Wavelength division device alarm analysis method and device, electronic device, and storage medium
By constructing an alarm root cause tree and using association rule learning algorithms to process current and historical alarm data of WDM devices, the problem of inaccurate fault location of WDM devices in complex network environments is solved, thereby improving fault diagnosis efficiency and operation and maintenance efficiency.
Patent Information
- Application Number
- CN202411997448.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Existing alarm analysis methods for wavelength division multiplexing (WDM) equipment are difficult to accurately locate faults in complex and dynamic network environments, cannot effectively handle a large number of chain reaction alarms, and lack systematic templates and hierarchical correlation analysis, resulting in low fault diagnosis efficiency.
By acquiring the current alarm data of the wavelength division multiplexing (WDM) device, an alarm root cause tree is constructed. Historical alarm data is processed using a preset association rule learning algorithm to determine association rules and frequent itemsets, generating an alarm root factor tree, and then determining the alarm root cause result tree, outputting the alarm analysis results.
It enables rapid and accurate location of faults in complex network environments, improving network operation and maintenance efficiency and reducing the risk of business interruption.
Smart Images

Figure CN119865422B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and more specifically, to a method, apparatus, electronic device, and storage medium for analyzing alarms in wavelength division multiplexing (WDM) equipment. Background Technology
[0002] Wavelength Division Multiplexing (WDM) equipment, as a key device in modern optical fiber communication networks, enables simultaneous transmission of multiple channels. By transmitting multiple optical signals of different wavelengths simultaneously on a single optical fiber, it can improve the transmission capacity and efficiency of the fiber. However, with the continuous expansion and increasing complexity of optical networks, faults and abnormal events encountered by WDM equipment during operation often do not occur in isolation but may trigger a series of related alarms, including redundant alarms, correlated alarms, and flash alarms. These alarms are not only numerous but also have complex direct or indirect causal relationships. When serious alarms occur and are not resolved in a timely manner, they will directly affect the continuity of services, leading to service interruptions and posing a severe challenge to network operation and maintenance. Alarm analysis methods for WDM equipment in related technologies typically employ rule-based matching strategies combined with simple statistical analysis techniques to achieve rapid identification and classification of equipment alarms, as well as preliminary fault location. However, the alarm analysis methods for wavelength division multiplexing (WDM) devices in related technologies rely on predefined rules and statistical patterns of historical alarm data to analyze the correlation between current alarms and historical alarms. They lack a hierarchical relationship of systematic templates, making it difficult to accurately locate the root cause of faults in complex and dynamically changing network environments.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This disclosure provides a method, apparatus, electronic device, and storage medium for analyzing alarms in wavelength division multiplexing (WDM) equipment, which at least solves the technical problems of WDM equipment alarm analysis methods provided in related technologies, such as difficulty in accurately locating faults in complex dynamic network environments, inability to effectively handle a large number of chain reaction alarms, and lack of systematic templates and hierarchical correlation analysis, resulting in low fault diagnosis efficiency.
[0005] According to one aspect of the present disclosure, a method for alarm analysis of a wavelength division multiplexing (WDM) device is provided, comprising: acquiring current alarm data of the WDM device; constructing an alarm root factor tree based on the current alarm data and a pre-constructed alarm root factor tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data; determining an alarm root cause result tree based on the current alarm data and the alarm root factor tree, wherein the alarm root cause result tree includes an alarm list and alarm handling suggestions; and outputting alarm analysis results based on the alarm root cause result tree.
[0006] Optionally, alarm data includes: alarm time, alarm type, alarm level, and device identifier.
[0007] Optionally, the construction of the alarm root cause tree includes: acquiring historical alarm data, wherein the historical alarm data includes multiple alarm data corresponding to multiple wavelength division multiplexing devices; processing the historical alarm data using a preset association rule learning algorithm to determine association rules; and determining the alarm root cause tree based on the association rules and the historical alarm data.
[0008] Optionally, the historical alarm data is processed using a preset association rule learning algorithm to determine association rules, including: traversing the historical alarm data based on the preset association rule learning algorithm to determine the support of each individual alarm, wherein the historical alarm data includes multiple individual alarms; determining frequent itemsets based on the support and a preset support threshold; determining rule confidence based on the frequent itemsets; and determining association rules based on the rule confidence and a preset confidence threshold.
[0009] Optionally, the alarm root cause tree is determined based on association rules and historical alarm data, including: determining the root node from historical alarm data according to preset root node confirmation rules; determining child nodes according to association rules, the root node and historical alarm data; and constructing the alarm root cause tree based on the root node and child nodes.
[0010] Optionally, an alarm root factor tree is constructed based on the current alarm data and the pre-built alarm root cause tree, including: matching alarm root cause nodes from the alarm root cause tree based on the current alarm data; determining associated nodes from the alarm root cause tree based on the alarm root cause nodes; and determining the alarm root factor tree based on the associated nodes and the root cause nodes.
[0011] Optionally, the alarm root cause node types include first-level nodes, second-level nodes, and third-level nodes. Based on the alarm root cause node, associated nodes are determined from the alarm root cause tree, including: in response to the alarm root cause node being a first-level node, determining the associated node as a null value; or, in response to the alarm root cause node being a second-level node, determining the first-level and third-level nodes associated with the alarm root cause node as associated nodes; or, in response to the alarm root cause node being a third-level node, determining the second-level and first-level nodes associated with the alarm root cause node as associated nodes.
[0012] Optionally, based on the current alarm data and the alarm root factor tree, an alarm root cause result tree is determined, including: obtaining associated alarm data related to the current alarm data based on the alarm root factor tree; matching the associated alarm data to the alarm root factor tree and adding alarm handling suggestions to the alarm root factor tree to obtain the alarm root cause result tree.
[0013] According to one embodiment of this disclosure, a wavelength division multiplexing (WDM) equipment alarm analysis apparatus is also provided, comprising: an acquisition module for acquiring current alarm data of the WDM equipment; a construction module for constructing an alarm root factor tree based on the current alarm data and a pre-constructed alarm root factor tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data; a determination module for determining an alarm root cause result tree based on the current alarm data and the alarm root factor tree, wherein the alarm root cause result data includes an alarm list and alarm suggestions; and an output module for outputting alarm analysis results based on the alarm root cause result tree.
[0014] Optionally, the construction module is also used to: acquire historical alarm data, wherein the historical alarm data includes various alarm data corresponding to various wavelength division multiplexing devices; process the historical alarm data using a preset association rule learning algorithm to determine association rules; and determine the alarm root cause tree based on the association rules and the historical alarm data.
[0015] Optionally, the construction module is also used to: traverse historical alarm data based on a preset association rule learning algorithm to determine the support of each individual alarm, wherein the historical alarm data includes multiple individual alarms; determine frequent itemsets based on the support and a preset support threshold; determine rule confidence based on the frequent itemsets; and determine association rules based on the rule confidence and a preset confidence threshold.
[0016] Optionally, the construction module is also used to: determine the root node from historical alarm data according to the preset root node confirmation rules; determine the child nodes according to the association rules, the root node and the historical alarm data; and construct the alarm root cause tree according to the root node and the child nodes.
[0017] Optionally, the building module is also used to: match alarm root cause nodes from the alarm root cause tree based on the current alarm data; determine associated nodes from the alarm root cause tree based on the alarm root cause nodes; and determine the alarm root factor tree based on the associated nodes and root cause nodes.
[0018] Optionally, the building module is also configured to: determine that the associated node is null in response to the alarm root cause node being a first-level node; or, determine that the first-level and third-level nodes associated with the alarm root cause node are associated nodes in response to the alarm root cause node being a second-level node; or, determine that the second-level and first-level nodes associated with the alarm root cause node are associated nodes in response to the alarm root cause node being a third-level node.
[0019] Optionally, the determination module is also used to: obtain associated alarm data related to the current alarm data based on the alarm root factor tree; match the associated alarm data to the alarm root factor tree and add alarm handling suggestions to the alarm root factor tree to obtain the alarm root cause result tree.
[0020] According to one embodiment of this disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure when it runs.
[0021] According to one embodiment of this disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the storage medium is located to execute the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure.
[0022] According to one embodiment of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure.
[0023] In this embodiment, by acquiring the current alarm data of the wavelength division multiplexing (WDM) device, constructing an alarm root factor tree based on the current alarm data and a pre-built alarm root cause tree, determining the alarm root cause result tree based on the current alarm data and the alarm root factor tree, and finally outputting the alarm analysis results based on the alarm root cause result tree, the goal of quickly and accurately locating the root cause of faults in complex network environments is achieved. This improves network operation and maintenance efficiency and reduces the risk of service interruption. It also solves the technical problems of the WDM device alarm analysis methods provided in related technologies, such as difficulty in accurately locating faults in complex dynamic network environments, inability to effectively handle a large number of chain reaction alarms, and lack of systematic templates and hierarchical correlation analysis, resulting in low fault diagnosis efficiency. Attached Figure Description
[0024] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this disclosure, illustrate exemplary embodiments of the present disclosure and are used to explain the disclosure, but do not constitute an undue limitation of the disclosure. In the drawings:
[0025] Figure 1 This is a flowchart of an alarm analysis method for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure;
[0026] Figure 2 This is a schematic diagram of an alarm analysis method for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure;
[0027] Figure 3 This is a schematic diagram of an alarm analysis system for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure;
[0028] Figure 4 This is a schematic diagram of another wavelength division multiplexing (WDM) device alarm analysis method according to one embodiment of the present disclosure;
[0029] Figure 5This is a schematic diagram of another wavelength division multiplexing (WDM) device alarm analysis method according to one embodiment of the present disclosure;
[0030] Figure 6 This is a structural block diagram of a wavelength division multiplexing (WDM) device alarm analysis apparatus according to one embodiment of the present disclosure. Detailed Implementation
[0031] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.
[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0033] Alarm analysis methods for wavelength division multiplexing (WDM) devices in related technologies typically employ rule-based matching strategies combined with simple statistical analysis techniques to achieve rapid identification and classification of device alarms, as well as preliminary fault location. However, these methods rely on predefined rules and statistical patterns of historical alarm data to analyze the correlation between current and historical alarms, lacking a systematic hierarchical framework. Consequently, they struggle to accurately pinpoint the root cause of faults in complex and dynamically changing network environments.
[0034] Specifically, rule-based alarm analysis methods for wavelength division multiplexing (WDM) devices, limited by their static rule sets and reliance on historical data, often fail to dynamically adapt to real-time network changes and emerging fault modes. When processing current alarms, they cannot effectively distinguish between derivative alarms and core issues, leading to the analysis process being potentially interfered with by a large amount of non-critical information and increasing the risk of misjudgment. Furthermore, the methods in these technologies do not fully consider the inherent connections between alarm levels and types when constructing alarm correlation models, lacking a template that can systematically and intuitively display the causal chain between alarms. Therefore, when facing complex network architectures and intertwined multi-level alarms, they cannot accurately pinpoint the root cause of faults. Especially when the network environment undergoes large-scale upgrades or architectural adjustments, or when new faults appear for the first time, the limitations of preset rules and the lag in historical data jointly weaken the accuracy and response speed of alarm analysis, making it difficult to provide effective fault diagnosis and resolution suggestions in a timely manner, thus delaying service recovery time and increasing the burden on network operations and maintenance.
[0035] According to an embodiment of this disclosure, a method embodiment for alarm analysis of wavelength division multiplexing (WDM) devices is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0036] This method embodiment can be executed in an electronic device or similar computing device that includes memory and a processor. Taking a computer terminal as an example, the computer terminal may include one or more processors (processors may include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), digital signal processing (DSP) chips, microcontroller units (MCUs), field-programmable gate arrays (FPGAs), neural network processors (NPUs), tensor processors (TPUs), artificial intelligence (AI) type processors, etc.) and memory for storing data. Optionally, the computer terminal may also include transmission devices, input / output devices, and display devices for communication functions. Those skilled in the art will understand that the above structural description is merely illustrative and does not limit the structure of the computer terminal. For example, the computer terminal may include more or fewer components than described above, or have a different configuration than described above.
[0037] The memory can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the wavelength division multiplexing (WDM) device alarm analysis method in this embodiment. The processor executes various functional applications and data processing by running the computer program stored in the memory, thereby realizing the aforementioned WDM device alarm analysis method. The memory may include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks (LANs), mobile communication networks, and combinations thereof.
[0038] The transmission device is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0039] Display devices can be, for example, touchscreen liquid crystal displays (LCDs) and touch displays (also referred to as "touchscreens" or "touch displays"). The LCD allows users to interact with the user interface of the mobile terminal. In some embodiments, the mobile terminal has a graphical user interface (GUI), which allows users to interact with the GUI through finger contact and / or gestures on a touch-sensitive surface. Optional human-computer interaction functions include: creating web pages, drawing, word processing, creating electronic documents, playing games, video conferencing, instant messaging, sending and receiving emails, call interfaces, playing digital video, playing digital music, and / or web browsing, etc. Executable instructions for performing the above human-computer interaction functions are configured / stored in one or more processor-executable computer program products or readable storage media.
[0040] Figure 1 This is a flowchart of an alarm analysis method for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure, such as... Figure 1 As shown, the method includes the following steps:
[0041] Step S11: Obtain the current alarm data of the wavelength division multiplexing (WDM) device;
[0042] Step S12: Based on the current alarm data and the pre-built alarm root cause tree, construct the alarm root factor tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data.
[0043] Step S13: Determine the alarm root cause result tree based on the current alarm data and alarm root factor tree. The alarm root cause result tree includes the alarm list and alarm handling suggestions.
[0044] Step S14: Output alarm analysis results based on the alarm root cause result tree.
[0045] The aforementioned wavelength division multiplexing (WDM) equipment refers to communication equipment that utilizes wavelength division multiplexing (WDM) technology in optical fiber communication networks. It is mainly divided into two categories: dense wavelength division multiplexing (DWDM) equipment and coarse wavelength division multiplexing (CWDM) equipment. Furthermore, WDM equipment can be further subdivided based on its physical form and functional characteristics: box-type WDM equipment and rack-mounted WDM equipment. These WDM devices achieve channel multiplexing by simultaneously transmitting multiple optical signals of different wavelengths in a single optical fiber, thereby greatly improving the transmission capacity of the optical fiber and the data transmission efficiency of the network. Specifically, WDM equipment typically includes components such as optical amplifiers, demultiplexers, multiplexers, tunable laser sources, and optical monitoring channels, providing high-bandwidth, low-latency data transmission services in scenarios such as long-distance transmission and data center interconnection. When a WDM device malfunctions or experiences an anomaly, it generates corresponding alarm data to indicate the health status of the equipment or network, helping maintenance personnel to promptly identify and resolve problems, ensuring stable network operation.
[0046] The aforementioned alarm root cause tree refers to a multi-level, structured fault correlation model constructed through in-depth analysis of a large amount of historical alarm data in wavelength division multiplexing network device management. Specifically, the alarm root cause tree uses data mining and machine learning techniques to process alarm data, identify the correlations and potential causal chains between different alarms, thereby forming a tree structure with a certain alarm as the root node and other related or derived alarms as child nodes.
[0047] The aforementioned alarm root factor tree refers to an analysis tree structure dynamically generated and specific to the current alarm context in wavelength division multiplexing (WDM) equipment alarm analysis, based on the specific alarm data generated by the current equipment and a pre-built alarm root factor tree model. Specifically, when a WDM equipment reports a new alarm, the system will filter and match nodes related to the current alarm from the alarm root factor tree through the alarm root factor tree construction process, forming a subtree structure centered on the current alarm and containing its potential causes and effects.
[0048] The aforementioned alarm root cause tree refers to a tree structure obtained through a series of data analyses and matching algorithms during the alarm analysis process of wavelength division multiplexing (WDM) equipment. This structure visually displays the causal relationship between the current alarm and its related alarms, along with suggested handling methods. It not only contains detailed alarm information but also clarifies the hierarchical relationships and correlations between alarms through the construction and matching of the alarm root cause tree, as well as fault handling suggestions based on alarm analysis.
[0049] For example, suppose a WDM (Wavelength Division Multiplexing) device suddenly reports an alarm. The WDM alarm analysis system then initiates the alarm analysis process. First, the alarm acquisition module receives the current alarm data reported by the WDM device via the NETCONF protocol. Second, the WDM alarm analysis system cross-compares the current alarm data with a pre-built alarm root cause tree model to construct a subtree structure reflecting the root cause of the current alarm data, i.e., the alarm root factor tree. Further, combining the alarm root factor tree with detailed information about the current alarm data, the WDM alarm analysis system deeply analyzes the correlation between alarms, generating an alarm root cause result tree. Finally, the alarm display module presents the completed alarm root cause result tree in an intuitive and user-friendly interface, making fault location clear and easy to understand, and providing readily available handling suggestions for each alarm, thereby enhancing operational convenience.
[0050] Based on the above steps S11 to S14, by acquiring the current alarm data of the wavelength division multiplexing (WDM) device, and constructing an alarm root factor tree based on the current alarm data and the pre-built alarm root cause tree, the alarm root cause result tree is determined based on the current alarm data and the alarm root factor tree. Finally, the alarm analysis results are output based on the alarm root cause result tree. This achieves the goal of quickly and accurately locating the root cause of faults in complex network environments, thereby improving network operation and maintenance efficiency and reducing the risk of service interruption. It also solves the technical problems of the WDM device alarm analysis methods provided in related technologies, such as difficulty in accurately locating faults in complex and dynamic network environments, inability to effectively handle a large number of chain reaction alarms, and lack of systematic templates and hierarchical correlation analysis, resulting in low fault diagnosis efficiency.
[0051] The alarm analysis method for wavelength division multiplexing (WDM) equipment in the embodiments of this disclosure will be further described below.
[0052] Optionally, in step S11, the alarm data includes: alarm time, alarm type, alarm level, and device identifier.
[0053] The alarm time mentioned above refers to the precise time point at which the wavelength division multiplexing (WDM) device detects and generates an alarm. It is usually represented by a timestamp and is used to record the specific moment when the alarm first occurs or the state changes.
[0054] The alarm types mentioned above refer to the classification of various specific abnormal situations occurring in wavelength division multiplexing (WDM) equipment, including but not limited to optical module mismatch, uplink interruption, downlink interruption, and optical module loss. Uplink interruption includes received signal loss, transmitted signal loss, Ethernet signal out of synchronization, Ethernet signal loss, and excessive input optical power; downlink interruption includes remote received signal loss and excessive remote input optical power; optical module loss includes laser lifetime warning alarms, laser transmission failure, signal loss, and input optical signal loss alarms.
[0055] The alarm levels mentioned above refer to the severity classification of alarms occurring in wavelength division multiplexing (WDM) equipment. Typically, alarm levels are categorized from highest to lowest as "urgent," "important," "minor," and "noticeable."
[0056] 1) Emergency: This indicates the most serious fault, which may have already caused or is about to cause the entire system to stop operating, requiring immediate action.
[0057] 2) Important: Indicates a serious fault that may affect some functions of the system, but the system can still operate and needs to be resolved as soon as possible.
[0058] 3) Minor: Indicates a minor fault that generally does not immediately affect system operation, but if left unaddressed, it may develop into a more serious problem.
[0059] 4) Prompt: Indicates some abnormal state of the equipment or system, but not enough to constitute a fault. It is used to prompt maintenance personnel that there may be potential problems that need attention.
[0060] The aforementioned device identifier refers to a specific identifier used to uniquely identify each device in a wavelength division network. It can be the device's serial number, MAC address, IP address, device name, or any other information that can ensure the device's unique identity in the network environment.
[0061] For example, suppose that at a certain point in time, a wavelength division multiplexing (WDM) device reports alarm data, with the following details:
[0062] Alarm time: 2023-04-05 14:30:00;
[0063] Alarm type: Signal loss;
[0064] Alarm level: Important;
[0065] Device Identifier: IP address: 192.168.1.5 or device name: WDM-EdgeNode-01.
[0066] The alarm data above indicates that at 14:30 on April 5, 2023, the device WDM-EdgeNode-01 (or its IP address 192.168.1.5) detected a signal loss alarm, indicating that there was a problem with the received signal. This alarm was marked as "important", meaning that it needs to be dealt with as soon as possible to avoid potential impact on network services.
[0067] Based on the above optional embodiments, the information such as timestamps, types, levels, and device identifiers contained in the alarm data can be used for subsequent fault analysis and historical records, helping the operation and maintenance team to summarize fault modes and optimize network design and maintenance processes.
[0068] Optionally, in step S12, the construction of the alarm root cause tree includes:
[0069] Step S121: Obtain historical alarm data, wherein the historical alarm data includes various alarm data corresponding to various wavelength division multiplexing devices;
[0070] Step S122: Process historical alarm data using a preset association rule learning algorithm to determine association rules;
[0071] Step S123: Determine the alarm root cause tree based on the association rules and historical alarm data.
[0072] The aforementioned pre-defined association rule learning algorithm refers to a statistical method used in data mining, aiming to discover strong correlations between different alarm events from a large amount of alarm data, that is, alarm combinations that frequently occur simultaneously in the alarm dataset. Specifically, the pre-defined association rule learning algorithm can be an Apriori algorithm, a Frequent Pattern Growth Algorithm (FP-growth algorithm), an Equivalence Class Clustering and Bottom-up Lattice Traversal (ECLAT algorithm), etc.
[0073] For example, firstly, a data acquisition module extracts various alarm data corresponding to different wavelength division multiplexing (WDM) devices from their historical operational data. This historical alarm data is then cleaned and encoded to remove duplicate, erroneous, and incomplete alarm data. Simultaneously, textual information such as alarm types is converted into numerical codes for algorithm processing. Secondly, the Apriori algorithm is used to process the collected historical alarm data, identifying frequently occurring combinations of alarm events and determining strong correlation rules between these events. Finally, based on the mined correlation rules and the original historical alarm data, an alarm root cause tree is constructed.
[0074] Based on the above optional embodiments, the association rule learning algorithm can reveal the potential causal relationship between different alarm events, so that the generated alarm root cause tree can more accurately reflect the causal chain of equipment failure, help operation and maintenance personnel to diagnose and solve problems more accurately, and thus improve the accuracy and efficiency of alarm analysis.
[0075] Optionally, in step S122, the historical alarm data is processed using a preset association rule learning algorithm to determine association rules, including:
[0076] Step S1221: Based on the preset association rule learning algorithm, the historical alarm data is traversed to determine the support level of each individual alarm. The historical alarm data includes multiple individual alarms.
[0077] Step S1222: Determine frequent itemsets based on support and a preset support threshold;
[0078] Step S1223: Determine the rule confidence based on frequent itemsets;
[0079] Step S1224: Determine the association rule based on the rule confidence and the preset confidence threshold.
[0080] The support mentioned above refers to the frequency of a single alarm or alarm combination occurring in a historical alarm dataset. Specifically, in association rule learning, support is a metric that measures the prevalence of a particular itemset (such as a certain alarm or alarm combination) in the dataset.
[0081] The aforementioned frequent itemsets refer to the set of items in a dataset whose frequency of occurrence exceeds or equals a preset threshold. In the method of wavelength division multiplexing (WDM) device alarm analysis, a frequent itemset specifically refers to a set containing one or more alarm events, wherein the number of times these alarm events co-occur in historical alarm data is greater than or equal to a preset support threshold.
[0082] The confidence level of the above rule refers to the proportion of all samples containing event A, in which event B also occurs. It is used to measure the reliability of the prediction of event B by association rules when event A is known to have occurred.
[0083] For example, in the scenario of alarm analysis for wavelength division multiplexing (WDM) devices, rule confidence can help determine possible causal relationships between alarm events. For instance, if a rule states "the probability that alarm B will also occur when alarm A occurs is X%", then the confidence level X% reflects the frequency with which alarm B occurs in the presence of alarm A. A high confidence level means that when alarm A occurs, the probability of alarm B occurring is high, thus indicating that alarm A may be a possible cause or triggering condition for alarm B.
[0084] For example, assuming the preset association rule learning algorithm is the Apriori algorithm, the support level of each individual alarm can be determined through the calculation process shown in formula (1):
[0085]
[0086] Where Support(A) is the support level for each individual alarm; A is the itemset; count(A) is the number of transactions containing itemset A; and N is the total number of transactions.
[0087] For example, firstly, the entire historical alarm dataset is traversed, and the support of each individual alarm is calculated using formula (1). If the support of an individual alarm is greater than or equal to a preset support threshold, it is added to a frequent 1-itemset. Subsequently, frequent 2-itemsets, frequent 3-itemsets, etc., are generated iteratively until no larger frequent itemsets satisfying the preset support threshold can be generated.
[0088] For example, assuming a preset support threshold of 30%, the historical alarm dataset contains the following alarm events:
[0089] 1) Optical module lost (EQPT_TRANSCEIVER_MISSING);
[0090] 2) Communication failure (COMM_FAIL);
[0091] 3) Received signal lost (RX_LOS);
[0092] 4) Transmit signal lost (TX_LOS).
[0093] The alarm record update table of the historical alarm dataset is shown in Table 1:
[0094] Table 1 Alarm Log Update Table
[0095]
[0096] In Table 1:
[0097] 1) EQPT_TRANSCEIVER_MISSING: It appears 4 times, and its support is 0.364, which is greater than the preset support threshold;
[0098] 2) COMM_FAIL: It appears 5 times, and its support is 0.455, which is greater than the preset support threshold;
[0099] 3) RX_LOS: Occurred 7 times, with a support of 0.636, which is greater than the preset support threshold;
[0100] 4) TX_LOS: It appears 4 times, and its support is 0.364, which is greater than the preset support threshold.
[0101] Therefore, the frequent 1-item set includes: [EQPT_TRANSCEIVER_MISSING, COMM_FAIL, RX_LOS, TX_LOS].
[0102] Furthermore, in frequent 1-item concentrations:
[0103] 1) EQPT_TRANSCEIVER_MISSING, COMM_FAIL: If it occurs twice, its support is 0.182, which is less than the preset support threshold.
[0104] 2) EQPT_TRANSCEIVER_MISSING, RX_LOS: Occurs 3 times, its support is 0.273, which is less than the preset support threshold.
[0105] 3) EQPT_TRANSCEIVER_MISSING, TX_LOS: Occurs twice, its support is 0.182, which is less than the preset support threshold.
[0106] 4) COMM_FAIL, RX_LOS: These occur 3 times, and their support is 0.273, which is less than the preset support threshold.
[0107] 5) COMM_FAIL, TX_LOS: These occur 0 times, so they are not considered.
[0108] 6) RX_LOS, TX_LOS: appear 4 times, their support is 0.364, which is greater than the preset support threshold.
[0109] Therefore, frequent 2-itemsets include: [RX_LOS, TX_LOS]. Since no combination can form a frequent 3-itemset that satisfies the support threshold, no higher-order frequent itemsets are generated.
[0110] For example, after determining the frequent itemsets, the rule confidence can be calculated according to formula (2):
[0111]
[0112] Here, A and B are two different itemsets; A→B represents the association rule from itemset A to itemset B; Support(A∪B) represents the proportion of samples where itemsets A and B occur simultaneously to the total number of samples; and Confidence(A→B) represents the rule confidence between itemsets A and B.
[0113] For example, taking the frequent 2-itemset constructed above as an example, since the frequent 2-itemset only contains [RX_LOS, TX_LOS], the rule confidence and association rules calculated according to formula (2) are as follows:
[0114] (1) Association rules:
[0115] 1) Rule 1: (RX_LOS→TX_LOS) (Loss of received signal leads to loss of transmitted signal);
[0116] 2) Rule 2: (TX_LOS→RX_LOS) (loss of transmitted signal leads to loss of received signal).
[0117] (2) The rule confidence level is:
[0118] 1)Confidence(RX_LOS→TX_LOS)=0.571;
[0119] 2)Confidence(TX_LOS→RX_LOS)=1.
[0120] Based on the above analysis, the confidence level of rule 2: (TX_LOS→RX_LOS) is 1, that is, 100%, which means that when TX_LOS (transmit signal loss) occurs, RX_LOS (receive signal loss) will definitely also occur, thus revealing that TX_LOS may be the direct cause or triggering condition of RX_LOS.
[0121] Based on the above optional embodiments, by using a preset association rule learning algorithm to process historical alarm data, it is possible not only to identify frequently occurring alarm events and their combinations, but also to identify possible causal relationships between alarm events by calculating rule confidence, thereby generating high-confidence association rules. This helps operation and maintenance personnel to identify possible root causes of faults more quickly and accurately when dealing with current alarms, take effective solutions, improve operation and maintenance efficiency, and reduce the risk of business interruption.
[0122] Optionally, in step S123, the alarm root cause tree is determined based on association rules and historical alarm data, including:
[0123] Step S1231: Determine the root node from historical alarm data according to the preset root node confirmation rules;
[0124] Step S1232: Determine child nodes based on association rules, root node, and historical alarm data;
[0125] Step S1233: Construct the alarm root cause tree based on the root node and child nodes.
[0126] The root node mentioned above refers to a specific alarm event selected as the starting point of the alarm root cause tree in alarm analysis. In the alarm analysis scenario of wavelength division multiplexing (WDM) equipment, the root node is usually an alarm that occurs frequently, has a wide impact, or is considered to have a high priority for processing. This alarm may directly or indirectly trigger a series of other alarm events.
[0127] For example, suppose the EQPT_TRANSCEIVER_MISSING alarm event occurs frequently in historical data and often leads to a series of subsequent alarms, then this event may be selected as the root node.
[0128] The aforementioned child nodes refer to alarm events that are directly or indirectly triggered by the root node in the alarm root cause tree. Child nodes are located below the root node in the hierarchical structure and are connected to the root node or other child nodes through preset association rules, reflecting the causal relationship or correlation between alarm events.
[0129] For example, after determining the root node, a series of association rules are obtained through the Apriori algorithm or other association rule learning algorithms. For instance, the rule "EQPT_TRANSCEIVER_MISSING→COMM_FAIL" indicates that when an "optical module loss" alarm occurs, there is a high probability that a "communication failure" alarm will subsequently occur, with a confidence level of over 80%. Therefore, the "communication failure" alarm is identified as a direct child node of the "optical module loss" alarm. Furthermore, the historical alarm data is traversed to find other alarm events that are strongly correlated with "optical module loss" or "communication failure," such as "RX_LOS" and "TX_LOS," which may also be added as child nodes to the alarm root cause tree.
[0130] For example, an alarm root cause tree in the alarm analysis process is shown in Table 2:
[0131] Table 2 Alarm Root Cause Tree
[0132]
[0133] Table 2 (continued)
[0134] 010101 0101 EQPT_DEG Unit disk hardware degradation alarm HARDWARE 3 010102 0101 FAN_SPD_HIGH Fan speed too high HARDWARE 3 010103 0101 FAN_SPD_LOW Fan speed too low alarm HARDWARE 3 010104 0101 IN_CURR_ABN Input current abnormality alarm HARDWARE 3 010105 0101 IN_CURR_HIGH Input current overload alarm HARDWARE 3 010106 0101 IN_CURR_LOW Low input current alarm HARDWARE 3 010201 0102 EQPT_DEG Unit disk hardware degradation alarm HARDWARE 3 010202 0102 FAN_SPD_HIGH Fan speed too high HARDWARE 3 010203 0102 FAN_SPD_LOW Fan speed too low alarm HARDWARE 3 … … … … … …
[0135] In Table 2, the identifier is used to track, match, and manage alarm events in the database; the parent node ID is used to represent the directly associated node of the current node. In the alarm root cause tree, each node (except the root node) has a parent node, and the hierarchical relationship between nodes can be constructed through the parent node ID; "HARDWARE" usually refers to alarms related to physical hardware devices; "ETH" represents alarms related to Ethernet interfaces or communication; "OCH" represents alarms related to signal transmission and quality of optical channels; "OSC" represents alarms related to optical monitoring paths; and "LOCAL" usually refers to alarms related to the internal device or local operating environment.
[0136] Based on the above optional embodiments, an alarm root cause tree is constructed according to the root node and child nodes, which can help operation and maintenance personnel quickly and accurately locate problems, reduce troubleshooting time, improve decision-making quality, and provide automated analysis and suggestions to optimize resource allocation, thereby significantly enhancing network maintenance and service recovery capabilities.
[0137] Optionally, in step S12, an alarm root factor tree is constructed based on the current alarm data and the pre-built alarm root factor tree, including:
[0138] Step S21: Based on the current alarm data, match the alarm root cause node from the alarm root cause tree;
[0139] Step S22: Based on the alarm root cause node, determine the associated node from the alarm root cause tree;
[0140] Step S23: Determine the alarm root factor tree based on the associated nodes and root cause nodes.
[0141] For example, assuming the current alarm data is "EQPT_DEG", the node information directly related to "EQPT_DEG" in the alarm root cause tree shown in Table 2 is shown in Table 3:
[0142] Table 3 "EQPT_DEG" Related Nodes
[0143] 010101 0101 EQPT_DEG Unit disk hardware degradation alarm HARDWARE 3 010201 0102 EQPT_DEG Unit disk hardware degradation alarm HARDWARE 3
[0144] Furthermore, based on the identified "EQPT_DEG" associated node, tracing its root node reveals that the parent node of the "EQPT_DEG" associated node is shown in Table 4:
[0145] Table 4 Parent Node of “EQPT_DEG”
[0146] 0101 01 EQPT_MISMATCH Unit disk mismatch HARDWARE 2 0102 01 COMM_FAIL Communication failure HARDWARE 2
[0147] Furthermore, the parent nodes of "EQPT_MISMATCH" and "COMM_FAIL" are shown in Table 5:
[0148] Table 5 shows the parent nodes of "EQPT_MISMATCH" and "COMM_FAIL".
[0149]
[0150] In Table 5, the parent node ID of “EQPT_ABSENCE_WARNING” is 0, which means that the current alarm event has no parent node. That is, “EQPT_ABSENCE_WARNING” is the root cause node of “EQPT_DEG”.
[0151] For example, the alarm root factor tree can be determined based on the associated node and root cause node of "EQPT_DEG".
[0152] Based on the above optional embodiments, the alarm root factor tree is determined according to the associated nodes and root cause nodes, which can provide a more systematic, efficient and accurate fault analysis tool for network maintenance, help the operation and maintenance team to identify and solve network problems more quickly, thereby ensuring the stable operation of the network and the continuity of services.
[0153] Optionally, in step S22, the types of alarm root cause nodes include first-level nodes, second-level nodes, and third-level nodes. Based on the alarm root cause nodes, related nodes are determined from the alarm root cause tree, including:
[0154] Step S221: In response to the alarm root cause node being a first-level node, determine that the associated node is null.
[0155] Step S222, or, in response to the alarm root cause node being a second-level node, determine the first-level and third-level nodes associated with the alarm root cause node as associated nodes.
[0156] Step S223, or, in response to the alarm root cause node being a level 3 node, determine the level 2 and level 1 nodes associated with the alarm root cause node as associated nodes.
[0157] For example, still taking "EQPT_DEG" as an example, its root node "EQPT_ABSENCE_WARNING" is a first-level node, "EQPT_MISMATCH" and "COMM_FAIL" are second-level nodes, and "EQPT_DEG" itself is a third-level node.
[0158] Based on the above optional embodiments, by determining the hierarchy of alarm root cause nodes and correspondingly finding their associated nodes, a more accurate and targeted alarm root factor tree can be constructed, thereby significantly improving the efficiency of fault diagnosis and resolution.
[0159] Optionally, in step S13, an alarm root cause result tree is determined based on the current alarm data and the alarm root factor tree, including:
[0160] Step S131: Based on the alarm root factor tree, obtain the associated alarm data related to the current alarm data;
[0161] Step S132: Match the associated alarm data to the alarm root factor tree and add alarm handling suggestions to the alarm root factor tree to obtain the alarm root cause result tree.
[0162] For example, assuming the current alarm is a third-level node "EQPT_DEG", by traversing the node relationships in the alarm root factor tree, the WDM equipment alarm analysis system will find the nodes directly associated with "EQPT_DEG" in the alarm root factor tree, and continue to search for all second-level and first-level nodes directly or indirectly associated with the current alarm. Further, after obtaining the associated nodes of "EQPT_DEG", the WDM equipment alarm analysis system will collect information such as alarm time, alarm type, alarm level, and device identifier of the aforementioned associated nodes. After obtaining all associated alarm data, the WDM equipment alarm analysis system will match the above data to the corresponding positions in the alarm root factor tree and add specific processing suggestions for each associated alarm node. For each matched alarm node, the WDM equipment alarm analysis system will provide corresponding processing suggestions based on a preset fault response strategy or expert maintenance knowledge base.
[0163] Based on the above optional embodiments, fault analysis and handling suggestions are integrated into a structured model, which improves the standardization and automation of the fault handling process, reduces human error, and improves operation and maintenance efficiency.
[0164] Figure 2 This is a schematic diagram of an alarm analysis method for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure, as shown below. Figure 2 As shown, in the process of analyzing alarms in wavelength division multiplexing (WDM) equipment, firstly, the acquisition module obtains equipment alarm events and resource models, and constructs a full-rule alarm root cause tree based on a priori association analysis algorithm using association rules. Then, based on the aforementioned alarm root cause tree, the corresponding alarm root factor tree and the current node position are generated. Subsequently, corresponding resource alarms are added to the relevant alarm list according to the resource tree type. Finally, the relevant alarms are matched to the corresponding alarm root cause trees, corresponding alarm matching suggestions are generated, and the root cause alarm list and alarm suggestion list data are output.
[0165] Figure 3 This is a schematic diagram of an alarm analysis system for a wavelength division multiplexing (WDM) device according to one embodiment of the present disclosure, such as... Figure 3 As shown, the system includes: a box-type wavelength division multiplexing (WDM) device, an alarm acquisition module, an alarm analysis module, an alarm matching module, an alarm display module, and a graphical user interface. The alarm acquisition module acquires alarm information from the box-type WDM device and inputs the target alarm into the alarm analysis module. The alarm analysis module analyzes and processes the target alarm to generate a corresponding alarm root cause tree. The alarm matching module generates an alarm root cause result tree based on the target alarm and the alarm root cause tree. The alarm display module displays the alarm root cause result tree on the graphical user interface.
[0166] Figure 4 This is a schematic diagram of another wavelength division multiplexing (WDM) device alarm analysis method according to one embodiment of the present disclosure, such as... Figure 4 As shown, upon receiving a raw analysis alarm, it is first converted into an alarm root cause node, and simultaneously, the database is queried for original alarms related to the same resource. Further, for the alarm root cause nodes constructed above, an alarm root factor tree framework is built, with the node as the core and based on the filtered root cause tree template. Finally, the corresponding positions of the original alarms related to the same resource and the alarm root factor tree framework are matched to generate the alarm root cause result tree.
[0167] Figure 5 This is a schematic diagram of another wavelength division multiplexing (WDM) device alarm analysis method according to one embodiment of the present disclosure, such as... Figure 5 As shown, firstly, using the alarm resource and the root cause tree template as input, the tree node where the current alarm belongs and the alarm root cause node are obtained. Specifically, the alarm type is converted according to the alarm code name and resource type, and specific node information is obtained through the alarm code name and alarm type. The node information includes, but is not limited to, root cause tree node type, identifier, and level. Secondly, the node tree of each level of the alarm type and the alarm root factor tree framework are constructed. Specifically, the parent and sibling nodes are saved based on the alarm, and the lower-level nodes are saved based on the alarm, thus synthesizing the overall alarm root factor tree framework. Further, all alarms of this category are obtained, and related alarms are traversed to determine whether the code and level are consistent. According to the alarm tree pattern, the corresponding position is matched according to the code and resource. Finally, the root cause result tree of the corresponding alarm is generated, and the corresponding alarm and suggestion are matched.
[0168] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.
[0169] This disclosure also provides a wavelength division multiplexing (WDM) device alarm analysis apparatus for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0170] Figure 6This is a structural block diagram of an alarm analysis device for wavelength division multiplexing (WDM) equipment according to one embodiment of the present disclosure, such as... Figure 6 As shown, the device includes:
[0171] The acquisition module 601 is used to acquire the current alarm data of the wavelength division multiplexing (WDM) equipment;
[0172] The construction module 602 is used to construct an alarm root factor tree based on the current alarm data and the pre-constructed alarm root factor tree, wherein the alarm root factor tree is used to characterize the root factor tree corresponding to the alarm data.
[0173] The determination module 603 is used to determine the alarm root cause result tree based on the current alarm data and the alarm root factor tree, wherein the alarm root cause result data includes the alarm list and alarm suggestions;
[0174] Output module 604 is used to output alarm analysis results based on the alarm root cause result tree.
[0175] Optionally, the construction module 602 is further configured to: acquire historical alarm data, wherein the historical alarm data includes various alarm data corresponding to various wavelength division multiplexing devices; process the historical alarm data using a preset association rule learning algorithm to determine association rules; and determine the alarm root cause tree based on the association rules and the historical alarm data.
[0176] Optionally, the construction module 602 is further configured to: traverse historical alarm data based on a preset association rule learning algorithm to determine the support of each individual alarm, wherein the historical alarm data includes multiple individual alarms; determine frequent itemsets based on the support and a preset support threshold; determine rule confidence based on the frequent itemsets; and determine association rules based on the rule confidence and a preset confidence threshold.
[0177] Optionally, the construction module 602 is further configured to: determine the root node from historical alarm data according to a preset root node confirmation rule; determine the child nodes according to the association rule, the root node and the historical alarm data; and construct an alarm root cause tree based on the root node and the child nodes.
[0178] Optionally, the construction module 602 is further configured to: match alarm root cause nodes from the alarm root cause tree based on the current alarm data; determine associated nodes from the alarm root cause tree based on the alarm root cause nodes; and determine the alarm root factor tree based on the associated nodes and the root cause nodes.
[0179] Optionally, the construction module 602 is further configured to: determine that the associated node is null in response to the alarm root cause node being a first-level node; or, determine that the first-level and third-level nodes associated with the alarm root cause node are associated nodes in response to the alarm root cause node being a second-level node; or, determine that the second-level and first-level nodes associated with the alarm root cause node are associated nodes in response to the alarm root cause node being a third-level node.
[0180] Optionally, the determining module 603 is further configured to: obtain associated alarm data related to the current alarm data based on the alarm root factor tree; match the associated alarm data to the alarm root factor tree and add alarm processing suggestions to the alarm root factor tree to obtain the alarm root cause result tree.
[0181] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.
[0182] According to one embodiment of this disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure when it runs.
[0183] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0184] S1, obtain the current alarm data of the wavelength division multiplexing (WDM) device;
[0185] S2, construct an alarm root factor tree based on the current alarm data and the pre-constructed alarm root cause tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data;
[0186] S3. Based on the current alarm data and alarm root factor tree, determine the alarm root cause result tree, where the alarm root cause result includes the alarm list and alarm handling suggestions;
[0187] S4, based on the alarm root cause result tree, output the alarm analysis results.
[0188] According to one embodiment of this disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the storage medium is located to execute the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure.
[0189] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:
[0190] S1, obtain the current alarm data of the wavelength division multiplexing (WDM) device;
[0191] S2, construct an alarm root factor tree based on the current alarm data and the pre-constructed alarm root cause tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data;
[0192] S3. Based on the current alarm data and alarm root factor tree, determine the alarm root cause result tree, where the alarm root cause result includes the alarm list and alarm handling suggestions;
[0193] S4, based on the alarm root cause result tree, output the alarm analysis results.
[0194] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0195] According to one embodiment of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the wavelength division multiplexing (WDM) device alarm analysis method in the embodiments of this disclosure.
[0196] Optionally, in this embodiment, the above-mentioned computer program product can be configured as a computer program that performs the following steps:
[0197] S1, obtain the current alarm data of the wavelength division multiplexing (WDM) device;
[0198] S2, construct an alarm root factor tree based on the current alarm data and the pre-constructed alarm root cause tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the alarm data;
[0199] S3. Based on the current alarm data and alarm root factor tree, determine the alarm root cause result tree, where the alarm root cause result includes the alarm list and alarm handling suggestions;
[0200] S4, based on the alarm root cause result tree, output the alarm analysis results.
[0201] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0202] In the above embodiments of this disclosure, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0203] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.
[0204] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0205] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0206] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0207] The above description is only a preferred embodiment of this disclosure. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principles of this disclosure, and these improvements and modifications should also be considered within the scope of protection of this disclosure.
Claims
1. A method for analyzing alarms in wavelength division multiplexing (WDM) equipment, characterized in that, include: Obtain the current alarm data of the wavelength division multiplexing (WDM) device; Based on the current alarm data and the pre-built alarm root cause tree, an alarm root factor tree is constructed, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the current alarm data; Based on the alarm root factor tree, obtain associated alarm data related to the current alarm data, wherein the associated alarm data are original alarms of the same resource; match the associated alarm data to the alarm root factor tree and add alarm handling suggestions to the alarm root factor tree to obtain an alarm root cause result tree, wherein the alarm root cause result tree includes an alarm list and the alarm handling suggestions; Based on the alarm root cause result tree, output the alarm analysis results.
2. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 1, characterized in that, Alarm data includes: alarm time, alarm type, alarm level, and device identifier.
3. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 1, characterized in that, The construction of the alarm root cause tree includes: Acquire historical alarm data, wherein the historical alarm data includes various alarm data corresponding to various wavelength division multiplexing devices; The historical alarm data is processed using a preset association rule learning algorithm to determine association rules; The alarm root cause tree is determined based on the association rules and the historical alarm data.
4. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 3, characterized in that, The process of using a preset association rule learning algorithm to process the historical alarm data and determine the association rules includes: Based on the preset association rule learning algorithm, the historical alarm data is traversed to determine the support level of each individual alarm, wherein the historical alarm data includes multiple individual alarms; Based on the support and the preset support threshold, determine the frequent itemsets; Determine the rule confidence level based on the frequent itemsets; The association rule is determined based on the rule confidence level and the preset confidence threshold.
5. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 3, characterized in that, Determining the alarm root cause tree based on the association rules and the historical alarm data includes: The root node is determined from the historical alarm data according to the preset root node confirmation rules; Based on the association rules, the root node, and the historical alarm data, the child nodes are determined; The alarm root cause tree is constructed based on the root node and the child nodes.
6. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 1, characterized in that, The step of constructing an alarm root factor tree based on the current alarm data and the pre-constructed alarm root factor tree includes: Based on the current alarm data, the alarm root cause node is matched from the alarm root cause tree; Based on the alarm root cause node, determine the associated node from the alarm root cause tree; The alarm root factor tree is determined based on the associated nodes and the root cause nodes.
7. The alarm analysis method for wavelength division multiplexing (WDM) equipment according to claim 6, characterized in that, The alarm root cause nodes include first-level nodes, second-level nodes, and third-level nodes. The step of determining associated nodes from the alarm root cause tree based on the alarm root cause nodes includes: In response to the alarm root cause node being of the first-level node type, the associated node is determined to be null. Alternatively, in response to the alarm root cause node being a secondary node, the primary and tertiary nodes associated with the alarm root cause node are determined as the associated nodes. Alternatively, in response to the alarm root cause node being a level 3 node, the level 2 and level 1 nodes associated with the alarm root cause node are identified as the associated nodes.
8. A wavelength division multiplexing (WDM) equipment alarm analysis device, characterized in that, include: The acquisition module is used to acquire the current alarm data of the wavelength division multiplexing (WDM) equipment; The construction module is used to construct an alarm root factor tree based on the current alarm data and the pre-constructed alarm root cause tree, wherein the alarm root factor tree is used to characterize the root cause tree corresponding to the current alarm data; The determination module is used to obtain associated alarm data related to the current alarm data based on the alarm root factor tree, wherein the associated alarm data is the original alarm of the same resource; match the associated alarm data to the alarm root factor tree and add alarm processing suggestions to the alarm root factor tree to obtain an alarm root cause result tree, wherein the alarm root cause result tree includes an alarm list and alarm suggestions; The output module is used to output alarm analysis results based on the alarm root cause result tree.
9. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the storage medium is located to perform the method according to any one of claims 1 to 7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for positioning 5G network virtualization cross-layer problem through AI algorithm
CN113542039A
Alarm correlation analysis method and device
CN114070709A