A Root Cause Location Method and System for Index Abnormality in Complex Processes

By constructing a DAG chart of complex business processes and calculating the conversion impact, combining large language model and graph retrieval technology, the root cause positioning problem of abnormal indicators in complex business processes is solved, and fast and accurate root cause analysis and diagnosis are achieved.

CN119850057BActive Publication Date: 2025-07-25BEIJING CITY UNIVERSITY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510315485.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-07-25
Estimated Expiration
2045-03-18

AI Technical Summary

Technical Problem

The prior art is difficult to quickly and accurately locate the root causes of indicator abnormalities in complex business processes, especially when the DAG graph structure is complex, the node types are diverse, and the granularity of indicators is inefficient and easy to misjudgment.

Method used

Build the initial process DAG, and use abstract processing of the aggregation nodes and shunt nodes to form a backbone process DAG, calculate the influence of the conversion process between nodes, and reversely traverse the DAG to determine the root cause positioning path, and build a root cause diagnostic question-and-answer system based on large language models and graph retrieval technology to realize cross-layer stage conversion analysis.

Benefits of technology

It improves the efficiency of root cause positioning of indicator abnormalities in complex business processes, improves the accuracy and efficiency of root cause analysis, and can quickly identify stage conversion items with a greater impact, reducing the dependence of manual judgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119850057B_ABST
    Figure CN119850057B_ABST
Patent Text Reader

Abstract

The present invention provides a root cause localization method and system for abnormal metrics facing complex processes. Aiming at problems such as numerous nodes in complex business processes, complex DAG graph structures, diverse operation types between nodes, inconsistent metric granularities of nodes, and great difficulty in root cause analysis, process DAG graphs with different abstraction levels are constructed from bottom to top. The influence degrees of operations such as transformation, shunt, and aggregation in each stage on abnormal metrics are calculated layer by layer from high to low according to the abstraction level. The influence degrees are comparable to each other, helping operation personnel quickly identify and locate the root cause path and individual stage transformation items with greater influence degrees. Among them, the conduction calculation of the influence degree is realized through the chain rule, so as to realize cross-layer stage transformation analysis. Further, based on the large language model and graph retrieval enhanced generation technology, a root cause diagnosis Q&A system is constructed in combination with abnormal record documents. The root cause diagnosis Q&A system further analyzes the reasons for abnormalities generated by stage transformation, improving the analysis efficiency of stage transformation abnormalities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of big data analysis, and in particular to a method and system for root cause location of abnormal indicators for complex processes. Background Art

[0002] Most traditional BI products display the year-on-year and month-on-month changes of indicators in a visual form, lacking the ability to diagnose and locate business problems. The analysis of business problems relies too much on manual judgment, resulting in relatively low efficiency and easy misjudgment. In recent years, with the development of large model technology, many BI manufacturers have successively launched ChatBI products based on large models, enabling operation personnel to carry out coherent data analysis and root cause location through multiple rounds of conversations. However, due to the limited reasoning ability of large models and the lack of scenario-based root cause location algorithms and contribution quantification indicators, many in-depth root cause analyses still need to be judged manually. Therefore, for various complex business processes of enterprises, when business indicators decline or change abnormally, how to quickly and accurately locate the root cause of the anomaly has become an urgent problem for many managers to solve.

[0003] The business processes of enterprises are usually represented by process DAG (Directed Acyclic Graph), where nodes represent certain stages or task units in the process, such as page reach, telemarketing call, quotation, transaction, etc. Complex business processes often involve numerous process nodes, complex DAG graph structures, diverse operation types between nodes (such as transformation, aggregation, splitting, etc.), and inconsistent indicator granularities for different nodes, making root cause analysis difficult. In recent years, technologies such as multi-agent, large language model, multi-modal, graph neural network, and association rule mining have been successively applied in the diagnosis and location of operation and maintenance faults. However, these methods do not consider factors such as process stages and conversion rates, and are difficult to apply to the root cause location scenarios of complex business processes. For example, patent (CN202110195548.6) completes root cause location by calculating the influence value and influence degree of the conversion in the initial stage and subsequent stages on the final indicator. This method is mainly applicable to business processes with fewer and relatively simple nodes and is difficult to be directly applied to complex business processes. Summary of the Invention

[0004] The present invention provides a method and system for root cause location of abnormal indicators for complex processes to solve the defect that the prior art is difficult to apply to the root cause location scenarios of complex business processes.

[0005] The present invention provides a method for root cause location of abnormal indicators for complex processes, including:

[0006] Construct an initial process DAG based on the current business process and establish the association between each node in the initial process DAG and its metrics; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal metrics are located and the business stages or task units before them;

[0007] Perform abstraction processing on the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the splitting node is greater than 1;

[0008] Based on the backbone process DAG, determine the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal metric;

[0009] Start traversing the initial process DAG in reverse from the node corresponding to the abnormal metric in the initial process DAG, and based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal metric, determine the root cause location path of the abnormal metric;

[0010] Record the abnormal manifestations of the abnormal metric and the root cause information determined manually to form an abnormal record document; use the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when the user conducts a root cause diagnosis query, receive the root cause diagnosis question and context information input by the user to the root cause diagnosis question answering system; the context information includes the root cause path and the relevant metric information of a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds the result back to the user, and determines the root cause of the abnormal stage transformation.

[0011] According to a root cause location method for abnormal metrics in a complex process provided by the present invention, performing abstraction processing on the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG includes: starting from the node with an in-degree of 0 in the initial process DAG and traversing forward. If the currently visited node is an aggregation node, call the aggregation processing step for the currently visited node and then continue traversing; if the currently visited node is a splitting node, call the splitting processing step for the currently visited node and then continue traversing; after the traversal is completed, obtain the backbone process DAG;

[0012] Among them, the aggregation processing steps for any aggregation node include: traversing backward the unvisited transformation branches of the aggregation node. If any transformation branch contains an aggregation node, call the aggregation processing steps for the aggregation node in that transformation branch to obtain the current process DAG, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; if none of the transformation branches contain an aggregation node, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from the transformation branch of any node to the node.

[0013] The splitting processing steps for any splitting node include: traversing forward the branches of the splitting node. If there is no splitting node in the branches of the splitting node, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG, and create a directed edge from the any splitting node to the virtual node corresponding to the aggregation node to obtain a new process DAG; otherwise, call the splitting processing steps for the splitting node in the branches of the splitting node to obtain the current process DAG, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from any node to the branches of the node.

[0014] According to a root cause location method for index anomalies in complex processes provided by the present invention, the method for determining the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the anomaly index based on the backbone process DAG includes:

[0015] Calculate the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the backbone process DAG on the anomaly index;

[0016] Traverse the backbone process DAG in the forward direction. If the currently visited node is a virtual node and there is no shunt node pointing to this node, then call the aggregation node drill-down step for the currently visited node and continue traversing. If the currently visited node is a shunt node in the initial process DAG and this node is connected to a virtual node by a directed edge, then call the shunt node drill-down step for the currently visited node and the virtual node it is connected to and continue traversing;

[0017] Among them, the aggregation node drill-down step for any virtual node includes: based on the node set of the aggregation node corresponding to this virtual node in the initial process DAG, construct each transformation branch of this aggregation node; take the indicators corresponding to the end nodes of each transformation branch of this aggregation node as key indicators, calculate the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the key indicators, and based on the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the key indicators, the influence degrees of the end nodes of each transformation branch corresponding to this key indicator on this virtual node, and the influence degree of this virtual node on the abnormal indicator, determine the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the abnormal indicator; if there are virtual nodes in each transformation branch, then call the aggregation node drill-down step for the virtual nodes in the corresponding transformation branches;

[0018] The shunt node drill-down step for any shunt node and the virtual node it is connected to includes: based on the node set of the aggregation node corresponding to this virtual node in the initial process DAG, construct each branch of this shunt node; take the indicators corresponding to the end nodes of each branch of this shunt node as key indicators, calculate the influence degrees of this shunt node, the transformation processes corresponding to the initial nodes of this shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key indicators, and based on the influence degrees of this shunt node, the transformation processes corresponding to the initial nodes of this shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key indicators, the influence degrees of the end nodes of each branch corresponding to this key indicator on this virtual node, and the influence degree of the transformation process corresponding to this shunt node and this virtual node on the abnormal indicator, determine the influence degrees of this shunt node, the transformation processes corresponding to the initial nodes of this shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the abnormal indicator; if there are virtual nodes in each branch, then call the shunt node drill-down step for the shunt node corresponding to the virtual node in the initial process DAG in the corresponding branch and this virtual node.

[0019] A root cause location method for index anomalies in complex processes provided by the present invention determines the influence degrees of the initial nodes and the transformation processes corresponding to adjacent nodes in each transformation branch on the anomaly index based on the influence degrees of the initial nodes and the transformation processes corresponding to adjacent nodes in each transformation branch on the key index, the influence degrees of the end nodes of each transformation branch corresponding to the key index on the virtual node, and the influence degree of the virtual node on the anomaly index, including:

[0020] For the initial node in any transformation branch, calculate the product of the influence degree of the initial node in this transformation branch on the key index of the same transformation branch, the influence degree of the end node of the transformation branch corresponding to the key index on the virtual node, and the influence degree of the virtual node on the anomaly index, as the influence degree of the initial node of this transformation branch on the anomaly index;

[0021] For the transformation process corresponding to adjacent nodes in any transformation branch, calculate the product of the influence degree of the transformation process corresponding to adjacent nodes in this transformation branch on the key index of the same transformation branch, the influence degree of the end node of the transformation branch corresponding to the key index on the virtual node, and the influence degree of the virtual node on the anomaly index, as the influence degree of the transformation process corresponding to adjacent nodes in this transformation branch on the anomaly index;

[0022] Among them, the influence degree of the end node of the transformation branch corresponding to any key index on the virtual node is the ratio of the difference in the index of this key index between this period and the previous period to the difference in the index associated with the aggregation node corresponding to the virtual node in the initial process DAG between this period and the previous period.

[0023] A root cause location method for index anomalies in complex processes provided by the present invention determines the influence degrees of the shunt node, the transformation processes corresponding to the shunt node and the initial nodes of each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the anomaly index based on the influence degrees of the shunt node, the transformation processes corresponding to the shunt node and the initial nodes of each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key index, the influence degrees of the end nodes of each branch corresponding to the key index on the virtual node, and the influence degree of the transformation process corresponding to the shunt node and the virtual node on the anomaly index, including:

[0024] For the shunt node, calculate the product of the influence degree of the shunt node on the key index in any branch, the influence degree of the end node of the branch corresponding to the key index on the virtual node, and the influence degree of the transformation process corresponding to the shunt node and the virtual node on the anomaly index, as the influence degree of the shunt node on the anomaly index;

[0025] For any transformation process corresponding to the shunt node and the initial nodes of each branch, as well as the transformation process corresponding to the adjacent nodes of each branch, calculate the product of the influence degree of this transformation process on the key indicators of the same branch, the influence degree of the branch end node corresponding to the key indicator on this virtual node, and the influence degree of the transformation process corresponding to this shunt node and this virtual node on the abnormal indicator, as the influence degree of this transformation process on the abnormal indicator.

[0026] According to a root cause location method for abnormal indicators in complex processes provided by the present invention, starting from the node corresponding to the abnormal indicator in the initial process DAG, traverse the initial process DAG in reverse, and based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes of the initial process DAG on the abnormal indicator, determine the root cause location path of the abnormal indicator, including:

[0027] Starting from the node corresponding to the abnormal indicator, traverse the initial process DAG in reverse. If the currently visited node is an aggregation node, when the change direction of the indicator value of the currently visited node is the same as that of the abnormal indicator, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to small, and use the greedy strategy to sequentially select the transformation branches with positive influence degrees greater than the preset threshold until the sum of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; when the change direction of the indicator value of the currently visited node is different from that of the abnormal indicator, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to small in absolute value, and use the greedy strategy to sequentially select the transformation branches with negative influence degrees and absolute values greater than the preset threshold until the sum of the absolute values of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; traverse in reverse until reaching a node with an in-degree of 0 to obtain the root cause location path of the abnormal indicator.

[0028] According to a root cause location method for abnormal indicators in complex processes provided by the present invention, after determining the root cause location path of the abnormal indicator, it further includes:

[0029] Calculate the root cause discrimination degree of each root cause location path, and select the root cause location path with the largest root cause discrimination degree as the most significant root cause location path;

[0030] Among them, the root cause discrimination degree of any root cause location path i is calculated based on the following method:

[0031] C(i)=α× +β×

[0032] Among them, C(i) is the root cause discrimination degree of the root cause location path i; α and β are custom coefficients, and α + β = 1; IR global (v) is the influence degree of the transformation process corresponding to the initial node or any adjacent node in the root cause location path i on the abnormal index; std(i) is the standard deviation of the influence degrees of the transformation processes corresponding to the initial node and each adjacent node in the root cause location path i on the abnormal index, and k is the number of root cause location paths.

[0033] The present invention also provides a root cause location system for index anomalies in complex processes, including:

[0034] An initial DAG construction module, configured to construct an initial process DAG based on the current business process and establish an association between each node in the initial process DAG and its index; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal index is located and the business stages or task units before them;

[0035] A DAG abstraction module, configured to perform abstraction processing on the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the splitting node is greater than 1;

[0036] An influence degree calculation module, configured to determine the influence degrees of the transformation processes corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal index based on the backbone process DAG;

[0037] A root cause location path output module, configured to start from the node corresponding to the abnormal index in the initial process DAG and traverse the initial process DAG in reverse, and determine the root cause location path of the abnormal index based on the influence degrees of the transformation processes corresponding to the initial node and any two adjacent nodes in the initial process DAG;

[0038] The root cause diagnosis Q&A system module is used to record the abnormal manifestations of the abnormal indicators and the root cause information determined by humans, forming an abnormal record document; adopt the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when the user conducts a root cause diagnosis query, receive the root cause diagnosis question and context information input by the user to the root cause diagnosis Q&A system; the context information includes the root cause path and the information of relevant indicators for the transformation of a certain abnormal stage; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds back the result to the user, and determines the root cause generated by the transformation of the abnormal stage.

[0039] According to a root cause location system for indicator anomalies in a complex process provided by the present invention, abstract processing is performed on the aggregation nodes and split nodes in the initial process DAG to obtain a backbone process DAG, including: starting from the node with an in-degree of 0 in the initial process DAG and traversing forward, if the currently accessed node is an aggregation node, call the aggregation processing step for the currently accessed node and then continue traversing; if the currently accessed node is a split node, call the split processing step for the currently accessed node and then continue traversing; after the traversal is completed, obtain the backbone process DAG;

[0040] Among them, the aggregation processing step for any aggregation node includes: traversing backward the unvisited transformation branches of the aggregation node, if any transformation branch contains an aggregation node, call the aggregation processing step for the aggregation node in the transformation branch to obtain the current process DAG, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; if none of the transformation branches contain an aggregation node, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from the transformation branch of any node to the node.

[0041] The splitting process for any splitting node includes: traversing the branches of the splitting node in the forward direction. If there is no splitting node in the branches of the splitting node, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG, obtaining a new process DAG; otherwise, call the splitting process for the splitting node in the branch of the splitting node to obtain the current process DAG, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG, obtaining a new process DAG; there is a directed edge from any node to the branches of the node.

[0042] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the root cause location method for index anomalies in complex processes as described in any one of the above.

[0043] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the root cause location method for index anomalies in complex processes as described in any one of the above.

[0044] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the root cause location method for index anomalies in complex processes as described in any one of the above.

[0045] A root cause localization method and system for abnormal indicators in complex processes provided by the present invention. Aiming at problems such as a large number of nodes in complex business processes, a complex DAG graph structure, diverse node types, inconsistent indicator granularity for different nodes, and great difficulty in root cause analysis, it constructs process DAG graphs with different abstraction levels from bottom to top, calculates the influence degrees of operations such as transformation, shunt, and aggregation on abnormal indicators layer by layer from high to low in terms of abstraction level. The influence degrees are comparable to each other, which can help operation personnel quickly identify and locate the root cause path and individual stage transformation items with greater influence degrees. Among them, the conduction calculation of influence degrees is realized through the chain rule, so as to achieve cross-layer stage transformation analysis. In addition, a root cause diagnosis Q&A system can be generated based on the large model + graph retrieval generation technology, combined with abnormal record documents. By the root cause diagnosis Q&A system, the reasons for abnormalities generated by stage transformation are further analyzed, effectively using past diagnosis experience to improve the analysis efficiency of stage transformation abnormalities. Subsequently, according to the actual situation, the abnormal record documents are added or updated, and then the knowledge graph is updated, so that the large language model retrieves the updated knowledge graph, and the Q&A results of root cause inquiry will be more accurate and comprehensive. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following-described drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0047] Figure 1 is a schematic flowchart of the root cause localization method for abnormal indicators in complex processes provided by the present invention;

[0048] Figure 2 is a schematic diagram of the aggregation node and transformation branch provided by the present invention;

[0049] Figure 3 is one of the schematic diagrams of the aggregation processing steps provided by the present invention;

[0050] Figure 4 is another schematic diagram of the aggregation processing steps provided by the present invention;

[0051] Figure 5 is a schematic diagram of the shunt node and its branches provided by the present invention;

[0052] Figure 6 is one of the schematic diagrams of the shunt processing steps provided by the present invention;

[0053] Figure 7 is another schematic diagram of the shunt processing steps provided by the present invention;

[0054] Figure 8 It is a schematic structural diagram of a root cause location system for abnormal indicators facing complex processes provided by the present invention;

[0055] Figure 9 It is a schematic structural diagram of an electronic device provided by the present invention. Specific embodiments

[0056] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts fall within the scope of protection of the present invention.

[0057] Figure 1 It is a schematic flowchart of a root cause location method for abnormal indicators facing complex processes provided by the present invention. As Figure 1 shown, the method includes:

[0058] Step 110, constructing an initial process DAG based on the current business process and establishing the association between each node in the initial process DAG and its indicator; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal indicators are located and the business stages or task units before them;

[0059] Step 120, abstracting the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG;

[0060] Among them, the in-degree of the aggregation node is greater than 1, and the out-degree of the splitting node is greater than 1;

[0061] Step 130, determining the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator based on the backbone process DAG;

[0062] Step 140, starting from the node corresponding to the abnormal indicator in the initial process DAG, traversing the initial process DAG in reverse, and determining the root cause location path of the abnormal indicator based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator;

[0063] Step 150: Record the abnormal manifestations of the abnormal indicators and the root cause information determined manually to form an abnormal record document; Use the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; When the user conducts a root cause diagnosis query, receive the root cause diagnosis question and context information input by the user to the root cause diagnosis question and answer system; The context information includes the root cause path and the information of relevant indicators for the transformation of a certain abnormal stage; The system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; The large language model summarizes the input, further feeds back the result to the user, and determines the root cause of the transformation of the abnormal stage.

[0064] Here, step 120 includes: Starting from the nodes with an in-degree of 0 in the initial process DAG, traverse forward. If the currently visited node is an aggregation node, call the aggregation processing step for the currently visited node and then continue traversing; If the currently visited node is a shunt node, call the shunt processing step for the currently visited node and then continue traversing; After the traversal is completed, obtain the backbone process DAG.

[0065] Among them, the aggregation processing step for any aggregation node includes: Traverse backward the unvisited transformation branches of this aggregation node. If any transformation branch contains an aggregation node, call the aggregation processing step for the aggregation node in this transformation branch to obtain the current process DAG, construct the node set of this aggregation node based on this aggregation node and the nodes in its transformation branches in the current process DAG, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG; If all transformation branches do not contain an aggregation node, construct the node set of this aggregation node based on this aggregation node and the nodes in its transformation branches in the current process DAG, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG; There is a directed edge from the transformation branch of any node to this node.

[0066] The splitting process for any splitting node includes: traversing the branches of the splitting node in the forward direction. If there is no splitting node among the branches of the splitting node, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG, create a directed edge from the said any splitting node to the virtual node corresponding to the aggregation node, and obtain a new process DAG; otherwise, call the splitting process for the splitting node in the branch of the splitting node to obtain the current process DAG, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG, and obtain a new process DAG; there is a directed edge from any node to the branches of the node.

[0067] Specifically, an initial process DAG is constructed based on the business progression order of the current business process. Among them, the nodes in the initial process DAG correspond to a business stage or task unit, and the end node of the initial process DAG is the business stage or task unit corresponding to the abnormal indicator. Subsequently, associations can be established between each node in the initial process DAG and its indicators, so as to facilitate root cause location in subsequent root cause location steps. It should be noted that the in-degree or out-degree of the nodes in the initial process DAG can be greater than 1. If the in-degree of a node is greater than 1, it can be called an aggregation node, representing that multiple different stages or task units are merged into one stage or task unit. Assume that the relevant business stages are A, B, C, and D, and the corresponding indicators are m a ﹑m b ﹑m c and m d , and the indicator values of these indicators in the current cycle are A(m a )﹑A(m b )﹑A(m c )and A(m d ), then there is A(m a )+A(m b )+A(m c )=A(m d ). The goal of aggregation is to achieve the convergence of several business stages / task units and their indicator values. If the out-degree of a node is greater than 1, it can be called a splitting node, representing that one business stage or task unit is split into multiple different stages or task units. Assume that the relevant business stages are A, B, C, and D, and the corresponding indicators are m a ﹑m b ﹑m c and m d, the metric values of these metrics in the current cycle are A(m a )﹑A(m b )﹑A(m c ) and A(m d ), then there is A(m a ) = A(m b ) + A(m c ) + A(m d ). The goal of shunting is to decompose and allocate the metric value of a certain business stage to different sub-business stages or task units.

[0068] After obtaining the initial process DAG, process DAG graphs with different abstraction levels can be constructed bottom-up in sequence until the backbone process DAG is obtained. On this basis, the influence degree of the backbone process DAG is calculated preferentially, and the virtual nodes representing sub-processes in the backbone process DAG are drilled down one by one, and the relevant influence degrees are allocated to different sub-processes. By gradually drilling down from the highest to the lowest abstraction level until all virtual nodes are expanded and analyzed. Finally, the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes (two nodes with a directed edge are called adjacent nodes) in the initial process DAG on the metric anomaly can be obtained.

[0069] Aiming at the problems of a large number of complex business process nodes, a complex DAG graph structure, diverse node types (such as aggregation nodes, shunting nodes), inconsistent metric granularities of different nodes, and great difficulty in root cause analysis, the embodiment of the present invention proposes a multi-level DAG graph construction algorithm, which constructs process DAG graphs with different abstraction levels bottom-up in sequence, continuously divides and abstracts the DAG graph until the backbone process DAG with the highest abstraction level is obtained. Specifically, it can start from the node with an in-degree of 0 in the initial process DAG (if there are multiple nodes with an in-degree of 0, randomly select one as the traversal starting point) and perform a forward traversal. It should be noted that a forward traversal means traversing along the direction of the directed edge, while a reverse traversal means traversing along the direction opposite to the directed edge, which will not be elaborated later. If the currently visited node is an aggregation node, after calling the aggregation processing step for the currently visited node, continue the traversal; if the currently visited node is a shunting node, after calling the shunting processing step for the currently visited node, continue the traversal; after the traversal is completed, the backbone process DAG can be obtained.

[0070] Among them, the aggregation processing step for any aggregation node includes: reversely traversing the unvisited transformation branches of the aggregation node. Here, the transformation branch of any node has a directed edge to this node, such as Figure 2As shown, the transformation branches of the aggregation node D are A, B, and C respectively. If any of the transformation branches also contains an aggregation node, after recursively calling the aggregation processing step for the aggregation node in that transformation branch, the current process DAG is obtained. Then, based on the aggregation node and the nodes in its transformation branch in the current process DAG, a node set of this aggregation node is constructed, and a virtual node corresponding to this aggregation node is created to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG, obtaining a new process DAG. If none of the transformation branches contains an aggregation node, based on the aggregation node and the nodes in its transformation branch in the current process DAG, a node set of this aggregation node is constructed, and a virtual node corresponding to this aggregation node is created to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG, obtaining a new process DAG.

[0071] As Figure 3 shown, the currently accessed aggregation node is D. Among them, nodes A, B, and C are located in two different transformation branches of this aggregation node. Traverse each transformation branch in reverse to check if it contains other aggregation operations. Since none of the transformation branches of the aggregation node D contains an aggregation node, the node set of the aggregation node D is constructed as {A, B, C, D}, and the recognized subgraph of this part is replaced by a new virtual node D'. Starting from the virtual node D', continue to traverse forward. When accessing the aggregation node J, traverse the transformation branch of this aggregation node in reverse and confirm that node H is an aggregation node. Therefore, the above-mentioned aggregation processing step will be executed on node H, that is, continue to traverse the transformation branch of node H in reverse and confirm whether there is an aggregation node on the transformation branch. If there is, continue to recursively call the aggregation processing step for the newly emerged aggregation node. The current situation is that there is no aggregation node on the transformation branch of node H. Therefore, the node set of node H can be constructed as {G, I, H}, and the recognized subgraph of this part is replaced by a new virtual node H'. Return to the aggregation node J. Since all the aggregation nodes on the transformation branch of this aggregation node have been replaced by the corresponding virtual nodes and no longer contain aggregation nodes, the node set of this aggregation node J is constructed as {E, F, D', H', J}, and the recognized subgraph is replaced by a new virtual node J', as Figure 4 shown.

[0072] The splitting processing step for any splitting node includes: traversing the branches of this splitting node forward. Among them, there is a directed edge from any node to the branch of this node, as Figure 5As shown, the branches of node A are B, C, and D respectively. If there is no shunt node among the branches of this shunt node, then determine the aggregation node corresponding to this shunt node (generally, shunting and aggregation will occur in pairs, and the branches of this shunt node will converge at its corresponding aggregation node), then construct the node set of this aggregation node based on this aggregation node and the nodes between this aggregation node and this shunt node, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG. At the same time, create a directed edge from this shunt node to the virtual node corresponding to this aggregation node to obtain a new process DAG. If there is another shunt node among the branches of this shunt node, then after calling the shunt processing step for the shunt node in the corresponding branch to obtain the current process DAG, then determine the aggregation node corresponding to this shunt node, and construct the node set of this aggregation node based on this aggregation node and the nodes between this aggregation node and this shunt node, so as to create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG.

[0073] As Figure 6 shown, the currently accessed shunt node is A. Traverse forward along its left branch and find that there is a shunt node B. Therefore, execute the shunt processing step for the shunt node B, that is, traverse the branches of the shunt node B forward to determine whether there is another shunt node among its branches. If there is, continue to recursively call the shunt processing step to process the shunt node on its branch. After confirming that there is no shunt node among its branches, determine the aggregation node G corresponding to this shunt node B, and construct the node set {C, D, E, F, G} of this aggregation node based on this aggregation node G and the nodes between this aggregation node G and this shunt node B, and create a virtual node G' corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG. Subsequently, continue to confirm whether there is another shunt node on other branches of the shunt node A. If there is, recursively call the shunt processing step to process the shunt node on the branch. After performing the above processing on all branches of the shunt node A, there will no longer be a shunt node on the branches of the shunt node A. Therefore, return to the shunt node A, locate its corresponding aggregation node J, and construct the node set {B, G', H, I, J} of this aggregation node based on this aggregation node and the nodes between this aggregation node and this shunt node, and create a virtual node J' corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG, as Figure 7 shown.

[0074] After obtaining the backbone process DAG, starting from the backbone process DAG, by gradually drilling down to analyze the virtual nodes in the backbone process DAG, determine the influence degree of the initial nodes and the transformation processes corresponding to any two adjacent nodes in the initial process DAG on the abnormal indicators. In some embodiments, the influence degree of the initial nodes and the transformation processes corresponding to any two adjacent nodes in the backbone process DAG on the abnormal indicators can be calculated first. Subsequently, traverse the backbone process DAG in the forward direction. If the currently visited node is a virtual node and there is no shunt node pointing to this node, then call the aggregation node drilling-down step for the currently visited node and continue traversing. If the currently visited node is a shunt node in the initial process DAG and this node is connected to a virtual node by a directed edge, then call the shunt node drilling-down step for the currently visited node and the virtual node it is connected to and continue traversing until the traversal is completed.

[0075] Among them, the method given in Patent CN202110195548.6 can be adopted to calculate the influence degree of the initial nodes and the transformation processes corresponding to any two adjacent nodes in the backbone process DAG on the abnormal indicators. It should be noted that for any sub-graph, this method can be used to calculate the influence degree of the initial nodes and the transformation processes corresponding to any two adjacent nodes in this sub-graph on the end node, and it will not be elaborated later when related calculations are involved.

[0076] For example, calculate the conversion rates of each adjacent node P i ﹑P i+1 in the current period and the previous period (1≦i≦k - 1), where P i ﹑P i+1 the conversion rate in the current period F (P i ->P i+1 ) and the conversion rate in the previous period F '(P i ->P i+1 ) are respectively expressed as follows.

[0077]

[0078]

[0079] Among them, mi is the index of node Pi, A(mi) is the index value of node Pi in the current period, and A'(mi) is the index value of node Pi in the previous period.

[0080] Calculate the impact value and impact rate of the initial node P1 and the transformation processes corresponding to each subsequent adjacent node on the end node mk respectively. Among them, the calculation method of the impact value of the initial node P1 on mk is as follows:

[0081]

[0082] The influence degree calculation method of P1 on m k is as follows:

[0083]

[0084] The influence value calculation method of the transformation process from P1 to P2 on m k is as follows:

[0085]

[0086] The influence degree calculation method of the transformation process from P1 to P2 on m k is as follows:

[0087]

[0088] Correspondingly, the influence value and influence degree of the transformation from P i to P i+1 on m k are respectively expressed as follows:

[0089]

[0090] Among them, the aggregation node drilling-down step for any virtual node includes: based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG, constructing each transformation branch of the aggregation node; taking the indicators corresponding to the end nodes of each transformation branch of the aggregation node as key indicators, calculating the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the key indicator of the same transformation branch (the calculation method is the same as above), and determining the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the abnormal indicator based on the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the key indicator of the same transformation branch, the influence degree of the end node of the transformation branch corresponding to each key indicator on the virtual node, and the influence degree of the virtual node on the abnormal indicator. Subsequently, confirm whether each transformation branch contains a virtual node. If a virtual node is included in each transformation branch, then execute the aggregation node drilling-down step for the virtual node in the corresponding transformation branch.

[0091] In some embodiments, for the initial node in any transformation branch, calculate the product of the influence degree of the initial node in the transformation branch on the key indicator of the same transformation branch, the influence degree of the terminal node of the transformation branch corresponding to the key indicator on the virtual node, and the influence degree of the virtual node on the abnormal indicator, as the influence degree of the initial node of the transformation branch on the abnormal indicator; for the transformation process corresponding to adjacent nodes in any transformation branch, calculate the product of the influence degree of the transformation process corresponding to adjacent nodes in the transformation branch on the key indicator of the same transformation branch, the influence degree of the terminal node of the transformation branch corresponding to the key indicator on the virtual node, and the influence degree of the virtual node on the abnormal indicator, as the influence degree of the transformation process corresponding to adjacent nodes in the transformation branch on the abnormal indicator; wherein, the influence degree of the terminal node of the transformation branch corresponding to any key indicator on the virtual node is the ratio of the difference between the indicator values of the key indicator in the current period and the previous period to the difference between the indicator values of the aggregated node associated with the virtual node in the initial process DAG in the current period and the previous period.

[0092] Assume that the virtual node is P'. w The two transformation branches are respectively {P h , P h+1 ,..., P h+m} and {P j , P j+1 ,..., P j+n}, and neither of the two transformation branches contains virtual nodes. P h+m and P j+n converge to the P w node, that is, the aggregated node corresponding to the virtual node P' w is P w . Taking the indicators corresponding to the terminal nodes of each transformation branch as the key indicators (m h+m , m j+n ), calculate the influence degrees of the initial nodes of each transformation branch and the transformation processes corresponding to each adjacent node on the key indicators of the same branch { IR (P h ), IR (P h → P h+1 ),..., IR (P h+m-1 → P h+m ),}, { IR (P j ), IR (P j → P j+1 ),..., IR (P j+n-1 → P j+n ).} After prior analysis and calculation, the influence degree of the virtual node P' w on the abnormal indicator can be obtained asIR global (P' w ). Next, calculate P h+m ﹑P j+n for the influence degree of the change of the P w index, expressed as equations (1) and (2). Finally, calculate the influence degree of the branch node and the transformation on the index anomaly. Here, taking P h and P h →P h+1 as an example, their influence degrees on the abnormal index are respectively expressed as equations (3) and (4). Multiply the three, and use the chain rule to realize the conduction calculation of the influence degree, so as to obtain the influence degree of the initial node and each adjacent node corresponding to the transformation process in the virtual node on the abnormal index.

[0093] IR (P h+m )=(A(m h+m ) - A'(m h+m )) / (A(m w ) - A'(m w )) (1)

[0094] IR (P j+n )=(A(m j+n ) - A'(m j+n )) / (A(m w ) - A'(m w )) (2)

[0095] IR global (P h ) =IR (P h )× IR (P h+m )× IR global (P' w ) (3)

[0096] IR global (P h →P h+1 ) =IR (P h →P h+1 )× IR (P h+m )× IR global (P' w ) (4)

[0097] Assume that the two transformation branches of the virtual node P' w are {P h , Ph+1 ,..., P h+m}, and {P' j , P j+1 ,..., P j+n}, and the conversion branch contains a virtual node P' j , P' j is not the last node of this conversion branch, P h+m and P j+n converge to P w node, that is, the virtual node P' w The corresponding aggregation node of is P w . P' j The influence degree on the abnormal index is expressed as formula (5). For example, if the second conversion branch set only contains the P' j node, that is, P' j is the last node of this conversion branch, then P' j The influence degree on the index anomaly can be expressed as formula (6). For the virtual node P' j , continue to drill down, and calculate the influence degree of the conversion process corresponding to the initial node and adjacent nodes in the conversion branch of P' j in turn in a similar manner.

[0098] IR global (P' j ) =IR (P' j ) × IR (P j+n ) × IR global (P' w ) (5)

[0099] IR global (P' j ) = ((A(m' j ) - A'(m' j )) / (A(m w ) - A'(m w ))) × IR global (P' w ) (6)

[0100] The steps for drilling down the shunt node for any shunt node and its connected virtual node include: constructing each branch of the shunt node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; using the metrics corresponding to the end nodes of each branch of the shunt node as key metrics, calculating the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the key metrics, and determining the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the abnormal metrics based on the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the key metrics, the influence degree of the branch end node corresponding to the key metric on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal metric; if a virtual node is included in any branch, calling the steps for drilling down the shunt node for the shunt node corresponding to the virtual node in the initial process DAG and the virtual node in the corresponding branch.

[0101] In some embodiments, for the shunt node, calculate the product of the influence degree of the shunt node on the key metric in any branch, the influence degree of the branch end node corresponding to the key metric on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal metric as the influence degree of the shunt node on the abnormal metric; for any conversion process among the conversion processes corresponding to the initial nodes of the shunt node and each branch and the conversion processes corresponding to the adjacent nodes of each branch, calculate the product of the influence degree of the conversion process on the key metric in the same branch, the influence degree of the branch end node corresponding to the key metric on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal metric as the influence degree of the conversion process on the abnormal metric.

[0102] Assume the shunt node is P g , and its two branches are {P h , P h+1 ,..., P h+m} and {P j , P j+1 ,..., P j+n}, and no virtual nodes are included in either of the two branches. P h+m and P j+n converge to the P w node, and its corresponding virtual node is P' w . Respectively use the metrics corresponding to the end nodes of each branch as key metrics (m h+m , m j+n ), and calculate the shunt node P gand the influence degrees of the conversions at each stage (i.e., the conversion process corresponding to the shunt node and the initial node of the branch and the conversion processes corresponding to adjacent nodes within the branch) on the key indicators of the same branch are { IR (P g ), IR (P g →P h ), IR (P h →P h+1 ),..., IR (P h+m-1 →P h+m ),}{ IR (P g ), IR (P g →P j ), IR (P j →P j+1 ),..., IR (P j+n-1 →P j+n )}. Through prior calculation and analysis, the influence degree of the conversion process corresponding to the shunt node P g to the virtual node P' w on the abnormal indicator is IR global (P g →P' w ). Next, calculate the influence degrees of P h+m and P j+n on the change of the P w indicator, similar to equations (1) and (2) in the previous section. Finally, calculate the influence degrees of the shunt node and the conversions at each stage on the abnormal indicator. Here, taking P g →P h and P h →P h+1 as examples, their influence degrees on the abnormal indicator are respectively expressed as equations (7) and (8). Multiply the three, and similarly, the conduction calculation of the influence degree is achieved through the chain rule, so as to obtain the influence degrees of the shunt node and the conversions at each stage within the virtual node on the abnormal indicator.

[0103] IR global (P g →P h ) =IR (P g →P h )× IR (P h+m )× IR global (P g →P' w ) (7)

[0104] IR global (P h →P h+1 ) =IR (P h →P h+1 )× IR (P h+m )× IR global (P g →P' w )(8)

[0105] Assume the shunt node is P g , and the two branches are {P h , P h+1 ,..., P h+m} and {P j , P' j+1 ,..., P j+n}, and the branches contain the virtual node P' j+1 , P j is also a shunt node, P h+m and P j+n converge to P w node, and its corresponding virtual node is P' w . P j →P' j+1 The influence degree on the abnormal index is expressed as formula (9). Subsequently, for the virtual node P' j+1 in the branch, determine its corresponding shunt node P j , and perform the shunt node drill-down step for the shunt node P j and the virtual node P' j+1 . Among them, if there are still virtual nodes in the branch of the shunt node P j , the processing method is the same as above.

[0106] IR global (P j →P' j+1 ) =IR (P j →P' j+1 )× IR (P j+n )× IR global (P g →P' w )(9)

[0107] After the influence degree is calculated, starting from the node corresponding to the abnormal index in the initial process DAG, traverse the initial process DAG in reverse. Based on the influence degree of the initial node of the initial process DAG and the transformation process corresponding to any two adjacent nodes on the abnormal index, determine the root cause location path of the abnormal index. Among them, it is possible to traverse the initial process DAG in reverse starting from the node corresponding to the abnormal index. If the currently visited node is an aggregation node, when the change direction of the index value of the currently visited node is the same as that of the abnormal index, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to small, and use the greedy strategy to sequentially select the transformation branches with positive influence degrees and greater than the preset threshold until the sum of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; when the change direction of the index value of the currently visited node is different from the abnormal index, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to small in absolute value, and use the greedy strategy to sequentially select the transformation branches with negative influence degrees and absolute values greater than the preset threshold until the sum of the absolute values of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; traverse in reverse until reaching a node with an in-degree of 0, thereby obtaining the root cause location path of the abnormal index. It can be seen that there can be multiple root cause location paths for the abnormal index. In this regard, after obtaining multiple root cause location paths, the root cause discrimination degree of each root cause location path can be calculated, and the root cause location path with the largest root cause discrimination degree can be selected as the most significant root cause location path;

[0108] Among them, the root cause discrimination degree of any root cause location path i is calculated based on the following method:

[0109] C(i)=α× +β×

[0110] Here, C(i) is the root cause discrimination degree of this root cause location path i; α and β are custom coefficients, and α + β = 1; IR global (v) is the influence degree of the transformation process corresponding to the initial node or any adjacent node within this root cause location path i on the abnormal index; std(i) is the standard deviation of the influence degrees of the transformation processes corresponding to the initial node and each adjacent node within this root cause location path i on the abnormal index, and k is the number of root cause location paths.

[0111] After determining the root cause location path of the abnormal indicator, a root cause diagnosis Q&A system can also be constructed based on large language models and GraphRAG (Graph-based Retrieval Augmented Generation) technology, in combination with the abnormal record document, to further analyze the reasons for the abnormalities generated during the phase transformation through the root cause diagnosis Q&A system. Specifically, the abnormal manifestations of the abnormal indicator and the root cause information determined manually can be recorded to form an abnormal record document. Subsequently, the GraphRAG technology is used to extract information such as entities, relationships, and covariates from the abnormal record document, generate communities and community summaries, and construct a knowledge graph. When the user conducts a root cause diagnosis query, the root cause diagnosis question and context information (including the root cause path and the indicator information related to a certain phase transformation with abnormalities) input by the user to the root cause diagnosis Q&A system are received. The system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the back-end large language model. The large language model summarizes the input and further feeds the result back to the user to determine the root cause of the phase transformation with abnormalities. Subsequently, according to the actual situation, the abnormal record document is added to or updated, thereby completing the update of the knowledge graph. When the large language model retrieves the updated knowledge graph, the Q&A results of the root cause inquiry will be more accurate and comprehensive.

[0112] In summary, for the problems of a large number of complex business process nodes, a complex DAG graph structure, diverse node types, inconsistent indicator granularities of different nodes, and great difficulty in root cause analysis in the method provided by the embodiments of the present invention, process DAG graphs with different abstraction levels are constructed layer by layer from bottom to top. The influence degrees of operations such as phase transformation, splitting, and aggregation on the abnormal indicator are calculated layer by layer from high to low according to the abstraction level. The influence degrees are comparable to each other, which can help operation personnel quickly identify and locate the root cause path and individual phase transformation items with greater influence degrees. Among them, the conduction calculation of the influence degree is realized through the chain rule, so as to achieve cross-layer phase transformation analysis. In addition, a root cause diagnosis Q&A system can be constructed based on large model + graph retrieval generation technology, in combination with the abnormal record document, to further analyze the reasons for the abnormalities generated during the phase transformation through the root cause diagnosis Q&A system, effectively utilize past diagnosis experience, and improve the analysis efficiency of phase transformation abnormalities. Subsequently, according to the actual situation, the abnormal record document is added to or updated, thereby completing the update of the knowledge graph, so that when the large language model retrieves the updated knowledge graph, the Q&A results of the root cause inquiry will be more accurate and comprehensive.

[0113] The root cause location system for abnormal indicators in complex processes provided by the present invention will be described below. The root cause location system for abnormal indicators in complex processes described below can be correspondingly referred to the root cause location method for abnormal indicators in complex processes described above.

[0114] Based on any of the above embodiments, Figure 8 is a schematic structural diagram of the root cause location system for abnormal indicators in complex processes provided by the present invention. As Figure 8 shown, the system includes:

[0115] An initial DAG construction module 810, configured to construct an initial process DAG based on the current business process and establish an association between each node in the initial process DAG and its indicator; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal indicators are located and the business stages or task units before them;

[0116] A DAG abstraction module 820, configured to perform abstraction processing on the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation nodes is greater than 1, and the out-degree of the splitting nodes is greater than 1;

[0117] An influence degree calculation module 830, configured to determine the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator based on the backbone process DAG;

[0118] A root cause location path output module 840, configured to start from the node corresponding to the abnormal indicator in the initial process DAG and traverse the initial process DAG in reverse, and determine the root cause location path of the abnormal indicator based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator;

[0119] A root cause diagnosis Q&A system module 850, configured to record the abnormal manifestations of the abnormal indicator and the root cause information determined manually to form an abnormal record document; extract entity and relationship information from the abnormal record document by using the GraphRAG technology to generate communities and community summaries, and construct a knowledge graph; when the user performs a root cause diagnosis query, receive the root cause diagnosis question and context information input by the user to the root cause diagnosis Q&A system; the context information includes the root cause path and the relevant indicator information of a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and uses the matching community summary in the knowledge graph as a prompt to input to the large language model at the back end; the large language model summarizes the input, and further feeds back the result to the user to determine the root cause of the abnormal stage transformation.

[0120] The system provided by the embodiments of the present invention addresses problems such as a large number of complex business process nodes, a complex DAG graph structure, diverse node types, inconsistent metric granularities for different nodes, and great difficulty in root cause analysis. It constructs process DAG graphs with different abstraction levels from bottom to top, calculates the influence degrees of operations such as transformation, splitting, and aggregation at each stage on abnormal metrics layer by layer from high to low in terms of abstraction level. The influence degrees are comparable to each other, which can help operation personnel quickly identify and locate the root cause path and individual stage transformation items with relatively large influence degrees. Among them, the conduction calculation of the influence degree is realized through the chain rule, so as to achieve cross-layer stage transformation analysis. In addition, a root cause diagnosis Q&A system can be constructed based on the large model + graph retrieval generation technology, combined with abnormal record documents. The root cause diagnosis Q&A system is used to further analyze the reasons for the anomalies generated by stage transformation, effectively utilize past diagnosis experience, and improve the analysis efficiency of stage transformation anomalies. Subsequently, according to the actual situation, the abnormal record documents are added or updated, and then the knowledge graph is updated, so that the large language model retrieves the updated knowledge graph, and the Q&A results of root cause inquiry will be more accurate and comprehensive.

[0121] Based on any of the above embodiments, abstract processing is performed on the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG, including:

[0122] Starting from the nodes with an in-degree of 0 in the initial process DAG, perform a forward traversal. If the currently visited node is an aggregation node, call the aggregation processing step for the currently visited node and then continue the traversal; if the currently visited node is a splitting node, call the splitting processing step for the currently visited node and then continue the traversal; after the traversal is completed, obtain the backbone process DAG;

[0123] Among them, the aggregation processing step for any aggregation node includes: reversely traversing the unvisited transformation branches of the aggregation node. If any transformation branch contains an aggregation node, call the aggregation processing step for the aggregation node in the transformation branch to obtain the current process DAG, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; if none of the transformation branches contain an aggregation node, construct the node set of the aggregation node based on the aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from the transformation branch of any node to the node.

[0124] The splitting process for any splitting node includes: traversing the branches of the splitting node in the forward direction. If there is no splitting node in the branches of the splitting node, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG. Create a directed edge from the any splitting node to the virtual node corresponding to the aggregation node to obtain a new process DAG; otherwise, call the splitting process for the splitting node in the branch of the splitting node to obtain the current process DAG, determine the aggregation node corresponding to the splitting node, construct the node set of the aggregation node based on the aggregation node and the nodes between it and the splitting node, and create a virtual node corresponding to the aggregation node to replace the subgraph corresponding to the node set of the aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from any node to the branch of the node.

[0125] Based on any of the above embodiments, the determining the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal index based on the backbone process DAG includes:

[0126] Calculate the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the backbone process DAG on the abnormal index;

[0127] Traverse the backbone process DAG in the forward direction. If the currently visited node is a virtual node and there is no splitting node pointing to this node, call the aggregation node drilling-down step for the currently visited node and then continue traversing. If the currently visited node is a splitting node in the initial process DAG and this node is connected to a virtual node by a directed edge, call the splitting node drilling-down step for the currently visited node and the virtual node it is connected to and then continue traversing;

[0128] Among them, the aggregation node drilling-down step for any virtual node includes: based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG, construct each transformation branch of the aggregation node; use the index corresponding to the end node of each transformation branch of the aggregation node as the key index, calculate the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the key index, and based on the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the key index, the influence degree of each transformation branch end node corresponding to the key index on the virtual node, and the influence degree of the virtual node on the abnormal index, determine the influence degree of the transformation process corresponding to the initial node and adjacent nodes in each transformation branch on the abnormal index; if there are virtual nodes in each transformation branch, call the aggregation node drilling-down step for the virtual nodes in the corresponding transformation branch;

[0129] The under-drilling steps of a shunt node for any shunt node and its connected virtual node include: constructing each branch of the shunt node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; taking the metrics corresponding to the end nodes of each branch of the shunt node as key metrics, and calculating the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the key metrics. Based on the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the key metrics, the influence degrees of the end nodes of each branch corresponding to the key metrics on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal metric, determine the influence degrees of the shunt node, the conversion processes corresponding to the initial nodes of the shunt node and each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the abnormal metric; if a virtual node is included in each branch, call the under-drilling steps of the shunt node corresponding to the virtual node in the initial process DAG and the shunt node of the virtual node.

[0130] Based on any of the above embodiments, based on the influence degrees of the conversion processes corresponding to the initial nodes and adjacent nodes in each conversion branch on the key metric, the influence degrees of the end nodes of each conversion branch corresponding to the key metric on the virtual node, and the influence degree of the virtual node on the abnormal metric, determining the influence degrees of the conversion processes corresponding to the initial nodes and adjacent nodes in each conversion branch on the abnormal metric includes:

[0131] For the initial node in any conversion branch, calculate the product of the influence degree of the initial node in the conversion branch on the key metric of the same conversion branch, the influence degree of the end node of the conversion branch corresponding to the key metric on the virtual node, and the influence degree of the virtual node on the abnormal metric, as the influence degree of the initial node in the conversion branch on the abnormal metric;

[0132] For the conversion process corresponding to the adjacent node in any conversion branch, calculate the product of the influence degree of the conversion process corresponding to the adjacent node in the conversion branch on the key metric of the same conversion branch, the influence degree of the end node of the conversion branch corresponding to the key metric on the virtual node, and the influence degree of the virtual node on the abnormal metric, as the influence degree of the conversion process corresponding to the adjacent node in the conversion branch on the abnormal metric;

[0133] Among them, the influence degree of the end node of any conversion branch corresponding to the key metric on the virtual node is the ratio of the difference between the metric of this period and the previous period of the key metric to the difference between the metric of this period and the previous period of the metric associated with the aggregation node corresponding to the virtual node in the initial process DAG.

[0134] Based on any of the above embodiments, determine the influence degree of the shunt node, the conversion processes corresponding to the shunt node and the initial nodes of each branch, and the conversion processes corresponding to the adjacent nodes of each branch on the abnormal index based on the influence degree of the key index, the influence degree of each branch end node corresponding to the key index on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal index, including:

[0135] For the shunt node, calculate the product of the influence degree of the shunt node on the key index in any branch, the influence degree of the branch end node corresponding to the key index on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal index, and use it as the influence degree of the shunt node on the abnormal index;

[0136] For any conversion process among the conversion processes corresponding to the shunt node and the initial nodes of each branch and the conversion processes corresponding to the adjacent nodes of each branch, calculate the product of the influence degree of the conversion process on the key index of the same branch, the influence degree of the branch end node corresponding to the key index on the virtual node, and the influence degree of the conversion process corresponding to the shunt node and the virtual node on the abnormal index, and use it as the influence degree of the conversion process on the abnormal index.

[0137] Based on any of the above embodiments, starting from the node corresponding to the abnormal index in the initial process DAG, traverse the initial process DAG in reverse, and determine the root cause location path of the abnormal index based on the influence degree of the initial node of the initial process DAG and the conversion process corresponding to any two adjacent nodes on the abnormal index, including:

[0138] Starting from the node corresponding to the abnormal metric, traverse the initial process DAG in reverse. If the currently visited node is an aggregation node, when the change direction of the metric value of the currently visited node is the same as that of the abnormal metric, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to small, and use the greedy strategy to sequentially select the transformation branches with positive influence degrees greater than the preset threshold until the sum of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; when the change direction of the metric value of the currently visited node is different from that of the abnormal metric, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node from large to absolute value, and use the greedy strategy to sequentially select the transformation branches with negative influence degrees and absolute values greater than the preset threshold until the sum of the absolute values of the influence degrees of the selected transformation branch end nodes on the currently visited node is greater than the preset threshold, and continue to traverse in reverse along the selected transformation branch; traverse in reverse until reaching a node with an in-degree of 0 to obtain the root cause location path of the abnormal metric.

[0139] Based on any of the above embodiments, after determining the root cause location path of the abnormal metric, the root cause location path output module is further configured to:

[0140] Calculate the root cause discrimination degree of each root cause location path, and select the root cause location path with the largest root cause discrimination degree as the most significant root cause location path;

[0141] Among them, the root cause discrimination degree of any root cause location path i is calculated based on the following method:

[0142] C(i)=α× +β×

[0143] Among them, C(i) is the root cause discrimination degree of the root cause location path i; α and β are custom coefficients, and α + β = 1; IR global (v) is the influence degree of the transformation process corresponding to the initial node or any adjacent node within the root cause location path i on the abnormal metric; std(i) is the standard deviation of the influence degrees of the transformation processes corresponding to the initial node and each adjacent node within the root cause location path i on the abnormal metric, and k is the number of root cause location paths.

[0144] Figure 9 is a schematic structural diagram of the electronic device provided by the present invention, as Figure 9As shown in the figure, the electronic device may include: a processor 910, a memory 920, a communications interface 930, and a communication bus 940. Among them, the processor 910, the memory 920, and the communication interface 930 complete communication with each other through the communication bus 940. The processor 910 may call logical instructions in the memory 920 to execute a method for locating the root cause of an abnormal index for a complex process. The method includes: constructing an initial process DAG based on the current business process and establishing an association between each node in the initial process DAG and its index; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal index is located and the business stages or task units before them; abstracting the aggregation nodes and shunt nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the shunt node is greater than 1; determining the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal index based on the backbone process DAG; starting from the node corresponding to the abnormal index in the initial process DAG, traversing the initial process DAG in reverse, and determining the root cause location path of the abnormal index based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal index; recording the abnormal performance of the abnormal index and the root cause information determined by humans to form an abnormal record document; using the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when the user conducts a root cause diagnosis query, receiving the root cause diagnosis question and context information input by the user to the root cause diagnosis question and answer system; the context information includes the root cause path and the index information related to a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds the result back to the user, and determines the root cause generated by the abnormal stage transformation where the abnormality exists.

[0145] In addition, when the logical instructions in the aforementioned memory 920 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.

[0146] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the root cause location method for abnormal indicators facing complex processes provided by the above-mentioned various methods. The method includes: constructing an initial process DAG based on the current business process and establishing the association between each node in the initial process DAG and its indicator; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal indicators are located and the business stages or task units before them; abstracting the aggregation nodes and shunt nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the shunt node is greater than 1; determining the influence degree of the initial node and the transformation process corresponding to any two adjacent nodes in the initial process DAG on the abnormal indicator based on the backbone process DAG; starting from the node corresponding to the abnormal indicator in the initial process DAG, traversing the initial process DAG in reverse, and determining the root cause location path of the abnormal indicator based on the influence degree of the initial node and the transformation process corresponding to any two adjacent nodes in the initial process DAG on the abnormal indicator; recording the abnormal performance of the abnormal indicator and the root cause information determined manually to form an abnormal record document; using the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when a user conducts a root cause diagnosis query, receiving the root cause diagnosis question and context information input by the user to the root cause diagnosis question and answer system; the context information includes the root cause path and the relevant indicator information of a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input and further feeds back the result to the user to determine the root cause generated by the abnormal stage transformation.

[0147] In another aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the root cause location method for abnormal indicators in complex processes provided above. The method includes: constructing an initial process DAG based on the current business process and establishing the association between each node in the initial process DAG and its indicators; the nodes of the initial process DAG correspond to the business stages or task units where the abnormal indicators are located and the business stages or task units before them; abstracting the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the splitting node is greater than 1; determining the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator based on the backbone process DAG; starting from the node corresponding to the abnormal indicator in the initial process DAG, traversing the initial process DAG in reverse, and determining the root cause location path of the abnormal indicator based on the influence degree of the transformation process corresponding to the initial node and any two adjacent nodes in the initial process DAG on the abnormal indicator; recording the abnormal performance of the abnormal indicator and the root cause information determined manually to form an abnormal record document; using the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when the user conducts a root cause diagnosis query, receiving the root cause diagnosis question and context information input by the user to the root cause diagnosis question-answering system; the context information includes the root cause path and the relevant indicator information of a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds the result back to the user, and determines the root cause generated by the abnormal stage transformation.

[0148] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0149] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A root cause location method for abnormal indicators in complex processes, characterized in that, Including: Construct an initial process DAG based on the current business process and establish the association between each node in the initial process DAG and its metrics; The nodes of the initial process DAG correspond to the business stages or task units where the abnormal metrics are located and the business stages or task units before them; Abstract the aggregation nodes and splitting nodes in the initial process DAG to obtain a backbone process DAG; the in-degree of the aggregation node is greater than 1, and the out-degree of the splitting node is greater than 1; Calculate the influence degree of the initial node in the backbone process DAG and the transformation process corresponding to any two adjacent nodes on the abnormal metric; Traverse the backbone process DAG in the forward direction. If the currently visited node is a virtual node and there is no splitting node pointing to this node, then call the aggregation node drill-down step for the currently visited node and continue traversing. If the currently visited node is a splitting node in the initial process DAG and this node is connected to a virtual node through a directed edge, then call the splitting node drill-down step for the currently visited node and the virtual node it is connected to and continue traversing; Among them, the aggregation node drill-down step for any virtual node includes: constructing each transformation branch of the aggregation node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; taking the metrics corresponding to the end nodes of each transformation branch of the aggregation node as key metrics, calculating the influence degree of the initial node and the adjacent nodes corresponding to the transformation process in each transformation branch on the key metric, and based on the influence degree of the initial node and the adjacent nodes corresponding to the transformation process in each transformation branch on the key metric, the influence degree of each transformation branch end node corresponding to the key metric on this virtual node, and the influence degree of this virtual node on the abnormal metric, determining the influence degree of the initial node and the adjacent nodes corresponding to the transformation process in each transformation branch on the abnormal metric; if there are virtual nodes in each transformation branch, then call the aggregation node drill-down step for the virtual nodes in the corresponding transformation branch; The under-drilling steps for any shunt node and its connected virtual node include: constructing each branch of the shunt node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; taking the metrics corresponding to the end nodes of each branch of the shunt node as key metrics, calculating the influence degrees of the shunt node, the transformation processes corresponding to the initial nodes of the shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key metrics, and determining the influence degrees of the shunt node, the transformation processes corresponding to the initial nodes of the shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the abnormal metric based on the influence degrees of the shunt node, the transformation processes corresponding to the initial nodes of the shunt node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key metrics, the influence degrees of the end nodes of each branch corresponding to the key metric on the virtual node, and the influence degree of the transformation process corresponding to the shunt node and the virtual node on the abnormal metric; if a virtual node is included in each branch, calling the under-drilling steps for the shunt node corresponding to the virtual node in the initial process DAG and the shunt node of the virtual node; Starting from the node corresponding to the abnormal metric in the initial process DAG, traverse the initial process DAG in reverse, and determine the root cause location path of the abnormal metric based on the influence degrees of the initial node of the initial process DAG and the transformation processes corresponding to any two adjacent nodes on the abnormal metric; Record the abnormal manifestations of the abnormal metric and the root cause information determined manually to form an abnormal record document; use the GraphRAG technology to extract entity and relationship information from the abnormal record document, generate communities and community summaries, and construct a knowledge graph; when the user conducts a root cause diagnosis query, receive the root cause diagnosis question and context information input by the user to the root cause diagnosis Q&A system; the context information includes the root cause path and the information of relevant metrics for a certain abnormal stage transformation; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds the result back to the user, and determines the root cause of the abnormal stage transformation.

2. The root cause location method for abnormal indicators facing complex processes according to claim 1, characterized in that Perform abstraction processing on the aggregation nodes and shunt nodes in the initial process DAG to obtain the backbone process DAG, including: Start a forward traversal from the node with an in-degree of 0 in the initial process DAG. If the currently visited node is an aggregation node, call the aggregation processing steps for the currently visited node and then continue the traversal; if the currently visited node is a shunt node, call the shunt processing steps for the currently visited node and then continue the traversal; after the traversal is completed, obtain the backbone process DAG; Among them, the aggregation processing steps for any aggregation node include: traversing backward the unvisited transformation branches of the aggregation node. If any transformation branch contains an aggregation node, call the aggregation processing steps for the aggregation node in this transformation branch to obtain the current process DAG, construct the node set of this aggregation node based on this aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG; if none of the transformation branches contain an aggregation node, construct the node set of this aggregation node based on this aggregation node and the nodes in its transformation branch in the current process DAG, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from the transformation branch of any node to this node. The splitting processing steps for any splitting node include: traversing forward the branches of the splitting node. If there is no splitting node in the branches of the splitting node, determine the aggregation node corresponding to this splitting node, construct the node set of this aggregation node based on this aggregation node and the nodes between it and this splitting node, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG, and create a directed edge from the any splitting node to the virtual node corresponding to this aggregation node to obtain a new process DAG; otherwise, call the splitting processing steps for the splitting node in the branches of this splitting node to obtain the current process DAG, determine the aggregation node corresponding to this splitting node, construct the node set of this aggregation node based on this aggregation node and the nodes between it and this splitting node, and create a virtual node corresponding to this aggregation node to replace the subgraph corresponding to the node set of this aggregation node in the current process DAG to obtain a new process DAG; there is a directed edge from any node to the branches of this node.

3. The root cause location method for abnormal indicators facing complex processes according to claim 2, characterized in that Based on the influence degrees of the initial nodes and adjacent node corresponding transformation processes in each transformation branch on the key indicator, the influence degrees of the end nodes of each transformation branch corresponding to the key indicator on this virtual node, and the influence degree of this virtual node on the abnormal indicator, determining the influence degrees of the initial nodes and adjacent node corresponding transformation processes in each transformation branch on the abnormal indicator includes: For the initial node in any transformation branch, calculate the product of the influence degree of the initial node in this transformation branch on the key indicator of the same transformation branch, the influence degree of the end node of the transformation branch corresponding to the key indicator on this virtual node, and the influence degree of this virtual node on the abnormal indicator, as the influence degree of the initial node in this transformation branch on the abnormal indicator; For the transformation processes corresponding to adjacent nodes in any transformation branch, calculate the product of the influence degree of the transformation processes corresponding to adjacent nodes in this transformation branch on the key indicator of the same transformation branch, the influence degree of the end node of the transformation branch corresponding to the key indicator on this virtual node, and the influence degree of this virtual node on the abnormal indicator, and use it as the influence degree of the transformation processes corresponding to adjacent nodes in this transformation branch on the abnormal indicator; Among them, the influence degree of the end node of the transformation branch corresponding to any key indicator on this virtual node is the ratio of the difference in the indicator of this key indicator between this cycle and the previous cycle to the difference in the indicator associated with the aggregation node corresponding to this virtual node in the initial process DAG between this cycle and the previous cycle.

4. The root cause location method for abnormal indicators in complex processes according to claim 3, characterized in that Based on this shunt node, the transformation processes corresponding to this shunt node and the initial nodes of each branch, and the influence degrees of the transformation processes corresponding to adjacent nodes of each branch on the key indicator, the influence degrees of the end nodes of each branch corresponding to the key indicator on this virtual node, and the influence degree of the transformation process corresponding to this shunt node and this virtual node on the abnormal indicator, determine the influence degrees of this shunt node, the transformation processes corresponding to this shunt node and the initial nodes of each branch, and the transformation processes corresponding to adjacent nodes of each branch on the abnormal indicator, including: For this shunt node, calculate the product of the influence degree of this shunt node on the key indicator in any branch, the influence degree of the end node of the branch corresponding to the key indicator on this virtual node, and the influence degree of the transformation process corresponding to this shunt node and this virtual node on the abnormal indicator, and use it as the influence degree of this shunt node on the abnormal indicator; For any transformation process among the transformation processes corresponding to this shunt node and the initial nodes of each branch and the transformation processes corresponding to adjacent nodes of each branch, calculate the product of the influence degree of this transformation process on the key indicator of the same branch, the influence degree of the end node of the branch corresponding to the key indicator on this virtual node, and the influence degree of the transformation process corresponding to this shunt node and this virtual node on the abnormal indicator, and use it as the influence degree of this transformation process on the abnormal indicator.

5. The root cause location method for abnormal indicators facing complex processes according to claim 1, characterized in that, Starting from the node corresponding to the abnormal indicator in the initial process DAG, traverse the initial process DAG in reverse, and based on the influence degrees of the initial node of the initial process DAG and the transformation processes corresponding to any two adjacent nodes on the abnormal indicator, determine the root cause location path of the abnormal indicator, including: Starting from the node corresponding to the abnormal metric, traverse the initial process DAG in reverse. If the currently visited node is an aggregation node and the change direction of the metric value of the currently visited node is the same as that of the abnormal metric, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node in descending order, and use the greedy strategy to sequentially select the transformation branches with positive influence degrees greater than the preset threshold until the sum of the influence degrees of the end nodes of the selected transformation branches on the currently visited node is greater than the preset threshold, and then continue to traverse in reverse along the selected transformation branch; if the change direction of the metric value of the currently visited node is different from that of the abnormal metric, sort the influence degrees of the end nodes of each transformation branch of the currently visited node on the currently visited node in descending order of absolute value, and use the greedy strategy to sequentially select the transformation branches with negative influence degrees and absolute values greater than the preset threshold until the sum of the absolute values of the influence degrees of the end nodes of the selected transformation branches on the currently visited node is greater than the preset threshold, and then continue to traverse in reverse along the selected transformation branch; traverse in reverse until reaching a node with an in-degree of 0 to obtain the root cause location path of the abnormal metric.

6. The root cause location method for abnormal indicators facing complex processes according to claim 5, characterized in that After determining the root cause location path of the abnormal metric, it further includes: Calculating the root cause discrimination degree of each root cause location path, and selecting the root cause location path with the largest root cause discrimination degree as the most significant root cause location path; Among them, the root cause discrimination degree of any root cause location path i is calculated based on the following method: C(i)=α× +β× Among them, C(i) is the root cause discrimination degree of the root cause location path i; α and β are custom coefficients, and α + β = 1; IR global (v) is the influence degree of the transformation process corresponding to the initial node or any adjacent node within the root cause location path i on the abnormal index; std(i) is the standard deviation of the influence degrees of the transformation processes corresponding to the initial node and each adjacent node within the root cause location path i on the abnormal index, and k is the number of root cause location paths.

7. A root cause location system for abnormal indicators in complex processes, characterized in that, including: An initial DAG construction module for constructing an initial process DAG based on the current business process and establishing the association between each node in the initial process DAG and its metric; The nodes of the initial process DAG correspond to the business stages or task units where the abnormal metric is located and the business stages or task units before them; A DAG abstraction module for abstracting the aggregation nodes and shunt nodes in the initial process DAG to obtain a backbone process DAG; The in-degree of the aggregation node is greater than 1, and the out-degree of the shunt node is greater than 1; An influence degree calculation module for calculating the influence degrees of the initial node in the backbone process DAG and the transformation process corresponding to any two adjacent nodes on the abnormal metric; traverse the backbone process DAG in the forward direction. If the currently visited node is a virtual node and there is no shunt node pointing to this node, call the aggregation node drilling step for the currently visited node and then continue to traverse. If the currently visited node is a shunt node in the initial process DAG and this node is connected to a virtual node through a directed edge, call the shunt node drilling step for the currently visited node and the virtual node it is connected to and then continue to traverse; Among them, the aggregation node drill-down step for any virtual node includes: constructing each transformation branch of the aggregation node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; using the indicators corresponding to the end nodes of each transformation branch of the aggregation node as key indicators, calculating the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the key indicators, and determining the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the abnormal indicator based on the influence degrees of the transformation processes corresponding to the initial nodes and adjacent nodes in each transformation branch on the key indicator, the influence degrees of the end nodes of each transformation branch corresponding to the key indicator on the virtual node, and the influence degree of the virtual node on the abnormal indicator; if a virtual node is included in each transformation branch, calling the aggregation node drill-down step for the virtual node in the corresponding transformation branch; The split node drill-down step for any split node and the virtual node connected thereto includes: constructing each branch of the split node based on the node set of the aggregation node corresponding to the virtual node in the initial process DAG; using the indicators corresponding to the end nodes of each branch of the split node as key indicators, calculating the influence degrees of the split node, the transformation processes corresponding to the initial nodes of the split node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key indicator, and determining the influence degrees of the split node, the transformation processes corresponding to the initial nodes of the split node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the abnormal indicator based on the influence degrees of the split node, the transformation processes corresponding to the initial nodes of the split node and each branch, and the transformation processes corresponding to the adjacent nodes of each branch on the key indicator, the influence degrees of the end nodes of each branch corresponding to the key indicator on the virtual node, and the influence degree of the transformation process corresponding to the split node and the virtual node on the abnormal indicator; if a virtual node is included in each branch, calling the split node drill-down step for the split node corresponding to the virtual node in the initial process DAG and the virtual node in the corresponding branch; The root cause location path output module is used to traverse the initial process DAG in reverse starting from the node corresponding to the abnormal indicator in the initial process DAG, and determine the root cause location path of the abnormal indicator based on the influence degrees of the transformation processes corresponding to the initial node and any two adjacent nodes of the initial process DAG on the abnormal indicator; The root cause diagnosis Q&A system module is used to record the abnormal manifestations of the abnormal indicators and the root cause information determined manually, forming an abnormal record document; using the GraphRAG technology to extract entity and relationship information from the abnormal record document, generating communities and community summaries, and constructing a knowledge graph; when the user conducts a root cause diagnosis query, receiving the root cause diagnosis question and context information input by the user to the root cause diagnosis Q&A system; the context information includes the root cause path and the information of relevant indicators for the transformation of a certain abnormal stage; the system retrieves the knowledge graph based on the root cause diagnosis question and context information, obtains the community summary with the highest semantic similarity to the query, and inputs the matching community summary in the knowledge graph as a prompt to the large language model at the back end; the large language model summarizes the input, further feeds back the result to the user, and determines the root cause generated by the transformation of the abnormal stage.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the root cause localization method for abnormal indicators in complex processes as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • A method and system for locating the root cause of indicator abnormality in process stages

    CN113011707B

  • Access method, device and system for relational node data of directed acyclic graph

    CN102541875A

  • Root cause positioning method and system for index anomaly in process stage

    CN113011707A

  • Root cause determination method and device and storage medium

    CN116974805A

  • GraphRAG-based large model question and answer method, system and equipment, medium and product

    CN119558401A