A customized list-based alarm event data processing method and system
Through the alarm event data processing method based on customized lists, the problems of repeated analysis and cross-platform data analysis in the existing technology are solved, multi-dimensional classification and multi-scenario analysis are realized, and the alarm analysis speed and system reliability are improved.
Patent Information
- Application Number
- CN202310524175.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-10
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2043-05-10
AI Technical Summary
When facing the same problem generated by multiple monitoring systems, existing technologies have problems such as large workload of repeated analysis, inability to aggregate data in multiple dimensions, inability to analyze data across platforms, and inability to locate the root cause of alarms, which affect the speed and efficiency of alarm analysis.
A customized list-based alarm event data processing method is adopted. By pre-processing the received alarm information, adding type tags and relevance tags, generating a task list, and executing multi-scenario analysis tasks, manual query operations are reduced and auxiliary analysis information is provided.
It realizes multi-dimensional classification and multi-scenario analysis of alarm events, improves the speed of alarm analysis, reduces manual intervention, reduces error rate, and improves system reliability and operation and maintenance efficiency.
Smart Images

Figure CN116541788B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of application topology association analysis and system operation and maintenance data processing, and in particular to a method and system for processing alarm event data based on a customized list. Background Art
[0002] With the integration of multiple monitoring systems and strategies, when a problem occurs, multiple different alarms are often generated simultaneously. Most of these alarms are not the root cause of the problem and require further manual analysis. Furthermore, the large number of related alarms creates redundant analysis workload, directly impacting the alarm analysis and handling process. If manual processing relies solely on experienced personnel based on their knowledge, handling a large number of alarms will inevitably consume significant manpower and resources, resulting in low efficiency and difficulty ensuring accuracy. Therefore, it is necessary to classify and aggregate alarms, automatically analyze them, provide more valuable alarm analysis results, and help accelerate alarm analysis.
[0003] To address this issue, existing technologies have proposed a variety of monitoring and alarm systems, such as APM, Splunk, Premetheus, and Hawkeye, as well as using the application configuration management platform CMDB to manage and track various configuration items in IT infrastructure, thereby better managing and maintaining IT systems.
[0004] However, the existing technology still has the following deficiencies in actual use:
[0005] 1) When many related alarms are generated at the same time due to the same problem, it is easy to generate a lot of repeated analysis workload, affecting work efficiency;
[0006] 2) It is impossible to aggregate and converge alarms in multiple dimensions and provide a summary of alarms by type;
[0007] 3) Unable to analyze alarm data and locate the root cause of the alarm or service module;
[0008] 4) It is impossible to conduct cross-platform data analysis on alarms or provide correlation data support.
[0009] Due to the above shortcomings, the existing technology at that time would bring too much repetitive work to the alarm analysis process, affecting the speed and efficiency of alarm positioning. Summary of the Invention
[0010] In order to address the deficiencies of the prior art, the present invention proposes a method and system for processing alarm event data based on a customized list, which realizes the multi-dimensional classification of alarm events and the customization and execution of multi-scenario analysis tasks, and provides functions such as operation correlation analysis, alarm correlation analysis, and cross-service analysis, thereby reducing the manual query operations of alarm analysts, providing auxiliary analysis information, and improving the speed of alarm analysis. At the same time, this technology can also help managers better understand the alarm status and the system operation status, realize the visualization of alarm information, and thus more effectively manage alarm events and improve the reliability and stability of the system. In addition, this technology can also automatically reduce the alarm notification process, reduce manual intervention, improve processing efficiency, and reduce error rates, which can effectively improve the operation and maintenance efficiency and management level of the business system.
[0011] To achieve the above objectives, the technical solutions adopted by the present invention include:
[0012] A method for processing alarm event data based on a customized list, characterized by comprising:
[0013] S1. Receive alarm information and perform preset data preprocessing on the alarm information to generate corresponding alarm events;
[0014] S2. Extracting an alarm object and an alarm source based on the alarm event, performing a first type classification operation based on the alarm object and the alarm source, and adding a first type tag to the alarm event based on the result of the first type classification operation, where the first type tag includes service anomaly, middleware anomaly, and business anomaly;
[0015] S3. Obtaining original alarm data corresponding to the alarm event according to the alarm source, performing a second type classification operation on the original alarm data, and adding a second type tag to the alarm event according to the result of the second type classification operation, where the second type tag includes status abnormality, request abnormality, and internal abnormality;
[0016] S4. Identify relevant services related to the alarm event based on the alarm object, perform operation impact analysis based on the relevant services, and add relevance tags to the alarm event based on the operation impact analysis;
[0017] S5. Generate a task list using the first type tag, the second type tag, and the correlation tag, wherein the task list includes alarm event analysis combinations with the same first type tag, alarm event analysis combinations with the same second type tag, and alarm event correlation combinations with the same correlation tag;
[0018] S6. Call the alarm information analysis task according to the task list, and adjust the task list according to the results generated by the alarm information analysis task;
[0019] S7. Perform alarm information analysis operations based on the adjusted task list.
[0020] Furthermore, step S6 includes:
[0021] Based on the alarm event analysis combination of the first type of tags, the operation impact analysis tasks are called respectively;
[0022] Based on the alarm event analysis combination of the second type of tags, the abnormal call chain analysis task is called separately;
[0023] According to the alarm event association combination, the associated alarm analysis tasks are called separately.
[0024] Furthermore, the operation impact analysis includes any one or more combinations of change object analysis, change status analysis, and change time analysis.
[0025] Furthermore, the abnormal call chain analysis includes abnormal request analysis and key service abnormal call analysis.
[0026] Furthermore, the associated alarm analysis includes alarm log key information analysis and dynamic alarm association analysis.
[0027] Furthermore, the method further comprises:
[0028] Revise the task list based on the output results of the alarm information analysis.
[0029] The present invention also relates to an alarm event data processing system based on a customized list, which is characterized by comprising:
[0030] An information preprocessing module is used to perform preset data preprocessing on the alarm information to generate corresponding alarm events;
[0031] A first type classification module is used to extract an alarm object and an alarm source based on an alarm event, perform a first type classification operation based on the alarm object and the alarm source, and add a first type label to the alarm event based on the result of the first type classification operation;
[0032] A second type classification module is used to obtain original alarm data corresponding to the alarm event according to the alarm source, perform a second type classification operation based on the original alarm data, and add a second type label to the alarm event according to the result of the second type classification operation;
[0033] The correlation analysis module is used to identify the relevant services related to the alarm event based on the alarm object, perform operation impact analysis based on the relevant services, and add correlation tags to the alarm event based on the operation impact analysis;
[0034] A checklist generation module, configured to generate a task checklist using the first type of tags, the second type of tags, and the relevance tags;
[0035] The list adjustment module is used to call the alarm information analysis task according to the task list and adjust the task list according to the results generated by the alarm information analysis task;
[0036] The analysis execution module is used to perform alarm information analysis operations based on the adjusted task list.
[0037] The present invention also relates to a computer-readable storage medium, characterized in that a computer program is stored on the storage medium, and the computer program implements the above method when executed by a processor.
[0038] The present invention also relates to an electronic device, characterized in that it comprises a processor and a memory;
[0039] The memory is used to store alarm information, alarm events and task lists;
[0040] The processor is used to execute the above method by calling alarm information, alarm events and task lists.
[0041] The present invention also relates to a computer program product, comprising a computer program and / or instructions, characterized in that the computer program and / or instructions implement the steps of the above method when executed by a processor.
[0042] The beneficial effects of the present invention are:
[0043] The customized list-based alarm event data processing method and system described in the present invention achieves multi-dimensional classification of alarm events and customization and execution of multi-scenario analysis tasks. It also enables customization and execution of multi-scenario analysis tasks based on alarm types, provides actual analysis data support for alarm analysts, and provides functions such as correlation analysis, alarm correlation analysis, and cross-service analysis, thereby reducing the manual query operations of alarm analysts, providing auxiliary analysis information, and improving the speed of alarm analysis. At the same time, by associating related alarms with the dependent middleware services, the connection between related alarms is increased, reducing alarm analysis time, and helping managers better understand the alarm status and system operation status, realizing visual display of alarm information, realizing cross-service alarm analysis, analyzing alarms from the perspective of the entire service, avoiding alarm service information silos, thereby more effectively managing alarm events and improving system reliability and stability. In addition, this technology can also automate the alarm processing process, reduce manual intervention, improve processing efficiency, reduce error rates, and effectively improve the operation and maintenance efficiency and management level of business systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 The figure is a flow chart of the alarm event data processing method based on the customized list of the present invention.
[0045] Figure 2 This is a structural diagram of the alarm event data processing system based on customized lists of the present invention. DETAILED DESCRIPTION
[0046] In order to more clearly understand the content of the present invention, it will be described in detail with reference to the accompanying drawings and embodiments.
[0047] The first aspect of the present invention relates to a process of steps as follows Figure 1 The customized list-based alarm event data processing method shown includes:
[0048] S1. Receive alarm information, perform preset data preprocessing on the alarm information and generate corresponding alarm events.
[0049] For example, various types of alarms from various alarm sources are received, and the data and format are uniformly processed as alarm events. Alarm object matching, alarm source data extraction, and type analysis are performed for these alarm events. Alarm object matching rules are based on fixed alarm sources and reported object information, matching them with CMDB data. These rules primarily focus on the deployment unit of a specific service, linking upwards to products and businesses, and downwards to dependent middleware and infrastructure. After all data is converted to the same format or structure, it needs to be aggregated. This means aggregating data from different alarm sources and grouping and categorizing it according to specific rules.
[0050] S2. Based on the alarm event, extract the alarm object and alarm source, perform the first type classification operation based on the alarm object and alarm source, and add the first type label to the alarm event based on the result of the first type classification operation. The first type label is preliminarily classified according to the alarm source and alarm information, including service anomaly, middleware anomaly and business anomaly.
[0051] Specifically, for alarm objects, after receiving various types of alarms, it is first necessary to determine which specific device or system these alarms belong to. Usually, a device list and corresponding relationship table are maintained in the system to help achieve automatic matching.
[0052] For the alarm source, after determining the alarm target, it is necessary to extract relevant data about the device from the alarm source. This data typically includes information such as the device name, IP address, port number, etc. Preferably, a corresponding program can be used to parse various types of alarms and extract the required information from them.
[0053] S3. Obtain original alarm data corresponding to the alarm event based on the alarm source, perform a second type classification operation based on the original alarm data, and add a second type label to the alarm event based on the result of the second type classification operation. The second type label includes status exception, request exception and internal exception.
[0054] Priority is given to extracting original alarm data based on the alarm source. In the second type of tags, status anomalies usually come from systems such as Zabbix and Prometheus, and additional correlation analysis can be performed on them; request anomalies mainly come from transaction monitoring or request monitoring, and the main focus is on analyzing the related request call chain; internal anomalies are more complex, such as log error monitoring, and they need to be refined twice to obtain key errors and try to classify them into clear status anomalies or request anomalies for further analysis.
[0055] S4. Identify the services associated with the alarm event based on the alarm object, perform operational impact analysis based on the services, and add relevance tags to the alarm event based on the operational impact analysis. Specifically, based on the alarm type, perform relevance impact analysis based on the application topology and assist in cross-service abnormal call chain analysis.
[0056] S5. Generate a task list using the first type tag, the second type tag, and the correlation tag, wherein the task list includes alarm event analysis combinations with the same first type tag, alarm event analysis combinations with the same second type tag, and alarm event correlation combinations with the same correlation tag.
[0057] S6. Call the alarm information analysis task based on the task list, and adjust the task list based on the results generated by the alarm information analysis task. Specifically, the following operations can be performed sequentially or asynchronously as needed: Based on the alarm event analysis combination of the first type of tags, respectively call the operation impact analysis task, including any one or more combinations of change object analysis, change status analysis, and change time analysis; Based on the alarm event analysis combination of the second type of tags, respectively call the abnormal call chain analysis task, including abnormal request analysis and key service abnormal call analysis; Based on the alarm event correlation combination, respectively call the associated alarm analysis task, including alarm log key information analysis and dynamic alarm correlation analysis.
[0058] Preferably, the user may choose to check the output results of the information analysis and revise the task list based on the check results, thereby obtaining a more efficient and accurate alarm information analysis process.
[0059] Preferably, the analysis work can be processed by a task execution engine, which can execute tasks according to the task list, and determine whether to execute subsequent tasks or replace analysis tasks of the same type based on the execution results of the previous task, and finally summarize and integrate all analysis data and display them for alarm analysis.
[0060] S7. Perform alarm information analysis operations based on the adjusted task list.
[0061] Specifically, for abnormal request analysis, we use the transaction serial number to go to the APM application performance system, query and obtain the problematic transaction call chain, analyze the abnormal nodes in the call chain (request failure, request time-consuming), and then summarize and train them according to the algorithm rules to recommend the preferred abnormal nodes. This information is then shared with the alarm analyst. For abnormal call analysis of key services, we use the transaction monitoring system and the key upstream and downstream call links of the service generated by the transaction system. When an alarm needs to be analyzed, we find the corresponding key upstream and downstream services based on the service where the alarm object is located, and check whether there are any abnormalities in the transaction calls between them. The judgment rule is to compare the service's request success rate, transaction time, call volume and other indicators with their average values over the recent period as dynamic thresholds to find the abnormal service node. The analysis results are pushed to the alarm analyst. For the analysis of key information in alarm logs, when a log alarm is generated, the system will associate the log system with the alarm rules to obtain the specific error content, and then perform data analysis on the alarm content to extract key alarm error information and content that may be needed for subsequent analysis (such as error code, business code, transaction serial number, etc.). By comparing the key error information with the maintained matching rules, most alarms can be further divided into status anomalies or request anomalies, providing preliminary data support for the next step of analysis; for dynamic alarm correlation analysis, alarms need to be marked according to their alarm objects and alarm levels. When a new alarm needs to be analyzed, the system will check whether the CMDB objects that the alarm object depends on have blocking alarms based on the object association relationship of CMDB. If so, its dependency and the blocking alarm will be pushed to the alarm analyst.
[0062] Taking a comprehensive analysis of the root cause of an alarm as an example, the specific implementation of the above method may include the following steps:
[0063] 1) Alarm data is uniformly processed and categorized. First, the original alarm is received and its content is classified. The alarm object information (syscode, appname, hostname), alarm source information (checker), alarm level (alermLevel), and alarm category (className) are extracted. Alarm information requiring analysis is pushed to the alarm analysis task queue.
[0064] 2) Secondary analysis of alarm types to generate a customized task analysis list. This system obtains analysis tasks from the message queue. Based on the alarm source and alarm content, the original alarm data is extracted, and the alarm data is secondary analyzed to obtain a clear alarm type. Based on the above information, a detailed analysis task is generated. Analysis example: Log alarms are refined into key error information in this step, and the alarm type is confirmed to be a request exception, and the transaction serial number is extracted and obtained. The alarm analysis tasks are initially: 1. Query whether the alarm service involves changes 2. Query whether the basic services that the alarm service depends on have blocking-level alarms 3. Query the abnormal call chain based on the refined transaction serial number
[0065] 3) Execute analysis tasks and dynamically adjust the task list. Obtain specific analysis tasks and alarm content from the message queue and execute the analysis tasks. After a single task is completed, the analysis result data is saved in the database and pushed to the task engine. The task engine determines whether to continue to execute subsequent tasks or replace other analysis tasks of the same type based on the previous analysis results. Analysis example: After the task is completed based on the transaction serial number, the analysis result does not match a valid exception call chain; the task engine determines that the analysis task is invalid and needs to execute an alternative analysis task, so it executes an exception call analysis based on upstream and downstream key services.
[0066] Another aspect of the present invention relates to an alarm event data processing system based on a customized list, the structure of which is as follows: Figure 2 As shown, including:
[0067] A first type classification module is used to extract an alarm object and an alarm source based on an alarm event, perform a first type classification operation based on the alarm object and the alarm source, and add a first type label to the alarm event based on the result of the first type classification operation;
[0068] A second type classification module is used to obtain original alarm data corresponding to the alarm event according to the alarm source, perform a second type classification operation based on the original alarm data, and add a second type label to the alarm event according to the result of the second type classification operation;
[0069] The correlation analysis module is used to identify the relevant services related to the alarm event based on the alarm object, perform operation impact analysis based on the relevant services, and add correlation tags to the alarm event based on the operation impact analysis;
[0070] A checklist generation module, configured to generate a task checklist using the first type of tags, the second type of tags, and the relevance tags;
[0071] The list adjustment module is used to call the alarm information analysis task according to the task list and adjust the task list according to the results generated by the alarm information analysis task;
[0072] The analysis execution module is used to perform alarm information analysis operations based on the adjusted task list.
[0073] By using this system, the above-mentioned calculation and processing method can be executed and the corresponding technical effects can be achieved.
[0074] An embodiment of the present invention also provides a computer-readable storage medium capable of implementing all steps of the method in the above embodiment. The computer-readable storage medium stores a computer program that implements all steps of the method in the above embodiment when executed by a processor.
[0075] An embodiment of the present invention also provides an electronic device for executing the above-mentioned method. As an implementation device of the method, the electronic device has at least a processor and a memory, and in particular, the memory stores the data and related computer programs required for executing the method, such as alarm information, alarm events and task lists, etc., and the processor calls the data and programs in the memory to execute all the steps of the implementation method and obtains the corresponding technical effects.
[0076] Preferably, the electronic device may include a bus architecture, which may include any number of interconnected buses and bridges, and the bus will include various circuits linked together by one or more processors and memories. The bus may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface between the bus and the receiver and transmitter. The receiver and transmitter can be the same component, namely a transceiver, which provides a unit for communicating with various other systems over a transmission medium. The processor is responsible for managing the bus and general processing, while the memory can be used to store data used by the processor when performing operations.
[0077] Additionally, the electronic device may further include components such as a communication module, an input unit, an audio processor, a display, and a power supply. The processor (or controller, operating control) employed may include a microprocessor or other processor device and / or logic device, which receives input and controls the operation of various components of the electronic device. The memory may be one or more of a cache, flash memory, a hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices, and may store the aforementioned data and information. It may also store programs for executing the relevant information, and the processor may execute the programs stored in the memory to implement information storage or processing. The input unit is used to provide input to the processor, and may, for example, be a keypad or touch input device. The power supply is used to provide power to the electronic device. The display is used to display objects such as images and text, and may, for example, be an LCD display. The communication module is a transmitter / receiver that sends and receives signals via an antenna. The communication module (transmitter / receiver) is coupled to the processor to provide input signals and receive output signals, similar to the case of a conventional mobile communication terminal. Based on different communication technologies, multiple communication modules can be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module. The communication module (transmitter / receiver) is also coupled to a speaker and a microphone via an audio processor to provide audio output via the speaker and receive audio input from the microphone, thereby implementing common telecommunications functions. The audio processor may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor is also coupled to a central processing unit, enabling local recording via the microphone and playback of stored audio via the speaker.
[0078] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0079] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A system that specifies the functions of a box or boxes.
[0080] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction system that is implemented in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0081] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The present invention is described in detail below. ...
[0082] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention are intended to be covered by the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A method for processing alarm event data based on a customized list, characterized in that: include: S1. Receive alarm information and perform preset data preprocessing on the alarm information to generate corresponding alarm events; S2. Extracting an alarm object and an alarm source based on the alarm event, performing a first type classification operation based on the alarm object and the alarm source, and adding a first type tag to the alarm event based on the result of the first type classification operation, where the first type tag includes service anomaly, middleware anomaly, and business anomaly; S3. Obtaining original alarm data corresponding to the alarm event according to the alarm source, performing a second type classification operation on the original alarm data, and adding a second type tag to the alarm event according to the result of the second type classification operation, where the second type tag includes status abnormality, request abnormality, and internal abnormality; S4. Based on the alarm object, identify the relevant services related to the alarm event, perform operational impact analysis based on the relevant services, and add correlation tags to the alarm event based on the operational impact analysis. Specifically, based on the alarm type, perform correlation impact analysis based on the application topology and assist in cross-service abnormal call chain analysis; S5. Generate a task list using the first type tag, the second type tag, and the correlation tag, wherein the task list includes alarm event analysis combinations with the same first type tag, alarm event analysis combinations with the same second type tag, and alarm event correlation combinations with the same correlation tag; S6. Call the alarm information analysis task according to the task list, and adjust the task list according to the results generated by the alarm information analysis task; S7. Perform alarm information analysis operations according to the adjusted task list; Step S6 includes: Based on the alarm event analysis combination of the first type of tags, the operation impact analysis tasks are called respectively; Based on the alarm event analysis combination of the second type of tags, the abnormal call chain analysis task is called separately; According to the alarm event association combination, the associated alarm analysis tasks are called separately.
2. The method according to claim 1, wherein The operation impact analysis includes any one or more combinations of change object analysis, change status analysis, and change time analysis.
3. The method according to claim 1, wherein The abnormal call chain analysis includes abnormal request analysis and key service abnormal call analysis.
4. The method according to claim 1, wherein The associated alarm analysis includes alarm log key information analysis and dynamic alarm association analysis.
5. The method according to claim 1, wherein The method further comprises: Revise the task list based on the output results of the alarm information analysis.
6. An alarm event data processing system based on a customized list, characterized in that: include: An information preprocessing module is used to perform preset data preprocessing on the alarm information to generate corresponding alarm events; A first type classification module is used to extract an alarm object and an alarm source based on an alarm event, perform a first type classification operation based on the alarm object and the alarm source, and add a first type tag to the alarm event based on the result of the first type classification operation, wherein the first type tag includes a service anomaly, a middleware anomaly, and a business anomaly; A second type classification module is used to obtain the original alarm data corresponding to the alarm event according to the alarm source, perform a second type classification operation based on the original alarm data, and add a second type tag to the alarm event according to the result of the second type classification operation, wherein the second type tag includes a state abnormality, a request abnormality, and an internal abnormality; The correlation analysis module is used to identify the relevant services related to the alarm event based on the alarm object, perform operational impact analysis based on the relevant services, and add correlation tags to the alarm event based on the operational impact analysis. Among them, according to the alarm type, correlation impact analysis based on the application topology is performed and cross-service abnormal call chain analysis is assisted; a list generation module, configured to generate a task list using the first type of tags, the second type of tags, and the correlation tags, wherein the task list includes alarm event analysis combinations having the same first type of tags, alarm event analysis combinations having the same second type of tags, and alarm event correlation combinations having the same correlation tags; The list adjustment module is used to call the alarm information analysis task based on the task list, adjust the task list based on the alarm information analysis task generation results, call the operation impact analysis task based on the alarm event analysis combination of the first type of label; call the abnormal call chain analysis task based on the alarm event analysis combination of the second type of label; and call the associated alarm analysis task based on the alarm event association combination; The analysis execution module is used to perform alarm information analysis operations based on the adjusted task list.
7. A computer-readable storage medium, characterized in that The storage medium stores a computer program, which implements the method according to any one of claims 1 to 5 when executed by a processor.
8. An electronic device, characterized in that: including processor and memory; The memory is used to store alarm information, alarm events and task lists; The processor is configured to execute the method according to any one of claims 1 to 5 by calling alarm information, alarm events and task lists.
9. A computer program product comprising a computer program and / or instructions, characterized in that When the computer program and / or instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Alarm analysis method and device, computer equipment and storage medium
CN111522859A
Data alarm method and device, electronic equipment and storage medium
CN115794566A
Data analysis method and device, electronic equipment and storage medium
CN115811463A