Flowchart Display Method, Apparatus, Electronic Device, and Computer-Readable Medium

By aggregating, matching and fusion of the business path information group at the same service initiator, and generating and displaying the business path flow chart, the problems of large flow chart errors and long abnormal detection cycles are solved, and the system's response speed and stability are improved.

CN119090995BActive Publication Date: 2025-07-22HUAQING RONGTIAN (BEIJING) SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411152695.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-21
Publication Date
2025-07-22
Estimated Expiration
2044-08-21

AI Technical Summary

Technical Problem

In the prior art, the business flow chart has large errors, long abnormal detection cycles, poor system stability, and inability to respond in time, resulting in the flow chart being unable to be displayed normally.

Method used

By obtaining the business path information group at the same service initiator, attribute aggregation, matching and fusion are performed, the business path flow chart is generated and displayed, and the response speed and stability are improved by combining the exception detection model.

Benefits of technology

Reduces business flow chart errors, improves the system's response speed in abnormal situations, avoids the flow chart being unable to be displayed normally, and enhances system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119090995B_ABST
    Figure CN119090995B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a flowchart display method, apparatus, electronic device, and computer-readable medium. A specific implementation of the method includes: obtaining a set of service path information groups and the message field information corresponding to the log system, wherein each service path information group in the set of service path information groups is initiated by the same service initiator, and the service path information groups in the set of service path information groups include: at least one service information corresponding path information with different attributes; matching the historical service path information group with the aggregated service path information group to obtain a matching result group, wherein the matching results in the matching result group represent matching consistent results and matching inconsistent results; and displaying the service path flowchart on the main page corresponding to the log system. This implementation reduces the error of the service flowchart, improves the response speed of the system when an abnormality occurs, and avoids the inability to display the flowchart normally.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technologies, and more particularly, to a flowchart display method, apparatus, electronic device, and computer-readable medium. Background Art

[0002] In the process of implementing business monitoring, due to the complexity of the production environment, it is difficult to form an effective display of the entire business process. Usually, it is necessary to form the monitoring of the business link through the business serial number. Flowchart display is a technology for displaying a flowchart. Aggregating business path information groups with the same business attributes in the business path information group set, and matching the historical business path information group with the aggregated business path information group can fully consider the correlation between the two, reduce the error of the business flowchart. Analyzing the matching results can respond to abnormal situations in a timely manner, thereby increasing the probability of normal flowchart display. In addition, performing regional anomaly detection on the business path flowchart can shorten the cycle of anomaly detection of the business path flowchart and improve the stability of the system. Currently, the commonly used method for flowchart display is: obtaining the business path flowchart through network traffic analysis, thereby realizing the display of the flowchart.

[0003] However, when using the above method, the following technical problems often exist:

[0004] First, due to the complexity of the business path information group set and the poor correlation between them, the generated business flowchart has a large error, and path anomalies between business information are likely to occur. Also, when an anomaly occurs, the system cannot respond in a timely manner, resulting in the stop of the flowchart construction process and the inability to normally display the flowchart.

[0005] Second, due to the possible complexity of the business path flowchart, the cycle of anomaly detection of the business path flowchart is long, and the detection result is likely to have a large error. Also, since the abnormal result cannot be responded to in a timely manner after being detected, the stability of the system is poor.

[0006] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not form the prior art known to those of ordinary skill in the art in this country. Summary of the Invention

[0007] This content part of the present disclosure is used to briefly introduce the concepts, which will be described in detail in the following detailed implementation part. This content part of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0008] Some embodiments of the present disclosure provide a flowchart display method, apparatus, electronic device, and computer-readable medium to solve one or more of the technical problems mentioned in the above background art section.

[0009] In a first aspect, some embodiments of the present disclosure provide a flowchart display method, the method comprising: obtaining a set of service path information groups and message field information corresponding to a log system, wherein each service path information group in the set of service path information groups is initiated by the same service initiator, and the service path information groups in the set of service path information groups include: at least one service information corresponding path information with different attributes; in response to determining that there is at least one service path information group in the set of service path information groups with the same service attribute corresponding to the path information, aggregating at least one service path information group with the same service attribute to obtain an aggregated service path information group; generating a historical service path information group according to the message field information corresponding to the log system; matching the historical service path information group with the aggregated service path information group to obtain a matching result group, wherein the matching results in the matching result group represent matching consistent results and matching inconsistent results; in response to determining that there is a matching result representing a matching consistent result in the matching result group, fusing the historical service path information group with the aggregated service path information group to obtain a fused service path information group; constructing a flowchart for the fused service path information group to obtain a service path flowchart; and displaying the service path flowchart on the main page corresponding to the log system.

[0010] Second aspect, some embodiments of the present disclosure provide a flowchart display device, the device comprising: an acquisition unit configured to acquire a set of service path information groups and the message field information corresponding to a log system, wherein each service path information group in the set of service path information groups is initiated by the same service initiator, and the service path information groups in the set of service path information groups include: at least one service information corresponding path information with different attributes; an aggregation unit configured to, in response to determining that there is at least one service path information group in the set of service path information groups whose corresponding service attributes of the path information are the same, aggregate at least one service path information group with the same service attribute to obtain an aggregated service path information group; a generation unit configured to generate a historical service path information group according to the message field information corresponding to the log system; a matching unit configured to match the historical service path information group with the aggregated service path information group to obtain a set of matching results, wherein the matching results in the set of matching results represent matching consistent results and matching inconsistent results; a fusion unit configured to, in response to determining that there is a matching result representing a matching consistent result in the set of matching results, fuse the historical service path information group and the aggregated service path information group to obtain a fused service path information group; a construction unit configured to construct a flowchart for the fused service path information group to obtain a service path flowchart; and a display unit configured to display the service path flowchart on the main page corresponding to the log system.

[0011] Third aspect, some embodiments of the present disclosure provide an electronic device, comprising: one or more processors; a storage device having stored thereon one or more programs, which when executed by the one or more processors cause the one or more processors to implement the method described in any implementation manner of the first aspect above.

[0012] Fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having stored thereon a computer program, wherein the program, when executed by a processor, implements the method described in any implementation manner of the first aspect above.

[0013] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: Through the flowchart display method of some embodiments of the present disclosure, the error of the business flowchart is reduced, the response speed of the system in case of an exception is improved, and the inability to normally display the flowchart is avoided. Specifically, the reasons for the large error in the business flowchart, the inability of the system to respond in a timely manner in case of an exception, and the inability to normally display the flowchart are as follows: Since the set of business path information is relatively complex and the correlation between them is poor, the generated business flowchart has a large error, and path exceptions are likely to occur between business information. Also, since the system cannot respond in a timely manner in case of an exception, the flowchart construction process stops, resulting in the inability to normally display the flowchart. Based on this, in the flowchart display method of some embodiments of the present disclosure, first, obtain the set of business path information and the message field information corresponding to the log system. Among them, each business path information group in the above-mentioned set of business path information is initiated by the same business initiator. The business path information groups in the set of business path information include: path information corresponding to at least one business information with different attributes. Thus, it can facilitate subsequent processing. Then, in response to determining that there is at least one business path information group in the above-mentioned set of business path information whose corresponding business attributes of the path information are the same, aggregate at least one business path information group with the same business attributes to obtain an aggregated business path information group. Thus, the complex set of business path information can be simplified. Next, generate a historical business path information group according to the above-mentioned message field information corresponding to the log system. Thus, a historical business path information group can be obtained. Then, match the above-mentioned historical business path information group with the above-mentioned aggregated business path information group to obtain a matched result group, where the matched results in the above-mentioned matched result group represent matched and unmatched results. Thus, the association relationship between the above-mentioned historical business path information group and the above-mentioned aggregated business path information group can be determined. After that, in response to determining that there is a matched result representing a matched result in the above-mentioned matched result group, fuse the above-mentioned historical business path information group and the above-mentioned aggregated business path information group to obtain a fused business path information group. Finally, construct a flowchart for the above-mentioned fused business path information group to obtain a business path flowchart. Thus, the error of the business flowchart can be reduced, and the response speed of the system in case of an exception can be improved. Display the above-mentioned business path flowchart on the main page corresponding to the above-mentioned log system. Thus, the inability to normally display the flowchart can be avoided. Therefore, the error of the business flowchart is reduced, the response speed of the system in case of an exception is improved, and the inability to normally display the flowchart is avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.

[0015] Figure 1 is a flowchart showing some embodiments of a method according to the present disclosure;

[0016] Figure 2 is a schematic structural diagram showing some embodiments of a flowchart display device according to the present disclosure;

[0017] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. Specific Embodiments

[0018] The embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for illustrative purposes and are not used to limit the protection scope of the present disclosure.

[0019] In addition, it should be noted that for the sake of convenience of description, only the parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0020] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules, or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules, or units.

[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0023] The present disclosure will be described in detail below with reference to the drawings and in combination with the embodiments.

[0024] Figure 1Flow 100 of some embodiments of the flowchart display method of the present disclosure. The flowchart display method includes the following steps:

[0025] Step 101, obtain the set of service path information groups and the message field information corresponding to the log system.

[0026] In some embodiments, the execution entity (e.g., a computing device) of the flowchart display method can obtain the set of service path information groups and the message field information corresponding to the log system through wired connection or wireless connection. Among them, each service path information group in the above set of service path information groups is initiated by the same service initiator. The service path information groups in the set of service path information groups include: the path information corresponding to at least one service information with different attributes.

[0027] Here, the above service initiator may refer to a client. The above at least one different attribute may refer to multiple different attributes. For example, the above at least one different attribute may include, but is not limited to, at least one of the following: response status attribute, device information attribute. The above response status attribute may represent the response success status attribute and the response failure status attribute. The above device information attribute may refer to the device model information attribute. The above service information corresponding path information may refer to the path information formed by connecting the processing flows of the service with a link. The processing flow of the above service may refer to first opening the client and then querying the service information. The above message field information may refer to the port field information of the log system and the service type field information of the log system.

[0028] It should be noted that the above wireless connection method may include, but is not limited to, 3G / 4G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other currently known or future-developed wireless connection methods.

[0029] Step 102, in response to determining that there is at least one service path information group in the set of service path information groups whose corresponding service attributes of the corresponding path information are the same, aggregate at least one service path information group with the same service attribute to obtain an aggregated service path information group.

[0030] In some embodiments, the above execution entity can, in response to determining that there is at least one service path information group in the set of service path information groups whose corresponding service attributes of the corresponding path information are the same, aggregate at least one service path information group with the same service attribute to obtain an aggregated service path information group.

[0031] As an example, the above-mentioned execution entity may, in response to determining that there is at least one business path information group in the above-mentioned business path information group set whose corresponding business attributes of the corresponding path information are the same, merge at least one business path information group with the same business attributes to obtain a merged business path information group, which is used as the aggregated business path information group.

[0032] Optionally, the above-mentioned execution entity may aggregate at least one business path information group with the same business attributes to obtain an aggregated business path information group by the following steps in response to determining that there is at least one business path information group in the above-mentioned business path information group set whose corresponding business attributes of the corresponding path information are the same:

[0033] First step, perform data deduplication on at least one business path information group with the same business attributes to obtain a business path information group after deduplication.

[0034] Here, the above-mentioned data deduplication may refer to removing duplicates.

[0035] Second step, perform data integration on each de-duplicated business path information in the above-mentioned business path information group after deduplication to obtain an integrated business path information group, which is used as the aggregated business path information group.

[0036] Step 103, generate a historical business path information group according to the message field information corresponding to the above-mentioned log system.

[0037] In some embodiments, the above-mentioned execution entity may generate a historical business path information group according to the message field information corresponding to the above-mentioned log system.

[0038] Here, the above-mentioned historical business path information group may refer to a business path information group generated in the past.

[0039] Optionally, the above-mentioned execution entity may generate a historical business path information group by the following steps according to the message field information corresponding to the above-mentioned log system:

[0040] First step, screen the message field information corresponding to the above-mentioned log system to obtain screened message field information, where the above-mentioned screened message field information includes: port number information, address information, timestamp information.

[0041] Here, the above-mentioned address information may refer to IP address information.

[0042] Second step, perform business type classification on the historical log data corresponding to the above-mentioned log system to obtain a classified business type group.

[0043] Here, the above-mentioned business type may refer to the type of business operations in the log system. For example, the above-mentioned business type may refer to the business query type.

[0044] In the third step, according to the above port number information and the above address information, call information storage is performed on the service information corresponding to the service type group after the above division to generate a group of stored information after the call.

[0045] As an example, the above execution entity can determine the location information of the service information corresponding to the service type group after the above division according to the above port number information and the above address information. Then, the above location information is called, and the called time information and location information are stored to generate a group of stored information after the call. Among them, the above location information includes: port number information and address information.

[0046] In the fourth step, according to the above timestamp information, time sorting is performed on the group of stored information after the call to obtain a time series of stored information after the call.

[0047] As an example, the above execution entity can sort the group of stored information after the call in ascending order according to the above timestamp information to obtain a time series of stored information after the call.

[0048] In the fifth step, according to the above time series of stored information after the call, service path information is created for the service type group after the above division to obtain a group of service path information corresponding to the service type.

[0049] In the sixth step, data aggregation is performed on multiple pieces of service path information corresponding to service types in the above group of service path information corresponding to service types that meet the preset aggregation conditions to obtain a group of aggregated service path information.

[0050] Here, the above preset aggregation condition may refer to the condition of "aggregating service path information with the same service type" set in advance.

[0051] In the seventh step, duplicate removal processing is performed on the above group of aggregated service path information to obtain a group of service path information after duplicate removal, which is used as a group of historical service path information.

[0052] Here, the above duplicate removal processing may refer to removing duplicate processing.

[0053] Step 104: Match the above group of historical service path information with the above group of aggregated service path information to obtain a group of matching results.

[0054] In some embodiments, the above execution entity can match the above group of historical service path information with the above group of aggregated service path information to obtain a group of matching results. Among them, the matching results in the above group of matching results represent matching consistent results and matching inconsistent results.

[0055] Here, the above-mentioned matching result group may refer to the association result group between the historical service path information in the above-mentioned historical service path information group and the aggregated service path information in the above-mentioned aggregated service path information group.

[0056] Optionally, the above-mentioned execution entity may match the above-mentioned historical service path information group with the above-mentioned aggregated service path information group through the following steps to obtain a matching result group:

[0057] In the first step, perform data format conversion on the above-mentioned historical service path information group and the above-mentioned aggregated service path information group to obtain a converted historical service path information group and a converted service path information group, where the data formats of the above-mentioned converted historical service path information group and the above-mentioned converted service path information group are consistent.

[0058] As an example, the above-mentioned execution entity may perform data format conversion on the above-mentioned historical service path information group and the above-mentioned aggregated service path information group through a format conversion tool to obtain a converted historical service path information group and a converted service path information group. The above-mentioned format conversion tool may refer to a format converter.

[0059] In the second step, compare the above-mentioned converted historical service path information group and the above-mentioned converted service path information group with a preset plurality of matching conditions to obtain a matching result group, where the above-mentioned matching result group includes: a service attribute matching result, a timestamp matching result, and a path information matching result. The above-mentioned service attribute matching result may represent a service attribute matching consistent result and a service attribute matching inconsistent result. The above-mentioned timestamp matching result may represent a timestamp matching consistent result and a timestamp matching inconsistent result. The path information matching result may represent a path information matching consistent result and a path information matching inconsistent result.

[0060] Here, the above-mentioned preset plurality of matching conditions may refer to the matching conditions of "service attribute, timestamp, and path information" set in advance.

[0061] Step 105, in response to determining that there is a matching result in the above-mentioned matching result group that represents a matching consistent result, fuse the above-mentioned historical service path information group and the above-mentioned aggregated service path information group to obtain a fused service path information group.

[0062] In some embodiments, the above-mentioned execution entity may, in response to determining that there is a matching result in the above-mentioned matching result group that represents a matching consistent result, fuse the above-mentioned historical service path information group and the above-mentioned aggregated service path information group to obtain a fused service path information group.

[0063] As an example, the above-mentioned execution entity may merge the above-mentioned historical business path information group and the above-mentioned aggregated business path information group to obtain a merged business path information group as the fused business path information group.

[0064] Optionally, after the above-mentioned "Step 105", the above method further includes:

[0065] First, in response to determining that there is a matching result indicating a non-matching result in the above-mentioned matched result group, at least one historical business path information and at least one aggregated business path information corresponding to the matching result indicating a non-matching result in the above-mentioned matched result group are divided according to business attributes, obtaining a divided business path information group, where the above-mentioned divided business path information group may indicate that the business attributes between each divided business path information are different.

[0066] As an example, the above-mentioned execution entity may determine the business attributes of at least one historical business path information in the above-mentioned matched result group corresponding to the matching result indicating a non-matching result and at least one aggregated business path information in the above-mentioned aggregated business path information, obtaining a business attribute result set, where the business attribute results in the above-mentioned business attribute result set represent the same business attribute results and different business attribute results. Then, at least one business path information corresponding to the business attribute result indicating a different business attribute result in the above-mentioned business attribute result set is determined, obtaining a business path information group as the divided business path information group.

[0067] Second, the above-mentioned divided business path information group is fused with the above-mentioned fused business path information group to obtain a target business path information group.

[0068] As an example, the above-mentioned execution entity may merge the above-mentioned divided business path information group and the above-mentioned fused business path information group to obtain a merged business path information group as the target business path information group.

[0069] Third, a flowchart of the above-mentioned target business path information group is constructed to obtain a target business path flowchart.

[0070] Fourth, the above-mentioned target business path flowchart is displayed on the main page corresponding to the above-mentioned log system.

[0071] Step 106, a flowchart of the above-mentioned fused business path information group is constructed to obtain a business path flowchart.

[0072] In some embodiments, the above-mentioned execution entity may construct a flowchart of the above-mentioned fused business path information group to obtain a business path flowchart.

[0073] Here, the above business path flow chart can represent a flow chart formed by the paths between various businesses.

[0074] As an example, the above execution entity can connect the process nodes of each of the above merged business path information in the merged business path information group to obtain a business path flow chart.

[0075] Step 107, display the above business path flow chart on the main page corresponding to the above log system.

[0076] In some embodiments, the above execution entity can display the above business path flow chart on the main page corresponding to the above log system.

[0077] Here, the above main page can refer to the home page.

[0078] Optionally, after the above "Step 107", the above method further includes:

[0079] Perform anomaly detection on the above business path flow chart to obtain an anomaly detection result, and call the above business path flow chart according to the above anomaly detection result.

[0080] Optionally, the above execution entity can perform anomaly detection on the above business path flow chart through the following steps to obtain an anomaly detection result, and call the above business path flow chart according to the above anomaly detection result:

[0081] The first step is to evenly divide the above business path flow chart into regions to obtain a set of business path flow chart regions.

[0082] Here, the number of nodes included in the business path flow chart regions in the above set of business path flow chart regions is the same.

[0083] As an example, the above execution entity can evenly divide the above business path flow chart into regions with a preset number of nodes as a group to obtain a set of business path flow chart regions. The above preset number of nodes can refer to 3 nodes.

[0084] The second step is to perform the following processing steps for each business path flow chart region in the above set of business path flow chart regions:

[0085] The first sub-step is to determine the number of nodes and the number of edges in the above business path flow chart region to obtain the number of graph corresponding nodes and the number of graph corresponding edges.

[0086] The second sub-step is to determine the graph corresponding density according to the above number of graph corresponding nodes and the above number of graph corresponding edges.

[0087] As an example, the above-mentioned execution entity can divide the number of corresponding edges of the above-mentioned graph by the number of corresponding nodes of the above-mentioned graph to obtain the corresponding density of the graph.

[0088] The third sub-step, in response to determining that the corresponding density of the above-mentioned graph is greater than the preset density, input the above-mentioned business process flowchart area into a pre-trained flowchart scoring model to obtain the score corresponding to the business process flowchart area.

[0089] Here, the above-mentioned preset density can refer to a preset density value. For example, the above-mentioned preset density can refer to 0.5. Here, the above-mentioned flowchart scoring model is a model used to score the above-mentioned business process flowchart area. The input of the above-mentioned flowchart scoring model is the business process flowchart area. The output of the above-mentioned flowchart scoring model is the score corresponding to the business process flowchart area. The above-mentioned flowchart scoring model includes an input layer, a graph convolutional layer, an edge feature extraction layer, a recurrent neural network layer, and an output layer. Among them, the above-mentioned graph convolutional layer can refer to a Graph Convolutional Network (GCN). The above-mentioned graph convolutional layer can be used to aggregate the feature information of the nodes in the business process flowchart area. The above-mentioned edge feature extraction layer can be used to extract the information of the edges connected by the nodes. The above-mentioned recurrent neural network layer can refer to a Recurrent Neural Network (RNN). The input of the above-mentioned input layer can refer to the business process flowchart area. The output of the above-mentioned output layer can refer to the score corresponding to the business process flowchart area.

[0090] The third step is to sort the obtained set of scores corresponding to the business process flowchart areas to obtain a sequence of scores corresponding to the business process flowchart.

[0091] As an example, the above-mentioned execution entity can sort the obtained set of scores corresponding to the business process flowchart areas from smallest to largest to obtain a sequence of scores corresponding to the business process flowchart.

[0092] The fourth step is to traverse the key nodes of each business process flowchart area corresponding to at least one score corresponding to the business process flowchart in the above-mentioned sequence of scores corresponding to the business process flowchart that is greater than the preset score threshold to obtain a set of key nodes.

[0093] Here, the above-mentioned preset score threshold can refer to the maximum value of the preset scores. For example, the above-mentioned preset score threshold can refer to 0.8.

[0094] The fifth step is to establish a behavior baseline for each path information corresponding to the above-mentioned set of key nodes to obtain a set of behavior baselines.

[0095] Here, the behavior baseline in the above-mentioned set of behavior baselines can refer to the normal benchmark of the key nodes corresponding to the key nodes in the above-mentioned set of key nodes.

[0096] In the sixth step, compare the key nodes in the above key node set with the behavior baselines in the above behavior baseline set to obtain a comparison result set.

[0097] Here, the comparison results in the above comparison result set can represent comparison consistent results and comparison inconsistent results.

[0098] In the seventh step, in response to determining that there is a comparison result in the above comparison result set that represents a comparison abnormal result, perform abnormal detection on the key node corresponding to the comparison result that represents the comparison abnormal result to obtain an abnormal detection result, and issue an alarm for the key node corresponding to the above abnormal detection result.

[0099] Here, the above comparison abnormal result may refer to a comparison inconsistent result.

[0100] In the eighth step, in response to determining that an alarm is triggered, perform node adjustment on the key node corresponding to the above abnormal detection result to obtain an adjusted key node, so as to call the business process flow chart corresponding to the above adjusted key node.

[0101] Here, the above node adjustment may refer to removing the abnormal edges connected to the node.

[0102] The relevant content in the above first step to eighth step is an inventive point of the present disclosure, which solves the second technical problem mentioned in the background art: "Since the business process flow chart may be complex, the cycle of abnormal detection of the business process flow chart is long, and it is easy to cause a large error in the detection result. Also, since the abnormal result cannot be responded to in time after being detected, the stability of the system is poor." The factors that lead to a long cycle of abnormal detection of the business process flow chart and poor stability of the system are often as follows: Since the business process flow chart may be complex, the cycle of abnormal detection of the business process flow chart is long, and it is easy to cause a large error in the detection result. Also, since the abnormal result cannot be responded to in time after being detected, the stability of the system is poor. If the above factors are solved, the effect of shortening the cycle of abnormal detection of the business process flow chart and improving the stability of the system can be achieved. To achieve this effect, first, the above business process flow chart is divided into regions on average to obtain a set of business process flow chart regions. Thus, the complex business process flow chart can be divided into regions and decomposed into multiple small regions for subsequent processing, which can save a lot of time and thus shorten the cycle of abnormal detection of the business process flow chart. Second, for each business process flow chart region in the above set of business process flow chart regions, the following processing steps are performed: The first sub-step is to determine the number of nodes and the number of edges in the above business process flow chart region to obtain the corresponding number of nodes in the graph and the corresponding number of edges in the graph. The second sub-step is to determine the corresponding density of the graph according to the above corresponding number of nodes in the graph and the above corresponding number of edges in the graph. The third sub-step is to, in response to determining that the corresponding density of the graph is greater than the preset density, input the above business process flow chart region into a pre-trained flow chart scoring model to obtain the score corresponding to the business process flow chart region. Thus, each small region can be scored, improving the speed of abnormal identification. Third, sort the obtained set of scores corresponding to the business process flow chart regions to obtain a sequence of scores corresponding to the business process flow chart. Fourth, traverse the key nodes of each business process flow chart region corresponding to at least one score corresponding to the business process flow chart in the above sequence of scores corresponding to the business process flow chart that is greater than the preset score threshold to obtain a set of key nodes. Thus, the nodes where abnormalities occur can be locked. Fifth, establish a behavior baseline for each path information corresponding to the above set of key nodes to obtain a set of behavior baselines. Sixth, compare the key nodes in the above set of key nodes with the behavior baselines in the above set of behavior baselines to obtain a set of comparison results. Thus, the abnormal behavior of the key nodes can be known. Seventh, in response to determining that there is a comparison result representing a comparison abnormal result in the above set of comparison results, perform abnormal detection on the key node corresponding to the comparison result representing the comparison abnormal result to obtain an abnormal detection result, and issue an alarm for the key node corresponding to the above abnormal detection result. Thus, the abnormal detection result can be responded to in time, thereby improving the stability of the system.In the eighth step, in response to determining that an alarm is triggered, node adjustment is performed on the key nodes corresponding to the above abnormal detection results to obtain adjusted key nodes, so as to call the business path flow chart corresponding to the above adjusted key nodes. Therefore, the cycle of abnormal detection of the business path flow chart is shortened, and the stability of the system is improved.

[0103] The above various embodiments of the present disclosure have the following beneficial effects: Through the flow chart display method of some embodiments of the present disclosure, the error of the business flow chart is reduced, the response speed of the system when an abnormality occurs is improved, and the inability to normally display the flow chart is avoided. Specifically, the reasons for the large error of the business flow chart, the inability of the system to respond in a timely manner when an abnormality occurs, and the inability to normally display the flow chart are as follows: Since the business path information set is relatively complex and the correlation between them is poor, the generated business flow chart has a large error, and path abnormalities between business information are likely to occur. Also, since the system cannot respond in a timely manner when an abnormality occurs, the construction process of the flow chart stops, resulting in the inability to normally display the flow chart. Based on this, in the flow chart display method of some embodiments of the present disclosure, first, the business path information set and the message field information corresponding to the log system are obtained. Among them, each business path information group in the above business path information set is initiated by the same business initiator, and the business path information groups in the business path information set include: path information corresponding to at least one business information of different attributes. Thus, it can facilitate subsequent processing. Then, in response to determining that there is at least one business path information group in the above business path information set whose corresponding path information has the same business attribute, at least one business path information group with the same business attribute is aggregated to obtain an aggregated business path information group. Thus, the complex business path information set can be simplified. Next, according to the message field information corresponding to the above log system, a historical business path information group is generated. Thus, a historical business path information group can be obtained. Then, the above historical business path information group is matched with the above aggregated business path information group to obtain a matched result group, where the matched results in the above matched result group represent matched consistent results and matched inconsistent results. Thus, the association relationship between the above historical business path information group and the above aggregated business path information group can be determined. After that, in response to determining that there is a matched result representing a matched consistent result in the above matched result group, the above historical business path information group and the above aggregated business path information group are fused to obtain a fused business path information group. Finally, a flow chart is constructed for the above fused business path information group to obtain a business path flow chart. Thus, the error of the business flow chart can be reduced, and the response speed of the system when an abnormality occurs can be improved. The above business path flow chart is displayed on the main page corresponding to the above log system. Thus, the inability to normally display the flow chart can be avoided. Therefore, the error of the business flow chart is reduced, the response speed of the system when an abnormality occurs is improved, and the inability to normally display the flow chart is avoided.

[0104] Further reference is made to Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a flowchart display method. These device embodiments correspond to Figure 1 the method embodiments shown, and the device can be specifically applied to various electronic devices.

[0105] As shown in Figure 2 , the flowchart display device 200 of some embodiments includes: an acquisition unit 201, an aggregation unit 202, a generation unit 203, a matching unit 204, a fusion unit 205, a construction unit 206, and a display unit 207. Among them, the acquisition unit 201 is configured to acquire a set of service path information groups and the message field information corresponding to the log system. Among them, each service path information group in the above set of service path information groups is initiated by the same service initiator, and the service path information groups in the set of service path information groups include: at least one service information corresponding path information with different attributes; the aggregation unit 202 is configured to, in response to determining that there is at least one service path information group corresponding path information with the same service attribute in the above set of service path information groups, aggregate at least one service path information group with the same service attribute to obtain an aggregated service path information group; the generation unit 203 is configured to generate a historical service path information group according to the message field information corresponding to the above log system; the matching unit 204 is configured to match the above historical service path information group with the above aggregated service path information group to obtain a matched result group, where the matched results in the above matched result group represent matched consistent results and matched inconsistent results; the fusion unit 205 is configured to, in response to determining that there is a matched result representing a matched consistent result in the above matched result group, fuse the above historical service path information group with the above aggregated service path information group to obtain a fused service path information group; the construction unit 206 is configured to construct a flowchart for the above fused service path information group to obtain a service path flowchart; the display unit 207 is configured to display the above service path flowchart on the main page corresponding to the above log system.

[0106] It can be understood that the units described in the device 200 correspond to the respective steps in the method described with reference to Figure 1 . Thus, the operations, features, and beneficial effects described above for the method also apply to the device 200 and the units included therein, and will not be repeated here.

[0107] Next, reference is made to Figure 3 , which shows a schematic structural diagram of an electronic device (such as a computing device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3The electronic device shown is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present disclosure.

[0108] As Figure 3 shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 302 or the programs loaded from the storage device 308 into the random access memory (RAM) 304. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 304 are connected to each other through the bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.

[0109] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included. Figure 3 Each block shown in

[0110] particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such some embodiments, the computer program may be downloaded and installed from the network through the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the functions defined in the methods of some embodiments of the present disclosure are executed.

[0111] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0112] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (Hyper Text Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0113] The above computer-readable medium may be included in the above electronic device; or may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: obtain a set of service path information and the message field information corresponding to the logging system, wherein each service path information group in the set of service path information is initiated by the same service initiator, and the service path information groups in the set of service path information include: at least one service information corresponding path information with different attributes; in response to determining that there is at least one service path information group in the set of service path information whose corresponding service attributes of the corresponding path information are the same, aggregate at least one service path information group with the same service attributes to obtain an aggregated service path information group; generate a historical service path information group according to the message field information corresponding to the logging system; match the historical service path information group with the aggregated service path information group to obtain a matched result group, wherein the matched results in the matched result group represent matched consistent results and unmatched results; in response to determining that there is a matched result representing a matched consistent result in the matched result group, fuse the historical service path information group and the aggregated service path information group to obtain a fused service path information group; construct a flowchart for the fused service path information group to obtain a service path flowchart; and display the service path flowchart on the main page corresponding to the logging system.

[0114] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions labeled in the blocks may occur in a different order than labeled in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0116] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes: an acquisition unit, an aggregation unit, a generation unit, a matching unit, a fusion unit, a construction unit, and a display unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the generation unit can also be described as "the unit that generates a historical service path information group according to the message field information corresponding to the above-mentioned log system".

[0117] The functions described above can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and so on.

[0118] The above description is only some preferred embodiments of the present disclosure and an explanation of the application of technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with technical features (but not limited to) having similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A method for displaying a flowchart, comprising: Obtaining a set of service path information groups and the message field information corresponding to the log system, wherein each service path information group in the set of service path information groups is initiated by the same service initiator, and the service path information groups in the set of service path information groups include: at least one service information corresponding path information with different attributes; In response to determining that there is at least one service path information group in the set of service path information groups whose corresponding service attributes of the corresponding path information are the same, aggregating at least one service path information group with the same service attribute to obtain an aggregated service path information group; Generating a historical service path information group according to the message field information corresponding to the log system; Matching the historical service path information group with the aggregated service path information group to obtain a matched result group, wherein the matched results in the matched result group represent matched consistent results and unmatched results; In response to determining that there is a matched result representing a matched consistent result in the matched result group, fusing the historical service path information group with the aggregated service path information group to obtain a fused service path information group; In response to determining that there is a matched result representing an unmatched result in the matched result group, performing service attribute division on at least one historical service path information and at least one aggregated service path information corresponding to the unmatched result in the matched result group to obtain a divided service path information group, wherein the divided service path information group can represent that the service attributes between the divided service path information are all different; Fusing the divided service path information group with the fused service path information group to obtain a target service path information group; Constructing a flowchart for the target service path information group to obtain a target service path flowchart; Displaying the target service path flowchart on the main page corresponding to the log system; Constructing a flowchart for the fused service path information group to obtain a service path flowchart; Displaying the service path flowchart on the main page corresponding to the log system.

2. The method according to claim 1, wherein The step of, in response to determining that there is at least one service path information group in the set of service path information groups whose corresponding service attributes of the corresponding path information are the same, aggregating at least one service path information group with the same service attribute to obtain an aggregated service path information group, includes: Performing data deduplication on at least one service path information group with the same service attribute to obtain a deduplicated service path information group; Integrating the deduplicated service path information in the deduplicated service path information group to obtain an integrated service path information group as the aggregated service path information group.

3. The method according to claim 1, wherein, After the step of displaying the service path flowchart on the main page corresponding to the log system, the method further includes: Performing anomaly detection on the service path flowchart to obtain an anomaly detection result, and calling the service path flowchart according to the anomaly detection result.

4. The method according to claim 1, wherein The step of generating a historical service path information group according to the message field information corresponding to the log system includes: Screen the message field information corresponding to the log system to obtain the screened message field information, where the screened message field information includes: port number information, address information, and timestamp information; Classify the historical log data corresponding to the log system according to business types to obtain the classified business type groups; According to the port number information and the address information, store the call information of the business information corresponding to the classified business type groups to generate a group of stored information after calls; According to the timestamp information, sort the group of stored information after calls by time to obtain a time series of stored information after calls; According to the time series of stored information after calls, create business path information for the classified business type groups to obtain a group of business path information corresponding to business types; Aggregate the multiple pieces of business path information corresponding to business types that meet the preset aggregation conditions in the group of business path information corresponding to business types to obtain a group of aggregated business path information; Perform duplicate removal processing on the group of aggregated business path information to obtain a group of business path information after duplicate removal, which is used as the group of historical business path information.

5. The method according to claim 1, wherein The matching of the group of historical business path information with the group of aggregated business path information to obtain a group of matching results includes: Perform data format conversion on the group of historical business path information and the group of aggregated business path information to obtain a group of historical business path information after conversion and a group of business path information after conversion, where the data formats between the group of historical business path information after conversion and the group of business path information after conversion are the same; Compare the group of historical business path information after conversion and the group of business path information after conversion with a preset number of matching conditions to obtain a group of matching results, where the group of matching results includes: business attribute matching results, timestamp matching results, and path information matching results. The business attribute matching results can represent the results of consistent business attribute matching and inconsistent business attribute matching. The timestamp matching results can represent the results of consistent timestamp matching and inconsistent timestamp matching. The path information matching results can represent the results of consistent path information matching and inconsistent path information matching.

6. A flowchart display device, comprising: An acquisition unit configured to acquire a set of business path information groups and message field information corresponding to a log system, where each business path information group in the set of business path information groups is initiated by the same business initiator, and the business path information groups in the set of business path information groups include: path information corresponding to at least one piece of business information with different attributes; An aggregation unit configured to, in response to determining that there are at least one business path information groups corresponding to the same business attribute among the path information corresponding to the business path information groups in the set of business path information groups, aggregate the at least one business path information groups with the same business attribute to obtain a group of aggregated business path information; A generation unit configured to generate a group of historical business path information according to the message field information corresponding to the log system; A matching unit, configured to match the historical service path information group with the aggregated service path information group to obtain a matched result group, wherein the matched results in the matched result group represent matched consistent results and unmatched inconsistent results; A fusion unit, configured to, in response to determining that there is a matched result representing a matched consistent result in the matched result group, fuse the historical service path information group and the aggregated service path information group to obtain a fused service path information group; After the fusion unit, the apparatus further includes: in response to determining that there is a matched result representing an unmatched inconsistent result in the matched result group, performing service attribute division on at least one historical service path information and at least one aggregated service path information corresponding to the unmatched inconsistent result in the matched result group to obtain a divided service path information group, wherein the divided service path information group can represent that the service attributes between the divided service path information are all different; fusing the divided service path information group with the fused service path information group to obtain a target service path information group; constructing a flowchart for the target service path information group to obtain a target service path flowchart; and displaying the target service path flowchart on the main page corresponding to the log system; A construction unit, configured to construct a flowchart for the fused service path information group to obtain a service path flowchart; A display unit, configured to display the service path flowchart on the main page corresponding to the log system.

7. An electronic device, comprising: One or more processors; A storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.

8. A computer-readable medium having a computer program stored thereon, wherein, The program, when executed by the processor, implements the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Business data processing method and device, computer readable medium and computer equipment

    CN114912944A

  • Workflow diagram generation program, apparatus and method

    US20100042745A1