Business system monitoring method and device, computer equipment and readable storage medium

By acquiring and analyzing the monitoring data of the business system, generating and sending alarm notifications based on interface priority, the problem of insufficient log monitoring alarm support capabilities in the prior art is solved, and efficient real-time log monitoring and key alarms are achieved.

CN119961079APending Publication Date: 2025-05-09北京新氧万维科技咨询有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311435580.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing business systems, especially ES databases, have weak support for log monitoring and alarms, making it difficult to achieve efficient real-time log monitoring and key alarms.

Method used

By obtaining the monitoring data of the target business system, including log data and error information of the target interface, an alarm notification is generated and sent based on the interface priority and error information. This method includes preset query conditions, filtering rules and alarm templates to ensure efficient log monitoring and alarm.

Benefits of technology

It realizes efficient real-time monitoring and key alarms of business system log data, and customizes alarm notifications through interface priority, improving alarm efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961079A_ABST
    Figure CN119961079A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a business system monitoring method, which comprises the following steps: acquiring monitoring data of a target business system, the monitoring data comprising log data and error information of a target interface, the target business system being configured with the target interface, and the target interface being pre-associated with an interface priority; according to the error information of the target interface, obtaining alarm log data from the log data; and according to the interface priority of the target interface and the alarm log data, generating a target alarm notification and sending the target alarm notification. According to the technical scheme provided by the embodiment of the invention, the log data needing to trigger the alarm can be quickly identified, and the target alarm notification is customized for the alarm log data and the related principal is notified through the pre-configured interface priority, so that efficient real-time log monitoring and key alarm are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of data processing technology, and in particular, to a business system monitoring method, apparatus, computer equipment, and computer-readable storage medium. Background Art

[0002] With the development of the Internet, business platforms need to face massive business requests, and the stability of their operation is particularly important. Business platforms generally need to configure databases, such as ES (Elasticsearch) databases. Taking ES database as an example, it is a distributed document storage and search engine that can be used to process large-scale data sets, such as logs, documents, time series data, etc. It is widely used in full-text search, text analysis, data aggregation and other fields.

[0003] The inventors have found that although ES databases are suitable for storing and querying various types of log data, their support for log monitoring and alarming is weak, making it difficult to achieve efficient real-time log monitoring and critical alarming.

[0004] It should be noted that the above content is not necessarily prior art, nor is it intended to limit the scope of patent protection of this application. Summary of the invention

[0005] The embodiments of the present application provide a business system monitoring method, apparatus, computer equipment, and computer-readable storage medium to solve or alleviate one or more of the technical problems raised above.

[0006] One aspect of an embodiment of the present application provides a business system monitoring method, the method comprising:

[0007] Acquire monitoring data of a target business system, the monitoring data including log data and error information of a target interface, the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority;

[0008] Acquire alarm log data from the log data according to the error information of the target interface;

[0009] A target alarm notification is generated and sent according to the interface priority of the target interface and the alarm log data.

[0010] Optionally, the monitoring data is obtained based on a query condition, the query condition is configured with a query log level and a query time window, and the query time window corresponds to a plurality of sub-time windows;

[0011] The obtaining of monitoring data of the target business system includes:

[0012] Obtaining the log data of the target business system within the query time window by querying the log level; and

[0013] Obtain error information of the target interface in each sub-time window, wherein the error information includes an error value.

[0014] Optionally, acquiring alarm log data from the log data according to the error information of the target interface includes:

[0015] Selecting one or more target sub-time windows from the multiple sub-time windows according to the error values ​​in each sub-time window and a preset filtering rule;

[0016] According to the one or more target sub-time windows, part of the log data is obtained from the log data to serve as the alarm log data.

[0017] Optionally, the target warning notification includes a text warning notification and / or an instant voice connection warning notification;

[0018] The generating and sending a target alarm notification according to the interface priority of the target interface and the alarm log data includes:

[0019] When the interface priority is the first priority, generating the instant voice connection alarm notification and the text alarm notification according to the alarm log data;

[0020] When the interface priority is lower than the first priority and the error values ​​of one or more sub-time windows meet a preset trigger condition, the text alarm notification is generated according to the alarm log data.

[0021] Optionally, the generating and sending a target alarm notification according to the interface priority of the target interface and the alarm log data further includes:

[0022] According to the alarm log data, obtain corresponding alarm information;

[0023] According to the alarm log data, obtain the corresponding error cause and processing suggestions;

[0024] When the corresponding error cause and processing suggestion are obtained, a first target alarm notification is generated according to a preset alarm template, the alarm information, the error cause and the processing suggestion;

[0025] In the case where the corresponding error cause and processing suggestion are not obtained, a second target alarm notification is generated according to a preset alarm template and the alarm information.

[0026] Optionally, according to the alarm log data, corresponding error causes and handling suggestions are obtained, including:

[0027] Matching the alarm log data with a preset error database, wherein the preset error database includes a plurality of error data, each error data being associated with an error cause and a processing suggestion;

[0028] When the alarm log data and the target error data in the preset database match successfully, a target error cause and a target processing suggestion associated with the target error data are obtained.

[0029] Optionally, the business system monitoring method further includes:

[0030] In the event that the alarm log data fails to match the preset error database, storing the alarm log data in a preset cache area;

[0031] When the target error cause and target processing suggestion corresponding to the alarm log data are obtained, the alarm log data is added as error data to the preset error database.

[0032] Optionally, a target alarm notification is generated and sent, including:

[0033] Acquire target object information associated with the target interface, the target object information including a voice connection interface and a communication interface;

[0034] An instant voice connection alarm notification is sent to the target object via the voice connection interface; and / or a text alarm notification is sent via the communication interface.

[0035] Another aspect of an embodiment of the present application provides a business system monitoring device, the device comprising:

[0036] A first acquisition module is used to acquire monitoring data of a target business system, wherein the monitoring data includes log data and error information of a target interface, wherein the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority;

[0037] A second acquisition module, used to acquire alarm log data from the log data according to the error information of the target interface;

[0038] The sending module is used to generate and send a target alarm notification according to the interface priority of the target interface and the alarm log data.

[0039] Another aspect of an embodiment of the present application provides a computer device, including:

[0040] at least one processor; and

[0041] a memory communicatively coupled to the at least one processor;

[0042] Wherein: the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.

[0043] Another aspect of an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method described above is implemented.

[0044] The above technical solution adopted in the embodiment of the present application may have the following advantages:

[0045] First, obtain the log data of the target business system and the error information of the target interface configured by the target business system. According to the error information of the target interface, filter and screen out the alarm log data from the log data. According to the interface priority and alarm log data pre-configured for the target interface, generate a target alarm notification and send it to the relevant person in charge. It can be seen that the embodiment of the present application can quickly identify the log data that needs to trigger an alarm through the error information of the target interface, and customize the target alarm notification and notify the relevant person in charge for the alarm log data through the pre-configured interface priority, thereby achieving efficient real-time log monitoring and critical alarms. The technical solution of the embodiment of the present application is highly flexible and applicable to a variety of scenarios. For example, it can be used for log monitoring of databases such as ES. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings exemplarily illustrate the embodiments and constitute a part of the specification, and together with the text description of the specification, are used to explain the exemplary implementation of the embodiments. The embodiments shown are for illustrative purposes only and do not limit the scope of the claims. In all drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0047] Figure 1 A flowchart of a business system monitoring method according to Embodiment 1 of the present application is schematically shown;

[0048] Figure 2 Schematically shows Figure 1 Sub-steps of step S100;

[0049] Figure 3 Schematically shows Figure 1 Sub-steps of step S102;

[0050] Figure 4 The monitoring system configuration interface of the business system monitoring method according to the first embodiment of the present application is schematically shown;

[0051] Figure 5 Schematically shows Figure 1 Sub-steps of step S104;

[0052] Figure 6 The newly added flow chart of the business system monitoring method according to the first embodiment of the present application is schematically shown;

[0053] Figure 7 Schematically shows Figure 6 Sub-steps of step S602;

[0054] Figure 8 Schematically shows Figure 6 Sub-steps of step S602;

[0055] Fig. 9 Schematically shows Figure 1 Sub-steps of step S104;

[0056] Fig.10 This is an application example diagram of the business system monitoring method according to the first embodiment of the present application;

[0057] Fig.11 This is an application example diagram of the business system monitoring method according to the first embodiment of the present application;

[0058] Fig.12 A block diagram schematically shows a business system monitoring device according to Embodiment 2 of the present application; and

[0059] Fig.13 The hardware architecture diagram of the computer device according to the third embodiment of the present application is schematically shown. DETAILED DESCRIPTION

[0060] In order to make the purpose, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application.

[0061] It should be noted that the descriptions involving "first", "second", etc. in the embodiments of the present application are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0062] In the description of the present application, it should be understood that the numerical labels before the steps do not indicate the order in which the steps are executed, but are only used to facilitate the description of the present application and to distinguish each step, and therefore should not be understood as a limitation on the present application.

[0063] First, the following terms are explained:

[0064] Log data: is a record of events, activities, or status generated by a computer system, application, device, or service. These records can exist in text or structured formats and are used to track system operation, performance, errors, security incidents, and other related information.

[0065] Interface: It is a communication point or interaction point between two or more independent systems, components or modules, which is used to define how these systems or components interact and communicate with each other.

[0066] Time window: It is a specific time period set on the timeline, which can be divided into different time units, including seconds, minutes, hours, days, months or even longer time spans.

[0067] ES (Elasticsearch) database: is a distributed document storage and search engine, specifically designed for full-text search and analysis of large-scale data sets. It stores data in JSON (JavaScript Object Notation, JS Object Notation) format and provides powerful search, aggregation and analysis capabilities.

[0068] PHP (Hypertext Preprocessor) business: various web applications and online services developed based on the PHP programming language.

[0069] Go(Golang) business: It is various applications, services and solutions developed using the Go programming language.

[0070] OOM (Out of Memory) time: refers to the system running out of available memory and unable to meet the memory requirements of running applications or processes.

[0071] K8S (Kubernetes): is an open source container orchestration and container management platform used to automate and simplify the deployment, expansion, management, and operation of containerized applications.

[0072] K8S Pod issues: Pod is the basic unit of container orchestration and management. K8S Pod issues can involve aspects such as Pod deployment, management, scheduling, monitoring, networking, storage, and interaction with other Kubernetes resources, such as Pod startup failure, Pod scheduling failure, multi-container collaboration issues, network issues, container security, etc.

[0073] Secondly, in order to facilitate those skilled in the art to understand the technical solutions provided in the embodiments of the present application, the relevant technologies are described below:

[0074] ES database is a distributed document storage and search engine that can be used to process large-scale data sets, such as logs, documents, time series data, etc. ES database is widely used in full-text search, text analysis, data aggregation and other fields. Although ES database can be used to store and query various types of log data, its support for log monitoring and alarm is weak, making it difficult to achieve efficient real-time log monitoring and key alarms.

[0075] To this end, the embodiment of the present application provides a technical solution for business system monitoring. In this technical solution: the log data of the business system can be monitored, the monitored log data can be filtered multiple times and multiple ways of notifying relevant personnel are supported, and the alarm log data can be persisted, and it can be run in the Python environment, is lightweight, and has a low threshold for use; the alarm rules are flexible and can be applied to log data in a variety of different formats. See below for details.

[0076] The technical solutions of the present application are described below through multiple embodiments. It should be noted that these embodiments can be implemented in a variety of different forms and should not be construed as being limited to the embodiments described here.

[0077] Embodiment 1

[0078] Figure 1 The flowchart of the business system monitoring method according to the first embodiment of the present application is schematically shown.

[0079] like Figure 1 As shown, the business system monitoring method may include steps S100 to S104, wherein:

[0080] Step S100, acquiring monitoring data of a target business system, wherein the monitoring data includes log data and error information of a target interface, the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority.

[0081] Step S102: acquiring alarm log data from the log data according to the error information of the target interface.

[0082] Step S104: Generate and send a target alarm notification according to the interface priority of the target interface and the alarm log data.

[0083] The business system monitoring method provided in this embodiment can quickly identify the log data that needs to trigger an alarm through the error information of the target interface, and customize the target alarm notification for the alarm log data and notify the relevant person in charge through the pre-configured interface priority, thereby realizing efficient real-time log monitoring and key alarms. The technical solution of the embodiment of the present application is highly flexible and applicable to a variety of scenarios, and can be used for log monitoring of ES databases, for example.

[0084] The following combination Figure 1 , each step in steps S100 to S104 and other optional steps are described in detail.

[0085] Step S100 , obtaining monitoring data of a target business system, the monitoring data including log data and error information of a target interface, the target business system being configured with the target interface, and the target interface being pre-associated with an interface priority.

[0086] The target business system can manage and execute various types of business, including PHP business, Go business, C# business, etc. Each target business system can provide one or more interfaces according to specific business needs to interact with the client. Among them, these interfaces (such as target interfaces) may be affected by various factors (such as parameters, permissions, and networks) during use, resulting in errors and error messages. Different interfaces can be pre-configured with different interface priorities, such as important interfaces and non-important interfaces, or first interface priority, second interface priority, etc. In this way, when an error occurs in the interface, it can be processed accordingly according to the interface priority.

[0087] Monitoring data may include various data of the target business system, such as performance data, error and exception data, security data, log data, business indicator data, resource utilization data, and third-party service data. In this embodiment, the monitoring data includes but is not limited to log data and target interface error information, which are used to detect and locate problems. It should be noted that other monitoring data may also be selected to meet the application requirements of different scenarios.

[0088] Monitoring data can be stored in various types of databases, including MySQL database, NoSQL database, ES database, etc. The monitoring data of the target business system can be obtained through a variety of solutions. Taking the ES database as an example, the monitoring data of the target business system stored in the database can be accessed in real time through the ES query interface.

[0089] Monitoring data can be all monitored data or part of the data.

[0090] In order to better save computer resources and improve alarm efficiency, an exemplary solution for obtaining monitoring data is provided below.

[0091] In an optional embodiment, the monitoring data is obtained based on a query condition, the query condition is configured with a query log level and a query time window, and the query time window corresponds to a plurality of sub-time windows. Figure 2 As shown, step S100 may include:

[0092] Step S200: acquiring the log data of the target business system within the query time window by querying the log level.

[0093] Step S202: Acquire error information of the target interface in each sub-time window, wherein the error information includes an error value.

[0094] The target business system generates a large amount of log data during operation, including but not limited to network log data, error log data, performance log data and access log data. On the one hand, a large amount of log data requires a large amount of storage space and computing resources to process and store, and on the other hand, it is difficult to mine valid data that needs to be alerted. Therefore, the log data of the target business system and the error information of the target interface can be initially screened through pre-configured query conditions to obtain log information that meets the query conditions. The query conditions may include query log levels and query time windows. Among them, the query log levels may include error, warning, etc. The query time window is determined by the query start time and the query end time, and may correspond to multiple sub-time windows. For example, the query start time is 16:50 and the query end time is 17:00, and the query time window is 16:50-17:00. If the query time window corresponds to ten independent sub-time windows of the same size, then the corresponding sub-time windows include: 16:50-16:51, 16:51-16:52... If the query time window corresponds to 60 independent sub-time windows of the same size, then the corresponding sub-time windows include: 16:50:00-16:50:10, 16:50:10-16:50:20, and so on.

[0095] Correspondingly, the obtained log data is the log data generated within the query time window and the log level is error or warning. Obtaining the error information of the target interface is to obtain the error information (such as error value, error type, error level) of the target interface in each sub-time window. The error value can be the number of errors that occurred on the target interface. For example, the number of errors per minute (sub-time window) of the target interface within 10 minutes (query time window) is obtained.

[0096] In this embodiment, by obtaining log data and error information of the target interface through pre-set query conditions, error log data and error information of a specific time period can be filtered and screened out, saving storage space and computing resources, reducing system burden, and improving the efficiency of identifying and locating problems, thereby helping to improve alarm efficiency.

[0097] In some embodiments, the query conditions may also include a custom filter tag to exclude log data that matches the filter tag, reduce redundant data, and thus perform data screening more accurately. Figure 3 The filter tag shown can be set to "URL Exclusion" to exclude specific URLs (Uniform Resource Locators).

[0098] In some embodiments, the detected errors may be formed into a time series, and then the time period with higher error levels and / or higher error frequencies may be analyzed based on the time series, and then the log data corresponding to the time period may be screened out. It should be noted that various feasible methods may be used to screen out the required log data according to actual needs.

[0099] Step S102 , obtaining alarm log data from the log data according to the error information of the target interface.

[0100] There is a certain correspondence between the error information of the target interface and the log data (error log data, log level is error or warning) obtained after the initial screening. For example, if the error value of the target interface within one minute is 10, that is, the target interface has 10 errors within one minute, the target business system will generate 10 error log data accordingly. Among them, the error log data is used to record the details of the corresponding error so that the operation and maintenance personnel can analyze the error and troubleshoot the problem. The error log data can be classified, for example, it can be divided into important error log data and minor error log data. If each error log data triggers an alarm, it may cause false alarms (insignificant or temporary minor error log data triggers an alarm), and these errors do not need to be processed immediately. Therefore, the obtained log data can be filtered twice to obtain part of the log data that needs to trigger an alarm as the alarm log data. The log data is filtered twice by the error information of the target interface and the preset filtering rules, which can reduce false alarms and alarm fatigue.

[0101] An exemplary secondary filtration scheme is provided below.

[0102] In an optional embodiment, if Figure 4 As shown, step S102 may include:

[0103] Step S400: selecting one or more target sub-time windows from the plurality of sub-time windows according to the error values ​​in the respective sub-time windows and a preset filtering rule.

[0104] Step S402: acquiring part of the log data from the log data according to the one or more target sub-time windows to serve as the alarm log data.

[0105] The preset filtering rules define the conditions for the log data to trigger an alarm, which can be the occurrence of a specific event, the reaching of a specific threshold, the inclusion of specific keywords in the log data, etc. In this embodiment, the preset filtering rules can include time window conditions and value conditions. For example, the query time window is 16:50-17:00, wherein the error value of the sub-time window 16:50-16:51 is 25, the error value of the sub-time window 16:51-16:52 is 45, the error value of the sub-time window 16:52-16:53 is 40, and the error value of the sub-time window 16:53-16:54 is 5. The preset filtering condition can be configured such that the error value for two consecutive minutes (time window condition) is greater than 35 (value condition) to timely detect the emergency of the target interface error. Based on this, the sub-time windows that meet the preset filtering conditions are 16:50-16:51 and 16:51-16:52. Take these two sub-time windows as target sub-time windows, and obtain part of the log data (log data generated in these two sub-time windows) from the log data corresponding to the entire query time window. This part of the log data is the log data that needs to trigger the alarm. It should be noted that the preset filtering conditions can be set according to the needs to meet different application requirements, and are not limited here. For example, Figure 3 As shown, the preset filtering condition in the above scenario can also be configured as the sum of the error values ​​for three consecutive minutes is greater than 100. Setting a longer time window condition can improve the reliability of fault detection. The corresponding target sub-time windows are: 16:50-16:51, 16:51-16:52 and 16:52-16:53. The alarm log data is the log data generated in these three target sub-time windows.

[0106] In the above optional embodiment, by presetting filtering rules and error values ​​of each sub-time window, the log data of the target business system can be secondary filtered to quickly identify and locate key log data that need to trigger an alarm, thereby reducing false alarms and alarm fatigue, reducing resource consumption, and alleviating system burden.

[0107] Of course, in some embodiments, the screening of the target sub-window may be further optimized as needed to obtain more effective alarm log data.

[0108] For example, adaptive threshold settings can be implemented based on historical data and statistical analysis. In this way, the threshold can be automatically adjusted according to data changes, rather than fixed preset values, so as to better adapt to data volatility. In specific applications, the number of requested accesses fluctuates. For example, when the number of accesses is small during idle periods, the number of errors generated per unit time (such as 25 per minute) needs to be filtered out. However, during peak periods, more errors may be generated per unit time, and 25 errors per minute do not need to be filtered out.

[0109] For another example, an abnormal detection algorithm (such as Isolation Forest) can be used to automatically identify abnormal target sub-windows, rather than just based on a threshold, or a clustering algorithm can be used to automatically mark windows to automatically identify target sub-windows.

[0110] For another example, nested time windows can be considered to allow for more fine-grained data filtering. For example, a large time window is selected first, and then a small time window is selected within it, and the final selected small time window is used as the target sub-window.

[0111] The above methods can be used individually or in combination according to specific requirements to improve the accuracy and efficiency of screening target sub-time windows.

[0112] Step S104 , generate and send a target alarm notification based on the interface priority of the target interface and the alarm log data.

[0113] After obtaining the log data (the alarm log data) that needs to trigger an alarm, different target alarm notifications can be customized for the alarm log data according to the interface priority of the target interface, so as to issue an alarm in different ways to improve the efficiency of the alarm and strengthen the priority management of the problem. The interface priority of the target interface can be pre-set manually or by machine based on factors such as the historical alarm frequency, historical error information, and historical alarm level of the target interface to achieve importance grading (important interfaces and non-important interfaces, etc.). In actual applications, target alarm notifications can be customized for the target interface in a variety of ways, and a number of exemplary schemes are provided below.

[0114] In an optional embodiment, the target warning notification includes a text warning notification and / or an instant voice connection warning notification.

[0115] Correspondingly, if Figure 5 As shown, step S104 may include:

[0116] Step S500, when the interface priority is the first priority, generating the instant voice connection alarm notification and the text alarm notification according to the alarm log data.

[0117] Step S502, when the interface priority is lower than the first priority and the error values ​​of one or more sub-time windows meet the preset trigger condition, generate the text alarm notification according to the alarm log data.

[0118] When the interface priority of the target interface is the first priority (such as an important interface), an instant voice connection alarm notification and a text alarm notification are generated based on the alarm log data. Among them, the instant voice alarm notification can be a telephone alarm, which can effectively improve the alarm response speed by using this direct connection alarm method. The text alarm notification can be sent in the form of SMS, email, instant message, etc. The text alarm notification can include detailed alarm content (error code, error time, error type, error cause, handling suggestions, etc.) to enhance the effectiveness of the alarm, which helps the relevant person in charge to accurately locate the error and accelerate error diagnosis.

[0119] When the interface priority of the target interface is lower than the first priority (such as a non-important interface), an alarm is generally not required. However, if the failure of the target interface is serious, it may still have a greater negative impact on the system. Therefore, it is also possible to further determine whether the error values ​​of multiple sub-time windows of the target interface meet the preset trigger conditions. Among them, triggering refers to triggering the preset filtering rules. The preset trigger conditions may include a preset trigger time and a preset trigger threshold. For example, the preset trigger time is 3 minutes, and the preset trigger threshold is 10 times. If the error values ​​of multiple sub-time windows of the target interface trigger the preset filtering rules more than or equal to 10 times within 3 minutes, it means that the target interface errors are frequent and an alarm is also required. Generate a text alarm notification based on the alarm log data to notify the relevant person in charge. If the preset trigger conditions are not met, no alarm is required.

[0120] It should be noted that other methods can also be used to more accurately determine whether an alarm is needed for a non-important interface. For example, a dynamic threshold can be generated based on a machine learning algorithm for historical data, so that the preset trigger condition can be adaptively set according to the actual situation. The error values ​​of multiple consecutive sub-time windows can be aggregated, and the error situation can be evaluated by calculating the average, standard deviation, percentile, etc., and whether an alarm is needed is determined based on the evaluation results. It can be determined whether an alarm is needed based on the severity and number of errors according to different error levels. The data detected in each sub-time window can also be input into a long short-term memory network model, and the probability of subsequent serious errors and the degree of impact on the overall system can be predicted through the long short-term memory network model, and whether an alarm is needed can be determined based on the probability of subsequent serious errors and the degree of impact on the overall system.

[0121] In this embodiment, different alarm rules are configured for different interface priorities to achieve importance grading, ensuring that alarms for important interfaces can be responded to more quickly, while reducing and lowering target alarm notifications for non-important interfaces, helping to focus on problems with important interfaces and reduce interference with non-important interfaces.

[0122] As mentioned above, target alarm notifications include voice connection alarm notifications and text alarm notifications, each of which has different advantages: instant voice connection alarm notifications (such as telephone connections, WeChat calls) can quickly convey alarm information in a short period of time, and the content of instant voice connection alarm notifications can only include alarm information (key information extracted from alarm log data, such as: error timestamp, error level, etc.). Text alarm notifications are not subject to time restrictions and can carry more detailed alarm content to provide a more comprehensive problem description, facilitate problem analysis and troubleshooting, and improve alarm efficiency and effectiveness. The following will provide multiple ways to generate target alarm notifications.

[0123] In an optional embodiment, if Figure 6 As shown, the business system monitoring method may further include:

[0124] Step S600: Obtain corresponding alarm information according to the alarm log data.

[0125] Step S602: Obtain corresponding error causes and processing suggestions based on the alarm log data.

[0126] Step S604, when the corresponding error cause and processing suggestion are obtained, a first target alarm notification is generated according to a preset alarm template, the alarm information, the error cause and the processing suggestion.

[0127] Step S606: If the corresponding error cause and processing suggestion are not obtained, a second target alarm notification is generated according to a preset alarm template and the alarm information.

[0128] Obtain the corresponding error causes and handling suggestions for the alarm log data. If any, add them to the target alarm notification (such as text alarm notification) to further provide a more comprehensive problem description, facilitate problem analysis and troubleshooting, and improve alarm efficiency and effectiveness.

[0129] In some embodiments, various methods may be used to obtain the corresponding error causes and processing suggestions. For example, a knowledge graph may be pre-built to store error data, causes, processing suggestions, and their relationships in a knowledge graph. Multiple keywords may be extracted from the alarm log data, and the knowledge graph may be queried using multiple keywords to obtain more error causes and processing suggestions, which may further obtain potential error causes and processing suggestions. A machine learning model or a deep network learning model may also be trained based on historical data (errors, error causes, processing suggestions, etc.). When used specifically, multiple keywords may be extracted from the alarm log data, and then the multiple keywords may be input into the machine learning model to predict available error causes and processing suggestions as much as possible.

[0130] In other embodiments, an error database may be preconfigured to store error data, as well as error causes and processing suggestions corresponding to the error data. Therefore, after obtaining the alarm log data, the error causes and processing suggestions corresponding to the alarm log data may be retrieved from the error database. In the case where the error causes and processing suggestions corresponding to the alarm log data are retrieved, the alarm information, the error causes and processing suggestions may be loaded into a preset alarm template to generate a first target alarm notification (which may be a first text alarm notification). In the case where the corresponding error causes and processing suggestions are not retrieved, the alarm information is loaded into a preset alarm template to generate a second target alarm notification (which may be a second text alarm notification). The first / second text alarm notification may be sent to the relevant person in charge via SMS, email, instant messaging, etc.

[0131] Specifically, Figure 7 As shown, step S602 may include:

[0132] Step S700, matching the alarm log data with a preset error database, wherein the preset error database includes a plurality of error data, each error data being associated with an error cause and a processing suggestion.

[0133] Step S702: when the alarm log data and the target error data in the preset database match successfully, obtain the target error cause and target processing suggestion associated with the target error data.

[0134] Match the alarm log data with the error database, where the error database can include multiple error data, each of which has a corresponding error cause and processing suggestion. Error data, error causes, and processing suggestions can be stored together in the error database in the form of KV key-value pairs, or stored in other locations according to specific needs, for example, storing processing suggestions in a preset help model library. Matching methods may include keyword matching, regular expression matching, semantic analysis, pattern matching, similarity analysis, metadata matching, etc.

[0135] The matching process is as follows: first match the field keywords in the alarm log data (such as timestamp, error code, device information, event type, etc.) with the preset basic error data model, which includes multiple error data. When the match returns a value (that is, there is target error data), further obtain the target error cause corresponding to the alarm log data (such as service timeout, OOM time, K8S Pod problem, query library timeout, cache database, etc.). Then match the preset help model library according to the error cause to obtain target processing suggestions.

[0136] In the above optional embodiment, by matching with the preset error database and then obtaining the error cause and processing suggestion corresponding to the alarm log data, the error cause and processing suggestion provide a clear problem description, which can greatly reduce the complexity of problem handling, thereby reducing operation and maintenance costs and improving the efficiency of operation and maintenance personnel.

[0137] In an optional embodiment, if Figure 8 As shown, step S602 may include:

[0138] Step S800: When the alarm log data and the preset error database fail to match, the alarm log data is stored in a preset cache area.

[0139] Step S802: When the target error cause and target processing suggestion corresponding to the alarm log data are obtained, the alarm log data is added as error data to the preset error database.

[0140] In this embodiment, the alarm log data that fails to match is recorded, and after the target interface error corresponding to the alarm log data is processed, the corresponding target error cause and target processing suggestion are obtained. Then the alarm log data is added to the preset error database, and the preset error database is improved and perfected through iteration, effectively tracking the problem history, so that similar interface errors in the future can be more easily solved, further improving the alarm efficiency and operation and maintenance efficiency.

[0141] The above embodiments describe the generation of target alarm notifications. The following describes how to send target alarm notifications.

[0142] In an optional embodiment, step S104 may further include:

[0143] Step S900, obtaining target object information associated with the target interface, wherein the target object information includes a voice connection interface and a communication interface.

[0144] Step S902: sending an instant voice connection alarm notification to the target object through the voice connection interface; and / or sending a text alarm notification through the communication interface.

[0145] The target object can be the operation and maintenance person in charge of the target interface (such as Figure 3 The target object information includes the voice connection interface and the communication interface. The voice connection interface may include the target object's ID, name, device name, contact information, permissions, etc. By calling the voice connection interface, an instant voice connection alarm notification may be sent to the target object. The communication interface may include the recipient's name, contact information, email address, instant messaging software personal interface, etc. By calling the communication interface, a text alarm notification may be sent to the target object.

[0146] In this embodiment, a voice connection interface and / or a communication interface is obtained and called to send a target alarm notification to a target object so that operation and maintenance personnel can quickly obtain and understand the alarm information, thereby improving the efficiency and effectiveness of the alarm.

[0147] In an optional embodiment, the target alarm notification may be configured with an alarm duration and alarm frequency to further improve alarm flexibility and alarm efficiency. The alarm duration and alarm frequency may be set according to specific needs. Figure 3 As shown in the figure, a maximum of 6 alarms are set within 60 minutes, that is, a maximum of 6 target alarm notifications are sent within 60 minutes.

[0148] In an optional embodiment, the alarm log data can also be stored in a preset database by calling a preset interface to facilitate querying historical data.

[0149] In an optional embodiment, the business system monitoring method is implemented in the form of a Python script. A startup entry res.py is configured for the user, and when the user clicks to start the script, the business system monitoring method can be implemented. It can be seen that the embodiment of the present application can be run in a Python environment, is lightweight, has a low threshold for use, and can be applied to log data in a variety of different formats.

[0150] In order to make this application easier to understand, the following Figures 10-11 An exemplary application is provided.

[0151] S11, call the ES query interface, and obtain the log data of the target business system and the number of API interface errors per minute (the error value of the target interface) from the ES database according to the preset query conditions.

[0152] S12, when the number of API interface errors in the current minute and the previous minute is greater than 35, the log data in the current minute and the previous minute are used as monitoring data / alarm data (alarm log data).

[0153] S13, obtaining the interface importance (interface priority) of the target interface. If the target interface is an important interface (first priority), execute S14; if the target interface is a non-important interface (lower than the first priority), execute S15.

[0154] S14, extract key information from monitoring data, directly issue an alarm via telephone, and then execute S16.

[0155] S15, determine whether the number of times a non-important interface triggers a preset filtering rule within a preset time (such as 3 minutes) exceeds a preset trigger threshold (10 times). If so, execute S16, if not, do not issue an alarm.

[0156] S16, analyzing the causes of errors in the monitoring data and obtaining corresponding processing suggestions.

[0157] The error cause analysis may be performed by matching the field keywords in the log according to the error model database. If the match is successful, the error cause (such as service timeout, OOM time, query library timeout, etc.) is obtained, and processing suggestions are obtained. If the match fails, the problem is recorded and subsequently added to the error model database.

[0158] S17, obtain the person in charge through the interface.

[0159] S18, sending an alarm notification through instant messaging software (such as Feishu) according to the alarm template.

[0160] S19, storing the monitoring data in the ES database.

[0161] In this exemplary application, it supports monitoring the log data of the business system, filtering the monitored log data multiple times, supporting multiple ways to notify relevant personnel, and supporting the persistence of alarm log data; it can run in the Python environment, is lightweight, and has a low threshold for use; the alarm rules are flexible and can be applied to log data in a variety of different formats.

[0162] Embodiment 2

[0163] Fig.12 The block diagram of the business system monitoring device according to the second embodiment of the present application is schematically shown. The device can be divided into one or more program modules, one or more program modules are stored in a storage medium, and are executed by one or more processors to complete the embodiment of the present application. The program module referred to in the embodiment of the present application refers to a series of computer program instruction segments that can complete specific functions. The following description will specifically introduce the functions of each program module in this embodiment. Fig.12 As shown, the device 1200 may include: a first acquisition module 1210, a second acquisition module 1220, and a sending module 1230, wherein:

[0164] A first acquisition module 1210 is used to acquire monitoring data of a target business system, wherein the monitoring data includes log data and error information of a target interface, wherein the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority;

[0165] A second acquisition module 1220, configured to acquire alarm log data from the log data according to the error information of the target interface;

[0166] The sending module 1230 is used to generate and send a target alarm notification according to the interface priority of the target interface and the alarm log data.

[0167] As an optional embodiment, the monitoring data is obtained based on a query condition, the query condition is configured with a query log level and a query time window, and the query time window corresponds to a plurality of sub-time windows;

[0168] Correspondingly, the first acquisition module 1210 is further used for:

[0169] Obtaining the log data of the target business system within the query time window by querying the log level; and

[0170] Obtain error information of the target interface in each sub-time window, wherein the error information includes an error value.

[0171] As an optional embodiment, the second acquisition module 1220 is further configured to:

[0172] Selecting one or more target sub-time windows from the multiple sub-time windows according to the error values ​​in each sub-time window and a preset filtering rule;

[0173] According to the one or more target sub-time windows, part of the log data is obtained from the log data to serve as the alarm log data.

[0174] As an optional embodiment, the target warning notification includes a text warning notification and / or an instant voice connection warning notification;

[0175] Correspondingly, the sending module 1230 is further used for:

[0176] In the case where the interface priority is the first priority, generating the instant voice connection alarm notification according to the alarm log data, and generating the text alarm notification according to the alarm log data;

[0177] When the interface priority is lower than the first priority and the error values ​​of one or more sub-time windows meet a preset trigger condition, the text alarm notification is generated according to the alarm log data.

[0178] As an optional embodiment, the sending module 1230 is further configured to:

[0179] According to the alarm log data, obtain corresponding alarm information;

[0180] According to the alarm log data, obtain the corresponding error cause and processing suggestions;

[0181] When the corresponding error cause and processing suggestion are obtained, a first text alarm notification is generated according to a preset alarm template, the alarm information, the error cause and the processing suggestion;

[0182] If the corresponding error cause and processing suggestion are not obtained, a second text alarm notification is generated according to a preset alarm template and the alarm information.

[0183] As an optional embodiment, the sending module 1230 is further configured to:

[0184] Matching the alarm log data with a preset error database, wherein the preset error database includes a plurality of error data, each error data being associated with an error cause and a processing suggestion;

[0185] When the alarm log data and the target error data in the preset database match successfully, a target error cause and a target processing suggestion associated with the target error data are obtained.

[0186] As an optional embodiment, the sending module 1230 is further configured to:

[0187] In the case where the alarm log data and the preset error database fail to match, storing the alarm log data;

[0188] When the target error cause and target processing suggestion corresponding to the alarm log data are obtained, the alarm log data is added as error data to the preset error database.

[0189] As an optional embodiment, the sending module 1230 is further configured to:

[0190] Acquire target object information associated with the target interface, the target object information including a voice connection interface and a communication interface;

[0191] An instant voice connection alarm notification is sent to the target object via the voice connection interface; and / or a text alarm notification is sent via the communication interface.

[0192] As an optional embodiment, the device 1200 is further used for:

[0193] By calling a preset interface, the alarm log data is stored in a preset database.

[0194] As an optional embodiment, the device 1200 is implemented in the form of a Python script.

[0195] Embodiment 3

[0196] Fig.13The schematic diagram of the hardware architecture of a computer device 10000 suitable for implementing the business system monitoring method according to the third embodiment of the present application is schematically shown. In some embodiments, the computer device 10000 may be a terminal device such as a smart phone, a wearable device, a tablet computer, a personal computer, a vehicle terminal, a game console, a virtual device, a workbench, a digital assistant, a set-top box, a robot, etc. In other embodiments, the computer device 10000 may be a rack server, a blade server, a tower server, or a cabinet server (including an independent server, or a server cluster composed of multiple servers), etc. Fig.13 As shown, the computer device 10000 includes but is not limited to: a memory 10010, a processor 10020, and a network interface 10030 that can communicate with each other through a system bus. Among them:

[0197] The memory 10010 includes at least one type of computer-readable storage medium, and the readable storage medium includes a flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 10010 may be an internal storage module of the computer device 10000, such as a hard disk or a memory of the computer device 10000. In other embodiments, the memory 10010 may also be an external storage device of the computer device 10000, such as a plug-in hard disk equipped on the computer device 10000, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. Of course, the memory 10010 may also include both the internal storage module of the computer device 10000 and its external storage device. In this embodiment, the memory 10010 is generally used to store the operating system and various application software installed in the computer device 10000, such as program code of the business system monitoring method, etc. In addition, the memory 10010 can also be used to temporarily store various data that have been output or will be output.

[0198] In some embodiments, the processor 10020 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other chips. The processor 10020 is generally used to control the overall operation of the computer device 10000, such as performing control and processing related to data interaction or communication with the computer device 10000. In this embodiment, the processor 10020 is used to run the program code stored in the memory 10010 or process data.

[0199] The network interface 10030 may include a wireless network interface or a wired network interface, and the network interface 10030 is generally used to establish a communication link between the computer device 10000 and other computer devices. For example, the network interface 10030 is used to connect the computer device 10000 to an external terminal through a network, and to establish a data transmission channel and a communication link between the computer device 10000 and the external terminal. The network may be a wireless or wired network such as an intranet, the Internet, the Global System of Mobile communication (GSM), Wideband Code Division Multiple Access (WCDMA), 4G network, 5G network, Bluetooth, Wi-Fi, etc.

[0200] It should be pointed out that Fig.13 Only a computer device having components 10010 - 10030 is shown, but it should be understood that implementation of all of the components shown is not a requirement, and more or fewer components may alternatively be implemented.

[0201] In this embodiment, the business system monitoring method stored in the memory 10010 can also be divided into one or more program modules and executed by one or more processors (such as processor 10020) to complete the embodiment of the present application.

[0202] Embodiment 4

[0203] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, wherein when the computer program is executed by a processor, the steps of the business system monitoring method in the embodiment are implemented.

[0204] In this embodiment, the computer-readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEP ROM), programmable read-only memory (PROM), magnetic memory, disk, optical disk, etc. In some embodiments, the computer-readable storage medium can be an internal storage unit of a computer device, such as a hard disk or memory of the computer device. In other embodiments, the computer-readable storage medium can also be an external storage device of a computer device, such as a plug-in hard disk equipped on the computer device, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. Of course, the computer-readable storage medium can also include both the internal storage unit of the computer device and its external storage device. In this embodiment, the computer-readable storage medium is generally used to store an operating system and various application software installed on the computer device, such as the program code of the business system monitoring method in the embodiment, etc. In addition, the computer-readable storage medium can also be used to temporarily store various types of data that have been output or are to be output.

[0205] Obviously, those skilled in the art should understand that the modules or steps of the above-mentioned embodiments of the present application can be implemented by general-purpose computer devices, they can be concentrated on a single computer device, or distributed on a network composed of multiple computer devices, optionally, they can be implemented by executable program codes of computer devices, so that they can be stored in a storage device and executed by the computer device, and in some cases, the steps shown or described can be executed in a different order from that herein, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0206] It should be noted that the above are only preferred embodiments of the present application, and the patent protection scope of the present application is not limited thereto. Any equivalent structure or equivalent process transformation made using the contents of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A business system monitoring method, characterized in that: The method comprises: Acquire monitoring data of a target business system, the monitoring data including log data and error information of a target interface, the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority; Acquire alarm log data from the log data according to the error information of the target interface; A target alarm notification is generated and sent according to the interface priority of the target interface and the alarm log data.

2. The method according to claim 1, characterized in that The monitoring data is obtained based on a query condition, the query condition is configured with a query log level and a query time window, and the query time window corresponds to a plurality of sub-time windows; The obtaining of monitoring data of the target business system includes: Obtaining the log data of the target business system within the query time window by querying the log level; and Obtain error information of the target interface in each sub-time window, wherein the error information includes an error value.

3. The method according to claim 2, characterized in that Acquiring alarm log data from the log data according to the error information of the target interface includes: Selecting one or more target sub-time windows from the multiple sub-time windows according to the error values ​​in each sub-time window and a preset filtering rule; According to the one or more target sub-time windows, part of the log data is obtained from the log data to serve as the alarm log data.

4. The method according to any one of claims 1 to 3, characterized in that: The target warning notification includes a text warning notification and / or an instant voice connection warning notification; The generating and sending a target alarm notification according to the interface priority of the target interface and the alarm log data includes: When the interface priority is the first priority, generating the instant voice connection alarm notification and the text alarm notification according to the alarm log data; When the interface priority is lower than the first priority and the error values ​​of one or more sub-time windows meet a preset trigger condition, the text alarm notification is generated according to the alarm log data.

5. The method according to any one of claims 1 to 3, characterized in that: The generating and sending a target alarm notification according to the interface priority of the target interface and the alarm log data also includes: According to the alarm log data, obtain corresponding alarm information; According to the alarm log data, obtain the corresponding error cause and processing suggestions; When the corresponding error cause and processing suggestion are obtained, a first target alarm notification is generated according to a preset alarm template, the alarm information, the error cause and the processing suggestion; In the case where the corresponding error cause and processing suggestion are not obtained, a second target alarm notification is generated according to a preset alarm template and the alarm information.

6. The method according to claim 5, characterized in that According to the alarm log data, obtain the corresponding error cause and handling suggestions, including: Matching the alarm log data with a preset error database, wherein the preset error database includes a plurality of error data, each error data being associated with an error cause and a processing suggestion; When the alarm log data and the target error data in the preset database match successfully, a target error cause and a target processing suggestion associated with the target error data are obtained.

7. The method according to claim 6, characterized in that Also includes: In the event that the alarm log data fails to match the preset error database, storing the alarm log data in a preset cache area; When the target error cause and target processing suggestion corresponding to the alarm log data are obtained, the alarm log data is added as error data to the preset error database.

8. The method according to any one of claims 1 to 3, characterized in that: Generate and send target alarm notifications, including: Acquire target object information associated with the target interface, the target object information including a voice connection interface and a communication interface; An instant voice connection alarm notification is sent to the target object via the voice connection interface; and / or a text alarm notification is sent via the communication interface.

9. A business system monitoring device, characterized in that: The device comprises: A first acquisition module is used to acquire monitoring data of a target business system, wherein the monitoring data includes log data and error information of a target interface, wherein the target business system is configured with the target interface, and the target interface is pre-associated with an interface priority; A second acquisition module, used to acquire alarm log data from the log data according to the error information of the target interface; The sending module is used to generate and send a target alarm notification according to the interface priority of the target interface and the alarm log data.

10. A computer device, characterized in that: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein: The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.