Root cause alarm positioning method and device of transaction relationship tree system and electronic equipment
By constructing a transaction tree and a scoring mechanism, abnormal subsystems and root cause alarms in the transaction relationship tree system are identified, solving the problem of root cause alarm filtering in existing technologies and improving the accuracy and efficiency of fault analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA CONSTRUCTION BANK
- Filing Date
- 2024-08-23
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, transaction relationship tree systems are prone to filtering out root cause alarms when a fault occurs, leading to inaccurate fault analysis.
By identifying abnormal transactions, a transaction tree is constructed. Based on the subsystem's operational status information and network information, alarms associated with the abnormal subsystem are found, and the alarms are scored to filter out the root cause alarms.
It improves the accuracy of root cause alarm location, increases the efficiency of fault analysis, and enables the rapid identification of fault causes, thus maintaining system stability.
Smart Images

Figure CN119094320B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to a root cause alarm positioning method and device of a transaction relationship tree system and electronic equipment. BACKGROUND
[0002] In the related art, when a transaction relationship tree system fails, low-level alarms in a fault time period are usually filtered out, only high-level alarms are retained, and then the remaining alarms are prioritized. However, this method of retaining high-level alarms according to alarm levels is likely to filter out root cause alarms. SUMMARY
[0003] The present application aims to at least partially solve one of the technical problems in the related art.
[0004] To this end, a first object of the present application is to provide a root cause alarm positioning method of a transaction relationship tree system to achieve accurate positioning of root cause alarms.
[0005] A second object of the present application is to provide a root cause alarm positioning device of a transaction relationship tree system.
[0006] A third object of the present application is to provide electronic equipment.
[0007] A fourth object of the present application is to provide a computer-readable storage medium.
[0008] A fifth object of the present application is to provide a computer program product.
[0009] To achieve the above objects, a root cause alarm positioning method of a transaction relationship tree system according to a first aspect of the present application comprises the following steps.
[0010] An abnormal transaction in the transaction relationship tree system is determined, and an original message log of the abnormal transaction is obtained;
[0011] A transaction tree of the abnormal transaction is constructed according to the original message log;
[0012] An abnormal subsystem in each subsystem of the transaction tree is determined according to running state information of the each subsystem;
[0013] Each alarm associated with the abnormal subsystem is found according to network information corresponding to the abnormal subsystem;
[0014] Each alarm is scored to obtain a score of each alarm;
[0015] A root cause alarm is determined from each alarm according to the score of each alarm.
[0016] To achieve the above object, the second aspect of the present application proposes a root cause alarm positioning device of a transaction relationship tree system, comprising:
[0017] An acquisition module is configured to determine an abnormal transaction in the transaction relationship tree system and acquire original message logs of the abnormal transaction;
[0018] A construction module is configured to construct a transaction tree of the abnormal transaction according to the original message logs;
[0019] A first determination module is configured to determine an abnormal subsystem in each subsystem according to running state information of the each subsystem in the transaction tree;
[0020] A search module is configured to search for each alarm associated with the abnormal subsystem according to network information corresponding to the abnormal subsystem;
[0021] A scoring module is configured to score the each alarm to obtain scores of the each alarm;
[0022] A second determination module is configured to determine a root cause alarm from the each alarm according to the scores of the each alarm.
[0023] To achieve the above object, the third aspect of the present application proposes an electronic device, comprising a processor and a memory connected with the processor;
[0024] The memory stores computer execution instructions;
[0025] The processor executes the computer execution instructions stored in the memory to implement the method according to the first aspect of the present application.
[0026] To achieve the above object, the fourth aspect of the present application proposes a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method according to the first aspect of the present application.
[0027] To achieve the above object, the fifth aspect of the present application proposes a computer program product, comprising a computer program, which is executed by a processor to implement the method according to the first aspect of the present application.
[0028] The root cause alarm positioning method, device, electronic equipment and storage medium of the transaction relationship tree system are provided in the application. The abnormal transaction in the system is determined, the transaction tree of the abnormal transaction is constructed according to the original log message of the abnormal transaction, the abnormal subsystem is positioned based on the running state information of each subsystem in the abnormal transaction tree, the accuracy of abnormal subsystem positioning is improved, the alarm associated with the abnormal subsystem is searched, the root cause alarm is screened out from the alarm associated with the abnormal subsystem according to the score of the alarm associated with the abnormal subsystem, the accuracy of root cause alarm positioning is improved, and the fault cause can be accurately found based on the root cause alarm, thereby improving the fault analysis efficiency.
[0029] Additional aspects and advantages of the application will be set forth in part in the description that follows, and in part will become apparent to those skilled in the art upon examination of the following and / or by practice of the application. BRIEF DESCRIPTION OF DRAWINGS
[0030] The above and / or additional aspects and advantages of the application will become apparent and be readily understood from the following description, taken in conjunction with the accompanying drawings, in which:
[0031] Figure 1 A flowchart of a transaction relationship tree system root cause alarm positioning method provided by an embodiment of the application;
[0032] Figure 2 A flowchart of another transaction relationship tree system root cause alarm positioning method provided by an embodiment of the application;
[0033] Figure 3 A flowchart of another transaction relationship tree system root cause alarm positioning method provided by an embodiment of the application;
[0034] Figure 4 A flowchart of another transaction relationship tree construction method provided by an embodiment of the application;
[0035] Figure 5 A hierarchical structure diagram of a transaction relationship tree provided by an embodiment of the application;
[0036] Figure 6 A structural diagram of a transaction relationship tree system root cause alarm positioning device provided by an embodiment of the application;
[0037] Figure 7 A structural diagram of an electronic device shown in an example embodiment of the present disclosure. DETAILED DESCRIPTION
[0038] Embodiments of the present application are described below in detail, examples of which are shown in the accompanying drawings, wherein the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the drawings are exemplary and are intended to explain the present application, and cannot be understood as a limitation of the present application.
[0039] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of the country and region.
[0040] The data acquisition, transmission, storage, use, processing, etc. in the technical solutions of the present application comply with the provisions of national laws and regulations.
[0041] It should be noted that in the embodiments of the present application, some existing industry solutions such as software, components, models, etc. may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0042] The root cause alarm positioning method and device of the transaction relationship tree system of the embodiments of the present application are described below with reference to the accompanying drawings.
[0043] The transaction relationship tree can be a hierarchical management set by a financial institution according to the management authority of different customers and personnel within the institution, which delimits the scope of member units under the group, collects authorized and relationship data, and assists in uniformly presenting account, fund, transaction, etc. information to group customers and personnel within the institution.
[0044] The transaction relationship tree can be a tree-structured customer information collective set for large group customers to reflect their business dealings or affiliation, which can unify large group account, fund transaction, etc. information.
[0045] The transaction relationship tree system can be understood as a transaction system with a transaction relationship tree.
[0046] The cash customer tree can be a tree-structured customer information collective set for group customers to reflect their business dealings or affiliation.
[0047] Figure 1 The flowchart of the root cause alarm positioning method of the transaction relationship tree system provided by the embodiments of the present application.
[0048] In the related art, when the transaction relationship tree system fails, low-level alarms in the failure time period can be filtered out, only high-level alarms are retained, and then the remaining alarms are prioritized. However, sometimes the low-level alarms may contain more important information, and this method of retaining high-level alarms according to alarm levels is likely to filter out root cause alarms.
[0049] To solve this problem, the embodiments of the present application provide a root cause alarm positioning method of a transaction relationship tree system to realize accurate positioning of root cause alarms, which can be applied to the optimized management of bank account transactions. As shown in the Figure 1 The root cause alarm positioning method of the transaction relationship tree system includes the following steps:
[0050] Step 101, determining an abnormal transaction in the transaction relationship tree system and obtaining the original message log of the abnormal transaction.
[0051] The failure of the transaction relationship tree system directly leads to the timeout and interruption of a part of transactions. In this embodiment, whether a transaction is an abnormal transaction can be determined according to the transaction duration, whether the transaction is interrupted, etc., so as to determine which transactions in the system are abnormal transactions. For example, if the transaction duration of a transaction is timed out or interrupted, it can be determined that the transaction is an abnormal transaction. The number of abnormal transactions can be one or more.
[0052] A transaction from start to end can leave a log of calling messages on the message bus, which can be referred to as an original message log. The original message log can include but is not limited to transaction serial number, requester information, responder information, log recording point, request message sending time, request message receiving time, response message sending time, response message receiving time, etc.
[0053] Step 102, constructing a transaction tree of the abnormal transaction according to the original message log.
[0054] The transaction tree can be a tree structure representing the calling relationship between the subsystems in the transaction.
[0055] In this embodiment, the original log information can be processed to obtain a plurality of message pairs in the abnormal transaction, a message pair including a request message and a response message, and a message pair representing one call. According to the plurality of message pairs, the subsystem responding to the request message is determined, and the transaction tree of the abnormal transaction is constructed according to the subsystem responding to the request message.
[0056] Step 103, determining an abnormal subsystem in each subsystem according to the running state information of each subsystem in the transaction tree.
[0057] Exemplarily, the running state information can include but is not limited to interface log, node time consumption, whether interruption occurs, etc.
[0058] For example, the node time consumption of each subsystem in the transaction tree can be counted, and the abnormal subsystems in each subsystem can be determined according to the node time consumption of each subsystem. For example, the difference between the node time consumption of each subsystem and the reference time consumption of each subsystem can be determined, and the subsystem with the largest difference can be determined as the abnormal subsystem, where the reference time consumption of each subsystem can be the average value of the node time consumption of each subsystem in normal transactions.
[0059] For example, the time consumption distribution of different subsystems in each transaction tree structure can be learned by using a deep learning algorithm such as a variational autoencoder (VAE), and the subsystems with abnormal node time consumption can be determined by comparing the node time consumption of each subsystem in the transaction tree of the abnormal transaction with the time consumption distribution of each subsystem, and the subsystems with abnormal node time consumption can be determined as the abnormal subsystems.
[0060] For example, the interface log abnormality detection model can be pre-trained, the interface logs of each subsystem can be input into the abnormality detection model, and it can be judged whether the interface logs of each subsystem are abnormal by using the abnormality detection model, and the subsystems with abnormal interface logs can be determined as the abnormal subsystems.
[0061] Step 104: According to the network information corresponding to the abnormal subsystem, each alarm associated with the abnormal subsystem is found.
[0062] For example, the network information can include but is not limited to the data communication network (DCN) where the abnormal subsystem is located, the network address such as the IP address, etc.
[0063] After locating the abnormal subsystem, the various types of alarms that these subsystems can be associated with in the fault occurrence time period can be found according to the network information corresponding to the abnormal subsystem, such as host alarms, database alarms, etc. Among them, the host alarm can be the host alarm of the network address where the abnormal subsystem is located, or the host alarm of the DCN where the abnormal subsystem is located, or all the host alarms that the abnormal subsystem can be associated with, etc.
[0064] Step 105: Scoring each alarm to obtain the score of each alarm.
[0065] In this embodiment, the alarm can be scored from multiple aspects, and the final score of the alarm can be determined according to the score of each aspect.
[0066] Exemplarily, each scoring parameter of the alarm can be scored to obtain a sub-score of each scoring parameter, and the sub-score of each scoring parameter can be weighted according to the weight of each scoring parameter to obtain the score of the alarm. Each scoring parameter can be, for example, alarm level, associated subsystem type, number of associated transactions, and the like. For example, the alarm level can be divided into multiple levels from high to low, such as critical, important, secondary, warning, and the like.
[0067] The associated subsystem type can refer to the type of other subsystems associated with the current alarm, such as upstream subsystems, downstream subsystems. Since the abnormality of one subsystem can affect other subsystems, and different subsystem types (such as upstream subsystems, downstream subsystems, parallel subsystems, and the like) can be affected in different degrees and ways, the associated subsystem type is an important consideration in the scoring process.
[0068] The number of associated transactions can refer to the number of transactions associated with the current alarm. One alarm can be associated with multiple transactions, and the number of associated transactions can reflect the influence range of the alarm on system transaction activities, for example, the more the number of associated transactions, the higher the score of this scoring parameter.
[0069] Exemplarily, the weight of each scoring parameter can be obtained according to historical alarms, or can be set according to actual needs, and no limitation is made thereto.
[0070] Since some low-level alarms can contain more important information, if high-priority alarms are filtered out according to alarm priority, the root cause alarm can be filtered out. Therefore, by scoring each scoring parameter of the alarm as a scoring basis, obtaining the final score of the alarm based on the sub-score of each scoring parameter, and filtering out the root cause alarm based on the final score, the accuracy of locating the root cause alarm can be improved.
[0071] Step 106, determining the root cause alarm from each alarm according to the score of each alarm.
[0072] The root cause alarm can refer to an alarm that can help find the root cause of system failure or abnormality.
[0073] Exemplarily, the score of each alarm can be compared with a threshold value, and if the score of the alarm is greater than the threshold value, the alarm can be determined as the root cause alarm, so that the root cause of system failure or abnormality can be found according to the root cause alarm. The root cause alarm can be one or more, and no limitation is made thereto.
[0074] For example, as the system failure cases increase and new scoring bases appear, machine learning can be used to determine the threshold and the weight of the scoring parameters, such as Logistic Regression (LR), Gradient Boosting Decision Tree (GBDT), and the like.
[0075] For example, the current average latency indicator of a certain business suddenly increases, and a large number of external interface error logs are found in the abnormal subsystem. From the appearance, it is highly likely that the problem is caused by the external partner. However, by searching the database node associated with the abnormal subsystem, it is found that there are multiple important level alarms on the node, and multiple transactions are affected, so it can be determined that the abnormality is more likely caused by the database. After the operation personnel confirmed that there were indeed a large number of slow queries on the node at that time, which caused the sudden increase of the average latency of the business, and the external interface error was only a symptom, the database slow query was the root cause of the failure. As can be seen, accurate alarm positioning can help operation personnel find the truth of the problem and improve the efficiency of failure analysis.
[0076] In addition, before a large-scale failure occurs, the system often has performance degradation, availability decline, and the like, which causes a small number of transaction flows to have problems, although it is not enough to be an abnormal event. If not handled in time, the problem will gradually accumulate and may trigger a failure. Alternatively, the low-level alarms associated with abnormal transactions can be determined, and the problem can be handled in advance by analyzing the low-level alarms in advance to avoid failure and realize failure warning.
[0077] In this embodiment, the transaction relationship tree system has a failure alarm diagnosis and positioning program in the background. The failure alarm diagnosis and positioning program monitors the front-end running data of the transaction relationship tree system in real time, collects alarm information after the system failure, determines the root cause alarm, and quickly locates the root cause of the alarm according to the root cause alarm. The problems existing in the system software and hardware are solved in time, the efficiency of solving the alarm problems in batches is improved, the stability of the system operation is maintained, and the transaction business handling experience of the operation personnel and users is improved.
[0078] In the embodiment of the application, the abnormal transaction in the system is determined, and the transaction tree of the abnormal transaction is constructed according to the original log message of the abnormal transaction. The running state information of each subsystem in the abnormal transaction tree is used to locate the abnormal subsystem, improve the accuracy of the abnormal subsystem positioning, find the alarm associated with the abnormal subsystem, filter the root cause alarm from the alarm associated with the abnormal subsystem according to the score of the alarm associated with the abnormal subsystem, and thus improve the accuracy of the root cause alarm positioning. Therefore, the failure cause can be accurately found based on the root cause alarm, and the failure analysis efficiency is improved.
[0079] The embodiment provides another root cause alarm positioning method of a transaction relationship tree system, Figure 2 A flowchart of the root cause alarm positioning method of the transaction relationship tree system provided in the embodiment of the application is shown in FIG. 2.
[0080] As shown in FIG. 2, the root cause alarm positioning method of the transaction relationship tree system can include the following steps: Figure 2
[0081] Step 201: determining an abnormal transaction in the transaction relationship tree system, and obtaining original message logs of the abnormal transaction.
[0082] In the embodiment, step 201 can adopt any implementation method in the embodiments of the application, and thus will not be described here again.
[0083] Step 202: processing the original message logs to obtain a plurality of message pairs.
[0084] Each message pair includes a request message and a response message, and one message pair represents one call.
[0085] In the embodiment, the original message logs are parsed and key information such as a timestamp, a transaction ID, an operation type (such as a request or a response), message content, and the like is extracted through a rule processing engine. Based on the log information, it is determined which log entries are request messages and which are response messages. Using a defined rule, the request messages and the response messages are matched based on the key information, and for each successfully matched request message and response message, they are combined into a message pair.
[0086] Step 203: generating a plurality of discrete tree nodes according to response parties of calls corresponding to the plurality of message pairs.
[0087] In the embodiment, information of services or components related to message processing can be retrieved from a configuration management database (CMDB), and according to the retrieved information of the services and components related to message processing, the response parties of the calls represented by each message pair are determined, and the plurality of discrete tree nodes are generated according to the response parties of the calls.
[0088] Each discrete tree node can represent a subsystem that responds to a request message.
[0089] Step 204: generating a transaction tree according to the plurality of discrete tree nodes.
[0090] In this embodiment, the root node of the transaction tree can be obtained from the serial number of the abnormal transaction, the root node of the transaction tree can refer to the subsystem that initiates the abnormal transaction, and it is determined whether several discrete nodes in all discrete tree nodes belong to the same discrete node. If several discrete nodes belong to the same discrete node, the discrete node to which they belong is determined as an upstream node, and the several discrete nodes are downstream nodes. Thus, the upstream and downstream relationships of the plurality of discrete nodes can be determined, the discrete nodes having the upstream and downstream relationships are connected into a tree chain, and one discrete node can appear in multiple tree chains. The multiple tree chains are merged according to the same parent chain and the like, an initial transaction tree is generated according to the merging result and the obtained root node, and horizontal merging, vertical merging and the like are performed on the initial transaction tree. Finally, the transaction tree is obtained.
[0091] For example, horizontal merging can be a merging operation performed at the same level of the transaction tree (i.e., between child nodes having the same parent node), and vertical merging can be a merging operation performed between different levels, such as directly promoting a child node to the position of its parent node (or a higher level), or merging multiple child trees into a larger child tree as a child node of a certain parent node.
[0092] In step 205, the abnormal subsystems in each subsystem are determined according to the running state information of each subsystem in the transaction tree.
[0093] In this embodiment, step 205 can use any of the implementation methods in the embodiments of the present application, and thus will not be described here.
[0094] In step 206, each alarm associated with the abnormal subsystem is found according to the network information corresponding to the abnormal subsystem.
[0095] In this embodiment, step 206 can use any of the implementation methods in the embodiments of the present application, and thus will not be described here.
[0096] After locating the abnormal subsystem, various types of alarms associated with the abnormal subsystem in the fault occurrence time period can be found. For example, for host alarms, the abnormal subsystem id (i.e., account), the DCN (i.e., network) where it is located, the IP (i.e., network address) where it is located, and the like can be used to associate from the precise range to the fuzzy range in a gradually expanded range manner.
[0097] For example, the host alarms of the network address where the abnormal subsystem is located can be associated according to the network information corresponding to the abnormal subsystem. If the host alarms of the network address are not associated, the host alarms of the DCN where the abnormal subsystem is located can be associated. If the host alarms of the DCN where the abnormal subsystem is located are not associated, all the host alarms that can be associated with the abnormal subsystem are associated.
[0098] For example, for database alarms, it can be directly determined whether corresponding alarms exist on the database nodes associated with the abnormal subsystem.
[0099] In this way, the alarms associated with the abnormal subsystem are searched in a manner of gradually expanding the range from the accurate range to the fuzzy range, and the alarm searching efficiency can be improved.
[0100] In step 207, each alarm is scored to obtain a score of each alarm.
[0101] In the embodiment, step 207 can adopt any one of the implementation methods in the embodiments of the present application, and thus will not be described here again.
[0102] In step 208, a root cause alarm is determined from each alarm according to the score of each alarm.
[0103] In the embodiment, step 208 can adopt any one of the implementation methods in the embodiments of the present application, and thus will not be described here again.
[0104] In the embodiment of the present application, a plurality of message pairs can be obtained by processing the original log messages of the abnormal transaction, a plurality of discrete tree nodes can be generated according to the response parties of the calls corresponding to the plurality of message pairs, and a transaction tree of the abnormal transaction can be generated based on the plurality of discrete tree nodes. In this way, the plurality of calls in the abnormal transaction are determined based on the original log messages, and the transaction tree is generated based on the response parties of the plurality of calls, so that the accuracy of the transaction tree can be improved.
[0105] The embodiment provides another root cause alarm positioning method of a transaction relationship tree system, Figure 3 A flowchart of the another root cause alarm positioning method of the transaction relationship tree system provided in the embodiment of the present application is shown.
[0106] As shown in the figure, the root cause alarm positioning method of the transaction relationship tree system can include the following steps: Figure 3
[0107] In step 301, an abnormal transaction in the transaction relationship tree system is determined, and an original message log of the abnormal transaction is obtained.
[0108] In the embodiment, step 301 can adopt any one of the implementation methods in the embodiments of the present application, and thus will not be described here again.
[0109] In step 302, a transaction tree of the abnormal transaction is constructed according to the original message log.
[0110] In the embodiment, step 302 can adopt any one of the implementation methods in the embodiments of the present application, and thus will not be described here again.
[0111] In step 303, node time consumptions of each subsystem in a normal transaction with the same structure as the transaction tree are obtained.
[0112] In this embodiment, the motion state information of each subsystem in the transaction tree of the abnormal transaction can include node time consumption, and the abnormal subsystem can be determined according to the node time consumption of each subsystem.
[0113] Since the transaction tree structures of different transactions can be the same, the node time consumption of each subsystem in a normal transaction having the same transaction tree structure as the abnormal transaction can be obtained, and the abnormal subsystem can be determined based on the node time consumption of each subsystem in the normal transaction.
[0114] In step 304, the node time consumption of each subsystem in the normal transaction is compared with the node time consumption of each subsystem in the transaction tree to obtain the time consumption increment of each subsystem.
[0115] In this embodiment, the node time consumption of each subsystem in the normal transaction can be compared with the node time consumption of the same subsystem in the abnormal transaction to determine the time consumption increment of each subsystem in the abnormal transaction. The time consumption increment can be represented by the difference between the node time consumption of the subsystem in the abnormal transaction and the node time consumption of the subsystem in the normal transaction. For example, the greater the time consumption increment of a subsystem in the abnormal transaction, the greater the probability that the subsystem is abnormal.
[0116] In step 305, the subsystem having the greatest time consumption increment in each subsystem is determined as the abnormal subsystem.
[0117] In this embodiment, the time consumption increments of each subsystem in the abnormal transaction can be compared, and the subsystem having the greatest time consumption increment is determined as the abnormal subsystem.
[0118] Since a problem in an upstream subsystem can affect a downstream subsystem, in order to improve the accuracy of abnormal subsystem positioning, the abnormal transaction can be analyzed in combination with the abnormal subsystem and its upstream subsystem. For example, the running state information of each subsystem in the transaction tree of the abnormal transaction can be used to determine a candidate abnormal subsystem in each subsystem, and the upstream subsystem of the abnormal subsystem can be determined according to the transaction tree. The abnormal subsystem can be determined from the upstream subsystem and the candidate abnormal subsystem according to the running state information of the upstream subsystem. For example, the time consumption increment of the upstream subsystem can be determined according to the running state information of the upstream subsystem. If the difference between the time consumption increment of the upstream subsystem and the time consumption increment of the candidate abnormal subsystem is less than a set threshold, the upstream subsystem can be finally determined as the abnormal subsystem.
[0119] The method for determining the candidate abnormal subsystem can refer to the method for determining the abnormal subsystem in the above embodiments.
[0120] Therefore, the candidate abnormal subsystem and its upstream subsystems positioned by the abnormal transaction are combined for analysis, the accuracy of abnormal subsystem positioning is improved, the range of root cause alarms is greatly reduced, and the position of the fault is covered as much as possible.
[0121] In step 306, each alarm associated with the abnormal subsystem is found according to network information corresponding to the abnormal subsystem.
[0122] In this embodiment, step 306 can adopt any implementation method in the embodiments of the present application, and thus will not be described here.
[0123] In step 307, each alarm is scored to obtain a score of each alarm.
[0124] In this embodiment, step 307 can adopt any implementation method in the embodiments of the present application, and thus will not be described here.
[0125] In step 308, a root cause alarm is determined from each alarm according to the score of each alarm.
[0126] In this embodiment, step 308 can adopt any implementation method in the embodiments of the present application, and thus will not be described here.
[0127] In the embodiments of the present application, the running state information of the subsystem can include node time consumption, and the subsystem with the largest time consumption increase can be determined as the abnormal subsystem by comparing the node time consumption of abnormal transactions and normal transactions with the same transaction tree structure, the positioning accuracy of the abnormal subsystem is improved, and the determination method is relatively simple.
[0128] The root cause alarm determined in the above embodiments can contain multiple alarms of multiple types, and the readability is relatively poor. If the root cause alarm is directly output, it can be inconvenient to locate the fault. Therefore, on the basis of the above embodiments, the root cause alarm positioning method can further include: clustering multiple root cause alarms to obtain multiple types of root cause alarms, merging root cause alarms of the same type to obtain one summary alarm of each type, and outputting multiple types of summary alarms in order from high to low according to the confidence of each type of root cause alarm.
[0129] For example, the types of alarms can include databases, application hosts, networks, internal programs, etc. Root cause alarms of the same type can be merged together, one summary root cause alarm of each type is retained, each type of alarm is given a confidence, and each type of retained root cause alarm is output in order according to the confidence, so as to facilitate the operation and maintenance personnel to quickly and accurately locate the fault.
[0130] It should be noted that if the root cause alarm of a certain type is one, the root cause alarm can be directly output as a summary alarm.
[0131] In the embodiments of the present application, the root cause alarms of the same type are merged by clustering the multiple root cause alarms, one summary alarm of the type is obtained, and the summary alarm is output according to the confidence of each type of root cause alarm. Since the output summary alarm is strong in readability, and is output according to the confidence, the operation and maintenance personnel can quickly and accurately locate the fault.
[0132] In an embodiment of the present application, the transaction relationship tree can be constructed in the manner shown in the figure. Figure 4 Figure 4 Another flowchart of the method for constructing a transaction relationship tree provided in the embodiments of the present application.
[0133] As shown in the figure, the method for constructing a transaction relationship tree includes the following steps. Figure 4
[0134] Step 401: generating an initial transaction relationship tree according to the created top-level node and management node.
[0135] In the embodiments, the top-level node can be the root node of the transaction relationship tree, and the management node can be the next level node of the top-level node, and the initial transaction relationship tree is established. For example, the top-level node can be the head office of a group, and the management node can be an authorized management agency node.
[0136] For example, the initial transaction relationship tree can include root node information and initial transaction information. According to the node information, it can include the head office customer, the affiliated financial company customer, the management node customer, etc. The initial transaction information can include customer information, opening bank information, account information, and transaction counterparty information, etc.
[0137] Step 402: taking the customer number of the head office customer, the affiliated financial company customer, the management node customer, and the customer on the group relationship tree as the root node, recursively obtaining the node customer on the cash customer tree, and taking the node customer as a new node.
[0138] In the embodiments, the customer number of the head office customer, the affiliated financial company customer, the management node customer, and the customer on the group relationship tree can be taken as the root node to find all cash customer trees (for example, one layer can be found), identify all customer nodes and registered accounts (for example, account categories include: current, one-stop main account, effective account, etc.) on the found cash customer tree, and find the corresponding customer, and take the obtained customer node as a new node.
[0139] Step 403: updating the initial transaction relationship tree according to the new node.
[0140] For example, the new node can be added to the initial transaction tree to update the initial transaction relationship tree.
[0141] Step 404, taking the customer number of the new node as the root node, continues to search in the cash customer tree until the new customer is not queried, and the transaction relationship tree is obtained.
[0142] For example, taking the customer number of the identified new node as the root node to find all cash customer trees, identifying all customer nodes and registered account numbers on the queried cash customer tree and finding the corresponding customers, and repeatedly repeating the process until there is no new customer or the cash customer tree cannot be queried with the new customer as the root node. Thus, the new node customers are added to the updated initial transaction relationship tree through recursive traversal, and the transaction relationship tree is finally obtained.
[0143] In this embodiment, through the above recursive search process, a complete transaction relationship tree can be constructed, which contains all customer nodes and account information associated directly or indirectly through the initial node.
[0144] In this embodiment, the customer number of the group headquarters customer, the affiliated financial company customer, the management node customer, and the customer on the group relationship tree can be taken as the root node to find all cash customer trees, identify all customer nodes and registered account numbers on the queried cash customer tree, and find the corresponding customers. Then, taking the customer number of the identified new customer as the root node, find all cash customer trees, identify all customer nodes and registered account numbers on the queried cash customer tree, and find the corresponding customers. Repeat the process until there is no new customer or the cash customer tree cannot be queried with the new customer as the root node. That is, taking the group headquarters customer, the affiliated financial company customer, the management node customer, and the customer on the group relationship tree as the initial node, the node customers obtained by recursion are new nodes. The newly created transaction relationship tree is established in synchronization with the group relationship tree top node customer number, and the newly created transaction relationship tree can be attributed to the first-level branch of the group headquarters customer. When the system has a new group relationship tree, the transaction relationship tree with the group headquarters customer as the top node is established by running batch at the end of the day.
[0145] In addition, when recursively searching for the next level node, if the next level node is another group relationship tree node, the attribution confirmation attribute has been confirmed, and the next level recursive search is not performed.
[0146] Optionally, according to the account-level authorization relationship and the customer-level authorization relationship, it can be determined that there is an authorization relationship in the transaction relationship tree. If the first node in the transaction relationship tree is only an authorized party, an authorization identifier is established for the first node. If the second node in the transaction relationship tree is only an authorized party, an authorized identifier is established for the second node. If the third node in the transaction relationship tree is both an authorized party and an authorized party, a bidirectional authorization identifier is established for the third node.
[0147] That is, according to the account-level authorization and the customer-level authorization relationship, the authorized node with the authorization relationship is identified as an authorized party, according to the account-level authorization and the customer-level authorization relationship, the authorized node with the authorization relationship is identified as an authorized party, according to the account-level authorization and the customer-level authorization relationship, the node with both authorization relationship and authorized relationship is identified as a two-way party, and the node without authorization and authorized relationship is identified as "none".
[0148] It should be noted that the authorization identification only shows the authorization relationship of the node in a transaction relationship tree, and if the node is repeated in multiple transaction relationship trees and the authorization relationship in each transaction relationship tree is different, the displayed authorization identification is different.
[0149] In the embodiment, the nodes in the transaction relationship tree can include a top node, a management node, a to-be-confirmed node, and a general node. The top node, i.e., the root node, can be a group headquarters. The management node customer input when a transaction relationship tree is newly created is automatically assigned as a management node by the financial company system. When the node customer is repeated in multiple transaction relationship trees, it is only used as a management node in one transaction relationship tree. A node with authorized identification or two-way identification and in the same group relationship tree as the top node is confirmed as a management node. The node is set as a general node in other repeated transaction relationship trees. A node with authorized identification or two-way identification except the management node is assigned as a to-be-confirmed node. The to-be-confirmed node is changed to a management node or a general node, which can be manually changed by an operator. The general node can be a member unit other than the top node, the management node, and the to-be-confirmed node.
[0150] The top node and the management node have uniqueness. The top node can only be a top node in one transaction relationship tree and cannot be a top node, a management node, or a to-be-confirmed node in other transaction relationship trees. The management node can only be a management node in one transaction relationship tree and cannot be a top node, a management node, or a to-be-confirmed node in other transaction relationship trees.
[0151] For example, the hierarchical structure of the transaction relationship tree can be as shown in Figure 5 wherein the group headquarters is the root node.
[0152] In the embodiment of the application, the group headquarters customer, the affiliated financial company customer, the management node customer, and the customers on the group relationship tree are all used as initial nodes. New nodes are found through recursive search, and the new nodes are added to the transaction relationship tree, thereby improving the accuracy and integrity of the transaction relationship tree.
[0153] To implement the above-mentioned embodiments, the application further provides a root cause alarm positioning device of a transaction relationship tree system.
[0154] Figure 6A structural schematic diagram of a root cause alarm positioning device of a transaction relationship tree system provided in an embodiment of the present application.
[0155] As shown in the figure, the root cause alarm positioning device 600 of the transaction relationship tree system comprises: Figure 6
[0156] An acquisition module 610, configured to determine an abnormal transaction in the transaction relationship tree system, and acquire an original message log of the abnormal transaction;
[0157] A construction module 620, configured to construct a transaction tree of the abnormal transaction according to the original message log;
[0158] A first determination module 630, configured to determine an abnormal subsystem in each subsystem according to running state information of the each subsystem in the transaction tree;
[0159] A search module 640, configured to search for each alarm associated to the abnormal subsystem according to network information corresponding to the abnormal subsystem;
[0160] A scoring module 650, configured to score the each alarm to obtain a score of the each alarm;
[0161] A second determination module 660, configured to determine a root cause alarm from the each alarm according to the score of the each alarm.
[0162] Further, in a possible implementation manner of the embodiment of the present application, the construction module 620 is configured to:
[0163] process the original message log to obtain a plurality of message pairs; wherein each message pair comprises a request message and a response message, and one message pair represents one call;
[0164] generate a plurality of discrete tree nodes according to response parties of the calls corresponding to the plurality of message pairs; wherein one discrete tree node represents a subsystem responding to the request information;
[0165] generate the transaction tree according to the plurality of discrete tree nodes.
[0166] Further, in a possible implementation manner of the embodiment of the present application, the construction module 620 is configured to:
[0167] determine an upstream and downstream relationship of the plurality of discrete tree nodes according to whether part of the plurality of discrete tree nodes belong to the same discrete node;
[0168] connect the plurality of discrete tree nodes into a plurality of tree chains according to the upstream and downstream relationship;
[0169] merge the plurality of tree chains to generate the transaction tree.
[0170] Further, in a possible implementation manner of the embodiment of the present application, the running state information includes node time consumption of the node, the first determining module 630 is configured to:
[0171] obtain the node time consumption of the subsystem in a normal transaction with the same transaction tree structure as the transaction tree;
[0172] compare the node time consumption of the subsystem in the normal transaction with the node time consumption of the subsystem in the transaction tree to obtain the time consumption increment of the subsystem;
[0173] determine the subsystem with the largest time consumption increment in the subsystems as the abnormal subsystem.
[0174] Further, in a possible implementation manner of the embodiment of the present application, the first determining module 630 is configured to:
[0175] determine the candidate abnormal subsystem in the subsystem according to the running state information of the subsystem in the transaction tree;
[0176] determine the upstream subsystem of the abnormal subsystem according to the transaction tree;
[0177] determine the abnormal subsystem from the upstream subsystem and the candidate abnormal subsystem according to the running state information of the upstream subsystem.
[0178] Further, in a possible implementation manner of the embodiment of the present application, the searching module 640 is configured to:
[0179] associate the host alarm of the network address according to the network address of the abnormal subsystem in the network information;
[0180] in response to no host alarm associated with the network address, associate the host alarm of the data communication network of the abnormal subsystem in the network information.
[0181] Further, in a possible implementation manner of the embodiment of the present application, the scoring module 650 is configured to:
[0182] score each scoring parameter of the alarm to obtain a sub-score of each scoring parameter;
[0183] weight the sub-score of each scoring parameter according to the weight of each scoring parameter to obtain the score of the alarm.
[0184] Further, in a possible implementation manner of the embodiment of the present application, the root cause alarm is multiple, and the apparatus can further include:
[0185] a clustering module, configured to cluster the plurality of root cause alarms to obtain a plurality of types of root cause alarms;
[0186] a merging module, configured to merge root cause alarms of a same type to obtain one summary alarm of each type;
[0187] an output module, configured to output the plurality of types of summary alarms in a descending order of confidence of root cause alarms of each type.
[0188] Further, in a possible implementation of the embodiment of the application, the apparatus can further include:
[0189] a generating module, configured to generate an initial transaction relationship tree according to the created top-level node and the management node;
[0190] a querying module, configured to take a client number of a group headquarters client, a client number of a financial company client to which the group headquarters client belongs, a client number of a management node client, and a client number of a client on the group relationship tree as a root node, and recursively obtain a node client on a cash client tree, and take the node client as a new node;
[0191] an updating module, configured to update the initial transaction relationship tree according to the new node;
[0192] The querying module is further configured to continue searching on the cash client tree with the client number of the new node as a root node until no new client is found, and obtain the transaction relationship tree.
[0193] Further, in a possible implementation of the embodiment of the application, the apparatus can further include:
[0194] a third determining module, configured to determine a node with an authorization relationship in the transaction relationship tree according to an account-level authorization relationship and a client-level authorization relationship;
[0195] a establishing module, configured to establish an authorization identifier for a first node in the transaction relationship tree in response to the first node being only an authorized party, establish an authorized identifier for a second node in the transaction relationship tree in response to the second node being only an authorized party, and establish a bidirectional authorization identifier for a third node in the transaction relationship tree in response to the third node being both an authorized party and an authorized party.
[0196] It should be noted that the foregoing explanation and description of the embodiment of the root cause alarm positioning method of the transaction relationship tree system also applies to the embodiment of the root cause alarm positioning apparatus of the transaction relationship tree system, which will not be described herein again.
[0197] In the embodiments of the present application, the abnormal transaction in the system is determined, and a transaction tree of the abnormal transaction is constructed according to the original log message of the abnormal transaction, the abnormal subsystem is located based on the running state information of each subsystem in the abnormal transaction tree, the accuracy of the abnormal subsystem positioning is improved, the alarm associated to the abnormal subsystem is searched, the root cause alarm is filtered out from the alarm associated to the abnormal subsystem according to the score of the alarm associated to the abnormal subsystem, and thus the accuracy of the root cause alarm positioning is improved, and then the fault reason can be accurately found based on the root cause alarm, and the fault analysis efficiency is improved.
[0198] To achieve the above-mentioned embodiments, the present application further provides an electronic device, comprising: a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; and the processor executes the computer execution instructions stored in the memory to implement the method provided by the foregoing embodiments.
[0199] To achieve the above-mentioned embodiments, the present application further provides an electronic device, comprising: a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; and the processor executes the computer execution instructions stored in the memory to implement the method provided by the foregoing embodiments.
[0200] As an example, Figure 7 is a structural schematic diagram of an electronic device shown in an example embodiment of the present disclosure, as Figure 7 As shown in the above electronic device 700, the electronic device 700 can further comprise:
[0201] The memory 710 and the processor 720, the bus 730 connecting different components (including the memory 710 and the processor 720), the memory 710 stores a computer program, and the processor 720 executes the program to implement the information collection method described in the embodiments of the present disclosure.
[0202] The bus 730 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of a variety of bus structures. For example, these architectures include but are not limited to industry standard architecture (ISA) bus, micro channel architecture (MAC) bus, enhanced ISA bus, video electronics standards association (VESA) local bus, and peripheral component interconnect (PCI) bus.
[0203] The electronic device 700 typically includes a variety of electronic device readable media. These media can be any available media that can be accessed by the electronic device 700, including volatile and non-volatile media, removable and non-removable media.
[0204] The storage 710 can also include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 760 can be provided for reading from and writing to a non-removable, non-volatile magnetic media (not shown and typically called a "hard drive"). Figure 7 Not shown, a non-transitory computer readable storage medium can also be used to store data that is (temporarily) moved to memory 710 (depending on certain criteria, for example on determining that such an action is more efficient than reading from storage 710). Figure 7 Not shown, a non-transitory computer readable storage medium can also be used to store data that is (temporarily) moved to memory 710 (depending on certain criteria, for example on determining that such an action is more efficient than reading from storage 710).
[0205] Program / utility 780 having a set (at least one) of program modules 770 can be stored in memory 710 by way of example, and not limiting, an operating system, one or more application programs, other program modules, and program data, each of which
[0206] Electronic device 700 can also communicate with one or more external devices 790 such as a keyboard or pointing device, a display 791, etc.; one or more devices that enable a user to interact with electronic device 700; and / or one or more devices (e.g., network card, modem, etc.) that enable electronic device 700 to communicate with one or more other computing devices. Such communication can occur via Input / Output (I / O) interface(s) 792. Still yet, electronic device 700 can communicate with one or more networks (such as one or more LANs, WANs, and / or the Internet through network adapter 793). As an example, network adapter 793 can be any of a variety of modems, including cable modem, digital subscriber line (DSL), and / or the like. Utilizing a modem, network adapter 793 provides functionality including, but not limited to, communication of data over a transmission medium for the electronic device 700. Although not shown, it should be understood that an off-the-shelf modem 793 can be used in conjunction with the electronic device 700. Further, it should be understood that the functionality of the modem 793 can be provided using a variety of hardware and / or software components, including but not limited to, a processor, a memory, a modem, a digital signal processor, and / or the like.
[0207] Processor 720 executes the program code accessed from the storage 710, by reading and
[0208] To achieve the above-mentioned embodiments, the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method provided by the foregoing embodiments.
[0209] To achieve the above-mentioned embodiments, the present application further provides a computer program product, comprising a computer program, wherein the computer program is executed by a processor to implement the method provided by the foregoing embodiments.
[0210] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the present application comply with relevant laws and regulations and do not violate public order and good customs.
[0211] It should be noted that the personal information from the user should be collected for legal and reasonable purposes, and should not be shared or sold outside these legal uses. In addition, such collection / sharing should be carried out after the user's informed consent, including but not limited to informing the user to read the user agreement / user notice before the user uses the function, and signing the agreement / authorization including authorization of relevant user information. In addition, any necessary steps should be taken to protect and ensure access to such personal information data, and ensure that other people with access to personal information data comply with their privacy policy and processes.
[0212] The present application is expected to provide embodiments in which the user can selectively prevent the use or access of personal information data. That is, the present disclosure is expected to provide hardware and / or software to prevent or block access to such personal information data. Once the personal information data is no longer needed, the risk is minimized by limiting data collection and deleting data. In addition, such personal information is de-identified, if applicable, to protect the privacy of the user.
[0213] In the foregoing embodiment description, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the skilled in the art can combine and combine the different embodiments or examples described in the specification and the features of the different embodiments or examples, without contradiction.
[0214] Moreover, the terms "first", "second", "third", etc. are used herein only to describe different steps or categories of steps in a claim for patent purposes, and are not to be construed as implying or implying relative importance or a number of indicated technical features. Thus, features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise explicitly specified.
[0215] Any process or method descriptions or descriptions of the flow diagrams described herein or otherwise described herein can be understood as representing modules, segments, or portions of code that include one or more executable instructions for implementing specific logical functions or steps in the process, and the preferred embodiments of the present application include additional implementations that can not be described in detail in the description of the preferred embodiments, and the skilled person in the art should understand that the preferred embodiments of the present application can be implemented in other ways, including in an order other than that shown or discussed, including in a substantially simultaneous manner or in reverse order, according to the functions involved.
[0216] The logic and / or steps represented in the flow diagrams or otherwise described herein, for example, can be considered as a list of executable instructions for implementing the logic function, which can be specifically embodied in any computer-readable medium for use by or in conjunction with an instruction execution system, device or apparatus, such as a computer-based system, a system including a processor, or other system that can take instructions from an instruction execution system, device or apparatus and execute them. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate or transport a program for use by or in conjunction with an instruction execution system, device or apparatus. More specific examples (non-exhaustive list) of computer-readable media include the following: electrical connections having one or more wires (electronic devices), portable computer disks (magnetic devices), random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memories), fiber optic devices, and portable compact disc read-only memories (CD ROMs). In addition, a computer-readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be electronically obtained, for example, by optical scanning of the paper or other medium, followed by electronic editing, interpretation or processing, if necessary, in other suitable manner, and then stored in a computer memory.
[0217] It should be understood that parts of the present application can be realized in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be realized as software or firmware stored in a memory and executed by a suitable instruction execution system. As such, if realized in hardware, and in another embodiment, any one or a combination of the following technologies known in the art can be used: discrete logic circuitry having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and the like.
[0218] Those skilled in the art of the present technology can understand that all or part of the steps carried out by the above-mentioned embodiments can be completed by a program instructing the relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, it includes one of the steps of the method embodiments or a combination thereof.
[0219] In addition, each functional unit in each embodiment of the present application can be integrated into one processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above-mentioned integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
[0220] The above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above-mentioned embodiments are exemplary and cannot be understood as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above-mentioned embodiments within the scope of the present application.
Claims
1. A root cause alarm localization method for a transaction relationship tree system, characterized in that, The method includes the following steps: Identify abnormal transactions in the transaction relationship tree system and obtain the original message logs of the abnormal transactions; The original message log is used to obtain multiple message pairs; multiple discrete tree nodes are generated according to the responders of the calls corresponding to the multiple message pairs; the transaction tree of the abnormal transaction is constructed according to the multiple discrete tree nodes; wherein, each message pair includes a request message and a response message, one message pair represents one call; one discrete tree node represents a subsystem that responds to the request message; Based on the operational status information of each subsystem in the transaction tree, abnormal subsystems are identified; wherein, the node consumption time of each subsystem in a normal transaction with the same transaction tree structure is obtained; the node consumption time of each subsystem in the normal transaction is compared with the node consumption time of each subsystem in the transaction tree to obtain the time increase of each subsystem; the subsystem with the largest time increase is identified as the abnormal subsystem. Based on the network information corresponding to the abnormal subsystem, locate each alarm associated with the abnormal subsystem; Each scoring parameter of each alarm is scored to obtain a sub-score for each scoring parameter; the sub-scores of each scoring parameter are weighted according to their respective weights to obtain the score for each alarm. Based on the scores of each alarm, the root cause alarm is identified from the alarms.
2. The method as described in claim 1, characterized in that, The step of generating the transaction tree based on the plurality of discrete tree nodes includes: The upstream and downstream relationships of the multiple discrete tree nodes are determined based on whether some of the discrete tree nodes belong to the same discrete node. Based on the upstream and downstream relationships of the multiple discrete tree nodes, the multiple discrete tree nodes are connected into multiple tree chains; The multiple tree chains are merged to generate the transaction tree.
3. The method as described in claim 1, characterized in that, The step of determining the abnormal subsystems in each subsystem based on the operating status information of each subsystem in the transaction tree further includes: Based on the operational status information of each subsystem in the transaction tree, candidate abnormal subsystems are determined among the subsystems. Based on the transaction tree, determine the upstream subsystem of the abnormal subsystem; Based on the operating status information of the upstream subsystem, the abnormal subsystem is determined from the upstream subsystem and the candidate abnormal subsystem.
4. The method as described in claim 1, characterized in that, The step of searching for each alarm associated with the abnormal subsystem based on the network information corresponding to the abnormal subsystem includes: Based on the network address of the abnormal subsystem in the network information, associate the host alarm with the network address; In response to a host alarm that is not associated with the network address, associate the host alarm with the data communication network where the abnormal subsystem is located in the network information.
5. The method as described in claim 1, characterized in that, The root cause alarms are multiple, and the method further includes: Clustering the multiple root cause alarms yields various types of root cause alarms; Root cause alarms of the same type are merged to obtain a summary alarm for each type; Output the summary alarms for each type of root cause alarm in descending order of confidence level.
6. The method as described in claim 1, characterized in that, The transaction relationship tree in the transaction relationship tree system is constructed in the following way: Based on the created top-level node and management node, generate the initial transaction relationship tree; Based on the customer IDs of the group headquarters customers, affiliated finance company customers, management node customers, and customers on the group relationship tree, the node customers are obtained recursively on the cash customer tree, and the node customers are added as new nodes. The initial transaction relationship tree is updated based on the newly added nodes; Using the customer ID of the newly added node as the root node, continue searching in the cash customer tree until no new customer is found, and obtain the transaction relationship tree.
7. The method as described in claim 6, characterized in that, Also includes: Based on account-level authorization relationships and customer-level authorization relationships, determine the nodes in the transaction relationship tree that have authorization relationships; In response to the fact that the first node in the transaction relationship tree is only the authorizing party, an authorization identifier is established for the first node; In response to the fact that the second node in the transaction relationship tree is only an authorized party, an authorized identifier is established for the second node; In response to the fact that the third node in the transaction relationship tree is both the authorizing party and the authorized party, a two-way authorization identifier is established for the third node.
8. A root cause alarm location device for a transaction relationship tree system, characterized in that, include: The acquisition module is used to identify abnormal transactions in the transaction relationship tree system and acquire the original message logs of the abnormal transactions. A construction module is used to obtain multiple message pairs from the original message log; generate multiple discrete tree nodes according to the responders of the calls corresponding to the multiple message pairs; and construct the transaction tree of the abnormal transaction according to the multiple discrete tree nodes; wherein, each message pair includes a request message and a response message, one message pair represents one call; and one discrete tree node represents a subsystem that responds to the request message. The first determining module is used to determine the abnormal subsystems in each subsystem based on the running status information of each subsystem in the transaction tree; wherein, it obtains the node consumption time of each subsystem in a normal transaction with the same structure as the transaction tree; compares the node consumption time of each subsystem in the normal transaction with the node consumption time of each subsystem in the transaction tree to obtain the time increase of each subsystem; and determines the subsystem with the largest time increase as the abnormal subsystem. The lookup module is used to look up each alarm associated with the abnormal subsystem based on the network information corresponding to the abnormal subsystem. The scoring module is used to score each scoring parameter of each alarm to obtain a sub-score for each scoring parameter; and to weight the sub-scores of each scoring parameter according to the weight of each scoring parameter to obtain the score of each alarm. The second determining module is used to determine the root cause alarm from the various alarms based on the scores of each alarm.
9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-7.
Citation Information
Patent Citations
Network security detection method and system
CN114615051A
Alarm analysis method and device, electronic equipment and storage medium
CN114760186A
Root cause alarm positioning method and device, equipment and medium
CN116112339A