Information processing method and device, electronic equipment, storage medium and product
By performing event analysis on real-time network information streams and combining non-real-time information for grouping and frequent item mining, the efficiency and accuracy issues in network event location analysis are resolved, enabling rapid and accurate root cause localization and situation assessment.
Patent Information
- Application Number
- CN202411427468.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-14
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-10-14
AI Technical Summary
In the analysis and localization of network incidents, existing technologies suffer from low efficiency and incomplete data, resulting in slow localization speed and poor accuracy. This is especially true in the analysis of faults, hidden dangers, and service degradation events, where it is difficult to quickly identify and determine the root cause.
By analyzing real-time network information streams to obtain non-real-time information, grouping events, and using the principle of frequent item mining to perform root cause localization and situational analysis, a comprehensive analysis is conducted by combining real-time and non-real-time information.
It improves the accuracy and efficiency of root cause localization and situation assessment of network incidents, enabling faster identification of key causes and potential risks, and providing more comprehensive analytical conclusions.
Smart Images

Figure CN119341900B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of communication technology, and in particular, to an information processing method and device, electronic equipment, storage medium and product. BACKGROUND
[0002] Currently, when performing problem positioning analysis of network events, the staff often needs to log in to other multiple network management systems in combination with their own operation and maintenance experience, view possible related information of the event, and then perform event root cause judgment and business impact range analysis.
[0003] However, since the possible related information of the event is distributed in different network management systems, the efficiency of the correlation analysis performed by the staff is low, the problem positioning speed and the business impact duration are limited by the speed of manual positioning analysis, and the data completeness for performing root cause judgment is not high, so that all the data of the triggered event cannot be analyzed completely, so that the overall analysis conclusion of the current event information cannot be understood, and the accuracy of the conclusion is also not high. SUMMARY
[0004] The present disclosure is proposed in view of the above problems. The present disclosure provides an information processing method and device, electronic equipment, storage medium and product.
[0005] According to one aspect of the present disclosure, an information processing method is provided, comprising: performing event analysis on a network real-time information stream to obtain first event information; obtaining non-real-time information associated with the first event information to obtain second event information; performing event grouping on the second event information to obtain an event information set; and performing root cause positioning and / or situation judgment analysis on the event information set based on a frequent item mining principle.
[0006] According to another aspect of the present disclosure, an information processing device is provided, comprising: an information analysis module configured to perform event analysis on a network real-time information stream to obtain first event information; an information acquisition module configured to obtain non-real-time information associated with the first event information to obtain second event information; an event grouping module configured to perform event grouping on the second event information to obtain an event information set; and a judgment analysis module configured to perform root cause positioning and / or situation judgment analysis on the event information set based on a frequent item mining principle.
[0007] According to another aspect of the present disclosure, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method of any one of the above embodiments.
[0008] According to another aspect of the present disclosure, a computer readable storage medium is provided, having stored thereon a computer program / instructions which, when executed by a processor, implement the method of any of the above embodiments.
[0009] According to another aspect of the present disclosure, a computer program product is provided, comprising computer program / instructions which, when executed by a processor, implement the method of any of the above embodiments.
[0010] As will be described in detail below, an information processing method and apparatus, electronic device, storage medium and product according to embodiments of the present disclosure. The present disclosure obtains first event information by analyzing network real-time information flow, and obtains second event information according to non-real-time information of the first event information. That is, the second event information at least includes the first event information and non-real-time information of the first event information. And event grouping is performed according to the second event information, so as to obtain an event information set. Finally, according to the principle of frequent item mining, root cause positioning and / or situation analysis of the event information set is performed, so as to quickly locate the fault reason, and thus quickly find a solution according to the fault reason. Specifically, the present disclosure obtains non-real-time information through the first event information, obtains the second event information, and combines the real-time information and the non-real-time information, so as to enrich the dimension information related to the network event. And the relationship between the network real-time information and the non-real-time information is comprehensively considered by using the principle of frequent item mining, and the frequency of which data appears together is analyzed, so as to more accurately perform root cause mining and / or situation analysis. In this way, when analyzing and performing root cause positioning on the network event, the data analyzed by the present disclosure has higher completeness, and the key reason and potential risk of the event can be more accurately identified, so as to improve the accuracy and efficiency of the network event root cause positioning and / or situation analysis.
[0011] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the subject technology. BRIEF DESCRIPTION OF DRAWINGS
[0012] The foregoing and other objects, features and advantages of the present disclosure will be more fully understood from the following detailed description taken in conjunction with the accompanying drawings, in which:
[0013] Figure 1 is a flowchart illustrating an information processing method according to an embodiment of the present disclosure.
[0014] Figure 2FIG. 1 is a schematic diagram illustrating an event flow list according to an embodiment of the present disclosure.
[0015] Figure 3 FIG. 2 is a schematic diagram illustrating a group rule configuration interface according to an embodiment of the present disclosure.
[0016] Figure 4 FIG. 3 is a flowchart illustrating a frequent item mining according to an embodiment of the present disclosure.
[0017] Figure 5 FIG. 4 is a flowchart illustrating an event information set processing according to an embodiment of the present disclosure.
[0018] Figure 6 FIG. 5 is a flowchart illustrating a frequent item set acquisition according to an embodiment of the present disclosure.
[0019] Figure 7 FIG. 6 is a schematic diagram illustrating an item set relationship according to an embodiment of the present disclosure.
[0020] Figure 8 FIG. 7 is a schematic diagram illustrating a simplification processing according to an embodiment of the present disclosure.
[0021] Figure 9 FIG. 8 is a schematic diagram illustrating a root cause event details view according to an embodiment of the present disclosure.
[0022] Figure 10 FIG. 9 is a flowchart illustrating another information processing method according to an embodiment of the present disclosure.
[0023] Figure 11 FIG. 10 is a block diagram illustrating an information processing apparatus according to an embodiment of the present disclosure.
[0024] Figure 12 FIG. 11 is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure.
[0025] Figure 13 FIG. 12 is a schematic diagram illustrating a computer program product according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0026] In order to make the objectives, technical solutions, and advantages of the present disclosure more apparent, the following will describe example embodiments according to the present disclosure in detail with reference to the accompanying drawings. Obviously, the described embodiments are only some of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the example embodiments described herein.
[0027] For IT systems, an incident usually refers to an unplanned service interruption, a decrease in service quality, or a situation that may affect service. For a communication operator, a network incident refers to a situation that causes a decrease in service processing capacity or even service blocking, affects user experience, and includes at least one of a network failure incident, a network hidden danger incident, and a service degradation incident, caused by device failure, connection interruption, line degradation, external environmental factors, external emergencies, etc.
[0028] After a network incident occurs, an operation and maintenance personnel often needs to rely on an IT network management support system to coordinate multiple professional joint troubleshooting, which is difficult and time-consuming, and has low monitoring efficiency. Taking a network failure incident as an example, when a network element is unreachable, an incident is often triggered based on a solidified alarm primary-secondary association rule, and related alarms are aggregated. Then, a worker logs in to multiple other network management systems, sets and tries different query conditions, views performance, switching, and other information that may be related to the failure, analyzes historical work order data to obtain failure cause classification, treatment measures, and other details of the failure, and further judges the failure cause, analyzes the business impact range, and finds a solution in combination with expert experience.
[0029] As can be seen, the efficiency of the correlation analysis performed by the worker is low, and the problem positioning speed and business impact duration are limited by the speed of manual positioning analysis. For example, for a network failure incident, in addition to the primary-secondary association and derivative association rules of the alarm, the efficiency of manual analysis combined with multi-dimensional data varies from person to person. The same failure can be quickly positioned by an experienced expert, but after replacing the worker, it may not be possible to correctly troubleshoot key performance indicators, engineering switching information, or historical work order data, making it difficult to quickly locate the failure cause, determine the impact range, and find a solution.
[0030] For example, a network hidden danger incident is not like a failure incident that can mostly find a breakthrough for problem troubleshooting and positioning through alarm monitoring. It needs to extract information from multiple data sources such as alarms, performance, and work orders to jointly determine the occurrence and elimination of network hidden dangers. The existing alarm monitoring-based analysis method cannot meet the needs of active discovery and rapid positioning of such incidents.
[0031] For example, a service degradation incident, in addition to the indicators that can be obtained from performance alarms, there are many rules in the vast amount of performance indicators. The existing alarm monitoring-based service degradation incident monitoring method cannot discover the problem in the first time.
[0032] Moreover, due to the need to log in to different systems to obtain incident-related information, network incident processing may be severely delayed, increasing the duration of network incident impact. Finally, the operation and maintenance experience of different workers cannot be solidified and iteratively optimized, and cannot be used as a reference for rule adjustment.
[0033] To solve at least part of the above problems, the present disclosure provides an information processing method. In the method, real-time network information flow and supplemented non-real-time information are used for root cause positioning and / or situation judgment analysis of event occurrence. In this way, information can be analyzed from two information dimensions of real-time and non-real-time, and the key reasons and potential risks of event occurrence can be more accurately identified, thereby improving the accuracy and efficiency of network event root cause positioning and / or situation judgment analysis.
[0034] The information processing method provided by the present disclosure will be described in detail below with reference to the accompanying drawings, Figure 1 is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As Figure 1 shown, the method specifically includes:
[0035] S101, event analysis is performed on the network real-time information flow to obtain first event information.
[0036] Specifically, when a condition satisfying event derivation is met in the network real-time information flow, the network real-time information satisfying the event derivation condition is obtained, and first event information is analyzed and obtained. Exemplarily, the first event information can be obtained based on root alarm triggering.
[0037] The event derivation condition can be understood as a condition for triggering an event. That is, when some specific conditions appear in the network real-time information flow, an event can be triggered. The event derivation condition can be derived from any network real-time information representing network anomalies, and the event derivation condition is set with different conditions according to different types of information included in the network real-time information flow. That is, the event derivation condition can be an alarm or other abnormal network real-time information.
[0038] The first event information at least includes part of the network real-time information in which an anomaly occurs. In addition, the first event information can also include other information, for example, the number of network element devices where the anomaly occurs, and the type of network element devices where the anomaly occurs.
[0039] The network real-time information flow can be understood as an information flow that can be directly obtained. Exemplarily, it can also be understood as an information flow that can be obtained without interacting with other systems.
[0040] The network real-time information flow includes but is not limited to at least one of alarms, performance indicators, logs, work orders, complaints, and engineering cut. The alarm can be understood as an alarm issued when the abnormality of other network real-time information exceeds a threshold. That is, when the abnormality of any type of information in the network real-time information reaches a certain degree, an alarm will be generated. The alarm can at least include attribute dimension information of the information where the anomaly occurs.
[0041] It should be noted that there is and only one alarm or abnormal information in any first event that best characterizes the characteristics of the first event, which is referred to as a root alarm in the subsequent disclosure. In theory, any abnormal information can be a root alarm of the first event. In actual scenarios, since the alarm is information whose abnormality exceeds a threshold, the root alarm is often the root cause of the first event. Among them, the root alarm and the first event have a one-to-many relationship: one first event contains only one root alarm, and one alarm can be associated with multiple first events. When the first event is triggered by multiple alarms, other alarms can be sub-alarms of the root alarm of the event.
[0042] For example, when the first event information is triggered based on an alarm (such as a fault alarm or a quality degradation alarm). For example, the first event can be triggered according to the occurrence of the alarm, and the first event can be eliminated after the alarm is cleared.
[0043] For example, when the first event information is triggered based on a performance indicator, the occurrence and clearing of the event can be determined according to a threshold of the performance indicator. For example, the trigger condition of the first event is that a performance indicator is lower than a lower limit of a first threshold, and the first event is cleared when the performance indicator meets the first threshold.
[0044] For example, when the first event information is triggered based on a log, the occurrence and clearing of the first event can be determined according to a log matching condition. For example, the first event can be triggered when the log occurs, and the first event can be eliminated within a first preset time window after the log occurs.
[0045] For example, when the first event information is triggered based on a work order, the occurrence and clearing of the event can be determined according to an analysis rule such as work order frequency. For example, the trigger condition of the first event is that the corresponding fault occurrence time of the latest work order that meets the rule, and the first event is cleared within a second preset time window after the work order is archived.
[0046] It should be understood that the first threshold, the second threshold, the first preset time window, and the second preset time window mentioned above are only examples for easy understanding, and the disclosure does not specifically limit the above values.
[0047] S102, acquiring non-real-time information associated with the first event information to obtain second event information.
[0048] This step means that after the first event is triggered, non-real-time information associated with the first event can be obtained according to different types of first events. The association relationship of the non-real-time information can be obtained in combination with historical business needs and operation and maintenance experience.
[0049] The non-real-time information herein can be understood as information that cannot be directly obtained. Exemplarily, the non-real-time information can also be understood as information from other external network systems or non-real-time data interfaces, and the information needs to be interacted with other systems or non-real-time data interfaces to obtain. For example, the external information such as work orders and engineering cut of external systems can be obtained through external system interfaces. The present disclosure does not specifically limit the type of non-real-time data interface, and the non-real-time data interface includes but is not limited to at least one of the following: a database query interface, a RESTful interface, and a SQL interface.
[0050] The information types included in the non-real-time information and the first event information can not be completely the same. The non-real-time information includes but is not limited to at least one of the following: an alarm, a performance indicator, a log, a work order, a complaint, and an engineering cut. According to different application scenarios, the types of non-real-time information required are also different, which will be described in detail below.
[0051] In an illustrative embodiment, when the information types included in the non-real-time information and the first event information are the same, the diversity of information is increased to some extent, so that the aspects of the first event are better understood, and the efficiency of subsequent root cause mining and / or situation judgment analysis is improved to some extent.
[0052] In another illustrative embodiment, when the information types included in the non-real-time information and the first event information are at least partially different, the non-real-time information can be used to supplement the first event information in multiple dimensions, providing a new analysis angle for subsequent root cause mining and / or situation judgment analysis, and to some extent, providing a deeper understanding of the first event, thereby improving the accuracy of root cause mining and / or situation judgment analysis.
[0053] The second event information includes the first event information and the non-real-time information related to the first event information. According to different non-real-time information, the method for obtaining the second event information is also different, which will be described in detail below, and will not be described here. The second event information at least includes the first event information, and in addition to this, the second event information can also include information related to the non-real-time information, which will be described in detail below.
[0054] Optionally, since the information format of the non-real-time information from different systems can be different from the format used, the non-real-time information can be parsed and converted after being obtained.
[0055] Optionally, the non-real-time information can also be stored to facilitate subsequent calling, thereby reducing the number of interactions with other systems and saving communication resources. Further, variable definition is required when storing the non-real-time information. The variable definition method includes but is not limited to at least one of the following: FIX, FIELD, SQL, REG, and ITF.
[0056] Among them, according to the type of non-real-time information, the variable definition method is also different. For example, when defining fixed text (such as text, numbers), FIX can be used. When using a certain fixed attribute field definition of a certain information (such as an alarm), FIELD can be used. When information needs to be retrieved from a database or other data sources based on complex query logic, SQL can be used. When a part of the information needs to be intercepted (such as intercepting a part of the alarm text), REG can be used. In addition, ITF can be used for self-definition, and after definition, it can be directly selected as a variable, for example, through the internal data interface of the system, the definition of the python function is carried out for the data collected to the system.
[0057] S103, grouping the second event information to obtain an event information set.
[0058] In this step, the second event information can be grouped based on a preconfigured grouping rule, thereby simplifying the second event information into a plurality of smaller event information sets, thereby reducing the algorithm complexity in subsequent frequent item mining processing.
[0059] Among them, the disclosure does not specifically limit the specific content of the grouping rule, which can be determined by itself according to the actual situation. Illustratively, the grouping rule is configured based on each attribute dimension of the root alarm information, or can be grouped according to the fixed value of the root alarm information, or can be a combination of the above two. The specific grouping process will be described in detail later.
[0060] S104, based on the principle of frequent item mining, root cause positioning and / or situation analysis of the event information set.
[0061] In this step, the event information set can be subjected to root cause positioning and / or situation analysis based on the principle of frequent item mining. Optionally, the event information set can be input into a trained frequent item mining module, and the root cause event and / or situation analysis point are output. Among them, the specific processing process of the frequent item mining module to the event information set will be described in detail later, which is not specifically limited here.
[0062] Among them, the manifestation form of the principle of frequent item mining includes but is not limited to at least one of the following: a frequent item mining algorithm, a frequent item mining module, and a third-party tool.
[0063] In summary, the disclosure obtains first event information by analyzing network real-time information flow, and obtains second event information according to non-real-time information of the first event information. That is, the second event information at least includes the first event information and non-real-time information of the first event information. The event grouping is performed according to the second event information, so as to obtain an event information set. Finally, according to the principle of frequent item mining, root cause positioning and / or situation judgment analysis are performed on the event information set, so as to quickly locate the fault reason, and thus quickly find a solution according to the fault reason. Specifically, the disclosure obtains non-real-time information through the first event information, obtains the second event information, combines the real-time information and the non-real-time information, and thus enriches the dimension information related to the network event. The relationship between the network real-time information and the non-real-time information is comprehensively considered by using the principle of frequent item mining, and the frequency of which data appears together is analyzed, so as to more accurately perform root cause mining and / or situation judgment analysis. In this way, when the network event is analyzed and the root cause is positioned, the data analyzed by the disclosure has higher completeness, the key reason and potential risk of the event can be more accurately identified, and thus the accuracy and efficiency of the network event root cause positioning and / or situation judgment analysis are improved.
[0064] In step S102, the specific steps of obtaining the second event information can include steps S1021-S1023:
[0065] S1021, determine the variable definition information corresponding to the first event information.
[0066] In this step, a first task can be sent to other systems or interfaces based on the first event, and the first task is used to request the variable definition information associated with the first event from the other systems or interfaces. The variable definition information at least includes the related information of the required non-real-time information.
[0067] S1022, based on the variable definition information, obtain the non-real-time information through a non-real-time data interface.
[0068] The other systems can send the required non-real-time information through the non-real-time data interface based on the variable definition information. Thus, the non-real-time information can be obtained through the non-real-time data interface.
[0069] S1023, associate the first event information with the non-real-time information, and obtain the second event information.
[0070] In this step, the non-real-time information and the association method of the first event information and the non-real-time information are different according to different application scenarios. The association method can include but is not limited to the following embodiment 1 and / or embodiment 2.
[0071] In an illustrative embodiment 1, the non-real-time information can be associated with the first event information as a configurable attribute of the first event information to obtain the second event information.
[0072] That is, when the first event cause needs to be mined (for example, root cause mining), in addition to the first event information already possessed, the non-real-time information can also be used as a supplement to the first event information. The non-real-time information plays a role in further supplementing the key information required for in-depth mining analysis. For example, for network elements located in the same loop, belonging to the same group of active-standby protection units, and having the same topology logical relationship in the NFV network, their same attribute information (for example, counting the frequency of occurrence of a specific alarm in the adjacent historical time window) can be extracted as a grouping reference for further mining analysis. The disclosure extracts and analyzes the information required for event analysis in a variable and flexible manner, unifies and simplifies the configuration, and provides higher analysis flexibility.
[0073] In another illustrative embodiment 2, the non-real-time information can be configured as supplemental alarm information of the first event information to obtain the second event information. That is, when the events or alarms derived from the first event need to be fully analyzed (for example, situation judgment analysis is performed), the non-real-time information can be used as supplemental alarm information. Specifically, in scenarios where important analysis conclusions of related events, hidden danger troubleshooting work order suggestion information, fault handling measure recommendation information, etc. are needed, when a certain type of alarm is detected, it is helpful to describe the alarm event to determine whether there is a specific log or performance change in the adjacent specific time window, and then supplemental alarm information can be generated. The supplemental alarm information at least includes the occurrence time of the supplemental alarm and the required key attribute information.
[0074] The supplemental alarm information includes but is not limited to one of the following: a single independent alarm information, a sub-alarm information corresponding to an original root alarm, and a sub-alarm information corresponding to a new root alarm.
[0075] In an illustrative embodiment, when the non-real-time information is configured as a single independent alarm information, it means that the root alarm of the abnormal non-real-time information is different from the root alarm triggering the first event, and the non-real-time information can trigger an event. This indicates that the non-real-time information is a root alarm, and a new event can be generated based on the non-real-time information. Optionally, when the non-real-time information is an alarm, it can be determined whether the alarm is a root alarm according to a list of “original root alarm in the rule and specific event in the adjacent time window”.
[0076] In another illustrative embodiment, when the non-real-time information is configured as the sub-alarm information corresponding to the root alarm of the original root alarm, it means that the abnormality of the non-real-time information is derived from the root alarm of the first event, and the root alarm of the non-real-time information is the same as the root alarm of the first event. At this time, the non-real-time information can be used as the supplementary information derived from the first event. When the first event is analyzed and processed subsequently, the non-real-time information needs to be considered comprehensively.
[0077] In another illustrative embodiment, when the non-real-time information is configured as the sub-alarm information corresponding to the root alarm of the new root alarm, it means that the abnormality of the non-real-time information is derived from the new root alarm. At this time, the non-real-time information can be used as the supplementary information derived from the new root alarm. When the event corresponding to the new root alarm is analyzed and processed subsequently, the non-real-time information needs to be considered comprehensively.
[0078] It should be understood that the above is only one illustrative embodiment provided by the present disclosure, and in actual application, the above non-real-time information association processing method (i.e., the above-mentioned embodiment 1 and embodiment 2) can also be used in combination. That is, according to actual needs, after obtaining the non-real-time information, part of the non-real-time information can be used as the configurable attribute of the first event information, and other non-real-time information can be configured as the supplementary alarm information of the first event information.
[0079] Optionally, the event flow list can be set or updated based on the second event information, so as to facilitate searching and reduce the number of interactions with other systems. The event flow list is used to maintain the first event information and / or the second event information. The event flow list includes at least one event information; any one of the event information includes at least one of the following: alarm type, alarm time, alarm content, alarm attribute, and identification information.
[0080] Further, the event flow list can also be displayed to the user. Thus, the event is provided with intuitive flow presentation, rule configuration, and flexible labeling interaction logic, so that the overall implementation scheme is coherent and smooth. The user can conveniently understand and operate the system, view and label event details, and improve the convenience of operation and user experience.
[0081] For example, when the events are all triggered by alarms, the specific style of the event flow list can refer to Figure 2 . Figure 2 is a schematic diagram of the event flow list of the embodiment of the present disclosure, as Figure 2As shown, the event flow list can include: time, alarm text, alarm attribute, and situation awareness identifier (to be described later). At this time, the alarm text can be understood as the event name. For example, the event can be triggered by an alarm, and the alarm is the root alarm, at this time, the event name and the root alarm name are the same. The alarm attribute can be understood as the configurable attribute of the above-mentioned event information, from Figure 2 As can be known from the above, any event can be described by at least one alarm attribute. Figure 2 When the leftmost symbol is symbol 002 or symbol 003, it can be considered that the event includes sub-alarm, symbol 003 is the display state of the sub-alarm of the event, and symbol 002 is the folded state of the sub-alarm of the event. When the leftmost symbol is empty, it means that the event does not include sub-alarm. When the leftmost symbol is symbol 001, it is the event of situation judgment and early warning, which has not actually occurred. When the root alarm row exists symbol 201, it can be considered that the event exists root cause positioning, and when symbol 203 exists, it can be considered that the event exists situation judgment point. The specific determination method of symbols 201, 202 and 203 will be described later.
[0082] It should be understood that the above-mentioned symbols and names are examples for easy understanding, and the specific settings can be determined by actual conditions.
[0083] In step S103, the specific grouping process includes:
[0084] Display the grouping rule; wherein the grouping rule includes: sequence set grouping rule and division frequent item set rule; or sequence set grouping rule.
[0085] In this step, the sequence set grouping rule is used for preliminary grouping of each event, for example, it can be used to limit the frequent events mined when carrying out frequent item mining in each "frequent item set grouping" to appear in the network element related to business logic (such as belonging to the same province, belonging to the same loop, belonging to the same network element). Specifically, the sequence set grouping rule can be understood as a rule for dividing events of the same network element type.
[0086] The division frequent item set rule is used to divide the events related to the network element set facing different application scenarios and providing different functions into respective sets, so as to delimit the event category range in each set to carry out the mining algorithm of the subsequent step. The rule obtained in any "sequence set grouping" in the same "frequent item set grouping" can be applied to other "sequence set groupings".
[0087] In addition, the present disclosure provides a grouping rule configuration page, which intuitively presents each rule and its attribute condition in the form of bubble cloud chart, and feeds back the event statistics result of the configured rule to facilitate the reference for rule adjustment. Figure 3is a schematic diagram illustrating a grouping rule configuration interface of an embodiment of the present disclosure, and specific reference can be made to Figure 3 , wherein the grouping rule 1, the grouping rule 2, and the grouping rule 3 are configuration pages of the grouping rules of the frequent item sets and the configuration page of the sequence set grouping rule in the preset time window length. The grouping rule 1 and the grouping rule 2 show the configuration pages of the grouping rules of the frequent item sets, and the grouping rule 3 shows the configuration page of the sequence set grouping rule. In the grouping rule 1, the grouping is mainly performed by using the network element type, the province, the large area (for example, the East China area), and the network element type. In the 301, the network element type is in an ‘or’ relationship, and in the 302, the province and the large area are in an ‘and’ relationship, that is, the device network element type of the events grouped according to the grouping conditions in the 301 and the 302 is EOR or TOR or the aggregation switch, and the location of the network element satisfies the grouping conditions of the province and the large area in the 302. The grouping rule 2 shows another grouping rule of the frequent item sets. That is, the configurable attribute (that is, the aforementioned configurable attribute) is screened while the network element type is screened. In the grouping rule 3, the network element type and the network element name can be used for grouping.
[0088] It should be understood that the above is only one embodiment for the convenience of understanding, and in actual application, the present disclosure does not specifically limit the style and type of the grouping rule configuration interface. That is, the grouping rule configuration interface can only display the configuration page of the grouping rule of the frequent item set, or can only display the configuration page of the sequence set grouping rule, and no limitation is made to this.
[0089] For any created grouping rule, the event information set can be obtained based on the historical event stream statistics data of the grouping rule. Optionally, the “invalid event” marking can be performed, so that the event types that can be ignored by the subsequent frequent item mining module are filtered, and the remaining events in the list are “valid events” within the range of the grouping rule. The invalid events can be set by themselves or obtained according to historical analysis, and the specific analysis method will be described below.
[0090] After the second event information is grouped, the event information set can be subjected to root cause positioning and / or situation judgment analysis based on the principle of frequent item mining. The following will be specifically described in combination with Figure 4 , Figure 4 is a flowchart of one frequent item mining of an embodiment of the present disclosure. As Figure 4 indicated, the analysis process can specifically include S1041-S1046.
[0091] S1041, sequence feature data in the event information set is obtained.
[0092] In this step, first, the event (for example, valid event) needs to be data cleaned and standardized, and then the feature extraction is performed according to the fixed preset rule, to ensure the consistency of the description data format of each event obtained.
[0093] The present disclosure does not specifically limit the type of feature extraction. Optionally, the features can be extracted from the real-time alarm information and / or non-real-time alarm information, and the feature information is arranged in a fixed order. According to the different types of information, the extracted features are also different. Figure 3
[0094] For example, when the information type for feature extraction is alarm, at least one of the following is mainly extracted, including but not limited to: network element type, alarm title (i.e. alarm name), configurable attribute and value information. The information type can be a nominal value information (such as topology attribute), or a numerical value information (such as frequency and other statistical information).
[0095] For example, when the information type for feature extraction is performance indicator, at least one of the following is mainly extracted, including but not limited to: network element type, indicator and value, configurable attribute and value information; the indicator is, for example, usage rate, network traffic, success rate, latency, and key performance indicator such as proportion.
[0096] For example, for log entries, at least one of the following is mainly extracted, including but not limited to: network element type, log content keyword information. The log content keyword covers features such as error code and log message keyword.
[0097] For example, when the information type for feature extraction is work order (such as fault work order, problem work order, complaint work order, etc.), at least one of the following is mainly extracted, including but not limited to: content keyword (such as complaint content), configurable attribute and value information.
[0098] After that, each feature information arranged in a fixed order is discretized and encoded to obtain the encoded sequence feature data sorted by the timestamp of the event occurrence. Next, the time window length of the sequence feature data belonging to different event information sets can be configured in the preset relative historical data interval range, and a large number of sequence features are obtained by sliding and intercepting through the preset sliding time window interval. Next, the support degree can be used to filter the sequence feature data to obtain a list of frequent items, which will be described in detail later.
[0099] The preset relative historical data interval range and the preset sliding time window interval can be preset with default values in the system initialization phase, for example Figure 3 In the above, the time window length can be used to filter events. In addition, the above grouping rules can also be configured, and if not configured, the system default value is used.
[0100] For example, you can refer to Figure 5 , Figure 5 This is a flowchart illustrating an embodiment of the event information collection processing disclosed herein, such as... Figure 5 As shown, after inputting the event information set, data cleaning and feature extraction are performed. The extracted features are then discretized and sequence encoded to obtain event sequence data sorted by timestamps. Here, P001, P002, and P003 are the sequence feature data, and 'time' represents the time the event occurred. Next, the sequence feature data is input to the frequent pattern mining module (a manifestation of the aforementioned frequent item mining principle), which outputs a first list of frequent itemsets, along with the itemset support and time window length information for each itemset. The methods for determining the specific frequent itemset list and other information will be detailed in steps S1042 and S1043.
[0101] Optionally, the frequent item mining principle can employ at least one of the publicly available algorithms such as Apriori and FP-Growth to process the sequence feature data.
[0102] S1042, Based on the principle of frequent item mining, the sequence feature data is subjected to frequent item mining and sorted to obtain the first frequent itemset list corresponding to the event information set.
[0103] The process of obtaining the first frequent itemset list can be described in detail as follows: Step 1 (mining) and Step 2 (sorting).
[0104] Step 1: Based on the principle of frequent item mining, determine the third frequent itemset list by using the support conditions corresponding to the event information set and the sequence feature data.
[0105] In this step, the support conditions corresponding to the event information set and the sequence feature data can be used to obtain a third list of frequent itemsets sorted from high to low frequency.
[0106] The support condition is used to filter events that occur more frequently than a preset threshold. For example, the support condition can be an itemset with a support greater than or equal to 0.2. Since the itemset {A, B} has a support of 0.3, which is greater than 0.2, the third frequent itemset list can include the itemset {A, B}.
[0107] The support criteria can be preset with default values during system initialization, or configured in the grouping rules. If no configuration is made, the system default values will be used, and the selection of whether the filtering criteria for each subset can be automatically adjusted by the system can be configured; in addition, during the automatic system operation phase, the system can automatically adjust the output based on the number of frequent itemsets to ensure that at least one valid frequent itemset is output.
[0108] Step 2, sorting the frequent item sets based on the first occurrence time of each frequent item set in the third frequent item set list, to obtain the first frequent item set list.
[0109] In this step, the first frequent item set list is obtained by sorting the third frequent item set list according to the occurrence time of each item in each frequent item set. For example, in the item set {A, B, C} and the item set {A, B, D}, the first item and the second item have the same occurrence time, and the occurrence time of event C is earlier than that of event D, so the item set {A, B, C} is earlier than the item set {A, B, D}. For another example, the item set {A, B, C} and the item set {A, B} are compared, although the occurrence time of the first two events is the same, the occurrence time of the last item of the item set {A, B} is earlier than that of the item set {A, B, C}, so the item set {A, B} is earlier than the item set {A, B, C}.
[0110] In the first frequent item set list, at least one of the following information can be recorded, including but not limited to: support information of each frequent item set, time window length information, and event number.
[0111] For easy understanding, please refer to Figure 6 , Figure 6 is a flow chart for obtaining frequent item sets according to an embodiment of the present disclosure, as Figure 6 shown, after obtaining the sequence set data (i.e. the sequence feature data), the sequence set data is sorted by time. Next, the sequence set data can be sorted again by support condition to obtain the frequent item set list (i.e. the third frequent item set list), and finally, the frequent item set list with time sequence information (i.e. the first frequent item set list) is obtained by using the first occurrence time of each sequence feature data.
[0112] S1043, based on the number of events in each frequent item set and the support of the item set, the statistical data of each event in the first frequent item set list is counted.
[0113] In this step, the support of the item set can be understood as the frequency of the occurrence of each event in the item set.
[0114] The statistical data can be understood as the data related to the item set, including but not limited to at least one of the following: the first count of the occurrence of each event in each subset, the second count of the non-occurrence of the event in each subset, the number of subsets, and the number of subsets with the same first item.
[0115] When the statistical data includes the first count of the occurrence of each event in each subset and / or the second count of the non-occurrence of the event in each subset, the frequency of the occurrence of each event in each item set can be counted, so as to facilitate the removal of events that are not related to the mining target or have weak correlation in step S1044.
[0116] When the statistics include the first same subset quantity and the subset quantity, it is convenient to divide the relationship of each subset in S1043b.
[0117] Further, the statistics further include at least one of the following: the occurrence count of the event in the second set, the support accumulation value corresponding to the second set corresponding to the event; wherein the second set is other events except the first set.
[0118] The step specifically includes steps S1043a-S1043b:
[0119] S1043a, for any one of the frequent item sets in the first frequent item set list, judging whether the frequent item set is a subset of the judged item set.
[0120] In this step, each item set can be judged and marked in turn whether it is a subset of the previous existing item set according to the order of the number of events in each item set from high to low and the support of the item set from high to low. For example, according to the number of events included in the item set, the item set {A, B, C} is before the item set {A, B}, wherein the events in the item set {A, B, C} and the item set {A, B} are sorted according to their respective supports. The item set {A, B} is a subset of the item set {A, B, C}. If there is a similar item set {A, B} which is a subset of the item set {A, B, C}, record the subset and accumulate the first count and the second count in the statistics table corresponding to the existing item set.
[0121] For example, please refer to Figure 6 For example, please refer to Figure 6In the following table, the first two item sets {xxx1, xxx2}, {xxx1, xxx2, xxx3} are taken as examples. {xxx1, xxx2} is a subset of {xxx1, xxx2, xxx3}, and {xxx1, xxx2, xxx3} is a subset of the item set {xxx1, xxx2, xxx3, xxx4}. That is, both {xxx1, xxx2} and {xxx1, xxx2, xxx3} are subsets of an item set. xxx1 appears in both subsets, and therefore, the appearance mark of {xxx1, xxx2} is 1, and the appearance mark of {xxx1, xxx2, xxx3} is also 1, and the total count of event appearance (i.e., the first count) is 2, which is shown in the first column of the list. The total count of event non-appearance (i.e., the second count) is 0. xxx3 does not appear in the subset {xxx1, xxx2}, and therefore, the subset appearance mark of xxx3 in the subset {xxx1, xxx2} is 0, and the appearance mark of {xxx1, xxx2, xxx3} is 1, and the total count is 1. The non-appearance mark is 1. In this way, the number of appearances and the number of non-appearances of each subset can be obtained. The number of same first item subsets can be obtained according to the number of appearances of each subset. The number of other set appearances can be understood as follows: xxx1 appears in a set that includes event xxx1, but {xxx1, xxx2} is not a subset of the set. For example, the item set {xxx1, xxx4, xxx5} does not include {xxx1, xxx2}, but includes event xxx1.
[0122] S1043b, when the frequent item set is a subset of the determined item set, for any event in the frequent item set, statistics of the event and each subset are counted.
[0123] In this step, in order to solve the problem that the sequence time span in the algorithm mining result is limited due to the limited length of the time window in the frequent item mining process. The present disclosure introduces a virtual subset. If the following conditions are met between the frequent item sets: there is a unique same and continuous event sequence in the two item sets, the last item of the event sequence is the last item of the virtual subset, and the first item of the event sequence is the first item of the item set to which the virtual subset belongs.
[0124] For example, refer to Figure 7 , Figure 7 is a schematic diagram illustrating an item set relationship of an embodiment of the present disclosure, in which Figure 7In the figure, the item set {2222, 3333, 4444} includes the item set {2222, 3333}, thus the item set {2222, 3333} is a subset of the item set {2222, 3333, 4444}, and the subset relationship of A to B is represented by a solid line, and the reverse direction of the arrow represents the subset. The item set {1111, 2222, 3333, 4444} and the item set {2222, 3333, 4444, 5555} contain a unique and same continuous event sequence {2222, 3333, 4444}, and the last item of the sequence {2222, 3333, 4444} is the last item of the item set {1111, 2222, 3333, 4444}, and the first item of the sequence {2222, 3333, 4444} is the first item of the sequence {2222, 3333, 4444, 5555}. Thus, the item set {1111, 2222, 3333, 4444} is a virtual subset of the item set {2222, 3333, 4444, 5555}, and the subset relationship of A to B is represented by a dashed line, and the reverse direction of the arrow represents the virtual subset.
[0125] Thus, based on the subset and virtual subset relationships between the item sets, the statistical data between the events and the subsets can be counted.
[0126] In S1044, the first list of frequent item sets is simplified based on the statistical data, and a second list of frequent item sets is obtained.
[0127] The specific steps of the simplification process can include: for any event, when the statistical data satisfies a first condition, the event is discarded. Otherwise, the event is an effective event and is retained. The simplification process helps to remove events that are not related to the mining target or have weak relevance, thereby reducing the bias and noise in the results. Furthermore, through simplification, events that have a significant impact on the mining results can be more accurately identified, and the accuracy of the entire mining process is improved.
[0128] The first condition includes at least one of the following: the first count is greater than a preset multiple. Depending on the relationship between the item sets, the first count is different.
[0129] In an illustrative embodiment, when the item set has no subset, virtual subset, or associated item set, the first condition can be that the first count in the item set is higher than a first preset multiple, and the first preset multiple is related to the number of other item sets. This can mean that the occurrence of the event in the current item set is accidental, or the association between it and other items in the current item set is not strong. Therefore, this event can be considered irrelevant in the current item set and can be discarded as an irrelevant event.
[0130] In another illustrative embodiment, the first condition can be that the number of item sets discarded for the event is higher than a second preset multiple when the item set exists a subset, a virtual subset or its associated item set. That is, when more item sets consider the event as an irrelevant event, the event can be discarded.
[0131] For a better understanding, reference can be made to Figure 8 , Figure 8 is a schematic diagram illustrating the simplified processing of an embodiment of the present disclosure. As shown in Figure 8 , all item sets include the event {1111}, after simplification, the event {1111} is discarded, and the simplified item set list is obtained as shown on the right side of Figure 8 .
[0132] If an event is discarded in all the item sets, the event is classified as an "invalid event", otherwise, it is the aforementioned valid event. If all the events in an item set are discarded, the item set is removed from the corresponding frequent item set list.
[0133] S1045, determining a root cause event vote count and / or a situation judgment vote count of the second frequent item set list, to obtain a vote count result.
[0134] In this step, the events in the second frequent item set list can be counted based on a preset first rule to obtain the vote count result. The vote count result includes but is not limited to at least one of the following: root cause event vote count, situation judgment vote count.
[0135] The first rule includes: a root cause event voting rule and / or a situation judgment voting rule; and / or, obtaining a result of counting votes of the events in the second frequent item set list by a user.
[0136] In an illustrative embodiment, when the first rule is the root cause event voting rule and / or the situation judgment voting rule, a root cause event vote counter and a situation judgment vote counter can be maintained for each event in each item set, and the initial values of both counters are 0, which can be adjusted according to the following steps:
[0137] First, according to the number of subsets (including subsets with the same first item or non-identical first item, excluding virtual subsets) and the number of events in each item set in the simplified frequent item set list, the event list in each item set is traversed in order, and for the events located in the front of the preset percentage (for example, the first 50%) in the sorted list of all events in the item set, the subset occurrence count is increased according to the root cause event vote count of the item set.
[0138] Next, if there are multiple directly connected item sets for a certain item set, it can be considered that the higher the number of events that appear in each directly connected item set, the more likely it is the root cause event. Among them, the directly connected item set can be understood as the item set closest to a subset of a certain frequent item set. For example, item set A is {1, 2, 3, 4, 5, 6}, item set B is {1, 2, 4, 6}, and item set C is {1, 3, 5, 6}. Item sets B and C are subsets of item set A, and item sets B and C are only different from item set A by two events. Therefore, item sets B and C are directly connected item sets of item set A, and item set A is the directly connected item set of item sets B and C.
[0139] Next, each event in each directly connected item set is traversed in turn, and the sum of the support degrees of other directly connected item sets that do not contain the event is used as the weight, and the voting count of the event as the root cause event of the item set is increased.
[0140] Finally, the alarm level of each event in each item set is automatically increased by the trend judgment point voting count, and the voting result is obtained, where the voting result and / or the mining result is the positioning and judgment condition. The positioning and judgment condition can be understood as the judgment rule of the root cause event.
[0141] In the system running state, based on the positioning and judgment condition, in one embodiment, when all events before the first event in the event sequence of a certain item set in the time window where the item set is located affect the judgment point event, the positioning and judgment condition is met, and the event is considered as the root cause of the item set. For example, if item set A includes events {1, 2, 3, 4, 5, 6}, item set B includes events {1, 2, 4, 6}, item set C includes events {1, 3, 5, 6}, item set B2 includes events {1, 2, 6}, and item set C2 includes events {1, 3, 6}. When events {1, 2} occur, according to the rule, event {1, 2} is judged as the root cause of event set {1, 2, 4, 6}.
[0142] For example, Figure 9 is a schematic diagram of a root cause event detail view of an embodiment of the present disclosure, please refer to Figure 9 The event stream list is monitored. When the events contained in each item set in the frequent item set appear and meet the positioning and judgment condition, the related events are associated with a certain frequent item set, and the "situation awareness identifier" item in all events related in the event stream can be used with a specific symbol, such as Figure 3The middle grouping rule 1 and the grouping rule 3. Thus, the event correlation root cause positioning and the event impact judgment detailed information are presented in the intuitive form in the event flow list.
[0143] The events in the event impact judgment area can be state identified according to whether they have occurred, and the current situation judgment point (when it has not actually occurred) can be presented in the form of a virtual event in the event flow list. Figure 2 The top is presented.
[0144] The disclosure can also obtain the result of the user voting count processing on the events in the second frequent item set list.
[0145] That is, the system can increase or decrease the "event correlation identification", "root cause event voting count" or "situation judgment point voting count" of an event in an item set according to the level of different expert users or the credibility of the expert user determined based on the historical labeling data of the expert user. When the event correlation identification counter value decreases to 0, the event is removed from the corresponding item set.
[0146] When a certain item set has a corresponding item set or a virtual corresponding item set, if all events of the item set in a certain positioning and judgment instance appear, the item set associated with the instance is moved to the corresponding item set state. If there are multiple corresponding item sets or virtual subsets of the item set in the process, the target item set order is determined according to the support degree from high to low, and if the newly added events in the sequence of the instance match other item sets, they are further moved to other item sets. Until the list of corresponding item sets or virtual corresponding item sets is traversed and the item set associated with the instance has no corresponding item set or virtual corresponding item set, the instance recognition process is completed.
[0147] In summary, the disclosure uses root cause event voting counters, situation judgment point voting counters, and event order and support conditions in frequent item sets to automatically identify root cause points and situation judgment points and filter irrelevant events. Through the intelligent root cause point and situation judgment point mining method, the system can more accurately identify key events and potential risks, and improve the accuracy and efficiency of network event fault root cause positioning and situation judgment.
[0148] S1046, determining a root cause event and / or a situation judgment result based on the voting count result.
[0149] Finally, the root cause event and / or the situation judgment result can be determined based on the voting count result. Further, the root cause event and / or the situation judgment result can be displayed.
[0150] Wherein, after determining the root cause event and / or situation judgment result, the expert can also be allowed to mark. The present disclosure allows the expert to mark the alarm, log and other events in the current state as the root cause event, or mark the alarm, performance degradation and other events as the situation judgment point. The corresponding root cause and situation judgment point mark can also be cancelled. Thus, the operation and maintenance personnel can combine experience to freely combine different data sources, edit / call the required script function, and flexibly customize the analysis task triggered by each type of event. Different sub-rules can be set for different events, different data and professionals, which is beneficial to solidify expert operation and maintenance experience and iterative optimization.
[0151] For example, refer to Figure 9 The detail view has a normal mode and a marking mode. The normal mode only presents the event current state, event root cause positioning, and event impact judgment event flow list. The marking mode can be opened to different levels of expert users with marking permission. An indication box indicating whether each event comes from the mining mode (i.e. the aforementioned frequent item mining principle) is marked, and an expert marking indication box is provided. The default value of the check state in the expert marking indication box of each positioning and judgment instance under each frequent item set is the indication box state of the mining mode. When the expert modifies and saves the marking state in the expert marking indication box of a positioning and judgment instance, a marking record is generated for the instance, and all events involved in the instance are archived in the historical knowledge base. When the same expert opens the same positioning and judgment instance, the check state in the expert marking indication box is preferentially queried for the historical marking results of the expert. If there is no historical marking, the default value is presented.
[0152] In addition, the expert can cancel the check of the event in the event current state, or further cancel the check of the item for which the expert cancels the root cause and situation judgment point mark, which indicates that the expert determines that the event is irrelevant to the positioning and judgment instance.
[0153] Optionally, the expert can also be allowed to configure (click the configuration button) an existing event outside the item set as a root cause event, or configure a different event type outside the item set as an event impact judgment point. If so, a copy of the item set is created in the list of frequent item sets corresponding to the original mining result, and the user-configured event is added to the copy of the item set. The corresponding “root cause event voting count” or “situation judgment point voting count” is assigned a value. The copy of the item set is not included in the subset statistics and the statistics of the corresponding item set in the new round of item set mining and updating process.
[0154] The above. The information processing method provided by the present disclosure can be combined according to actual conditions, and the present disclosure does not specifically limit it. Specifically, the information processing method steps provided by the present disclosure can be referred toFigure 10 , Figure 10 is a flow chart illustrating another information processing method according to an embodiment of the present disclosure, as shown in Figure 10 After real-time data and non-real-time data are calculated respectively using a mining algorithm (i.e., through frequent mining model) and a rule, and after intelligent operation and expert experience configuration, root cause and / or situation judgment are performed after feedback, so that root cause mining and / or situation judgment are more convenient and fast.
[0155] The present disclosure also provides an information processing device. Figure 11 is a block diagram illustrating an information processing device according to an embodiment of the present disclosure, as shown in Figure 11 The information processing device 1100 includes:
[0156] An information analysis module 1101 is configured to perform event analysis on a network real-time information stream to obtain first event information.
[0157] An information acquisition module 1102 is configured to obtain second event information by associating non-real-time information related to the first event information.
[0158] An event grouping module 1103 is configured to perform event grouping on the second event information to obtain an event information set.
[0159] A judgment analysis module 1104 is configured to perform root cause positioning and / or situation judgment analysis on the event information set based on a frequent item mining principle.
[0160] In an exemplary embodiment, the information processing device 1100 is further configured to obtain second event information by associating non-real-time information related to the first event information, including: determining variable definition information corresponding to the first event information; obtaining the non-real-time information through a non-real-time data interface based on the variable definition information; and performing association processing on the first event information and the non-real-time information to obtain the second event information.
[0161] In an exemplary embodiment, the information processing device 1100 is further configured to perform association processing on the first event information and the non-real-time information to obtain the second event information, including: associating the non-real-time information as a configurable attribute of the first event information to obtain the second event information.
[0162] and / or,
[0163] configuring the non-real-time information as supplementary alarm information of the first event information to obtain the second event information; wherein the supplementary alarm information includes: single independent alarm information, sub-alarm information corresponding to the original root alarm, and sub-alarm information corresponding to the new root alarm.
[0164] In an example embodiment, the information processing apparatus 1100 is further configured to update an event list based on the second event information; display the event list; wherein the event list is used to maintain the first event information and / or the second event information; wherein the event list comprises at least one event information; and wherein any one of the event information comprises at least one of an alarm type, an alarm time, an alarm content, an alarm attribute, and identification information.
[0165] In an example embodiment, the information processing apparatus 1100 is further configured to group the second event information into a set of event information based on a preconfigured grouping rule; and wherein the grouping rule is configured based on each attribute dimension of root alarm information.
[0166] In an example embodiment, the information processing apparatus 1100 is further configured to display the grouping rule; and wherein the grouping rule comprises a sequence set grouping rule and a division frequent item set rule; or a sequence set grouping rule.
[0167] In an example embodiment, the information processing apparatus 1100 is further configured to perform root cause positioning and / or situation judgment analysis on the set of event information based on a frequent item mining principle, comprising: obtaining sequence feature data in the set of event information; mining and sorting the sequence feature data based on the frequent item mining principle to obtain a first frequent item set list corresponding to the set of event information; based on the number of events in each frequent item set and the support degree of the item set, counting statistical data of each event in the first frequent item set list; simplifying the first frequent item set list based on the statistical data to obtain a second frequent item set list; determining root cause event voting counts and / or situation judgment voting counts of the second frequent item set list to obtain voting count results; and determining root cause events and / or situation judgment results based on the voting count results.
[0168] In an example embodiment, the information processing apparatus 1100 is further configured to mine and sort the sequence feature data based on the frequent item mining principle to obtain a first frequent item set list corresponding to the set of event information, comprising: determining a third frequent item set list based on the support degree condition corresponding to the set of event information and the sequence feature data using the frequent item mining principle; and sorting the frequent item sets in the third frequent item set list based on the first occurrence time of each frequent item set to obtain the first frequent item set list.
[0169] In an example embodiment, the information processing device 1100 is further configured to count statistics of each event in the first frequent item set list based on the number of events in each frequent item set and the support of the item set, including: for any one frequent item set in the first frequent item set list, determining whether the frequent item set is a subset of the judged item set; when the frequent item set is a subset of the judged item set, counting statistics between each event in the frequent item set and each subset; wherein the statistics include at least one of: a first count of the event appearing in each subset, a second count of the event not appearing in each subset, the number of subsets, and the number of first items in the same subset.
[0170] In an example embodiment, the information processing device 1100 is further configured to simplify the first frequent item set list based on the statistics to obtain a second frequent item set list, including: for any one event, when the statistics satisfy a first condition, discarding the event; wherein the first condition includes: the first count is greater than a first preset multiple, and the third count is greater than a second preset multiple; wherein the third count is related to the frequent item set in which the event is discarded.
[0171] In an example embodiment, the information processing device 1100 is further configured to determine the root cause event vote count and / or the situation judgment vote count of the second frequent item set list to obtain a vote count result, including: based on a preset first rule, counting votes for events in the second frequent item set list to obtain the vote count result, the first rule including: a root cause event voting rule and / or a situation judgment voting rule.
[0172] and / or,
[0173] Obtaining a result of counting votes for events in the second frequent item set list by a user.
[0174] In an example embodiment, the information processing device 1100 is further configured to the first rule further includes: a positioning judgment determination condition; wherein the positioning judgment determination condition is obtained based on the root cause event vote result and / or the situation judgment vote result.
[0175] In an example embodiment, the information processing device 1100 is further configured to display the root cause event and / or the situation judgment result.
[0176] Figure 12 A hardware block diagram of an electronic device is provided for the embodiments of the present disclosure. The electronic device 1200 according to the embodiments of the present disclosure at least includes a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the signal transmission method described in any of the above embodiments.
[0177] Figure 12 The illustrated electronic device 1200 specifically includes a central processing unit (CPU) 1201, a graphics processing unit (GPU) 1202, and a memory 1203. These units are interconnected via a bus 1204. The CPU 1201 and / or GPU 1202 can function as the aforementioned processor, and the memory 1203 can function as the aforementioned memory storing computer-readable instructions. Furthermore, the electronic device 1200 may also include a communication unit 1205, a storage unit 1206, an output unit 1207, an input unit 1208, and an external device 1209, all of which are also connected to the bus 1204.
[0178] Figure 13 This is a schematic diagram of a computer-readable storage medium provided in an embodiment of this disclosure. (As shown...) Figure 13 As shown, a computer-readable storage medium 1300 according to an embodiment of the present disclosure stores computer-readable instructions 1301 thereon. When executed by a processor, the computer-readable instructions 1301 implement the signal transmission method described in any of the preceding embodiments of the present disclosure. The computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.
[0179] This disclosure further provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the information processing method described in any of the preceding embodiments of this disclosure.
[0180] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0181] The block diagrams of devices, apparatuses, equipment, systems referred to in the present disclosure are merely illustrative examples and are not intended to require or imply that the connection, arrangement, configuration must be as shown in the block diagrams. These devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner as will be appreciated by those skilled in the art. Words such as "include," "contain," "have," etc. are open-ended words that are to be interpreted to mean "including but not limited to," and are to be interpreted not to exclude other items. The words "or" and "and" as used herein are to be interpreted as the word "and / or," and are to be interpreted not to exclude other items. The word "such as" as used herein is to be interpreted as the phrase "such as but not limited to," and is to be interpreted not to exclude other items.
[0182] In addition, as used herein, the "or" as used in the context "at least one of A, B, or C" : means A or B or C or any combination thereof. Further, the phrase "example of" is not meant to be limiting in terms of the examples described. For example, the phrase "example of A, B, or C" means A or B or C, or any combination thereof.
[0183] It is also important to note that the systems and methods of the present disclosure can be embodied in a variety of forms including, but not limited to, a data processor, a computer program product, a computer, one or more tangible computer readable storage devices, one or more computer-implemented methods, information, or a bit of information. Additionally the systems and methods of the present disclosure can be embodied as one or more computers or computer implementations that include one or more processors or one or more memory modules.
[0184] Various changes, modifications and alterations in the teachings and techniques described herein can be made without departing from the teachings that are defined by the appended claims. Further, the scope of the claims of the present disclosure is not limited to the specific aspects described herein. Processes, machines, manufacture, compositions of matter, means, methods, or steps, presently existing or later to be developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufacture, compositions of matter, means, methods, or steps.
[0185] The above description of the disclosed aspects is meant to be illustrative of the application and not limiting. Various modifications of the aspects will be apparent to those with ordinary skill in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0186] The foregoing description has been presented for the purposes of illustration and description. Furthermore, the description is not intended to limit the embodiments of the disclosure to the forms disclosed herein. Although the various example aspects and embodiments have been described herein with regard to particular aspects and embodiments, those skilled in the art will recognize that certain modifications, changes, substitutions, additions and sub-combinations can be made without departing from the spirit of the disclosure.
Claims
1. An information processing method, characterized in that, The method includes: Perform event analysis on the real-time network information stream to obtain the first event information; Obtain non-real-time information associated with the first event information to obtain second event information; the second event information includes at least: the first event information and non-real-time information; the non-real-time information is determined based on the variable definition information corresponding to the first event information; the non-real-time information is obtained based on an external network system or a non-real-time data interface. The second event information is grouped into event groups to obtain an event information set; Based on the principle of frequent item mining, the event information set is used to perform root cause localization and / or situational analysis; the principle of frequent item mining is used to obtain the degree of correlation between various information.
2. The method according to claim 1, characterized in that, The step of obtaining the non-real-time information associated with the first event information to obtain the second event information includes: Determine the variable definition information corresponding to the first event information; Based on the variable definition information, the non-real-time information is obtained through a non-real-time data interface; The first event information is correlated with the non-real-time information to obtain the second event information.
3. The method according to claim 2, characterized in that, The step of associating the first event information with the non-real-time information to obtain the second event information includes: The non-real-time information is used as a configurable attribute of the first event information for information association to obtain the second event information; And / or, The non-real-time information is configured as supplementary alarm information to the first event information to obtain the second event information; The supplementary alarm information includes: a single independent alarm message, sub-alarm information corresponding to the original root alarm, and sub-alarm information corresponding to the new root alarm.
4. The method according to claim 1, characterized in that, The method further includes at least one of the following: Update the event log list based on the second event information; Display the event log list; The event log list is used to maintain the first event information and / or the second event information; The event log list includes at least one event information; any one of the event information includes at least one of the following: alarm type, alarm time, alarm content, alarm attribute, and identification information.
5. The method according to claim 1, characterized in that, The process of grouping the second event information to obtain an event information set includes: Based on pre-configured grouping rules, the second event information is grouped to obtain the event information set; The grouping rules are configured based on the attribute dimensions of the root alarm information.
6. The method according to claim 5, characterized in that, The method further includes: Display the grouping rules; The grouping rules include: sequence set grouping rules and frequent itemset partitioning rules; or, sequence set grouping rules.
7. The method according to any one of claims 1-6, characterized in that, The root cause localization and / or situational analysis of the event information set based on the frequent item mining principle includes: Obtain sequence feature data from the event information set; Based on the principle of frequent item mining, the sequence feature data is subjected to frequent item mining and sorted to obtain the first frequent itemset list corresponding to the event information set. Based on the number of events and the support of each frequent itemset, statistical data of each event in the first frequent itemset list are calculated. Based on the statistical data, the first frequent itemset list is simplified to obtain the second frequent itemset list; Determine the root cause event vote count and / or situation assessment vote count for the second frequent itemset list to obtain the vote count results; Based on the voting count results, the root cause events and / or situation assessment results are determined.
8. The method according to claim 7, characterized in that, The frequent item mining and sorting of the sequence feature data based on the principle of frequent item mining yields a first frequent itemset list corresponding to the event information set, including: Based on the principle of frequent item mining, the third frequent itemset list is determined by using the support conditions corresponding to the event information set and the sequence feature data. The first frequent itemset list is obtained by sorting the frequent itemsets based on the first occurrence time of each frequent itemset in the third frequent itemset list.
9. The method according to claim 7, characterized in that, The statistical data for each event in the first frequent itemset list, based on the number of events and itemset support in each frequent itemset, includes: For any frequent itemset in the first frequent itemset list, determine whether the frequent itemset is a subset of the already determined itemsets; When the frequent itemset is a subset of the already judged itemset, for any event in the frequent itemset, statistical data between the event and each subset is calculated. The statistical data includes at least one of the following: a first count of events occurring in each subset, a second count of events not occurring in each subset, the number of subsets, and the number of subsets with the same first item.
10. The method according to claim 7, characterized in that, The process of simplifying the first frequent itemset list based on the statistical data to obtain the second frequent itemset list includes: For any given event, if the statistical data satisfies the first condition, the event is discarded. The first condition includes: a first count is greater than a first preset multiple, and a third count is greater than a second preset multiple; wherein the third count is related to the frequent itemset of the event that is discarded.
11. The method according to claim 7, characterized in that, The determination of the root cause event voting count and / or situational assessment voting count for the second frequent itemset list, to obtain the voting count results, includes: Based on a preset first rule, events in the second frequent itemset list are voted and counted to obtain the voting count result. The first rule includes: root cause event voting rule and / or situational assessment voting rule. And / or, Obtain the results of user voting and counting of events in the second frequent itemset list.
12. The method according to claim 11, characterized in that, The first rule also includes: location analysis and judgment conditions; wherein, the location analysis and judgment conditions are obtained based on the root cause event voting results and / or situation analysis voting results.
13. The method according to claim 7, characterized in that, The method further includes: Displays the root cause events and / or situation assessment results.
14. An information processing device, characterized in that, The device includes: The information analysis module is used to perform event analysis on real-time network information streams to obtain first event information; An information acquisition module is used to obtain second event information by associating the first event information with non-real-time information; the second event information includes at least: the first event information and non-real-time information; the non-real-time information is determined based on the variable definition information corresponding to the first event information; the non-real-time information is obtained based on an external network system or a non-real-time data interface. The event grouping module is used to group the second event information to obtain a set of event information; The analysis module is used to perform root cause localization and / or situational analysis on the event information set based on the principle of frequent item mining; the principle of frequent item mining is used to obtain the degree of correlation between various pieces of information.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1-13.
16. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-13.
17. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-13.
Citation Information
Patent Citations
Information system performance three-dimensional monitoring method based on multi-source heterogeneous data fusion
CN109656793A
Alarm fusion system and method based on data center anomaly monitoring
CN110399278A