Abnormal event monitoring and alarming method and related equipment
By setting up an abnormal monitoring rule base and alarm strategy for different alarm data sources, the problem of difficult for traditional alarm systems to adapt to the rapid change of data and false alarms and missed reports is solved, and higher alarm accuracy and refined processing are achieved.
Patent Information
- Application Number
- CN202510119517.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-06
AI Technical Summary
Traditional data monitoring and alarm mechanisms are difficult to adapt to the rapidly changing data characteristics, are prone to false alarms and missed alarms, and lack adaptive adjustment capabilities, making it difficult to accurately capture complex and changeable data patterns.
By setting up the corresponding abnormality monitoring rule base for different alarm data sources, the abnormality monitoring rules for the alarm data source to be monitored are determined, the data is monitored based on these rules, the alarm data collection is obtained, and the alarm strategy of each alarm data is determined based on the business scenario information to realize differentiated alarm processing.
It improves the accuracy of alarms, reduces false alarms and missed alarms, makes the alarms more refined, and realizes differentiated alarm processing of various alarm data.
Smart Images

Figure CN119942720A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of big data, and in particular to a monitoring and alarm method for abnormal events and related equipment. Background Art
[0002] With the rapid development of information technology, the amount of data generated by all walks of life has exploded. It has become crucial to effectively use these massive data for real-time monitoring and anomaly detection. As the first layer of protection for industrial processes, the performance of the alarm system is directly related to process safety, product quality, production costs and even casualties. It is an important factor affecting the national economy and people's livelihood. A large number of accident investigations and analyses have shown that a scientific and reasonable alarm system is of great significance for effectively ensuring the safety, reliability and economy of industrial process operations.
[0003] Traditional data monitoring and alarm mechanisms often rely on manually set thresholds and rules, which are difficult to adapt to the rapidly changing data characteristics and are prone to false positives and false negatives. Existing data anomaly monitoring systems usually use fixed template matching to identify anomalies, or use simple statistical models to set alarm conditions. These methods lack adaptive adjustment capabilities and are difficult to accurately capture anomalies when faced with complex and changing data patterns. They also increase system maintenance costs and false alarm rates. Summary of the invention
[0004] The embodiment of the present invention provides a monitoring alarm method and related equipment for abnormal events. The corresponding abnormal monitoring rule base is set for different alarm data sources, which can improve the accuracy of the alarm and reduce the situation of false alarms and missed alarms. At the same time, the alarm strategy set for each alarm data makes the alarm more refined and realizes the differentiated alarm processing of each alarm data.
[0005] A first aspect of the present invention provides a monitoring and alarm method for abnormal events, comprising:
[0006] Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored;
[0007] Monitoring the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0008] Determining an alarm strategy corresponding to each alarm data in the alarm data set;
[0009] Based on the alarm strategy, alarms are respectively issued for the alarm data in the alarm data set.
[0010] A second aspect of the present invention provides a monitoring and alarm device for abnormal events, comprising:
[0011] A first determination module is used to determine the abnormality monitoring rules corresponding to the alarm data source to be monitored;
[0012] A monitoring module, used to monitor the data of the alarm data source to be monitored based on the abnormal monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0013] A second determination module, used to determine the alarm strategy corresponding to each alarm data in the alarm data set;
[0014] The alarm module is used to respectively alarm the alarm data in the alarm data set based on the alarm strategy.
[0015] In a possible design, the first determining module is specifically configured to:
[0016] Determine the type of the alarm data source to be monitored;
[0017] The abnormality monitoring rule is determined according to the type of the alarm data source to be monitored.
[0018] In a possible design, the second determining module is specifically configured to:
[0019] Determine the business scenario information corresponding to each alarm data in the alarm data set;
[0020] An alarm strategy for each alarm data is determined according to the business scenario information.
[0021] In a possible design, the alarm strategy is an alarm strategy corresponding to a time dimension, and the second determination module determines the alarm strategy for each alarm data according to the business scenario information, including:
[0022] Determine a first subset of alarm data in the alarm data set that continuously triggers an alarm within a preset time period;
[0023] Determining the alarm strategy for the first alarm data subset as a periodic limit alarm;
[0024] Determine a second alarm data subset corresponding to the periodic notification business scenario in the alarm data set;
[0025] Determining the alarm strategy of the second alarm data subset as a periodic fixed alarm;
[0026] Determine a third alarm data subset corresponding to the real-time business scenario in the alarm data set;
[0027] The alarm strategy of the third alarm data subset is determined as real-time alarm.
[0028] In a possible design, the alarm strategy is an alarm strategy corresponding to a level dimension, and the second determination module determines the alarm strategy for each alarm data according to the business scenario information, including:
[0029] Determining the importance level corresponding to the business scenario information;
[0030] An alarm strategy for each alarm data is determined according to the importance level.
[0031] In a possible design, the alarm module is specifically used for:
[0032] Determine whether there are N alarm data associated with the service in the alarm data set, where N is an integer greater than or equal to 2;
[0033] If yes, determining the priority of each of the N alarm data;
[0034] Based on the alarm strategy, an alarm is issued for the alarm data whose priority is higher than a preset threshold among the N alarm data.
[0035] A third aspect of the present invention provides an electronic device, comprising a memory and a processor, wherein the processor is used to implement the steps of the abnormal event monitoring and alarm method as described in the first aspect when executing a computer management program stored in the memory.
[0036] A fourth aspect of the present invention provides a computer-readable storage medium having a computer management program stored thereon, which, when executed by a processor, implements the steps of the abnormal event monitoring and alarm method as described in the first aspect above.
[0037] In summary, it can be seen that in the embodiment provided by the present invention, the abnormal monitoring rules corresponding to the alarm data source to be monitored are determined; the data of the alarm data source to be monitored is monitored based on the abnormal monitoring rules to obtain the alarm data set corresponding to the alarm data source to be monitored; the alarm strategy corresponding to each alarm data in the alarm data set is determined; and the alarm data in the alarm data set are respectively alarmed based on the alarm strategy. Therefore, setting corresponding abnormal monitoring rule bases for different alarm data sources can improve the accuracy of the alarm and reduce the situation of false alarms and missed alarms. At the same time, the alarm strategy set for each alarm data makes the alarm more refined and realizes differentiated alarm processing for each alarm data. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 A schematic diagram of a process flow of a monitoring and alarm method for abnormal events provided by an embodiment of the present invention;
[0039] Figure 2A virtual structural diagram of a monitoring and alarm device for abnormal events provided by an embodiment of the present invention;
[0040] Figure 3 A schematic diagram of the hardware structure of the abnormal event monitoring and alarm device provided by an embodiment of the present invention;
[0041] Figure 4 A schematic diagram of an electronic device according to an embodiment of the present invention;
[0042] Figure 5 A schematic diagram of an embodiment of a computer-readable storage medium provided for an embodiment of the present invention. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0044] In the following description, specific embodiments of the present invention will be described with reference to steps and symbols performed by one or more computers, unless otherwise stated. Therefore, these steps and operations will be mentioned several times as being performed by a computer, and computer execution referred to herein includes operations by a computer processing unit of electronic signals representing data in a structured form. This operation converts the data or maintains it at a location in the computer's memory system, which can be reconfigured or otherwise change the operation of the computer in a manner familiar to testers in the field. The data structure maintained by the data is a physical location in the memory, which has specific characteristics defined by the data format. However, the principles of the present invention are described in the above text, which does not represent a limitation, and testers in the field will understand that the various steps and operations described below can also be implemented in hardware.
[0045] The principles of the present invention operate with many other general or special purpose computing, communication environments or configurations. Examples of well-known computing systems, environments and configurations suitable for use with the present invention may include, but are not limited to, handheld phones, personal computers, servers, multiprocessor systems, microcomputer-based systems, mainframe computers, and distributed computing environments, including any of the above systems or devices.
[0046] The terms "first", "second", and "third" in the present invention are used to distinguish different objects rather than to describe a specific order. In addition, the terms "include", "have", and any variations thereof are intended to cover non-exclusive inclusions.
[0047] The abnormal event monitoring and alarm method provided by the present invention is described below from the perspective of the abnormal event monitoring and alarm device. The abnormal event monitoring and alarm device can be a server or a service unit in the server, and is not specifically limited.
[0048] See also Figure 1 , Figure 1 A flow chart of a monitoring and alarming method for abnormal events provided by an embodiment of the present invention, wherein the monitoring and alarming method for abnormal events comprises:
[0049] 101. Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored.
[0050] In this embodiment, the monitoring and alarming device for abnormal events can first determine the type of the alarm data source to be monitored, and determine the abnormal monitoring rules according to the type of the alarm data source to be monitored, wherein the monitoring and alarming device for abnormal events accesses and manages the alarm data source to be monitored through the data source module, and determines the abnormal monitoring rules corresponding to the abnormal events in the alarm data source to be monitored according to the type of the alarm data source to be monitored. The following is an explanation of various types of alarm data sources to be monitored:
[0051] For streaming data sources such as Kafka, subscription configuration, serializer configuration, Schema Registry configuration, and monitoring item configuration are provided. Monitoring items can be agreed fields or fields obtained from the Schema Registry.
[0052] For data sources such as relational databases, JDBC connector configuration and CDC configuration are provided. If you choose the JDBC connector, you also need to write incremental SQL scripts and set the execution frequency. If it is MYSQL CDC, the MYSQL service needs to be set to enable binlog and provide a REST mode data source. If this mode is selected, the user will actively call the REST interface to push data, and the monitoring items need to be defined through interface parameters.
[0053] It can be understood that after configuring the data source to be monitored and the monitoring items, the "or" and "and" logical operators and the rule unit sequence number are used to organize the abnormal rules of each monitoring item, so that complex data patterns can be more accurately identified and responded to. The following are the steps to organize the abnormal rules of each monitoring item through "or" and "and" and the rule unit sequence number:
[0054] Define rule units: define the abnormal condition of each monitoring item as a rule unit. For example, if the monitoring item is temperature, the abnormal condition may be that the temperature is higher than the first preset value or the temperature is lower than the second preset value, then two rule units can be defined: "temperature higher than the first preset value" and "temperature lower than the second preset value".
[0055] Use the "and" operator: Use the "and" operator when multiple conditions need to be met at the same time. For example, if an exception rule requires that the temperature is higher than the first preset value and the humidity is also too high, then the "temperature is higher than the first preset value" rule unit and the "humidity is higher than the third preset value" rule unit can be connected with the "and" operator.
[0056] Use the "OR" operator: Use the "OR" operator when any condition can trigger an exception. For example, if an exception rule is that the temperature is higher than the first preset value or too low, you can connect the "Temperature is higher than the first preset value" rule unit and the "Temperature is lower than the second preset value" rule unit with the "OR" operator.
[0057] Rule unit sequence numbering: Assign a unique sequence number to each rule unit, which helps to manage and debug when the rules are complex. For example, the "temperature is higher than the first preset value" rule unit can be numbered 1, the "temperature is lower than the second preset value" rule unit can be numbered 2, and the "humidity is higher than the third preset value" rule unit can be numbered 3.
[0058] Construct rule combinations: Use the rule units and logical operators defined above to construct more complex rule combinations. For example, a rule combination can be: "(1 or 2) and 3", which means that an exception is triggered when the temperature is higher than the first preset value or the temperature is lower than the second preset value, and the humidity is higher than the third preset value.
[0059] The above description uses the "or" and "and" operators as examples. Of course, other operators may also be used, such as "if", "if again", and "else". There is no specific limitation, as long as the abnormal monitoring rules of the alarm data source to be monitored can be determined.
[0060] 102. Monitor the data of the alarm data source to be monitored based on the abnormal monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored.
[0061] In this embodiment, after determining the abnormal monitoring rules, the abnormal event monitoring and alarming device can monitor the data of the monitored alarm data source according to the abnormal monitoring rules, and then obtain the alarm data that meets the abnormal monitoring rules, thereby obtaining the alarm data set.
[0062] 103. Determine the alarm strategy corresponding to each alarm data in the alarm data set.
[0063] In this embodiment, the monitoring and alarming device for abnormal events may first determine the business scenario information corresponding to each alarm data in the alarm data set, and determine the alarm strategy corresponding to each alarm data according to the business scenario information.
[0064] It should be noted that the alarm strategy includes an alarm strategy in the time dimension and an alarm strategy in the level dimension, which are described below respectively:
[0065] 1. Alarm strategy in the time dimension:
[0066] The monitoring and alarm device of abnormal events determines the alarm strategy of each alarm data according to the business scenario information, including:
[0067] Determine a first subset of alarm data in the alarm data set that continuously triggers an alarm within a preset time period;
[0068] Determine the alarm strategy of the first alarm data subset as a periodic limit alarm;
[0069] Determine a second alarm data subset corresponding to the periodic notification business scenario in the alarm data set;
[0070] Determining the alarm strategy of the second alarm data subset as a periodic fixed alarm;
[0071] Determine a third alarm data subset corresponding to the real-time business scenario in the alarm data set;
[0072] The alarm policy for the third alarm data subset is determined as real-time alarm.
[0073] In this embodiment, the business scenario information includes but is not limited to regular notification business scenarios, real-time business scenarios, and periodic limited alarm scenarios; and the alarm strategy for each alarm data is determined according to the business scenario. The following is a specific description in combination with the scenario:
[0074] 1. Periodic limit alarm scenario;
[0075] It can be determined whether there is a first alarm data subset in the alarm data set that continuously triggers an alarm within a preset time period; if so, the alarm strategy of the first alarm data subset is determined as a periodic limited alarm, for example, only one alarm is triggered within a preset time period, that is, for alarm data that continuously triggers the same alarm content, only one alarm is triggered;
[0076] 2. Regularly notify business scenarios;
[0077] It can be determined whether there is a periodic notification business scenario in the alarm data set, that is, the alarm data appearing in this scenario will only be notified periodically. When it is determined that there is a second alarm data subset corresponding to the periodic notification business scenario in the alarm data set, the alarm strategy of the second alarm data subset is determined as a periodic fixed alarm.
[0078] 3. Real-time business scenarios;
[0079] Determine a third alarm data subset corresponding to the real-time business scenario in the alarm data set; determine the alarm strategy of the third alarm data subset as real-time alarm. For alarm data that requires real-time notification, define the alarm strategy of alarm data of this type of scenario as real-time alarm.
[0080] That is to say, the alarm strategy includes real-time alarm, periodic limited alarm, and periodic fixed alarm in the time dimension. The periodic limited alarm is required for the scenario where the abnormal monitoring rule is continuously triggered within the preset time. For example, the alarm will not be pushed after the abnormal rule is triggered again within 10 minutes. The periodic fixed alarm is required for business scenarios such as regular notification. In the process of monitoring alarm data, it can be determined which alarm strategy is needed for the alarm data, and then the alarm data is alarmed through the alarm strategy.
[0081] 2. Alarm strategy in level dimension:
[0082] The monitoring and alarm device of abnormal events determines the alarm strategy of each alarm data according to the business scenario information, including:
[0083] Determine the importance level corresponding to the business scenario information;
[0084] The alarm strategy for each alarm data is determined according to the importance level.
[0085] In this embodiment, the monitoring and alarming device for abnormal events can determine the importance level corresponding to the business scenario information; and determine the alarm strategy for each alarm data according to the importance level. It can be understood that here, the monitoring and alarming device for abnormal events can use the business scenario as the level dimension, and of course, it can also use a single alarm data as the level dimension, without specific limitation. When a single alarm data is used as the level dimension, the importance level of each alarm data can be determined according to the content of the alarm data, and then the alarm strategy is determined according to the importance level. The level dimension includes red, orange, and yellow levels, and the darker the color, the more serious the abnormal event.
[0086] 104. Alarm the alarm data in the alarm data set respectively based on the alarm strategy.
[0087] In this embodiment, after the alarm strategy is determined, alarms may be respectively issued for the alarm data in the alarm data set based on the alarm strategy.
[0088] It should be noted that when an alarm is issued for alarm data, it can also be determined whether there are N alarm data associated with the business in the alarm data set, where N is an integer greater than or equal to 2; if so, the priority of each alarm data in the N alarm data is determined; and based on the alarm strategy, an alarm is issued for the alarm data with a priority higher than a preset threshold in the N alarm data. The business association can be an inclusion relationship, where one business alarm will definitely cause another business alarm. In this case, it is only necessary to issue an alarm for the alarm data with the highest priority among the alarm data with business association, which can effectively suppress the occurrence or deterioration of alarm flooding.
[0089] In addition, in order to ensure that the alarm system can normally play its protective function and timely discover unreasonable designs, the performance of the alarm system should be evaluated regularly. In the present invention, the alarm performance is evaluated by an overload model, a stability model, and a prediction model. The evaluation is jointly determined by three indicators: the average alarm rate, the maximum alarm rate, and the over-limit alarm rate. The following is a specific description:
[0090] Overload model: This model can be used to evaluate performance under extreme or beyond-design load conditions. It can help understand how the alarm system will perform when faced with excessive stress, such as whether it will collapse, the extent of performance degradation, etc.
[0091] Stability model: This model is designed to assess the stability of the system under normal or expected load conditions. It focuses on whether the system can maintain stable performance during regular use without significant fluctuations or failures.
[0092] Predictive model: This model may use historical data or system characteristics to predict the performance of the system in the future. It helps to identify potential performance issues in advance so that measures can be taken to prevent them.
[0093] Three indicators:
[0094] Average alarm rate: This indicator may indicate the average frequency of system alarm triggering within a certain period of time. It reflects the stability of the overall system performance. A higher average alarm rate may mean that the system has more problems or unstable factors.
[0095] Maximum alarm rate: This metric indicates the highest alarm frequency triggered by the system in a specific time period. It reveals the performance of the system under extreme conditions and helps to understand the system's ability to withstand pressure.
[0096] Exceeding alarm rate: This metric may refer to the frequency with which the system triggers an alarm that exceeds a set threshold. It is used to assess whether the system frequently has performance issues that exceed the expected or acceptable range.
[0097] The performance evaluation results of the three models (overload, stability, and prediction) are measured together through the three indicators mentioned above (average alarm rate, maximum alarm rate, and over-limit alarm rate). In other words, when evaluating system performance, it is necessary to comprehensively consider the performance of the three models on the three indicators. By comparing and analyzing these indicators, we can have a comprehensive understanding of the system's performance level and take appropriate measures to optimize system performance.
[0098] It should also be noted that in order to share the computing pressure of the monitoring and alarm device for abnormal events, an edge computing engine can also be set up. The engine provides the calculation process of the abnormal alarm to the edge in the form of a REST interface, and provides a REST interface for triggering the alarm. The calculation process of the abnormal alarm will be implemented by the edge calling the system SDK. The processing of other parts, such as abnormal monitoring rule management, alarm strategy management and alarm push, is still handled by the monitoring and alarm device for abnormal events, so that the edge can share part of the computing pressure.
[0099] In summary, it can be seen that in the embodiment provided by the present invention, the abnormal monitoring rules corresponding to the alarm data source to be monitored are determined; the data of the alarm data source to be monitored is monitored based on the abnormal monitoring rules to obtain the alarm data set corresponding to the alarm data source to be monitored; the alarm strategy corresponding to each alarm data in the alarm data set is determined; and the alarm data in the alarm data set are respectively alarmed based on the alarm strategy. Therefore, setting corresponding abnormal monitoring rule bases for different alarm data sources can improve the accuracy of the alarm and reduce the situation of false alarms and missed alarms. At the same time, the alarm strategy set for each alarm data makes the alarm more refined and realizes differentiated alarm processing for each alarm data.
[0100] The above describes the embodiment of the present invention from the perspective of the monitoring and alarming method of abnormal events. The following describes the embodiment of the present invention from the perspective of the monitoring and alarming device of abnormal events.
[0101] See also Figure 2 , a virtual structural diagram of a monitoring and alarming device for abnormal events in an embodiment of the present invention, wherein the monitoring and alarming device 200 for abnormal events comprises:
[0102] The first determination module 201 is used to determine the abnormality monitoring rule corresponding to the alarm data source to be monitored;
[0103] A monitoring module 202, configured to monitor the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0104] A second determination module 203 is used to determine the alarm strategy corresponding to each alarm data in the alarm data set;
[0105] The alarm module 204 is used to respectively alarm the alarm data in the alarm data set based on the alarm strategy.
[0106] In a possible design, the first determining module 201 is specifically configured to:
[0107] Determine the type of the alarm data source to be monitored;
[0108] The abnormality monitoring rule is determined according to the type of the alarm data source to be monitored.
[0109] In a possible design, the second determining module 203 is specifically configured to:
[0110] Determine the business scenario information corresponding to each alarm data in the alarm data set;
[0111] An alarm strategy for each alarm data is determined according to the business scenario information.
[0112] In a possible design, the alarm strategy is an alarm strategy corresponding to a time dimension, and the second determination module 203 determines the alarm strategy for each alarm data according to the business scenario information, including:
[0113] Determine a first subset of alarm data in the alarm data set that continuously triggers an alarm within a preset time period;
[0114] Determining the alarm strategy for the first alarm data subset as a periodic limit alarm;
[0115] Determine a second alarm data subset corresponding to the periodic notification business scenario in the alarm data set;
[0116] Determining the alarm strategy of the second alarm data subset as a periodic fixed alarm;
[0117] Determine a third alarm data subset corresponding to the real-time business scenario in the alarm data set;
[0118] The alarm strategy of the third alarm data subset is determined as real-time alarm.
[0119] In a possible design, the alarm strategy is an alarm strategy corresponding to the level dimension, and the second determination module 203 determines the alarm strategy of each alarm data according to the business scenario information, including:
[0120] Determining the importance level corresponding to the business scenario information;
[0121] An alarm strategy for each alarm data is determined according to the importance level.
[0122] In a possible design, the alarm module 204 is specifically used for:
[0123] Determine whether there are N alarm data associated with the service in the alarm data set, where N is an integer greater than or equal to 2;
[0124] If yes, determining the priority of each of the N alarm data;
[0125] Based on the alarm strategy, an alarm is issued for the alarm data whose priority is higher than a preset threshold among the N alarm data.
[0126] above Figure 2 The monitoring and alarming device for abnormal events in the embodiment of the present invention has been described from the perspective of modular functional entities. The monitoring and alarming device for abnormal events in the embodiment of the present invention is described in detail from the perspective of hardware processing. Please refer to FIG. 300, which is a schematic diagram of an embodiment of the monitoring and alarming device 300 for abnormal events in the embodiment of the present invention. The monitoring and alarming device 300 for abnormal events includes:
[0127] An input device 301, an output device 302, a processor 303 and a memory 304 (the number of the processor 303 can be one or more, Figure 3 In some embodiments of the present invention, the input device 301, the output device 302, the processor 303 and the memory 304 may be connected via a communication bus or other means, wherein: Figure 3 The communication bus connection is taken as an example.
[0128] Wherein, by calling the operation instruction stored in the memory 304, the processor 303 is used to perform the following steps:
[0129] Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored;
[0130] Monitoring the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0131] Determining an alarm strategy corresponding to each alarm data in the alarm data set;
[0132] Based on the alarm strategy, alarms are respectively issued for the alarm data in the alarm data set.
[0133] By calling the operation instructions stored in the memory 304, the processor 303 is also used to execute Figure 1 Any method in the corresponding embodiment.
[0134] See also Figure 4 , Figure 4A schematic diagram of an electronic device according to an embodiment of the present invention.
[0135] like Figure 4 As shown, an embodiment of the present invention provides an electronic device, including a memory 410, a processor 420, and a computer program 411 stored in the memory 410 and executable on the processor 420. When the processor 420 executes the computer program 411, the following steps are implemented:
[0136] Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored;
[0137] Monitoring the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0138] Determining an alarm strategy corresponding to each alarm data in the alarm data set;
[0139] Based on the alarm strategy, alarms are respectively issued for the alarm data in the alarm data set.
[0140] In the specific implementation process, when the processor 420 executes the computer program 411, it can achieve Figure 1 Any implementation manner in the corresponding embodiments.
[0141] Since the electronic device introduced in this embodiment is a device used to implement a monitoring and alarm device for an abnormal event in the embodiment of the present invention, based on the method introduced in the embodiment of the present invention, technical personnel in this field can understand the specific implementation method of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of the present invention will not be described in detail here. As long as the equipment used by technical personnel in this field to implement the method in the embodiment of the present invention falls within the scope of protection of the present invention.
[0142] Please refer to Figure 500, which is a schematic diagram of an embodiment of a computer-readable storage medium provided by an embodiment of the present invention.
[0143] As shown in Figure 500, the embodiment of the present invention further provides a computer-readable storage medium 500, on which a computer program 511 is stored. When the computer program 511 is executed by a processor, the following steps are implemented:
[0144] Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored;
[0145] Monitoring the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored;
[0146] Determining an alarm strategy corresponding to each alarm data in the alarm data set;
[0147] Based on the alarm strategy, alarms are respectively issued for the alarm data in the alarm data set.
[0148] In the specific implementation process, the computer program 511 is executed by the processor to achieve Figure 1 Any implementation manner in the corresponding embodiments.
[0149] It should be noted that in the above embodiments, the description of each embodiment has its own emphasis, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0150] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0151] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0152] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0153] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0154] The embodiment of the present invention also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device executes the following Figure 1 The process in the corresponding embodiment.
[0155] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.
[0156] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0157] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There are other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0158] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0159] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0160] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.
[0161] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A monitoring and alarm method for abnormal events, characterized in that: include: Determine the abnormal monitoring rules corresponding to the alarm data source to be monitored; Monitoring the data of the alarm data source to be monitored based on the abnormality monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored; Determining an alarm strategy corresponding to each alarm data in the alarm data set; Alarms are respectively issued for the alarm data in the alarm data set based on the alarm strategy.
2. The method according to claim 1, characterized in that The determination of the abnormal monitoring rules corresponding to the alarm data source to be monitored includes: Determine the type of the alarm data source to be monitored; The abnormality monitoring rule is determined according to the type of the alarm data source to be monitored.
3. The method according to claim 1, characterized in that The step of determining the alarm strategy corresponding to each alarm data in the alarm data set comprises: Determine the business scenario information corresponding to each alarm data in the alarm data set; An alarm strategy for each alarm data is determined according to the business scenario information.
4. The method according to claim 3, characterized in that: The alarm strategy is an alarm strategy corresponding to the time dimension, and the alarm strategy for each alarm data determined according to the business scenario information includes: Determine a first subset of alarm data in the alarm data set that continuously triggers an alarm within a preset time period; Determining the alarm strategy for the first alarm data subset as a periodic limit alarm; Determine a second alarm data subset corresponding to the periodic notification business scenario in the alarm data set; Determining the alarm strategy of the second alarm data subset as a periodic fixed alarm; Determine a third alarm data subset corresponding to the real-time business scenario in the alarm data set; The alarm strategy of the third alarm data subset is determined as real-time alarm.
5. The method according to claim 3, characterized in that: The alarm strategy is an alarm strategy corresponding to the level dimension, and the alarm strategy for each alarm data determined according to the business scenario information includes: Determining the importance level corresponding to the business scenario information; An alarm strategy for each alarm data is determined according to the importance level.
6. The method according to any one of claims 1 to 5, characterized in that The respectively alarming the alarm data in the alarm data set based on the alarm strategy comprises: Determine whether there are N alarm data associated with the service in the alarm data set, where N is an integer greater than or equal to 2; If yes, determining the priority of each of the N alarm data; Based on the alarm strategy, an alarm is issued for the alarm data whose priority is higher than a preset threshold among the N alarm data.
7. A monitoring and alarm device for abnormal events, characterized in that: include: A first determination module is used to determine the abnormality monitoring rules corresponding to the alarm data source to be monitored; A monitoring module, used to monitor the data of the alarm data source to be monitored based on the abnormal monitoring rule to obtain an alarm data set corresponding to the alarm data source to be monitored; A second determination module, used to determine the alarm strategy corresponding to each alarm data in the alarm data set; The alarm module is used to respectively alarm the alarm data in the alarm data set based on the alarm strategy.
8. The device according to claim 7, characterized in that The first determining module is specifically used for: Determine the type of the alarm data source to be monitored; The abnormality monitoring rule is determined according to the type of the alarm data source to be monitored.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to implement the abnormal event monitoring and alarm method as described in any one of claims 1 to 6 when executing the computer management program stored in the memory.
10. A computer-readable storage medium having a computer management program stored thereon, characterized in that: When the computer management program is executed by the processor, the abnormal event monitoring and alarm method as described in any one of claims 1 to 6 is implemented.