Link monitoring method and apparatus, storage medium, and electronic device
Patent Information
- Application Number
- CN202311532378.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2043-11-16
AI Technical Summary
[0003]有鉴于此,本发明实施例提供了一种链路监控方法、装置、存储介质及电子设备,以解决现有技术缺乏针对较为复杂的链路的问题快速定位能力,从而难以得到监控分析结果的问题;也就是说,本发明实施例可对较为复杂的链路进行监控分析,以得到监控分析结果,可有效精准定位到具体异常的链路,便于相关运维人员进行排障
[0017] This invention can acquire N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and the at least one target liveness detection file corresponding to a link supports the detection of the corresponding link. M and N are both positive integers. Then, based on each target liveness detection file among the N target liveness detection files, the corresponding links in the M links can be detected to obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. Each link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under the corresponding target liveness detection file. Based on this, the target liveness detection results can be determined based on the link liveness detection results of each link under each corresponding target liveness detection file. The target liveness detection results include: the probe data of each node to be livened in each link, and the probe data of a node to be livened is determined based on the node liveness detection results of the corresponding node under each corresponding target liveness detection file. Based on the target liveness detection results, monitoring and analysis are performed on M links to obtain monitoring and analysis results. It can be seen that the embodiments of the present invention can use N target liveness detection files to perform liveness detection on any link to obtain monitoring and analysis results, thus enabling the monitoring and analysis of relatively complex links to obtain monitoring and analysis results. Based on this, specific abnormal links can be effectively and accurately located, facilitating troubleshooting by relevant operation and maintenance personnel.
Smart Images

Figure CN117596183B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a link monitoring method, apparatus, storage medium, and electronic device. Background Technology
[0002] Currently, data transfer protocols (such as SFTP (SSH File Transfer Protocol) or FTP (File Transfer Protocol)) are widely used in various scenarios, including finance and education. SFTP, in particular, involves more complex access paths and is suitable for scenarios with high security requirements, such as those in finance. However, when anomalies occur in these complex paths, existing technologies lack the ability to quickly locate problems, making it difficult to obtain monitoring and analysis results. Therefore, how to monitor and analyze complex paths to obtain accurate results has become a research hotspot. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a link monitoring method, device, storage medium, and electronic device to solve the problem that the prior art lacks the ability to quickly locate problems in relatively complex links, thus making it difficult to obtain monitoring and analysis results; that is, embodiments of the present invention can monitor and analyze relatively complex links to obtain monitoring and analysis results, and can effectively and accurately locate specific abnormal links, making it easier for relevant operation and maintenance personnel to troubleshoot.
[0004] According to one aspect of the present invention, a link monitoring method is provided, the method comprising:
[0005] Obtain N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files. At least one target liveness detection file corresponding to a link can be used to detect the liveness of the corresponding link. M and N are both positive integers.
[0006] Based on each of the N target liveness detection files, the corresponding links in the M links are liveness detected, and the link liveness detection results of each link in the M links under each corresponding target liveness detection file are obtained. Each link liveness detection result includes: the node liveness detection results of each node to be liveness detected in the corresponding link under a corresponding target liveness detection file.
[0007] Based on the link activation results of each link under each corresponding target activation file, the target activation results are determined. The target activation results include: the activation data of each node to be activated in each link, and the activation data of a node to be activated is determined based on the node activation results of the corresponding node to be activated under each corresponding target activation file.
[0008] Based on the target activity detection results, the M links are monitored and analyzed to obtain the monitoring and analysis results.
[0009] According to another aspect of the present invention, a link monitoring device is provided, the device comprising:
[0010] The acquisition unit is used to acquire N target liveness detection files;
[0011] The processing unit is used to determine M links under the target transmission protocol. Each link includes at least one node to be probed. Each link corresponds to at least one target probe file among the N target probe files. The at least one target probe file corresponding to a link supports the use of probes for the corresponding link. M and N are both positive integers.
[0012] The processing unit is further configured to perform liveness detection on the corresponding links in the M links based on each of the N target liveness detection files, and obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. A link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under a corresponding target liveness detection file.
[0013] The processing unit is further configured to determine the target activation result based on the link activation result of each link under each corresponding target activation file. The target activation result includes the activation data of each node to be activated in each link, and the activation data of a node to be activated is determined based on the node activation result of the corresponding node to be activated under each corresponding target activation file.
[0014] The processing unit is also used to monitor and analyze the M links based on the target detection results to obtain monitoring and analysis results.
[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device including a processor and a memory storing a program, wherein the program includes instructions that, when executed by the processor, cause the processor to perform the methods mentioned above.
[0016] According to another aspect of the present invention, a non-transitory computer-readable storage medium is provided storing computer instructions for causing a computer to perform the methods mentioned above.
[0017] This invention can acquire N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and the at least one target liveness detection file corresponding to a link supports the detection of the corresponding link. M and N are both positive integers. Then, based on each target liveness detection file among the N target liveness detection files, the corresponding links in the M links can be detected to obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. Each link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under the corresponding target liveness detection file. Based on this, the target liveness detection results can be determined based on the link liveness detection results of each link under each corresponding target liveness detection file. The target liveness detection results include: the probe data of each node to be livened in each link, and the probe data of a node to be livened is determined based on the node liveness detection results of the corresponding node under each corresponding target liveness detection file. Based on the target liveness detection results, monitoring and analysis are performed on M links to obtain monitoring and analysis results. It can be seen that the embodiments of the present invention can use N target liveness detection files to perform liveness detection on any link to obtain monitoring and analysis results, thus enabling the monitoring and analysis of relatively complex links to obtain monitoring and analysis results. Based on this, specific abnormal links can be effectively and accurately located, facilitating troubleshooting by relevant operation and maintenance personnel. Attached Figure Description
[0018] Further details, features, and advantages of the invention are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:
[0019] Figure 1 A flowchart illustrating a link monitoring method according to an exemplary embodiment of the present invention is shown;
[0020] Figure 2 A schematic diagram of a link according to an exemplary embodiment of the present invention is shown;
[0021] Figure 3 A schematic diagram of a target detection result according to an exemplary embodiment of the present invention is shown;
[0022] Figure 4 A flowchart illustrating another link monitoring method according to an exemplary embodiment of the present invention is shown;
[0023] Figure 5 A flowchart illustrating yet another link monitoring method according to an exemplary embodiment of the present invention is shown;
[0024] Figure 6A schematic diagram of abnormal link information according to an exemplary embodiment of the present invention is shown;
[0025] Figure 7 A schematic block diagram of a link monitoring device according to an exemplary embodiment of the present invention is shown;
[0026] Figure 8 A structural block diagram of an exemplary electronic device that can be used to implement embodiments of the present invention is shown. Detailed Implementation
[0027] Embodiments of the present invention will now be described in more detail with reference to the accompanying drawings. While some embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the invention. It should be understood that the accompanying drawings and embodiments are for illustrative purposes only and are not intended to limit the scope of protection of the invention.
[0028] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.
[0029] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc., mentioned in this invention are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.
[0030] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0031] The names of the messages or information exchanged between the multiple devices in the embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of these messages or information.
[0032] It should be noted that the execution subject of the link monitoring method provided in this embodiment of the invention can be one or more electronic devices, and this invention does not limit this; wherein, the electronic device can be a terminal (i.e., a client) or a server. Therefore, when the execution subject includes multiple electronic devices, and among the multiple electronic devices includes at least one terminal and at least one server, the link monitoring method provided in this embodiment of the invention can be jointly executed by the terminal and the server. Accordingly, the terminal mentioned herein can include, but is not limited to: smartphones, tablets, laptops, desktop computers, smartwatches, smart voice interaction devices, smart home appliances, etc. The server mentioned herein can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, etc.
[0033] Based on the above description, this embodiment of the invention proposes a link monitoring method, which can be executed by the aforementioned electronic device (terminal or server); or, the link monitoring method can be executed jointly by the terminal and the server. For ease of explanation, the following description will use the execution of the link monitoring method by an electronic device as an example; such as Figure 1 As shown, the link monitoring method may include the following steps S101-S104:
[0034] S101, obtain N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and at least one target liveness detection file corresponding to a link can be used to detect the liveness of the corresponding link. M and N are both positive integers.
[0035] A target liveness detection file can be any file, such as a 50KB file or a 60KB file, etc., and this embodiment of the invention does not limit this. Preferably, any two target liveness detection files can be different to avoid mutual overwriting or interference when any two target liveness detection files are used to detect liveness on the same link. Accordingly, a target liveness detection file can support the detection of liveness on each link included in at least one of the M links.
[0036] Optionally, the electronic device may store multiple liveness detection files. In this case, the electronic device may select N target liveness detection files from the multiple liveness detection files stored in it to obtain N target liveness detection files; or, the electronic device may obtain N liveness detection file download links and treat each liveness detection file downloaded from each of the N liveness detection file download links as a target liveness detection file to obtain N target liveness detection files, and so on; the embodiments of the present invention do not limit the method of obtaining N target liveness detection files.
[0037] Optionally, the electronic device may include a liveness detection module (Sftp-prober, a type of probe). In this case, the electronic device can obtain a target liveness detection file through the liveness detection module; that is, the liveness detection module may include the target liveness detection file. Optionally, the electronic device may include N liveness detection modules, where one liveness detection module corresponds to one target liveness detection file, meaning one liveness detection module can obtain one target liveness detection file. In this case, one liveness detection module supports liveness detection on each link included in at least one of the M links through the corresponding target liveness detection file. For ease of explanation, the following description will use one liveness detection module corresponding to one target liveness detection file as an example.
[0038] Optionally, the number of electronic devices can be one or more; when there are multiple electronic devices, a link monitoring system can be formed, and N liveness detection modules can be distributed and deployed on different electronic devices. The liveness detection modules can be used to detect in real time whether the online transmission protocol is alive and functioning normally.
[0039] In this embodiment of the invention, the target transfer protocol can be SFTP or FTP, etc., and this embodiment of the invention is not limited to this. Preferably, the target transfer protocol in this embodiment of the invention can be SFTP. SFTP involves more complex access links (i.e., transmission links or links), thereby enabling rapid location of problems in complex links. SFTP is a secure file transfer protocol based on SSH (Secure Shell). Using the SFTP protocol can provide a secure network encryption algorithm during file transfer, thereby ensuring secure data transmission. For ease of explanation, the following description will use SFTP as the target transfer protocol.
[0040] To ensure secure transmission, applications with high security requirements, such as those in the financial sector, typically use the SFTP protocol for secure data transfer. SFTP access links involve multiple layers, which may include, but are not limited to: external networks (such as domain names), EIPs (Elastic IPs, providing public network bandwidth services), BLBs (load balancers, which distribute application traffic across multiple devices to handle massive access requests and achieve horizontal scaling), leased lines (generally used in financial scenarios, such as between banking institutions where dedicated fiber optic lines are used for security reasons, isolating them from ordinary public network links), and VPNs (Virtual Private Networks), etc.; this embodiment of the invention does not limit this. Therefore, for access links with multiple layers, a universal solution is needed to quickly pinpoint which layer is faulty.
[0041] For example, such as Figure 2 As shown, taking multiple electronic devices as an example, user access paths typically fall into two main categories: one is accessing SFTP via a domain name, and the other, for users with higher security requirements, is accessing SFTP via a dedicated line or VPN. Specifically, user requests originating from a public domain name will pass through the domain name - EIP - BLB - SFTP - GFS, while user requests originating from a dedicated line or VPN will pass through the dedicated line / VPN - BLB - SFTP - GFS (in this case, the institution (such as a bank) needs to pre-whitelist the BLB). It should be noted that GFS is short for GlusterFS, an open-source distributed storage system that is generally used in conjunction with SFTP. Users use SFTP for secure, encrypted file transfers, and file access can then occur on GlusterFS. The devices corresponding to the domain name, EIP, BLB, SFTP, and GFS can each be considered as active nodes to be probed.
[0042] Correspondingly, Figure 2 The number of links shown can be 8, meaning M can be 8. Optionally, N can be 2. Taking one detection module corresponding to one target detection file as an example, the number of detection modules can be 2, and one detection module is responsible for detecting the activity of each link in a certain type of link. N can also be 4, meaning the number of detection modules can also be 4. In this case, the electronic device where one detection module is located can be located in a data center, so one detection module can detect the activity of each link in its data center, or it can detect the activity of one or more links across data centers, and so on. This embodiment of the invention does not limit this.
[0043] Optionally, the liveness detection links required by a liveness detection module can be set based on experience or actual needs, and this embodiment of the invention does not limit this; that is, at least one liveness detection module corresponding to a link (i.e., the liveness detection module where each target liveness detection file in at least one target liveness detection file corresponding to a link is located) can be set based on experience or actual needs, and this embodiment of the invention does not limit this.
[0044] S102, based on each of the N target liveness detection files, perform liveness detection on the corresponding links in the M links to obtain the liveness detection results of each link in the M links under each corresponding target liveness detection file, and a link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under a corresponding target liveness detection file.
[0045] It should be understood that, for any one of the N target liveness detection files, the electronic device can determine at least one link corresponding to any one target liveness detection file from the M links, and based on any one target liveness detection file, perform liveness detection on each link in the at least one link corresponding to any one target liveness detection file, obtaining the link liveness detection result of each link in the at least one link corresponding to any one target liveness detection file under any one target liveness detection file. In other words, for any link among the M links, the electronic device can determine at least one target liveness detection file that supports liveness detection on any link from the N target liveness detection files, that is, determine at least one target liveness detection file corresponding to any link, and perform liveness detection on any link based on each target liveness detection file in the at least one target liveness detection file corresponding to any link, obtaining the link liveness detection result of any link under each corresponding target liveness detection file (i.e., the link liveness detection result of any link under each target liveness detection file in the at least one target liveness detection file corresponding to any link).
[0046] Based on this, for any link among the M links, the electronic device can perform liveness detection on any link based on the corresponding target liveness detection file through each of the at least one liveness detection modules corresponding to any link, and obtain the liveness detection result of any link under each of the at least one liveness detection modules corresponding to any link. The liveness detection result of a link under a liveness detection module can refer to the liveness detection result of the corresponding link under the corresponding target liveness detection file.
[0047] Optionally, during each link monitoring process, a target liveness detection file can support H liveness detections (i.e., H rounds of liveness detection) for each corresponding link, where H is a positive integer. Based on this, for any node to be detected in any link among the M links, and any target liveness detection file in at least one target liveness detection file corresponding to any link, the electronic device can perform H liveness detections on any node to be detected based on any target liveness detection file, and obtain H node liveness detection results for any node to be detected under any target liveness detection file.
[0048] Optionally, the electronic device may further include a decision analysis module (Sftp-judger, an analysis and control unit). Based on this, the liveness detection module containing any target liveness detection file can send the liveness detection results of H nodes under any target liveness detection file for any node to be detected to the decision analysis module; or, it can send the probe data of any node to be detected under any target liveness detection file to the decision analysis module (i.e., send the target liveness detection results to the decision analysis module), etc.; the embodiments of the present invention do not limit this. Optionally, the liveness detection module containing any target liveness detection file and the decision analysis module may be located in the same electronic device or in different electronic devices; it should be understood that when the liveness detection module containing any target liveness detection file and the decision analysis module are located in different electronic devices, the electronic device of the liveness detection module containing any target liveness detection file can send the node liveness detection results or probe data, etc., to the electronic device where the decision analysis module is located. Correspondingly, if a target liveness detection file corresponds to a liveness detection module, then the liveness detection module containing any target liveness detection file can send the liveness detection results of any node to be detected under any target liveness detection file to the decision analysis module; or, send the detection point data of any node to be detected under any target liveness detection file to the decision analysis module, and so on.
[0049] In this embodiment of the invention, the decision analysis module can host multiple liveness detection modules from different clusters and analyze the detection point data within a certain time range.
[0050] S103, based on the link liveness detection results of each link under each corresponding target liveness detection file, determine the target liveness detection results. The target liveness detection results include: the detection point data of each node to be liveness detected in each link, and the detection point data of a node to be liveness detected is determined based on the node liveness detection results of the corresponding node to be liveness detected under each corresponding target liveness detection file.
[0051] It should be understood that after obtaining the H node liveness detection results for any node to be detected under each corresponding target liveness detection file (i.e., the H node liveness detection results for each target liveness detection file in at least one target liveness detection file corresponding to any node to be detected), the detection point data for any node to be detected can be determined based on the H node liveness detection results for each corresponding target liveness detection file. Here, at least one target liveness detection file corresponding to any node to be detected refers to at least one target liveness detection file corresponding to any link where the node to be detected resides.
[0052] In one implementation, for any node to be detected in any link of M links, and any target detection file in at least one target detection file corresponding to any link, the electronic device can integrate the detection results of H nodes of any node to be detected under any target detection file to obtain the detection point data of any node to be detected under any target detection file, and add the detection point data of any node to be detected under any target detection file to the detection point data of any node to be detected, so that the detection point data of any node to be detected includes the detection point data of any node to be detected under each corresponding target detection file.
[0053] For example, suppose a node liveness detection result includes upload time, download time, liveness detection failure counter, file comparison result, and the IP address (Internet address) of the corresponding node to be detected. Protocol (the protocol for interconnecting networks) and the source IP address of the detection module where the corresponding target detection file is located (i.e., the source IP address of the electronic device in the detection module). The detection data of any node to be detected under any target detection file includes: the source IP address (Resource) of the detection module where the target detection file is located, the IP address (Destination) of any node to be detected, the target detection failure counter (exceptionCnt) of any node to be detected under any target detection file, the weighted sum of H upload times of any node to be detected under any target detection file (writeMeanCostTime, such as the average upload time after accumulating H times), the weighted sum of H download times of any node to be detected under any target detection file (readMeanCostTime, such as the average download time after accumulating H times), and the target file comparison result (checkSumDiff) of any node to be detected under any target detection file. Optionally, for any node to be tested and the comparison results of H files under any target test file, if the number of successful comparisons is greater than or equal to a preset comparison threshold, then checkSumDiff can be determined as a successful comparison result (can be set to true); if the number of successful comparisons is less than the preset comparison threshold, then checkSumDiff can be determined as a failed comparison result (can be set to false). Optionally, exceptionCnt can be a weighted summation of H failure counters for any node to be tested and the target test file, or it can be the median calculation result among the H failure counters, etc. It should be noted that the embodiments of the present invention do not limit the weight values in any weighted summation process; for example, weighted summation can refer to mean calculation or summation calculation, etc.
[0054] For example, assuming that at least one target liveness detection file corresponding to any liveness detection node includes liveness detection file 1 and liveness detection file 2, then the detection data of any liveness detection node includes the detection data of any liveness detection node under liveness detection file 1, and the detection data of any liveness detection node under liveness detection file 2. Taking writeMeanCostTime in the detection data of any liveness detection node under liveness detection file 1 as an example, writeMeanCostTime in the detection data of any liveness detection node under liveness detection file 1 can be "the average calculation result of H upload times of any liveness detection node under liveness detection file 1".
[0055] In another implementation, for any node to be detected in any link of M links, and any target detection file in at least one target detection file corresponding to any link, the electronic device can integrate the detection results of H nodes under each corresponding target detection file for any node to be detected to obtain the detection point data of any node to be detected, so that the detection point data of any node to be detected under each corresponding target detection file is integrated into one detection point data.
[0056] For example, assuming that at least one target liveness detection file corresponding to any liveness detection node includes liveness detection file 1 and liveness detection file 2, then the Resource in the detection data of any liveness detection node can be "the source address IP of the liveness detection module where liveness detection file 1 is located; the source address IP of the liveness detection module where liveness detection file 2 is located", Destination can be "the address IP of any liveness detection node; the address IP of any liveness detection node", writeMeanCostTime can be "the weighted sum of the H upload times of any liveness detection node under liveness detection file 1; the weighted sum of the H upload times of any liveness detection node under liveness detection file 2", and so on.
[0057] S104. Based on the target activity detection results, monitor and analyze M links to obtain monitoring and analysis results.
[0058] In this embodiment of the invention, a target liveness detection result can be stored in a bucket within the decision analysis module. A bucket can contain, but is not limited to, the following types of data: liveness detection data from the liveness detection module to the external network (i.e., detection point data), liveness detection data from the liveness detection module to the EIP, liveness detection data from the liveness detection module to the BLB, liveness detection data from the liveness detection module to the SFTP (stored in a variable-length array), and liveness detection data from the liveness detection module to the GFS (stored in a variable-length array). Figure 3 As shown. Since SFTP instances and GFS instances can consist of multiple different instances, this embodiment of the invention uses a variable-length array for storage; for example, Figure 3 This corresponds to three different SFTP instance data sets. Each SFTP instance can access one GFS. Based on this, the electronic device can use the decision analysis module to monitor and analyze M links based on the target liveness detection results, and obtain the monitoring and analysis results; in other words, the electronic device containing the decision analysis module can monitor and analyze M links based on the target liveness detection results, and obtain the monitoring and analysis results.
[0059] Optionally, the core data structure in the decision analysis module can be a multidimensional array to store data through multiple data buckets. The first dimension, bucketsize, can be 10 or 11, etc., and this embodiment of the invention does not limit this. Taking a first dimension bucket size of 10 as an example, in this case, only the most recent 10 target detection results are stored. If the number exceeds this, it can be automatically overwritten in the modulo 10 manner. For example, 1740000010 will overwrite the historical data of 1740000000.
[0060] Optionally, the electronic device may also send the target liveness detection results to ETCD (a distributed key-value storage system) so that ETCD can store the target liveness detection results.
[0061] This invention can acquire N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and the at least one target liveness detection file corresponding to a link supports the detection of the corresponding link. M and N are both positive integers. Then, based on each target liveness detection file among the N target liveness detection files, the corresponding links in the M links can be detected to obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. Each link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under the corresponding target liveness detection file. Based on this, the target liveness detection results can be determined based on the link liveness detection results of each link under each corresponding target liveness detection file. The target liveness detection results include: the probe data of each node to be livened in each link, and the probe data of a node to be livened is determined based on the node liveness detection results of the corresponding node under each corresponding target liveness detection file. Based on the target liveness detection results, monitoring and analysis are performed on M links to obtain monitoring and analysis results. It can be seen that the embodiments of the present invention can use N target liveness detection files to perform liveness detection on any link to obtain monitoring and analysis results, thus enabling the monitoring and analysis of relatively complex links to obtain monitoring and analysis results. Based on this, specific abnormal links can be effectively and accurately located, facilitating troubleshooting by relevant operation and maintenance personnel.
[0062] Based on the above description, this embodiment of the invention also proposes a more specific link monitoring method, which can be executed by the aforementioned electronic device (terminal or server); or, the link monitoring method can be executed jointly by the terminal and the server. For ease of explanation, the following description will use the execution of the link monitoring method by an electronic device as an example; please refer to [link to previous text]. Figure 4 The link monitoring method may include the following steps S401-S405:
[0063] S401, obtain N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and at least one target liveness detection file corresponding to a link supports the use of detecting the liveness of the corresponding link.
[0064] In one implementation, for links that use external domain names, Sftp-prober needs to be deployed on external network nodes (simulating that the user side uses a public network link, i.e., a domain name node) and internal network nodes (mainly including probes for EIP, BLB, SFTP, and GFS). That is, when a link uses an external domain name, at least one active node to be probed in that link can include, but is not limited to, domain names, EIPs, BLBs, SFTPs, and GFS. For the deployment of Sftp-prober on the internal network side, it will also be distributed in two data centers (such as data center 1 and data center 2).
[0065] In another implementation, for links using dedicated lines or VPNs, Sftp-prober needs to be deployed on internal network nodes (mainly including BLB, SFTP, and GFS); that is, when a link uses a dedicated line or VPN, at least one node to be probed in that link can include, but is not limited to, BLB, SFTP, and GFS.
[0066] S402, for any node to be tested in any link of the M links, and any target test file in at least one target test file corresponding to any link, upload any target test file to any node to be tested, and record the upload time of any node to be tested under any target test file.
[0067] It should be noted that after Sftp-prober is deployed, a local configuration can be loaded. This local configuration can include a liveness detection interval, which determines the liveness detection interval (also known as the frequency of liveness detection message transmission, i.e., sending a liveness detection message once at the specified interval). This allows liveness detection to be performed on each of the M links at regular intervals; in other words, liveness detection can begin at regular intervals. Optionally, the local configuration can also include a timeout period. Optionally, the local configuration can be set based on experience or actual needs; this embodiment of the invention does not limit this.
[0068] Optionally, an electronic device (i.e., the electronic device of the detection module containing any target liveness detection file) can establish a connection with any node to be detected. That is, the detection module containing any target liveness detection file can establish a connection with any node to be detected and record the connection establishment time. This connection establishment time is then added to the node liveness detection result of any node under any target liveness detection file, ensuring that the node liveness detection result of any node under any target liveness detection file includes the connection establishment time. In this embodiment of the invention, after the connection is established, any target liveness detection file can be uploaded to any node to be detected.
[0069] S403, based on the upload time of any node to be tested under any target test file, determine the node test result of any node to be tested under any target test file, and determine the link test result of any link under any target test file, so as to realize the test of the corresponding links in M links based on each of the N target test files, and obtain the link test result of each link in M links under each corresponding target test file.
[0070] Furthermore, once any target liveness detection file is successfully uploaded to any liveness detection node, that target liveness detection node can include that target liveness detection file. Based on this, the electronic device can also download any target liveness detection file from any liveness detection node to record the download time of any target liveness detection file on any liveness detection node.
[0071] Accordingly, when determining the node liveness detection result of any node to be tested under any target liveness detection file based on the upload time of any node to be tested under any target liveness detection file, the node liveness detection result of any node to be tested under any target liveness detection file can be determined based on the upload time and download time of any node to be tested under any target liveness detection file. In other words, the upload time of any node to be tested under any target liveness detection file can be added to the node liveness detection result of any node to be tested under any target liveness detection file, and the download time of any node to be tested under any target liveness detection file can be added to the node liveness detection result of any node to be tested under any target liveness detection file, so that the node liveness detection result of any node to be tested under any target liveness detection file includes: the upload time and download time of any node to be tested under any target liveness detection file. Optionally, each time a liveness test is written, such as uploading a target liveness test file to be written to any liveness test node, after downloading (i.e. reading) any target liveness test file from any liveness test node, any liveness test node can delete any target liveness test file. This can avoid leaving dirty data in any liveness test node and can also avoid leaving dirty data in the GFS layer.
[0072] Optionally, the node liveness detection result for any node to be detected under any target liveness detection file may also include a file comparison result. In this case, the electronic device may also, after downloading any target liveness detection file from any node to be detected, obtain the downloaded liveness detection file corresponding to any target liveness detection file, and determine whether the downloaded liveness detection file and any target liveness detection file (i.e., the source file) are the same; if the downloaded liveness detection file and any target liveness detection file are the same, the comparison pass result will be used as the file comparison result in the node liveness detection result of any node to be detected under any target liveness detection file (i.e., the file comparison result of any node to be detected under any target liveness detection file); if the downloaded liveness detection file and any target liveness detection file are different, the comparison fail result will be used as the file comparison result in the node liveness detection result of any node to be detected under any target liveness detection file, such as... Figure 5 As shown.
[0073] Specifically, when determining whether a downloaded probe file is identical to any target probe file, the MD5 (Message Digest Algorithm) value of the downloaded probe file can be determined, and the MD5 value of any target probe file can also be determined. The MD5 values of the downloaded probe file and the target probe file are then compared to determine if they are identical. If the MD5 values of the downloaded probe file and the target probe file are the same, then they are considered identical; if they are different, then they are considered different. Based on this, the MD5 value can be used to check the integrity of the downloaded probe file's content and the consistency of its metadata (such as the file's last modification time).
[0074] Optionally, the node liveness detection result for any node to be tested under any target liveness detection file may also include a liveness detection failure counter. In this case, the electronic device may also count the liveness detection failure counter when it detects that any node to be tested has failed to liveness detection under any target liveness detection file, that is, increment the liveness detection failure counter by 1, and the initial value of the liveness detection failure counter can be 0; furthermore, it may iteratively execute the upload of any target liveness detection file to any node to be tested until liveness detection is successful or the number of failed liveness detection retries for any node to be tested under any target liveness detection file reaches a preset liveness detection threshold, so as to determine the node liveness detection result for any node to be tested under any target liveness detection file. Specifically, it may iteratively execute the upload of any target liveness detection file to any node to be tested, and if the upload is successful, the upload time can be recorded; and any target liveness detection file can be downloaded from any node to be tested, and so on.
[0075] In this embodiment of the invention, during the uploading of any target liveness detection file, if the upload time reaches the timeout period, it can be detected that any node to be tested has failed to test for liveness under any target liveness detection file; or, during the downloading of any target liveness detection file, if the download time reaches the timeout period, it can be detected that any node to be tested has failed to test for liveness under any target liveness detection file; or, when error information (such as connection failure or response failure) is detected for any node to be tested, it can be detected that any node to be tested has failed to test for liveness under any target liveness detection file, and so on; this embodiment of the invention does not limit this. Optionally, the timeout period corresponding to the upload time and the timeout period corresponding to the download time can be the same or different, and this embodiment of the invention does not limit this; when the timeout period corresponding to the upload time and the timeout period corresponding to the download time are different, the local configuration can include the timeout period corresponding to the upload time (e.g., upload timeout) and the timeout period corresponding to the download time (e.g., download timeout).
[0076] It should be noted that the preset liveness detection threshold can be 3 or 4, etc., and this embodiment of the invention does not limit this. Optionally, when it is detected that any liveness detection failure of any node to be detected under any target liveness detection file is detected, in addition to incrementing the liveness detection failure counter by 1, any other information in the liveness detection result of any node to be detected under any target liveness detection file can be empty, or can be all 0, etc.; this embodiment of the invention does not limit this.
[0077] Optionally, after a liveness detection fails, it can be automatically retried (i.e., automatically iteratively execute the above-mentioned process of uploading any target liveness detection file to any node to be detected). The retry interval for each failure can be 1 second or 2 seconds, etc., and this embodiment of the invention does not limit this.
[0078] Optionally, the node liveness detection results of any node to be liveness detected under any target liveness detection file may also include, but are not limited to: sftpName (cluster name), date (timestamp of data (such as node liveness detection results or detection point data, etc.) reported to Sftp-judger), isTheSameAZ (whether the Sftp-prober used to send the liveness detection message (such as the target liveness detection file) and the node receiving the liveness detection message are in different data centers, i.e., whether any node to be liveness detected and the liveness detection module where any target liveness detection file is located are in different data centers), DestHost (the node to be liveness detected, i.e. the node being liveness detected), etc.; the embodiments of the present invention do not limit this.
[0079] S404, Based on the link liveness detection results of each link under each corresponding target liveness detection file, determine the target liveness detection results. The target liveness detection results include: the detection point data of each node to be liveness detected in each link, and the detection point data of a node to be liveness detected is determined based on the node liveness detection results of the corresponding node to be liveness detected under each corresponding target liveness detection file.
[0080] S405, based on the target activity detection results, monitor and analyze M links to obtain monitoring and analysis results.
[0081] Specifically, the electronic device can determine whether there is at least one abnormal data point in the target activity detection results to monitor and analyze M links. If there is at least one abnormal data point in the target activity detection results, the abnormal indication content corresponding to each abnormal data point can be determined to obtain the monitoring and analysis results. The monitoring and analysis results can include the abnormal indication content corresponding to each abnormal data point. Each abnormal indication content includes: abnormal link information of the link corresponding to the abnormal data point, and / or a screening and judgment report under the corresponding abnormal data point. Furthermore, the abnormal indication content corresponding to each abnormal data point can be displayed. Optionally, if there is no abnormal data point in the target activity detection results, normal monitoring indication information can be used as the monitoring and analysis result, etc. Normal monitoring indication information can be used to indicate that the activity detection is normal, that is, to indicate that the transmission of each link is normal, etc.
[0082] In this embodiment of the invention, the probe data of a node to be probed may include at least one of the following: the upload time and download time of the corresponding node to be probed. Optionally, the upload time of a node to be probed may include the upload time of the corresponding node to be probed under each corresponding target probe file, and the download time of a node to be probed may include the download time of the corresponding node to be probed under each corresponding target probe file.
[0083] Based on this, when determining whether there is at least one abnormal data point in the target liveness detection results, for any link among the M links, it can be determined whether there is an abnormal point to be detected in any link. If there is an abnormal point to be detected in any link, the specified time consumption of each node to be detected in any link is determined based on the target liveness detection results. Then, based on the specified time consumption of each node to be detected in any link, it can be determined whether there is an abnormal node in any link. If there is an abnormal node in any link, the detection data of the abnormal node in any link is taken as abnormal data. The difference between the specified time consumption of the abnormal node in any link and the specified time consumption of other nodes to be detected in any link is greater than a preset difference threshold. Optionally, the preset difference threshold can be set according to experience or according to actual needs, and this embodiment of the invention does not limit it in this way.
[0084] It should be noted that, for any live node to be tested in any link, if the difference between the specified time consumption of any live node to be tested and the specified time consumption of other live nodes to be tested in any link is greater than a preset difference threshold, then the live node to be tested can be determined to be an abnormal node in any link; wherein, other live nodes to be tested can be any live node to be tested in any link other than any live node to be tested, or can be the live node to be tested with the minimum specified time consumption in any link, etc.; the embodiments of the present invention do not limit this.
[0085] Optionally, a specified time may include at least one of the following: the upload time, download time, and weighted sum of the upload time and download time of the corresponding node to be tested. Optionally, when a specified time consumption includes at least two of the following: the upload time consumption and download time consumption of the corresponding active node to be tested, and the weighted sum of the upload time consumption and download time consumption of the corresponding active node to be tested, if the difference between each time consumption information (such as the upload time consumption of any active node to be tested) and the corresponding time consumption information of the specified time consumption of other active nodes to be tested in any link is greater than a preset difference threshold, it can be determined that the difference between the specified time consumption of any active node to be tested and the specified time consumption of other active nodes to be tested in any link is greater than the preset difference threshold; or, if the difference between any time consumption information of the specified time consumption of any active node to be tested and the corresponding time consumption information of the specified time consumption of other active nodes to be tested in any link is greater than the preset difference threshold, it can be determined that the difference between the specified time consumption of any active node to be tested and the specified time consumption of other active nodes to be tested in any link is greater than the preset difference threshold, etc.; the embodiments of the present invention do not limit this.
[0086] For example, consider a specified time interval including the upload and download times of the corresponding active node to be tested. If the differences between each time interval in the specified time interval of any active node to be tested and the corresponding time interval in the specified time interval of other active nodes to be tested in any link are all greater than a preset difference threshold, then it can be determined that the difference between the specified time interval of any active node to be tested and the specified time interval of other active nodes to be tested in any link is greater than the preset difference threshold. In this case, when the difference between the upload time interval of any active node to be tested and the upload time interval of other active nodes to be tested in any link is greater than the preset difference threshold, and the difference between the download time interval of any active node to be tested and the download time interval of other active nodes to be tested in any link is greater than the preset difference threshold, it can be determined that the specified time interval of any active node to be tested is greater than the preset difference threshold, thus identifying any active node to be tested as an abnormal node in any link.
[0087] In one specific implementation, the specified time for a node to be tested for liveness can include the specified time for the corresponding node to be tested for liveness in each corresponding target liveness test file, and the specified time for a node to be tested for liveness in a target liveness test file can include at least one of the following: the upload time of the corresponding node to be tested for liveness in the corresponding target liveness test file, the download time of the corresponding node to be tested for liveness in the corresponding target liveness test file, and the weighted sum of the upload time and download time of the corresponding node to be tested for liveness in the corresponding target liveness test file.
[0088] Based on this, each target liveness detection file in at least one target liveness detection file corresponding to any link can be traversed, and the currently traversed target liveness detection file is taken as the current target liveness detection file. Based on the specified time consumption of each node to be tested in any link under the current target liveness detection file, it can be determined whether any link has an abnormal node under the current target liveness detection file. If any link has an abnormal node under the current target liveness detection file, then at least one abnormal node in any link under the current target liveness detection file can be obtained. After traversing each target liveness detection file in at least one target liveness detection file corresponding to any link, Q abnormal nodes in any link can be obtained, where Q is a positive integer. For example, any link may include 1 abnormal node, and this abnormal node is determined based on the specified time consumption of each node to be tested in any link under the first target liveness detection file; or, for example, any link may include two abnormal nodes, a first abnormal node and a second abnormal node. The first abnormal node and the second abnormal node can be determined based on the specified time consumption under the same target liveness detection file, or they can be determined based on the specified time consumption under different target liveness detection files. This embodiment of the invention does not limit this.
[0089] In another specific implementation, the specified time consumption of a node to be tested includes at least one of the following: the weighted sum of the specified times consumption of the corresponding node under each target test file (such as the weighted sum of the upload times consumption of the corresponding node under each target test file, the weighted sum of the download times consumption of the corresponding node under each target test file, etc.), and the specified time consumption of the corresponding node under any target test file (such as the upload time or download time consumption of the corresponding node under any target test file). In this case, it is possible to directly determine whether there is an abnormal node in any link based on the specified time consumption of each node to be tested in any link, that is, only one judgment is made, without having to traverse each target test file in at least one target test file corresponding to any link.
[0090] For ease of explanation, the following explanations will use one target liveness detection file for each node to be tested, that is, the explanation will take the upload time of one node to be tested, including the upload time of the corresponding node to be tested under the corresponding target liveness detection file, and so on.
[0091] Optionally, the probe data for a node to be probed may also include a probe failure counter for the corresponding node. Optionally, the probe failure counter for a node to be probed may include the probe failure counter for the corresponding node in each target probe file.
[0092] In one implementation, when determining whether there is an anomaly to be detected in any link, for any liveness detection node in any link, it can be determined whether any liveness detection node is an anomaly to be detected; if there is an abnormal liveness detection failure counter and / or abnormal time consumption in the detection data of any liveness detection node, then any liveness detection node can be determined as an anomaly to be detected. The abnormal liveness detection failure counter refers to a liveness detection failure counter that is greater than or equal to the liveness detection failure counter threshold. The abnormal time consumption includes at least one of the following: abnormal upload time consumption, abnormal download time consumption, and abnormal summation time consumption. Abnormal upload time consumption refers to upload time consumption that exceeds the upload time consumption threshold. Abnormal download time consumption refers to download time consumption that exceeds the download time consumption threshold. Abnormal summation time consumption refers to summation time consumption that exceeds the summation time consumption threshold. And a summation time consumption is determined by the upload time consumption and download time consumption of the corresponding liveness detection node. Optionally, the upload time threshold, download time threshold, summation time threshold, and liveness detection failure counter threshold can all be set based on experience or actual needs; this embodiment of the invention does not limit this. Optionally, the upload time threshold and download time threshold can be the same or different; this embodiment of the invention does not limit this. Optionally, a summation time can be a weighted sum of the upload time and download time of the corresponding liveness detection node.
[0093] As can be seen, embodiments of the present invention can verify whether all probe data in the same bucket (i.e., data bucket) has abnormal liveness detection failure counters and / or abnormal latency to determine the anomaly to be detected. For example, assuming the liveness detection failure counter threshold is 3, and abnormal latency includes abnormal summation latency (such as average latency), with a summation latency threshold of 2000 milliseconds, then if any probe data of a node to be detected has a liveness detection failure counter greater than or equal to 3, and / or, any probe data of a node to be detected has a summation latency greater than 2000 milliseconds, then any node to be detected can be determined as an anomaly to be detected.
[0094] In another implementation, when determining whether there is an outlier to be detected in any link, for any live node to be detected in any link, the historical time data corresponding to the specified time of any live node to be detected can be obtained, and outlier detection can be performed on any live node to be detected based on the historical time data and the specified time of any live node to be detected; if any live node to be detected is an outlier, then any live node to be detected can be determined as an outlier to be detected.
[0095] It should be noted that if the specified time for any node to be tested includes the upload time of any node to be tested, then the historical time data can include multiple historical upload times for any node to be tested, where a historical upload time is the upload time of the corresponding node to be tested at a historical testing moment; if the specified time for any node to be tested includes the download time of any node to be tested, then the historical time data can include multiple historical download times for any node to be tested, where a historical download time is the download time of the corresponding node to be tested at a historical testing moment; if the specified time for any node to be tested includes the weighted sum of the upload time and download time of any node to be tested, then the historical time data can include the weighted sum of the historical upload time and historical download time of any node to be tested at multiple historical testing moments.
[0096] Optionally, when a specified time consumption includes at least two of the following: the upload time consumption, download time consumption, and the weighted sum of the upload time consumption and download time consumption of the corresponding active node, outlier detection can be performed on any active node based on each time consumption information and historical time consumption data in the specified time consumption of any active node. If any active node is an outlier under each time consumption information, then any active node can be determined to be an outlier; or, if any active node is an outlier under each time consumption information in at least one time consumption information, then any active node can be determined to be an outlier, and so on; the embodiments of the present invention do not limit this. For ease of explanation, the following will use any one of the following as an example: a specified time consumption includes the upload time consumption, download time consumption, and the weighted sum of the upload time consumption and download time consumption of the corresponding active node.
[0097] For example, assuming that the historical time consumption data includes the upload time of the most recent 10 times, that is, the historical upload time at 10 historical liveness detection moments, then the historical upload time at 10 historical liveness detection moments can be used to detect outliers for any node to be detected.
[0098] In one specific implementation, when detecting outliers for any node to be detected based on historical latency data and a specified latency of any node to be detected, the expected historical latency at each of multiple historical detection times can be calculated to obtain the expected specified latency of any node to be detected. If the difference between the specified latency of any node to be detected and the expected specified latency is greater than the expected latency threshold, then any node to be detected can be determined to be an outlier; if the difference between the specified latency of any node to be detected and the expected specified latency is less than or equal to the expected latency threshold, then any node to be detected can be determined not to be an outlier. Optionally, the expected latency threshold can be set based on experience or based on actual needs; this embodiment of the invention does not limit this. The expected specified latency can also be referred to as the latency baseline.
[0099] In another specific implementation, when detecting outliers for any node to be detected based on historical time-consuming data and a specified time consumption for any node to be detected, a first variance can be calculated using the historical specified time consumption of any node to be detected at each historical detection time, and a second variance can be calculated using the historical specified time consumption of any node to be detected at each historical detection time and the specified time consumption of any node to be detected. If the difference between the second variance and the first variance is greater than the variance difference threshold, then any node to be detected can be determined to be an outlier; if the difference between the second variance and the first variance is less than or equal to the variance difference threshold, then any node to be detected can be determined not to be an outlier. Optionally, the variance difference threshold can be set based on experience or based on actual needs, and this embodiment of the invention does not limit this.
[0100] In another specific implementation, when detecting outliers for any node to be detected based on historical time consumption data and a specified time consumption for any node to be detected, cluster analysis can be performed on the historical specified time consumption of any node at each historical detection time to obtain multiple cluster centers. If the distance between the specified time consumption of any node to be detected and each of the multiple cluster centers is greater than a preset distance threshold, then any node to be detected can be determined as an outlier; if the distance between the specified time consumption of any node to be detected and any of the multiple cluster centers is less than or equal to the preset distance threshold, then any node to be detected can be determined as not an outlier. Optionally, the preset distance threshold can be set based on experience or based on actual needs, and this embodiment of the invention does not limit this.
[0101] It should be noted that electronic devices support dynamically updating historical time-consuming data using a sliding window. This allows for the dynamic updating of multiple historical liveness detection moments, thereby updating the historical specified time consumption for each of these moments. This ensures that the historical time-consuming data will not be outdated and cause distortion in subsequent analysis. In other words, multiple historical liveness detection moments can refer to the multiple historical liveness detection moments most recent to the current system time.
[0102] In this embodiment of the invention, an anomaly indication includes a screening and judgment report under the corresponding anomaly point data. Based on this, when determining the anomaly indication corresponding to each anomaly point data in at least one anomaly point data set, for any anomaly point data set in the at least one anomaly point data set, screening and judgment data of the node to be investigated indicated by that anomaly point data set can be obtained. The screening and judgment data includes at least one of the following: resource usage information of the process of the corresponding node to be investigated (i.e., process CPU (Central Processing Unit)), CPU idle rate (i.e., overall CPU IDLE), average load (i.e., load avg), number of read transfer bytes, and number of write transfer bytes. Then, based on the screening and judgment data, a screening and judgment report under any anomaly point data set can be determined to determine the anomaly indication corresponding to any anomaly point data set. The number of read transfer bytes can be the number of read transfer bytes of the corresponding node to be investigated within a preset transfer duration, and the number of write transfer bytes can be the number of write transfer bytes of the corresponding node to be investigated within a preset transfer duration. Optionally, the preset transfer duration can be set based on experience or based on actual needs; this embodiment of the invention does not limit this.
[0103] Optionally, historical screening data corresponding to each screening information in the screening judgment data can be obtained separately, and outlier detection can be performed on each screening information based on each screening information and the historical screening data corresponding to each screening information. If each screening information passes the outlier detection, that is, each screening information is not an outlier (there is no sudden increase), the screening judgment report can be used to indicate that it is not a problem of the active node to be investigated and its own service indicated by any abnormal point data, but is more inclined to judge that it is a fluctuation in grid transmission.
[0104] Optionally, if the resource usage information of a process is too high (i.e., an outlier, with a sudden increase), the number of sessions of the node to be explored indicated by any outlier data can be further determined. If the number of sessions remains unchanged but the number of read transfer bytes or write transfer bytes increases suddenly (i.e., there is an outlier), or the number of sessions increases suddenly but the number of read transfer bytes or write transfer bytes remains stable, the screening and judgment report can be used to indicate that the time consumed by the node to be explored indicated by any outlier data is affected by the sudden increase in the number of concurrent users or the sudden increase in node traffic.
[0105] Optionally, if the CPU idle rate is greater than a preset idle rate threshold (e.g., 50% or 60%), or the average load is greater than a preset load threshold (e.g., CPU logical cores), the screening and judgment report can be used to indicate that the performance capacity of the active node to be investigated indicated by any abnormal point data has reached a bottleneck, etc.
[0106] Furthermore, upon receiving an anomaly indication, a notification can be proactively pushed to frontline operations and maintenance personnel, displaying the anomaly indication content, such as anomaly link information and screening and judgment reports. For example, ... Figure 6 As shown, taking the example of anomaly indication content including abnormal link information, if the SFTP layer is abnormal, then abnormal link information containing SFTP layer abnormality can be displayed; among them, the dashed line can represent the detected time-consuming abnormal points.
[0107] This invention can acquire N target liveness detection files and determine M links under a target transmission protocol. Each link includes at least one node to be detected, and each link corresponds to at least one target liveness detection file among the N target liveness detection files. Furthermore, the at least one target liveness detection file corresponding to a link supports liveness detection for that link. Based on this, for any node to be detected in any of the M links, and for any target liveness detection file among the at least one target liveness detection file corresponding to any link, the target liveness detection file is uploaded to the node to be detected to record the upload time of the node under the target liveness detection file. Based on the upload time of the node under the target liveness detection file, the node liveness detection result of the node under the target liveness detection file is determined, thereby determining the link liveness detection result of any link under the target liveness detection file. This achieves liveness detection for the corresponding links in the M links based on each target liveness detection file among the N target liveness detection files, obtaining the link liveness detection result of each link in the M links under each corresponding target liveness detection file. Furthermore, based on the link liveness detection results of each link under each corresponding target liveness detection file, the target liveness detection results can be determined. The target liveness detection results include: the probe data of each node to be livened in each link, and the probe data of a node to be livened is determined based on the node liveness detection results of the corresponding node under each corresponding target liveness detection file. Based on the target liveness detection results, monitoring and analysis are performed on M links to obtain monitoring and analysis results. It is evident that this embodiment of the invention provides an effective transmission sensing method, especially an effective SFTP sensing method for longer transmission links. That is, this embodiment of the invention can monitor and analyze relatively complex links to obtain monitoring and analysis results, quickly locating which layer has a problem. Furthermore, after analyzing abnormal data, the abnormal indication content in the monitoring and analysis results can be pushed to the front-line maintenance personnel in real time for reminders, enabling maintenance personnel to perceive problems at the second level, facilitating troubleshooting.
[0108] Based on the description of the relevant embodiments of the above link monitoring method, this invention also proposes a link monitoring device, which can be a computer program (including program code) running in an electronic device; such as Figure 7 As shown, the link monitoring device may include an acquisition unit 701 and a processing unit 702. The link monitoring device can perform... Figure 1 or Figure 4 The link monitoring method shown indicates that the link monitoring device can operate the above-mentioned unit:
[0109] Acquisition unit 701 is used to acquire N target liveness detection files;
[0110] Processing unit 702 is used to determine M links under the target transmission protocol, where each link includes at least one node to be probed, each link corresponds to at least one target probe file among the N target probe files, and at least one target probe file corresponding to a link supports the use of probes for the corresponding link, where M and N are both positive integers.
[0111] The processing unit 702 is further configured to perform liveness detection on the corresponding links in the M links based on each of the N target liveness detection files, and obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. A link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under a corresponding target liveness detection file.
[0112] The processing unit 702 is further configured to determine the target activation result based on the link activation result of each link under each corresponding target activation file. The target activation result includes the activation data of each node to be activated in each link, and the activation data of a node to be activated is determined based on the node activation result of the corresponding node to be activated under each corresponding target activation file.
[0113] The processing unit 702 is further configured to monitor and analyze the M links based on the target detection results, and obtain monitoring and analysis results.
[0114] In one implementation, when processing unit 702 performs liveness detection on corresponding links in the M links based on each of the N target liveness detection files, and obtains the link liveness detection results for each of the M links under each corresponding target liveness detection file, it can be specifically used for:
[0115] For any node to be tested in any of the M links, and any target detection file in at least one target detection file corresponding to any link, upload the target detection file to the node to be tested, and record the upload time of the node to be tested under the target detection file.
[0116] Based on the upload time of any node to be tested under any target test file, the node test result of any node to be tested under any target test file is determined, thereby determining the link test result of any link under any target test file. This enables the corresponding links in the M links to be tested based on each of the N target test files, and obtains the link test result of each link in the M links under each corresponding target test file.
[0117] In another embodiment, the processing unit 702 may also be used for:
[0118] Download any target liveness detection file from any of the nodes to be detected, and record the download time of any node to be detected under any target liveness detection file;
[0119] When processing unit 702 determines the node activation result of any node to be activated under any target activation file based on the upload time of any node to be activated under any target activation file, it can be specifically used for:
[0120] Based on the upload and download times of any node to be tested under any target liveness testing file, determine the node liveness testing result of any node to be tested under any target liveness testing file.
[0121] In another embodiment, the node detection result of any node to be detected under any target detection file further includes a detection failure counter; the processing unit 702 can also be used for:
[0122] When it is detected that any of the nodes to be tested for liveness fails under any of the target liveness testing files, the liveness testing failure counter is counted.
[0123] The process of iteratively uploading any target liveness detection file to any node to be tested continues until the liveness detection is successful or the number of failed retry attempts by any node to be tested under any target liveness detection file reaches a preset liveness detection threshold, in order to determine the node liveness detection result of any node to be tested under any target liveness detection file.
[0124] In another embodiment, the node detection result of any node to be detected under any target detection file further includes file comparison results; the processing unit 702 can also be used for:
[0125] After downloading any target liveness detection file from any of the nodes to be detected, the downloaded liveness detection file corresponding to the target liveness detection file is obtained, and it is determined whether the downloaded liveness detection file and the target liveness detection file are the same.
[0126] If the downloaded liveness detection file is the same as any of the target liveness detection files, the comparison result will be used as the file comparison result of any node to be detected in the node liveness detection results under any of the target liveness detection files;
[0127] If the downloaded liveness detection file is different from any of the target liveness detection files, the comparison failure result will be used as the file comparison result of any node to be detected in the node liveness detection results under any of the target liveness detection files.
[0128] In another implementation, the processing unit 702, based on each of the N target activation files, performs activation testing on the corresponding links in the M links to obtain the activation results of each link in the M links under each target activation file, and can specifically be used for:
[0129] For any node to be tested in any link of the M links, and any target liveness file in at least one target liveness file corresponding to the link, H liveness tests are performed on the node to be tested based on the target liveness file to obtain H node liveness test results of the node to be tested under the target liveness file, where H is a positive integer;
[0130] When determining the target activation result based on the link activation results of each link under each corresponding target activation file, the processing unit 702 can specifically be used for:
[0131] The detection results of H nodes under any target detection file for any node to be detected are integrated to obtain the detection point data of any node to be detected under any target detection file. This detection point data is then added to the detection point data of the node to be detected, so that the detection point data of the node to be detected includes the detection point data of the node under each corresponding target detection file; or...
[0132] The detection results of H nodes under each target detection file for any node to be detected are integrated to obtain the detection point data of any node to be detected, so that the detection point data of any node to be detected under each target detection file is integrated into one detection point data.
[0133] In another embodiment, when the processing unit 702 monitors and analyzes the M links based on the target activation results and obtains the monitoring and analysis results, it can be specifically used for:
[0134] Determine whether there is at least one abnormal data point in the target detection results, so as to realize the monitoring and analysis of the M links;
[0135] If there is at least one abnormal data point in the target detection results, then the abnormal indication content corresponding to each abnormal data point in the at least one abnormal data point is determined to obtain the monitoring and analysis results; wherein, an abnormal indication content includes: abnormal link information of the link corresponding to the corresponding abnormal data point, and / or screening judgment report under the corresponding abnormal data point.
[0136] Display the anomaly indication content corresponding to each anomaly point data.
[0137] In another implementation, the detection data of a node to be detected includes at least one of the following: the upload time and download time of the corresponding node to be detected; when determining whether there is at least one abnormal data point in the target detection result, the processing unit 702 may specifically be used to:
[0138] For any one of the M links, determine whether there is an anomaly to be detected in any one link;
[0139] If the anomaly to be detected exists in any of the links, then based on the target liveness detection results, the specified time consumption for each liveness to be detected node in any of the links is determined;
[0140] Based on the specified time consumption of each active node to be explored in any link, it is determined whether there is an abnormal node in any link. If there is an abnormal node in any link, the exploration data of the abnormal node in any link is taken as abnormal point data. The difference between the specified time consumption of the abnormal node in any link and the specified time consumption of other active nodes to be explored in any link is greater than a preset difference threshold.
[0141] In another implementation, the detection data of a node to be detected also includes a detection failure counter for the corresponding node; when determining whether there is an abnormal point to be detected in any of the links, the processing unit 702 may specifically be used to:
[0142] For any node to be detected in any link, determine whether the node to be detected is an anomaly point to be detected.
[0143] If any of the probe data for a node to be probed contains an abnormal detection failure counter and / or abnormal latency, then that node is determined to be an abnormal point to be detected. The abnormal detection failure counter refers to a detection failure counter greater than or equal to a detection failure counter threshold. The abnormal latency includes at least one of the following: abnormal upload latency, abnormal download latency, and abnormal summation latency. The abnormal upload latency refers to an upload latency exceeding an upload latency threshold. The abnormal download latency refers to a download latency exceeding a download latency threshold. The abnormal summation latency refers to a summation latency exceeding a summation latency threshold, and a summation latency is determined by the upload latency and download latency of the corresponding node to be probed; or...
[0144] Obtain historical time data corresponding to a specified time consumption for any node to be investigated, and perform outlier detection on any node to be investigated based on the historical time consumption data and the specified time consumption of any node to be investigated; if any node to be investigated is detected as an outlier, then determine any node to be investigated as an anomaly to be detected.
[0145] In another implementation, an anomaly indication includes a screening and judgment report under the corresponding anomaly point data: when determining the anomaly indication corresponding to each anomaly point data in the at least one anomaly point data, the processing unit 702 can specifically be used to:
[0146] For any one of the at least one abnormal data points, obtain the screening and judgment data of the node to be investigated indicated by the abnormal data point. The screening and judgment data includes at least one of the following: resource usage information of the process of the corresponding node to be investigated, CPU idle rate, average load, number of read transfer bytes, and number of write transfer bytes.
[0147] Based on the screening and judgment data, a screening and judgment report is determined for any anomaly data point, so as to determine the anomaly indication content corresponding to any anomaly data point.
[0148] According to one embodiment of the present invention, Figure 1 or Figure 4 Each step involved in the method shown can be derived from... Figure 7 The link monitoring device shown in the diagram is operated by each unit.
[0149] According to another embodiment of the present invention, Figure 7Each unit in the illustrated link monitoring device can be individually or entirely merged into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This achieves the same operation without affecting the technical effects of the embodiments of the present invention. The above units are based on logical function division. In practical applications, the function of one unit can be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of the present invention, any link monitoring device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by multiple units.
[0150] According to another embodiment of the present invention, the following can be performed by running on a general-purpose electronic device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). Figure 1 or Figure 4 The computer program (including program code) for each step involved in the corresponding method shown, to construct such... Figure 7 The link monitoring device shown herein, and the link monitoring method for implementing embodiments of the present invention, are described. The computer program may be recorded on, for example, a computer storage medium, loaded onto the aforementioned electronic device via the computer storage medium, and run therein.
[0151] This invention can acquire N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files, and the at least one target liveness detection file corresponding to a link supports the detection of the corresponding link. M and N are both positive integers. Then, based on each target liveness detection file among the N target liveness detection files, the corresponding links in the M links can be detected to obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. Each link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under the corresponding target liveness detection file. Based on this, the target liveness detection results can be determined based on the link liveness detection results of each link under each corresponding target liveness detection file. The target liveness detection results include: the probe data of each node to be livened in each link, and the probe data of a node to be livened is determined based on the node liveness detection results of the corresponding node under each corresponding target liveness detection file. Based on the target liveness detection results, monitoring and analysis are performed on M links to obtain monitoring and analysis results. It can be seen that the embodiments of the present invention can use N target liveness detection files to perform liveness detection on any link to obtain monitoring and analysis results, thus enabling the monitoring and analysis of relatively complex links to obtain monitoring and analysis results. Based on this, specific abnormal links can be effectively and accurately located, facilitating troubleshooting by relevant operation and maintenance personnel.
[0152] Based on the description of the method and apparatus embodiments above, an exemplary embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, which, when executed by the at least one processor, causes the electronic device to perform the method according to an embodiment of the present invention.
[0153] An exemplary embodiment of the present invention also provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of the present invention.
[0154] An exemplary embodiment of the present invention also provides a computer program product, including a computer program, wherein, when executed by a computer's processor, the computer program is used to cause the computer to perform a method according to an embodiment of the present invention.
[0155] refer to Figure 8The present invention will now be described in the form of a structural block diagram of an electronic device 800 that can serve as a server or client of the present invention, which is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0156] like Figure 8 As shown, the electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. The RAM 803 may also store various programs and data required for the operation of the device 800. The computing unit 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0157] Multiple components in electronic device 800 are connected to I / O interface 805, including: input unit 806, output unit 807, storage unit 808, and communication unit 809. Input unit 806 can be any type of device capable of inputting information to electronic device 800. Input unit 806 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of electronic device. Output unit 807 can be any type of device capable of presenting information and may include, but is not limited to, a display, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 808 may include, but is not limited to, disks and optical discs. Communication unit 809 allows electronic device 800 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.
[0158] The computing unit 801 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above. For example, in some embodiments, the link monitoring method can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via ROM 802 and / or communication unit 809. In some embodiments, the computing unit 801 can be configured to perform the link monitoring method by any other suitable means (e.g., by means of firmware).
[0159] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0160] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0161] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0162] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0163] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0164] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other.
[0165] Furthermore, it should be understood that the above-disclosed embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of the present invention. Therefore, any equivalent variations made in accordance with the claims of the present invention are still within the scope of the present invention.
Claims
1. A link monitoring method, characterized in that, include: Obtain N target liveness detection files and determine M links under the target transmission protocol. Each link includes at least one node to be detected. Each link corresponds to at least one target liveness detection file among the N target liveness detection files. At least one target liveness detection file corresponding to a link can be used to detect the liveness of the corresponding link. M and N are both positive integers. Based on each of the N target liveness detection files, the corresponding links in the M links are liveness detected, and the link liveness detection results of each link in the M links under each corresponding target liveness detection file are obtained. Each link liveness detection result includes: the node liveness detection results of each node to be liveness detected in the corresponding link under a corresponding target liveness detection file. Based on the link activation results of each link under each corresponding target activation file, the target activation results are determined. The target activation results include: the activation data of each node to be activated in each link, and the activation data of a node to be activated is determined based on the node activation results of the corresponding node to be activated under each corresponding target activation file. Based on the target activity detection results, the M links are monitored and analyzed to obtain the monitoring and analysis results.
2. The method according to claim 1, characterized in that, The step involves probing the corresponding links in the M links based on each of the N target probing files, obtaining the link probing results for each of the M links under each corresponding target probing file, including: For any node to be tested in any of the M links, and any target detection file in at least one target detection file corresponding to any link, upload the target detection file to the node to be tested, and record the upload time of the node to be tested under the target detection file. Based on the upload time of any node to be tested under any target test file, the node test result of any node to be tested under any target test file is determined, thereby determining the link test result of any link under any target test file. This enables the corresponding links in the M links to be tested based on each of the N target test files, and obtains the link test result of each link in the M links under each corresponding target test file.
3. The method according to claim 2, characterized in that, The method further includes: Download any target liveness detection file from any of the nodes to be detected, and record the download time of any node to be detected under any target liveness detection file; The step of determining the node liveness detection result of any node to be detected under any target liveness detection file based on the upload time of any node to be detected under any target liveness detection file includes: Based on the upload and download times of any node to be tested under any target liveness testing file, determine the node liveness testing result of any node to be tested under any target liveness testing file.
4. The method according to claim 3, characterized in that, The node activation result of any node to be activated under any target activation file also includes an activation failure counter; the method further includes: When it is detected that any of the nodes to be tested for liveness fails under any of the target liveness testing files, the liveness testing failure counter is counted. The process of iteratively uploading any target liveness detection file to any node to be tested continues until the liveness detection is successful or the number of failed retry attempts by any node to be tested under any target liveness detection file reaches a preset liveness detection threshold, in order to determine the node liveness detection result of any node to be tested under any target liveness detection file.
5. The method according to claim 3, characterized in that, The node activation result of any node to be activated under any target activation file also includes file comparison results; the method further includes: After downloading any target liveness detection file from any of the nodes to be detected, the downloaded liveness detection file corresponding to the target liveness detection file is obtained, and it is determined whether the downloaded liveness detection file and the target liveness detection file are the same. If the downloaded liveness detection file is the same as any of the target liveness detection files, the comparison result will be used as the file comparison result of any node to be detected in the node liveness detection results under any of the target liveness detection files; If the downloaded liveness detection file is different from any of the target liveness detection files, the comparison failure result will be used as the file comparison result of any node to be detected in the node liveness detection results under any of the target liveness detection files.
6. The method according to claim 1, characterized in that, The step involves probing the corresponding links in the M links based on each of the N target probing files, obtaining the link probing results for each of the M links under each corresponding target probing file, including: For any node to be tested in any link of the M links, and any target liveness file in at least one target liveness file corresponding to the link, H liveness tests are performed on the node to be tested based on the target liveness file to obtain H node liveness test results of the node to be tested under the target liveness file, where H is a positive integer; The determination of target activation results based on the link activation results of each link under each corresponding target activation file includes: The detection results of H nodes under any target detection file for any node to be detected are integrated to obtain the detection point data of any node to be detected under any target detection file. This detection point data is then added to the detection point data of the node to be detected, so that the detection point data of the node to be detected includes the detection point data of the node under each corresponding target detection file; or... The detection results of H nodes under each target detection file for any node to be detected are integrated to obtain the detection point data of any node to be detected, so that the detection point data of any node to be detected under each target detection file is integrated into one detection point data.
7. The method according to claim 1, characterized in that, Based on the target activation results, the M links are monitored and analyzed to obtain monitoring and analysis results, including: Determine whether there is at least one abnormal data point in the target detection results, so as to realize the monitoring and analysis of the M links; If there is at least one abnormal data point in the target detection results, then the abnormal indication content corresponding to each abnormal data point in the at least one abnormal data point is determined to obtain the monitoring and analysis results; wherein, an abnormal indication content includes: abnormal link information of the link corresponding to the corresponding abnormal data point, and / or screening judgment report under the corresponding abnormal data point. Display the anomaly indication content corresponding to each anomaly point data.
8. The method according to claim 7, characterized in that, The probe data for a live node to be probed includes at least one of the following: the upload time and download time of the corresponding live node to be probed; The determination of whether there is at least one abnormal data point in the target detection results includes: For any one of the M links, determine whether there is an anomaly to be detected in any one link; If the anomaly to be detected exists in any of the links, then based on the target liveness detection results, the specified time consumption for each liveness to be detected node in any of the links is determined; Based on the specified time consumption of each active node to be explored in any link, it is determined whether there is an abnormal node in any link. If there is an abnormal node in any link, the exploration data of the abnormal node in any link is taken as abnormal point data. The difference between the specified time consumption of the abnormal node in any link and the specified time consumption of other active nodes to be explored in any link is greater than a preset difference threshold.
9. The method according to claim 8, characterized in that, The probe data for a node to be probed also includes a probe failure counter for the corresponding node; determining whether there is an anomaly to be detected in any link includes: For any node to be detected in any link, determine whether the node to be detected is an anomaly point to be detected. If any of the probe data for a node to be probed contains an abnormal detection failure counter and / or abnormal latency, then that node is determined to be an abnormal point to be detected. The abnormal detection failure counter refers to a detection failure counter greater than or equal to a detection failure counter threshold. The abnormal latency includes at least one of the following: abnormal upload latency, abnormal download latency, and abnormal summation latency. The abnormal upload latency refers to an upload latency exceeding an upload latency threshold. The abnormal download latency refers to a download latency exceeding a download latency threshold. The abnormal summation latency refers to a summation latency exceeding a summation latency threshold, and a summation latency is determined by the upload latency and download latency of the corresponding node to be probed; or... Obtain historical time data corresponding to a specified time consumption for any node to be investigated, and perform outlier detection on any node to be investigated based on the historical time consumption data and the specified time consumption of any node to be investigated; if any node to be investigated is detected as an outlier, then determine any node to be investigated as an anomaly to be detected.
10. The method according to claim 7, characterized in that, An anomaly indication includes a screening and judgment report under the corresponding anomaly point data: determining the anomaly indication content corresponding to each anomaly point data in the at least one anomaly point data includes: For any one of the at least one abnormal data points, obtain the screening and judgment data of the node to be investigated indicated by the abnormal data point. The screening and judgment data includes at least one of the following: resource usage information of the process of the corresponding node to be investigated, CPU idle rate, average load, number of read transfer bytes, and number of write transfer bytes. Based on the screening and judgment data, a screening and judgment report is determined for any anomaly data point, so as to determine the anomaly indication content corresponding to any anomaly data point.
11. A link monitoring device, characterized in that, The device includes: The acquisition unit is used to acquire N target liveness detection files; The processing unit is used to determine M links under the target transmission protocol. Each link includes at least one node to be probed. Each link corresponds to at least one target probe file among the N target probe files. The at least one target probe file corresponding to a link supports the use of probes for the corresponding link. M and N are both positive integers. The processing unit is further configured to perform liveness detection on the corresponding links in the M links based on each of the N target liveness detection files, and obtain the link liveness detection results of each link in the M links under each corresponding target liveness detection file. A link liveness detection result includes: the node liveness detection results of each node to be detected in the corresponding link under a corresponding target liveness detection file. The processing unit is further configured to determine the target activation result based on the link activation result of each link under each corresponding target activation file. The target activation result includes the activation data of each node to be activated in each link, and the activation data of a node to be activated is determined based on the node activation result of the corresponding node to be activated under each corresponding target activation file. The processing unit is also used to monitor and analyze the M links based on the target detection results to obtain monitoring and analysis results.
12. An electronic device, characterized in that, include: processor; as well as Stored program memory, The program includes instructions that, when executed by the processor, cause the processor to perform the method according to any one of claims 1-10.
13. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-10.
Citation Information
Patent Citations
Communication protocol conversion method, equipment, system and gateway equipment
CN113556359A
Micro-service activity detection registration method and device
CN116708543A