Monitoring methods, devices, equipment, media and program products based on knowledge graphs

Through the monitoring method based on knowledge graph, the changes in data sources are monitored in real time and an automated disposal solution is generated, which solves the problem of lagging deployment of monitoring tools, and achieves rapid response and efficient deployment of the monitoring end.

CN115658424BActive Publication Date: 2025-09-02CCB FINTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211187224.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2025-09-02
Estimated Expiration
2042-09-27

AI Technical Summary

Technical Problem

The deployment and configuration of existing monitoring tools mainly relies on manual operations, resulting in lagging in the deployment of monitoring tools and being unable to quickly respond to changes in resources and applications in the system, affecting the normal operation of services.

Method used

Build a target knowledge graph based on the knowledge graph, monitor data changes in the data source in real time, obtain the location information and types of changing knowledge, generate an automated disposal plan, and send it to the automation platform for follow-up updates on the monitoring end.

Benefits of technology

It improves the follow-up efficiency of monitoring tools, ensures that the monitoring end can quickly respond to changes in the objects to be monitored in the system, and improves the monitoring deployment efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115658424B_ABST
    Figure CN115658424B_ABST
Patent Text Reader

Abstract

The present disclosure provides a monitoring method based on a knowledge graph, which can be applied to the field of automatic operation and maintenance technology. The method includes: in response to data change information of a data source, determining the knowledge change operation of a target knowledge graph; in response to the knowledge change operation of a target knowledge graph, obtaining the position information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change; generating an automated disposal plan for the data change information based on the position information, the type of knowledge that has changed, and the type of change, wherein the automated disposal plan is used for the monitoring end to perform follow-up updates on data changes of the data source; and sending the automated disposal plan to an automated platform. The present disclosure also provides a monitoring device, equipment, storage medium, and program product based on a knowledge graph.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence technology, specifically to the field of automatic operation and maintenance technology, and in particular to a monitoring method, device, equipment, medium and program product based on knowledge graph. Background Art

[0002] With the advancement of computer technology, information technology, cloud computing, and other technologies, electronic systems are becoming increasingly complex. Consequently, monitoring tools and methods are evolving accordingly, with a growing variety of monitoring types and indicators. To ensure service reliability and security, monitoring tools must be deployed and configured promptly for all new or changed resources and applications in the system to ensure continuous and stable business operations.

[0003] In related technologies, the deployment and configuration of monitoring tools are all performed manually. A small number of steps have achieved automated deployment and configuration, but their triggering and concatenation still need to be completed manually. Changes in resources, applications, etc. in the system cannot be quickly reflected on the monitoring end, resulting in delayed deployment of monitoring tools on the monitoring end, low deployment efficiency, and even affecting the normal operation of the service.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0005] In view of the above problems, the present disclosure provides a knowledge graph-based monitoring method, apparatus, device, medium and program product to improve the efficiency of monitoring deployment.

[0006] According to a first aspect of the present disclosure, a monitoring method based on a knowledge graph is provided, comprising: determining a knowledge change operation of a target knowledge graph in response to data change information of a data source, wherein the target knowledge graph is pre-constructed based on data of the data source, and the target knowledge graph maintains a connection with the data source;

[0007] In response to a knowledge change operation of a target knowledge graph, obtaining location information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change;

[0008] generating an automated processing plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change, wherein the automated processing plan is used by the monitoring end to dynamically update the data change of the data source; and

[0009] The automated treatment plan is sent to the automated platform.

[0010] According to an embodiment of the present disclosure, pre-building a target knowledge graph based on the data of the data source includes:

[0011] Constructing a first knowledge graph of objects to be monitored, topological relationships between the objects to be monitored and their related components, and deployment location information of the objects to be monitored based on data in a database of the system architecture;

[0012] Build a second knowledge graph of monitoring tools, packaged versions, and installation and deployment location information based on data from the automation platform database;

[0013] Constructing a third knowledge graph of monitoring tool configuration file versions and corresponding configuration information based on the data in the application configuration database;

[0014] The first knowledge graph, the second knowledge graph and the third knowledge graph are fused to generate a target knowledge graph.

[0015] According to an embodiment of the present disclosure, the step of fusing the first knowledge graph, the second knowledge graph, and the third knowledge graph to generate a target knowledge graph includes:

[0016] According to the correspondence between the monitoring tool package version and the configuration version, the deployment knowledge and configuration knowledge of the monitoring tool are integrated;

[0017] The monitoring relationship between the monitoring tool and the object to be monitored is determined according to the deployment location information of the monitoring tool and the object to be monitored, so as to complete the knowledge fusion of the monitoring tool and the object to be monitored.

[0018] According to an embodiment of the present disclosure, generating an automated handling solution for the data change information based on the location information, the changed knowledge type, and the change type includes:

[0019] Determining local knowledge structure information of the changed knowledge according to the position information;

[0020] Arranging an action plan for the data change information according to the type of knowledge that has changed and the type of change; and

[0021] The local knowledge structure information is filled into the action plan to generate an automated handling plan for the data change information.

[0022] According to an embodiment of the present disclosure, the data change information includes a data source tag and a data change type tag. The operation of determining the knowledge change of the target knowledge graph in response to the data change information of the data source includes:

[0023] The corresponding knowledge change operation in the target knowledge graph is determined according to the data change type, and the data change type includes addition, update and deletion.

[0024] According to an embodiment of the present disclosure, it further includes:

[0025] Performing knowledge reasoning on the target knowledge graph to determine knowledge missing information of the target knowledge graph;

[0026] The target knowledge graph is updated according to the knowledge missing information.

[0027] According to an embodiment of the present disclosure, performing knowledge reasoning on the target knowledge graph includes:

[0028] Inferring a first topological relationship between types of objects to be monitored based on the topological relationship between the objects to be monitored;

[0029] Inferring a second topological relationship between the type of the monitoring tool and the type of the object to be monitored based on the topological relationship between the monitoring tool and the object to be monitored;

[0030] Determining a knowledge graph schema for inference based on the first topological relationship and the second topological relationship; and

[0031] The knowledge missing information of the target knowledge graph is determined based on the schema of the target knowledge graph and the inferred knowledge graph schema.

[0032] A second aspect of the present disclosure provides a monitoring device based on a knowledge graph, comprising: a first determining module, configured to determine a knowledge change operation of a target knowledge graph in response to data change information of a data source, wherein the target knowledge graph is pre-constructed based on data of the data source, and the target knowledge graph maintains a connection with the data source;

[0033] An acquisition module, configured to respond to a knowledge change operation on a target knowledge graph and acquire location information of the changed knowledge in the target knowledge graph, a type of knowledge that has changed, and a type of change;

[0034] a generation module, configured to generate an automated processing plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change, wherein the automated processing plan is used by the monitoring end to dynamically update the data change in the data source;

[0035] The sending module is used to send the automated disposal plan to the automated platform.

[0036] The third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned knowledge graph-based monitoring method.

[0037] The fourth aspect of the present disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to execute the above-mentioned knowledge graph-based monitoring method.

[0038] The fifth aspect of the present disclosure also provides a computer program product, including a computer program, which implements the above-mentioned knowledge graph-based monitoring method when executed by a processor.

[0039] The monitoring method based on the knowledge graph provided by the embodiment of the present disclosure determines the knowledge change operation of the target knowledge graph by monitoring the data change information of the data source in real time, wherein the target knowledge graph is pre-built based on the data of the data source, and the target knowledge graph maintains a connection with the data source; obtains the location information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change; generates an automated disposal plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change; and sends the automated disposal plan to the automation platform. Compared with the existing technology, the monitoring method provided by the embodiment of the present disclosure is based on the knowledge graph, collects and identifies the status change information of the monitored objects and monitoring tools in real time, and composes the follow-up response that the monitoring end needs to make, and sends it to the automation platform in real time. It can quickly respond to the changes of the monitored objects in the system, make corresponding configuration changes on the monitoring end, greatly improve the follow-up efficiency of the monitoring tools, and provide monitoring deployment efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0041] Figure 1 Schematically illustrates an application scenario diagram of a monitoring method, apparatus, device, medium, and program product based on a knowledge graph according to an embodiment of the present disclosure;

[0042] Figure 2 The flowchart of the monitoring method based on the knowledge graph according to the embodiment of the present disclosure is schematically shown;

[0043] Figure 3 The flowchart of the method for constructing the target knowledge graph according to the embodiment of the present disclosure is schematically shown;

[0044] Figure 4a The structure diagram of the first knowledge graph according to an embodiment of the present disclosure is schematically shown;

[0045] Figure 4b Schematically shows a structural diagram of a second knowledge graph according to an embodiment of the present disclosure;

[0046] Figure 4c Schematically shows a structural diagram of a third knowledge graph according to an embodiment of the present disclosure;

[0047] Figure 4d The schematic diagram of the structure of the target knowledge graph according to the embodiment of the present disclosure is shown schematically;

[0048] Figure 5 A flowchart of a method for generating an automated treatment plan according to an embodiment of the present disclosure is schematically shown;

[0049] Figure 6 A flowchart of performing knowledge reasoning on a target knowledge graph according to an embodiment of the present disclosure is schematically shown;

[0050] Figure 7 Schematically shows a structural block diagram of a monitoring device based on a knowledge graph according to an embodiment of the present disclosure; and

[0051] Figure 8 A block diagram of an electronic device suitable for implementing a knowledge graph-based monitoring method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0052] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0053] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0054] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0055] When expressions such as "at least one of A, B and C, etc." are used, they should generally be interpreted in accordance with the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0056] Based on the above technical problems, an embodiment of the present disclosure provides a monitoring method based on a knowledge graph, the method comprising: determining the knowledge change operation of a target knowledge graph in response to data change information of a data source, wherein the target knowledge graph is pre-constructed based on the data of the data source, and the target knowledge graph maintains a connection with the data source; in response to the knowledge change operation of the target knowledge graph, obtaining the position information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change; generating an automated disposal plan for the data change information based on the position information, the type of knowledge that has changed, and the type of change, wherein the automated disposal plan is used for the monitoring end to perform follow-up updates on data changes of the data source; and sending the automated disposal plan to an automation platform.

[0057] Figure 1 The application scenario diagram of the knowledge graph-based monitoring method, apparatus, equipment, medium and program product according to an embodiment of the present disclosure is schematically shown.

[0058] like Figure 1 As shown, the application scenario 100 according to this embodiment may include an automatic operation and maintenance scenario. A network 104 is used as a medium for providing a communication link between terminal devices 101, 102, 103 and a server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0059] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0060] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.

[0061] Server 105 can be a server that provides various services, such as a backend management server (for example only) that supports websites browsed by users using terminal devices 101, 102, and 103. The backend management server can collect and identify status change information of monitored objects and monitoring tools in real time based on the knowledge graph, and compile the follow-up response required by the monitoring terminal and send it to the automation platform to implement follow-up updates of the monitoring terminal.

[0062] It should be noted that the monitoring method based on the knowledge graph provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the monitoring device based on the knowledge graph provided in the embodiment of the present disclosure can generally be set in the server 105. The monitoring method based on the knowledge graph provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the monitoring device based on the knowledge graph provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105.

[0063] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0064] The following will be based on Figure 1 The scene described by Figures 2 to 6 The knowledge graph-based monitoring method of the disclosed embodiment is described in detail.

[0065] Figure 2 A flowchart of a knowledge graph-based monitoring method according to an embodiment of the present disclosure is schematically shown.

[0066] like Figure 2 As shown, the knowledge graph-based monitoring method of this embodiment includes operations S210 to S240, and the knowledge graph-based monitoring method can be executed by a server or other computing devices.

[0067] In operation S210 , a knowledge change operation of a target knowledge graph is determined in response to data change information of a data source.

[0068] According to an embodiment of the present disclosure, the target knowledge graph is pre-constructed based on the data of the data source, and the target knowledge graph remains connected to the data source.

[0069] According to an embodiment of the present disclosure, the data change information includes a data source tag and a data change type tag. The corresponding knowledge change operation in the target knowledge graph is determined according to the data change type, and the data change type includes addition, update and deletion.

[0070] In one example, monitored objects can be categorized into two main groups: resources and applications. Monitoring types can be further categorized into hardware monitoring, system monitoring, database monitoring, application monitoring, network monitoring, log monitoring, security monitoring, service monitoring, performance monitoring, and business monitoring. Each type includes a variety of monitoring metrics. Monitoring tools must be deployed and configured as quickly as possible for all new or changed resources and applications in the system. However, since different monitored objects correspond to different monitoring tools and components, these tools are deployed in a distributed manner across different servers, and configuration data is stored in different types of databases.

[0071] In order to more intuitively understand the addition or change of various resources and applications in the system, the embodiment of the present disclosure constructs a target knowledge graph based on the data of each data source, and represents the relationship between the monitored objects, monitoring tools, version information, and configuration content information through the knowledge graph. When the data of the data source changes, such as the new installation of a certain hardware, the new deployment of a certain application or service, the update of a certain application configuration, the offline of a certain service, etc., the addition, deletion and update of the data of the monitored object, the target knowledge graph will change accordingly. The knowledge change operation of the target knowledge graph is adapted to the data change of the data source connected to it, that is, when a certain data of the data source is updated, the knowledge change operation of the target knowledge graph is also updated. The knowledge graph forms a stable connection with each data source, docks the data structures on both sides, and adopts a polling mechanism or an active trigger mechanism for data source changes to return data changes in real time; when the data change information of the data source is identified, the knowledge graph performs corresponding data change operations on the addition, update, and deletion of the data.

[0072] In operation S220, in response to a knowledge change operation of a target knowledge graph, location information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change are obtained.

[0073] In one example, after determining the knowledge changes in the target knowledge graph, in order to complete the follow-up update of the monitoring end as quickly as possible, it is necessary to obtain the type of knowledge that has changed, the type of change, and the specific location in the knowledge graph, so as to obtain information related to the monitored object or monitoring tool that has changed, including version information, configuration version and configuration content, etc., to prepare for the subsequent automated disposal plan.

[0074] In operation S230 , an automated handling solution for the data change information is generated according to the location information, the type of the changed knowledge, and the change type.

[0075] In operation S240 , the automated treatment plan is sent to an automated platform.

[0076] According to an embodiment of the present disclosure, the automated processing solution is used for the monitoring end to perform follow-up updates according to data changes in the data source.

[0077] In one example, different handling plans can be pre-arranged for different combinations of change types (such as addition, update, deletion) and types of knowledge that have changed (such as those related to the monitored object, monitoring tool version, and configuration). The handling plan refers to the automated processing flow for a certain scenario. Different combinations, i.e., different scenarios, correspond to different handling plans. The target handling plan is determined based on the type of knowledge that has changed and the type of change. Preferably, an automated handling plan for the data change information can also be generated in real time based on the location information, the type of knowledge that has changed, and the type of change. For details on the generation plan of the automated handling plan, please refer to Figure 5 Operations S231 to S233 are not described in detail here.

[0078] The automated handling solution determined in operation S230 is sent to the automation platform and mapped into a series of actions similar to a task flow in the automation platform, including but not limited to issuing, installing, initializing, starting, stopping, configuring and updating, etc. The series of actions are executed to complete the follow-up update of the monitoring end.

[0079] The knowledge graph-based monitoring method provided by the embodiment of the present disclosure collects and identifies status change information of the monitored objects and monitoring tools in real time based on the knowledge graph, and arranges the follow-up responses required by the monitoring end and sends them to the automation platform in real time. It can respond quickly to changes in the monitored objects in the system and make corresponding configuration changes on the monitoring end, thereby greatly improving the follow-up efficiency of the monitoring tools and improving monitoring deployment efficiency.

[0080] The following will be combined Figures 3 to 4d Introduce the method for constructing the target knowledge graph in the embodiment of the present disclosure. Figure 3 A flowchart of a method for constructing a target knowledge graph according to an embodiment of the present disclosure is schematically shown. Figure 4a The structure diagram of the first knowledge graph according to an embodiment of the present disclosure is schematically shown; Figure 4b Schematically shows a structural diagram of a second knowledge graph according to an embodiment of the present disclosure; Figure 4c Schematically shows a structural diagram of a third knowledge graph according to an embodiment of the present disclosure; Figure 4d The schematic diagram of the structure of the target knowledge graph according to the embodiment of the present disclosure is shown schematically; Figure 3 As shown, it includes operations S310 to S340.

[0081] In operation S310 , a first knowledge graph of objects to be monitored, topological relationships between the objects to be monitored and related components, and deployment location information of the objects to be monitored is constructed based on data in a database of a system architecture.

[0082] In one example, a knowledge graph is constructed of the topological relationships and deployment location information of various monitored objects such as resources, applications, and other related components in the system. The related components can be middleware, service components, and all components that are broadly related to the monitored objects. Specifically, data on the system architecture in the enterprise CMDB is obtained, with a focus on resource and application type data; based on the extracted entity tables, attribute tables, relationship tables, and other types of data, the schema of the knowledge graph is designed, or a dynamic schema of the knowledge graph is used, that is, a global structure of entities, their attributes, and the relationships between entities, so that the entered data has a corresponding knowledge structure for storage; the acquisition module of the data platform is used to connect to the CMDB to collect the corresponding data, and perform data deletion, mapping, and other sorting work; finally, the data entry interface of the knowledge graph is used or data is directly written to the database for data entry to generate the first knowledge graph. An example of the knowledge structure formed is as follows: Figure 4a shown.

[0083] In operation S320 , a second knowledge graph of monitoring tools, packaged versions, and installation and deployment location information is constructed based on data in the automation platform database.

[0084] In one example, the automation platform-related database may include the enterprise CMDB, the automation platform project configuration library or table (such as Redis, Nacos, ES), etc.; extract relevant data, mainly the packaged installation versions of the monitoring tools and their corresponding deployment location information, the relative location information of the configuration files after installation, the configuration version information, etc., map them into triple relationships and attribute data, and store them in the second knowledge graph. The knowledge structure formed is as follows: Figure 4b shown.

[0085] In operation S330 , a third knowledge graph of monitoring tool configuration file versions and corresponding configuration information is constructed based on the data in the application configuration database.

[0086] In one example, the application configuration-related database may include the enterprise CMDB, the configuration library or table of each monitoring tool project (such as Redis, Nacos, ES), etc.; extract relevant data, mainly the configuration version corresponding to each packaged installation version of the monitoring tool and its specific configuration content information, etc., map it into triple relationships and attribute data, and store it in the knowledge graph. The knowledge structure formed is as follows: Figure 4c shown.

[0087] In operation S340, the first knowledge graph, the second knowledge graph, and the third knowledge graph are fused to generate a target knowledge graph.

[0088] According to an embodiment of the present disclosure, operation S340 further includes operation S341 and operation S342.

[0089] In operation S341 , the deployment knowledge and configuration knowledge of the monitoring tool are integrated according to the correspondence between the package version and the configuration version of the monitoring tool.

[0090] In operation S342 , a monitoring relationship between the monitoring tool and the object to be monitored is determined based on the deployment location information of the monitoring tool and the object to be monitored, so as to complete the knowledge fusion between the monitoring tool and the object to be monitored.

[0091] In one example, the first knowledge graph, the second knowledge graph, and the third knowledge graph are fused to generate a target knowledge graph. Specifically, the monitoring tool knowledge is fused, and the deployment and configuration knowledge of the monitoring tool are fused based on the correspondence between the packaged version and the configuration version of the monitoring tool. It should be noted that this knowledge may come from the automation platform or the monitoring tool configuration library, and the knowledge source should be selected according to the actual situation; the monitoring tool and the knowledge of the object to be monitored are fused, and the monitoring relationship of the monitoring tool to the monitored object is fused based on the correspondence between the deployment location information of the two (or the deployment location information in the configuration information). The knowledge structure of the target knowledge graph is as follows: Figure 4d No.

[0092] Figure 5 The flowchart of the method for generating an automated treatment plan according to an embodiment of the present disclosure is schematically shown. Figure 5 As shown, operation S230 includes operations S231 to S233.

[0093] In operation S231 , local knowledge structure information of the changed knowledge is determined according to the location information.

[0094] In operation S232 , an action plan for the data change information is compiled according to the changed knowledge type and the change type.

[0095] In operation S233 , the local knowledge structure information is filled into the action plan to generate an automated handling plan for the data change information.

[0096] In one example, for knowledge changes, relevant information is combined, a set of processing actions is arranged, and sent to the automation platform to complete the follow-up update of the monitoring end. Specifically, different processing schemes are arranged for different combinations of the type of change (such as addition, update, deletion) and the type of knowledge changed (such as related to the monitored object, monitoring tool version, and configuration). For example, if a new monitoring object is added, a monitoring tool for the same type of monitoring object needs to be configured. For example, if the monitoring tool configuration changes, the configuration file of the corresponding position needs to be changed. According to the knowledge change position information, the local knowledge structure information of the position is obtained in the target knowledge graph obtained after knowledge fusion. For example, if the monitored object changes, the knowledge structure information with a topological relationship with the object is obtained, including monitoring tools, related components, deployment location information, monitoring tool version information, and monitoring configuration information, etc. These knowledge information are filled into the action plan determined by operation S232 to generate a specific executable automation processing scheme. This automation processing scheme is similar to a task flow workflow automatically executed by the automation platform. Compared with manual configuration, the method of the embodiment of the present disclosure has higher monitoring deployment efficiency and is more sensitive to changes in resources or applications in the system.

[0097] After knowledge fusion, knowledge reasoning can be performed to further update and improve the target knowledge graph. Figure 6 A flowchart for performing knowledge reasoning on a target knowledge graph according to an embodiment of the present disclosure is schematically shown.

[0098] like Figure 6 As shown, it includes operation S410 and operation S420.

[0099] In operation S410, knowledge reasoning is performed on the target knowledge graph to determine knowledge missing information of the target knowledge graph;

[0100] In operation S420, the target knowledge graph is updated according to the knowledge missing information.

[0101] According to an embodiment of the present disclosure, a first topological relationship between types of objects to be monitored is inferred based on the topological relationship between the objects to be monitored; a second topological relationship between the type of monitoring tool and the type of object to be monitored is inferred based on the topological relationship between the monitoring tool and the object to be monitored; the inferred knowledge graph schema is determined based on the first topological relationship and the second topological relationship; and the knowledge missing information of the target knowledge graph is determined based on the schema of the target knowledge graph and the inferred knowledge graph schema.

[0102] In one example, in order to further improve the knowledge graph, it is necessary to perform knowledge reasoning on the target knowledge graph and reason out more complex topological relationships based on existing topological relationships, including using the topological relationships between specific objects to be monitored to reason out the first topological relationship between the types of objects to be monitored, using the topological relationships of specific monitoring tools to monitor specific objects to be monitored, and reasoning out the second topological relationship between the monitoring tool type and the type of monitored object. Scalable, it is also possible to reason out the monitoring relationship between the packaged version and the monitored object. The graphical schema of the reasoned knowledge graph determined based on these topological relationships is compared with the existing graphical schema of the target knowledge graph to determine the missing knowledge information, mark the missing knowledge areas, and issue prompts to the user. Optionally, for the missing knowledge areas, the data source corresponding to the missing parts is identified, and prompts are given for supplementing the missing information to update and improve the target knowledge graph.

[0103] Based on the above-mentioned monitoring method based on knowledge graph, the present disclosure also provides a monitoring device based on knowledge graph. Figure 7 The device is described in detail.

[0104] Figure 7 The structural block diagram of the knowledge graph-based monitoring device according to an embodiment of the present disclosure is schematically shown.

[0105] like Figure 7 As shown, the knowledge graph-based monitoring device 700 of this embodiment includes a first determination module 710, an acquisition module 720, a generation module 730 and a sending module 740.

[0106] The first determination module 710 is configured to determine a knowledge change operation for a target knowledge graph in response to data change information from a data source, wherein the target knowledge graph is pre-built based on data from the data source and is connected to the data source. In one embodiment, the first determination module 710 can be configured to perform operation S210 described above, which will not be further described herein.

[0107] The acquisition module 720 is used to respond to the knowledge change operation of the target knowledge graph and obtain the location information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change. In one embodiment, the acquisition module 720 can be used to perform the operation S220 described above, which will not be repeated here.

[0108] Generation module 730 is configured to generate an automated resolution plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change. The automated resolution plan is used by the monitoring terminal to dynamically update data changes in response to data changes at the data source. In one embodiment, generation module 730 may be configured to perform operation S230 described above, and will not be further described here.

[0109] The sending module 740 is used to send the automated treatment plan to the automated platform. In one embodiment, the sending module 730 can be used to perform the operation S240 described above, which will not be repeated here.

[0110] According to an embodiment of the present disclosure, any multiple modules among the first determination module 710, the acquisition module 720, the generation module 730, and the sending module 740 can be combined into one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the first determination module 710, the acquisition module 720, the generation module 730, and the sending module 740 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in an appropriate combination of any of them. Alternatively, at least one of the first determining module 710 , the acquiring module 720 , the generating module 730 and the sending module 740 may be at least partially implemented as a computer program module, which may perform corresponding functions when executed.

[0111] Figure 8 A block diagram of an electronic device suitable for implementing a knowledge graph-based monitoring method according to an embodiment of the present disclosure is schematically shown.

[0112] like Figure 8As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage part 908 into a random access memory (RAM) 903. The processor 901 may, for example, include a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include an onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0113] Various programs and data required for the operation of the electronic device 900 are stored in the RAM 903. The processor 901, ROM 902, and RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in one or more memories.

[0114] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card or a modem. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed in the drive 910 as needed, so that a computer program read therefrom can be installed into the storage portion 908 as needed.

[0115] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0116] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above and / or one or more memories other than ROM 902 and RAM 903.

[0117] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the knowledge graph-based monitoring method provided by the embodiments of the present disclosure.

[0118] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 901 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0119] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0120] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0121] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0123] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways, even if such combinations and / or couplings are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or couplings are intended to fall within the scope of this disclosure.

[0124] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A monitoring method based on knowledge graph, characterized in that: The monitoring method comprises: In response to data change information of a data source, determining a knowledge change operation of a target knowledge graph, wherein the target knowledge graph is pre-built based on data of the data source, and the target knowledge graph maintains a connection with the data source; In response to a knowledge change operation of a target knowledge graph, obtaining location information of the changed knowledge in the target knowledge graph, the type of knowledge that has changed, and the type of change; generating an automated processing plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change, wherein the automated processing plan is used by the monitoring end to dynamically update the data change of the data source; and Sending the automated treatment plan to the automated platform; Wherein, pre-building a target knowledge graph based on the data of the data source includes: Constructing a first knowledge graph of objects to be monitored, topological relationships between the objects to be monitored and their related components, and deployment location information of the objects to be monitored based on data in a database of the system architecture; Build a second knowledge graph of monitoring tools, packaged versions, and installation and deployment location information based on data from the automation platform database; Constructing a third knowledge graph of monitoring tool configuration file versions and corresponding configuration information based on the data in the application configuration database; Performing knowledge fusion on the first knowledge graph, the second knowledge graph, and the third knowledge graph to generate a target knowledge graph; The step of generating an automated handling solution for the data change information according to the location information, the type of knowledge that has changed, and the type of change includes: Determining local knowledge structure information of the changed knowledge according to the position information; Arranging an action plan for the data change information according to the type of knowledge that has changed and the type of change; and The local knowledge structure information is filled into the action plan to generate an automated handling plan for the data change information.

2. The monitoring method according to claim 1, characterized in that: The fusing the first knowledge graph, the second knowledge graph, and the third knowledge graph to generate a target knowledge graph includes: According to the correspondence between the monitoring tool package version and the configuration version, the deployment knowledge and configuration knowledge of the monitoring tool are integrated; The monitoring relationship between the monitoring tool and the object to be monitored is determined according to the deployment location information of the monitoring tool and the object to be monitored, so as to complete the knowledge fusion of the monitoring tool and the object to be monitored.

3. The monitoring method according to claim 1, wherein: The data change information includes a data source tag and a data change type tag. The operation of determining the knowledge change of the target knowledge graph in response to the data change information of the data source includes: The corresponding knowledge change operation in the target knowledge graph is determined according to the data change type, and the data change type includes addition, update and deletion.

4. The monitoring method according to claim 2, further comprising: Performing knowledge reasoning on the target knowledge graph to determine knowledge missing information of the target knowledge graph; The target knowledge graph is updated according to the knowledge missing information.

5. The monitoring method according to claim 4, characterized in that: The knowledge reasoning on the target knowledge graph includes: Inferring a first topological relationship between types of objects to be monitored based on the topological relationship between the objects to be monitored; Inferring a second topological relationship between the type of the monitoring tool and the type of the object to be monitored based on the topological relationship between the monitoring tool and the object to be monitored; Determining a knowledge graph schema for inference based on the first topological relationship and the second topological relationship; and The knowledge missing information of the target knowledge graph is determined based on the schema of the target knowledge graph and the inferred knowledge graph schema.

6. A monitoring device based on a knowledge graph, comprising: A first determining module is configured to determine a knowledge change operation of a target knowledge graph in response to data change information of a data source, wherein the target knowledge graph is pre-built based on data of the data source and the target knowledge graph maintains a connection with the data source; An acquisition module, configured to respond to a knowledge change operation on a target knowledge graph and acquire location information of the changed knowledge in the target knowledge graph, a type of knowledge that has changed, and a type of change; a generation module, configured to generate an automated processing plan for the data change information based on the location information, the type of knowledge that has changed, and the type of change, wherein the automated processing plan is used by the monitoring end to dynamically update the data change in the data source; A sending module, configured to send the automated disposal plan to an automated platform; Wherein, pre-building a target knowledge graph based on the data of the data source includes: Constructing a first knowledge graph of objects to be monitored, topological relationships between the objects to be monitored and their related components, and deployment location information of the objects to be monitored based on data in a database of the system architecture; Build a second knowledge graph of monitoring tools, packaged versions, and installation and deployment location information based on data from the automation platform database; Constructing a third knowledge graph of monitoring tool configuration file versions and corresponding configuration information based on the data in the application configuration database; Performing knowledge fusion on the first knowledge graph, the second knowledge graph, and the third knowledge graph to generate a target knowledge graph; Wherein, the generating module is further used for: Determining local knowledge structure information of the changed knowledge according to the position information; Arranging an action plan for the data change information according to the type of knowledge that has changed and the type of change; and The local knowledge structure information is filled into the action plan to generate an automated handling plan for the data change information.

7. An electronic device comprising: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors are enabled to perform the monitoring method according to any one of claims 1 to 5. 8 . A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, causes the processor to execute the monitoring method according to claim 1 .

9. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the monitoring method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data monitoring method and device for knowledge graph

    CN113971236A

  • Operation and maintenance management system and method based on knowledge base

    CN114706994A