allowed to actively input via voice input. When a user actively inputs via voice, a voice recognition tool performs semantic recognition on the voice and converts the voice information into text information. Therefore, after obtaining the text information, it is necessary to extract the text information according to the corresponding extraction process to obtain the feature data corresponding to the current event. For example, the feature data of the current event may include multiple features such as the time, location, people, and actions involved in the current event.

[0079] Please see Figure 6 As shown, in one embodiment, the preprocessing module 300 is used to tag the basic data and store the tagged basic data in a database. After acquiring the basic data, it is classified and tagged to allow the basic data to have multiple tags, facilitating rapid extraction of the basic data based on the tags. The preprocessing module 300 includes an initialization module 301, a tagging rule module 302, a mapping module 303, and a storage module 304.

[0080] In one embodiment, the initialization module 301 is used to initialize a classification training dataset, in which multiple labels are set. First, the data in the dataset is clustered according to selected data features, and the data in the dataset is classified and labeled according to the clustering results, with multiple labels set. Second, the initialized classification model is trained on the classified and labeled dataset to obtain a trained classification model. Finally, the trained classification model is tested, and a model dataset is established based on the test results.

[0081] In one embodiment, the tag rule module 302 is used to establish corresponding tag rules based on the tags. The tags and tag rules can be pre-defined; for example, the tags may include tags such as the time, location, people, and actions of the event, but are not limited to these, and can be determined according to actual needs and the application scenario of the event.

[0082] In one embodiment, the mapping module 303 is used to establish a mapping between the basic data and the tags according to the tag rules. Specifically, in the process of establishing the mapping relationship between the basic data and the tags, the basic data in the database is filtered according to different tag rules. A mapping relationship is then established between the basic data in the database that conforms to the corresponding tag rules and the corresponding tags.

[0083] In one embodiment, the storage module 304 is used to store the mapped basic data in a database. By tagging the basic data, the basic data always corresponds to a tag. Therefore, the mapped basic data is stored in the database.

[0084] It's important to note that tagging the basic data is for database sharding and table partitioning during storage, facilitating subsequent filtering, screening, and analysis. Furthermore, after acquiring the basic data but before tagging and creating the tag library, standardized field addition and mapping operations can be performed. These standardized field addition and mapping operations facilitate subsequent storage, filtering, and statistical analysis of the basic data.

[0085] In one embodiment, the target data acquisition module 400 is used to acquire target data, which is data generated by the user during operation. It is understood that the target data is data generated by the user during actual operation, such as the type of event actively described by the user. By analyzing the type of event actively described by the user, it is possible to determine the possible errors in the event. Specifically, for the user, active input of data is allowed via text input. However, this is not limited to this and can be determined according to actual needs; for example, the user may also be allowed to actively input via voice input. When the user actively inputs via voice, a voice recognition tool can be used to perform semantic recognition on the voice and convert the voice information into text information. Therefore, after acquiring the text information, it is necessary to extract the text information according to the corresponding extraction process to obtain the feature data included in the current event.

[0086] Please see Figure 7 As shown, in one embodiment, the data comparison module 500 is used to compare the target data with the basic data and obtain comparison weight data. The data comparison module 500 may include an extraction module 501, a matching module 502, and a comparison module 503.

[0087] In one embodiment, the extraction module 501 is used to extract target feature parameters from the target data. It is understood that the main features of the user-described event can be extracted using the PCA data compression algorithm; for example, the extracted content may include features such as the time, location, people, and actions of the event. After feature extraction from the basic data, the basic data is compared with the features in the initial classification training dataset, and the user-described event is classified using the k-nearest neighbor algorithm.

[0088] In one embodiment, the matching module 502 is used to perform label matching on the target feature parameters. Labels can be pre-defined, and these labels must be consistent with the labels in the base data and the label mapping rules. Then, a corresponding mapping relationship is established between the classified target data and the labels. During the process of establishing the mapping relationship between the base data and the labels, the base data in the database is filtered according to different label rules. Furthermore, a mapping relationship is established between the base data in the database that conforms to the corresponding label rules and the corresponding labels. Therefore, by performing label matching on the target feature parameters, the target data is mapped to corresponding labels.

[0089] In one embodiment, the comparison module 503 is used to compare the target feature parameters with the basic data and obtain comparison weight data. It allows querying the target data and basic data corresponding to the current label based on the label. Simultaneously, it compares the target data and basic data under the current label and obtains comparison weight data. It should be noted that during the comparison process, a comparison model is used to compare the key features of the target data and the key features of the basic data. For example, the key features may include the specific problem, the solution, and the final result.

[0090] In one embodiment, the warning information generation module 600 is used to generate warning information based on the comparison weight data. After obtaining the comparison weight data, warning information can be generated according to different levels of the comparison weight data. It is understood that the warning information includes error information that may occur during the current user's operation. The warning information can be displayed in an information bar to provide the user with corresponding warning information.

[0091] Please see Figure 8 As shown, in one embodiment, the intelligent early warning information processing device 100 may further include a feedback module 700 and a display module 800. The feedback module 700 records the user's specific actions regarding the early warning information and provides feedback on these actions to optimize the early warning information. Simultaneously, the display module 800 allows recording user behavior, such as the number of automatically entered errors, the number of manually entered errors, the number of times error prompts were triggered, and the adoption status of error prompt solutions during actual operation. The display module 800 can output the recorded data according to a preset timeframe to improve the early warning effect.

[0092] Please see Figure 9As shown, the present invention also provides an electronic device 101, including one or more memories 102 and a processor 103, and may further include a computer program stored in the memory 102 and executable on the processor 103, such as a processing method program based on intelligent early warning information. The electronic device 101 may be a computer, a laptop computer, a tablet computer, a workbench, or a personal digital assistant, etc. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein. In some embodiments, the processor 103 may be composed of integrated circuits, for example, it may be composed of a single packaged integrated circuit, or it may be composed of multiple integrated circuits packaged with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips, etc. The processor 103 is the control unit of the electronic device 101. It connects to various components of the electronic device 101 through various interfaces and lines. It executes various functions of the electronic device 101 and processes data by running or executing programs or modules stored in the memory 102 and calling data stored in the memory 102.

[0093] It should be noted that when the processor of the electronic device 101 executes the computer program, it implements the steps in the above-mentioned intelligent early warning information processing method. Therefore, all implementation methods based on the intelligent early warning information processing method are applicable to the electronic device 101 and can achieve the same or similar beneficial effects.

[0094] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in the above-described intelligent early warning information processing method. The computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.

[0095] In summary, this invention provides a method, system, device, and medium for processing intelligent early warning information. The early warning information is generated based on error log data and user-inputted data, effectively enhancing the utilization value of error log data. Simultaneously, it can extract relevant information from user-described events and identify the main characteristics of the current event, then determine potential errors at the current time through event type matching. Early warning information can save manpower and time costs and effectively mitigate error risks. Therefore, this invention effectively overcomes the various shortcomings of existing technologies and has high industrial application value.

[0096] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A method for processing intelligent early warning information, characterized in that, include: Acquire basic data, which includes error log data automatically collected by the system and / or data manually entered by the user; the error log data is generated by applications deployed on different servers of the logging system; the data manually entered by the user is used to supplement the basic data. The basic data is tagged, and the tagged basic data is stored in the database; Acquire target data, which is based on data generated by the user during the operation; The target data is compared with the basic data, and the comparison weight data is obtained. Based on the comparison weight data, an early warning message is generated; The step of tagging the basic data and storing the tagged basic data in the database includes: Initialize the classification training dataset and set multiple labels in the classification training dataset; Establish corresponding tag rules based on the tags; According to the labeling rules, a mapping is established between the basic data and the labels; The mapped basic data is stored in a database; After classifying and labeling the basic data, a decision tree is constructed based on the basic data in the database. The decision tree includes multiple layers, each layer including attribute nodes and rule nodes. Each attribute node has a corresponding rule node, and the attribute node includes multiple error log data.

2. The method for processing intelligent early warning information according to claim 1, characterized in that, The basic data includes multiple categories of information, which include specific problems, solutions, and final results, and these categories are interconnected.

3. The method for processing intelligent early warning information according to claim 2, characterized in that, The solutions are mapped to rating labels, which include positive, moderate, and extreme approaches. The rating labels represent the weight of the current solution on the final result.

4. The method for processing intelligent early warning information according to claim 1, characterized in that, Build a decision tree within the database, and add caching and dataset indexes.

5. The method for processing intelligent early warning information according to claim 4, characterized in that, The step of comparing the target data with the basic data and obtaining the comparison weight data includes: Extract the target feature parameters from the target data; Perform label matching on the target feature parameters; The target feature parameters are compared with the basic data, and the comparison weight data is obtained. The comparison weight data includes three levels: mild, moderate, and severe, and the comparison weight data represents the degree of correlation between the target data and the basic data.

6. The method for processing intelligent early warning information according to claim 1, characterized in that, In the step of generating warning information based on the comparison weight data, the warning information includes error information that the current user may make during the operation.

7. A device for processing intelligent early warning information, characterized in that, include: The basic data acquisition module is used to acquire basic data, which includes error log data automatically collected by the system and / or user-inputted data; the error log data is generated by applications deployed on different servers of the log system; the user-inputted data is supplemented to the basic data by the user actively inputting it. A preprocessing module is used to tag the basic data and store the tagged basic data in a database; The target data acquisition module is used to acquire target data, which is based on data generated by the user during the operation process; A data comparison module is used to compare the target data with the basic data and obtain comparison weight data; and The early warning information generation module is used to generate early warning information based on the comparison weight data; The step of tagging the basic data and storing the tagged basic data in the database includes: Initialize the classification training dataset and set multiple labels in the classification training dataset; Establish corresponding tag rules based on the tags; According to the labeling rules, a mapping is established between the basic data and the labels; The mapped basic data is stored in a database; After classifying and labeling the basic data, a decision tree is constructed based on the basic data in the database. The decision tree includes multiple layers, each layer including attribute nodes and rule nodes. Each attribute node has a corresponding rule node, and the attribute node includes multiple error log data.

8. An electronic device, characterized in that, The system includes a processor coupled to a memory, the memory storing program instructions, and when the program instructions stored in the memory are executed by the processor, the system implements the intelligent early warning information processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, Includes a program that, when run on a computer, causes the computer to perform a method for processing intelligent early warning information as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Multi-system association early warning method, device and equipment and computer readable storage medium

    CN109710585A