Fault root cause positioning method and device, electronic equipment, storage medium and program

By creating a full-scale entity event graph in the IT system and using heterogeneous graph neural network to predict causal relationships, the problem of difficulty in IT system failure location is solved, and fast and accurate root cause analysis is achieved, improving the stability and efficiency of the system.

CN119988076APending Publication Date: 2025-05-13BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510063579.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing IT systems lack auxiliary tools for rapid fault location and root cause analysis when failure occurs, resulting in long failure time and low positioning accuracy, which affects system stability and efficiency.

Method used

By creating a full-scale entity event graph, a sub-graph of entity event is generated and a heterogeneous graph neural network is used to predict causal relationships, a causal graph diagram of target events is constructed, and the root cause of failure is finally determined.

Benefits of technology

It improves the extraction rate and positioning accuracy of the root cause of failure, reduces the failure time, and improves the stability and efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119988076A_ABST
    Figure CN119988076A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a fault root cause positioning method and device, electronic equipment, a storage medium and a program. The method comprises the following steps: creating a total entity event graph of a target alarm event; wherein the full-quantity entity event graph comprises associated events and associated entities of the target alarm event, and association relationships between the events and corresponding entities; generating an entity event sub-graph corresponding to the target reference event according to the total entity event graph; inputting each entity event sub-graph into a heterogeneous graph neural network so as to predict a causal relationship between the target reference events according to the entity event sub-graphs through the heterogeneous graph neural network; generating a target event causal graph of the target alarm event according to the causal relationship among the target reference events; and determining a target fault root cause of the target alarm event according to the target event causal graph of the target alarm event. According to the technical scheme, the fault root cause of the system can be accurately extracted, the fault time is shortened, and the stability and efficiency of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of fault detection technology, and in particular to a fault root cause locating method, device, electronic device, storage medium and program. Background Art

[0002] With the continuous development of IT (Information Technology) systems, the process of informatization, digitization and networking is getting faster and faster. The service scope of IT systems covers human social production and daily life, including public services, online finance, business transactions, industrial production and other industries.

[0003] In the process of realizing the present invention, the inventors found that the continuous expansion of the scale of IT systems has led to an increasingly complex operating environment for IT systems. Although various monitoring tools currently available have helped to significantly improve the operating status of IT systems, when a network failure or system failure occurs, faced with massive network monitoring data and a huge system, IT operations and maintenance lack auxiliary judgments and solution recommendations for IT failures, and the IT system cannot quickly obtain sufficient information for fault location and level analysis. Summary of the invention

[0004] The embodiments of the present invention provide a method, device, electronic device, storage medium and program for locating the root cause of a fault, which can accurately extract the root cause of a system fault, reduce the fault time, and improve the stability and efficiency of the system.

[0005] According to one aspect of the present invention, a method for locating a root cause of a fault is provided, comprising:

[0006] Creating a full entity event graph of the target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between the event and the corresponding entity;

[0007] Generate an entity event subgraph corresponding to a target reference event according to the full entity event graph;

[0008] Inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network;

[0009] Generate a target event causal graph of the target alarm event according to the causal relationship between each of the target reference events;

[0010] A target fault root cause of the target alarm event is determined according to a target event cause-effect graph of the target alarm event.

[0011] According to another aspect of the present invention, a fault root cause locating device is provided, comprising:

[0012] A full entity event graph creation module, used to create a full entity event graph of a target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between events and corresponding entities;

[0013] An entity event subgraph generation module, used to generate an entity event subgraph corresponding to a target reference event according to the full entity event graph;

[0014] A causal relationship prediction module, used for inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network;

[0015] A target event causal graph generation module, used to generate a target event causal graph of the target alarm event according to the causal relationship between the target reference events;

[0016] The target fault root cause determination module is used to determine the target fault root cause of the target alarm event according to the target event cause-effect graph of the target alarm event.

[0017] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0018] at least one processor; and

[0019] a memory communicatively connected to the at least one processor; wherein,

[0020] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the fault root cause locating method described in any embodiment of the present invention.

[0021] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the fault root cause locating method described in any embodiment of the present invention when executed.

[0022] According to another aspect of the present invention, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the method for locating a root cause of a fault according to any embodiment of the present invention is implemented.

[0023] The embodiment of the present invention creates a full entity event graph of the target alarm event, so as to obtain the associated events and associated entities of the target alarm event, as well as the association relationship between the event and the corresponding entity through the full entity event graph. Furthermore, an entity event subgraph corresponding to the target reference event is generated according to the full entity event graph, so that each entity event subgraph is input into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraph through the heterogeneous graph neural network, and then generate a target event causal graph of the target alarm event according to the causal relationship between each target reference event, and finally determine the target fault root cause of the target alarm event according to the target event causal graph of the target alarm event. The above technical scheme can solve the problems of low extraction rate and positioning accuracy of the root cause of the fault in the existing system when locating the root cause of the fault, and can accurately extract the root cause of the fault of the system, reduce the fault time, and improve the stability and efficiency of the system.

[0024] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0026] Figure 1 This is a flow chart of a method for locating the root cause of a fault provided in Embodiment 1 of the present invention;

[0027] Figure 2 is a flow chart of a method for locating the root cause of a fault provided by Embodiment 2 of the present invention;

[0028] Figure 3 It is a structural schematic diagram of an entity relationship diagram provided by Embodiment 2 of the present invention;

[0029] Figure 4 This is a schematic diagram of the structure of a full entity event graph provided by Embodiment 2 of the present invention;

[0030] Figure 5 is a structural schematic diagram of an entity event subgraph provided in Embodiment 2 of the present invention;

[0031] Figure 6 This is a schematic diagram of an overall process for locating the root cause of a system failure provided by Embodiment 2 of the present invention;

[0032] Figure 7 is a schematic diagram of the structure of sub-graph sample data provided by Embodiment 2 of the present invention;

[0033] Figure 8 It is a structural schematic diagram of a target event causal graph provided by the second embodiment of the present invention;

[0034] Fig. 9 is a schematic diagram of a fault root cause locating device provided in Embodiment 3 of the present invention;

[0035] Fig.10 A schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. DETAILED DESCRIPTION

[0036] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0037] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0038] Embodiment 1

[0039] Figure 1 This is a flowchart of a method for locating the root cause of a fault provided by the first embodiment of the present invention. This embodiment is applicable to the case where an event causal graph is constructed based on the causal relationship between events predicted by a heterogeneous graph neural network, and the root cause of the fault is located based on the constructed event causal graph. The method can be executed by a device for locating the root cause of a fault. The device can be implemented by software and / or hardware, and can generally be integrated in an electronic device. The electronic device can be a terminal device or a server device. As long as the method for locating the root cause of a fault can be executed, the embodiment of the present invention does not limit the specific device type of the electronic device. Accordingly, Figure 1As shown, the method includes the following operations:

[0040] S110. Create a full entity event graph of the target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between events and corresponding entities.

[0041] Among them, the alarm event may refer to the alarm information recorded when an abnormal situation occurs in the system, which may trigger the fault root cause location process. The target alarm event may refer to the alarm event that requires root cause analysis. Exemplarily, the target alarm event may be an alarm event generated by the system in real time, or it may be a historical alarm event of the system selected according to current needs. The full entity event graph may be a graph structure constructed for the target alarm event, which can reflect the association relationship between all entities and events associated with the target alarm event. The associated events of the target alarm event may be events included in the full entity event graph. The associated entities of the target alarm event may be entities included in the full entity event graph.

[0042] The fault root cause location method provided in the embodiment of the present invention is applicable to any type of system that needs to perform root cause location analysis. Exemplarily, the system may include, but is not limited to, distributed systems, centralized systems, cluster systems, and other types of hardware and / or software systems. The embodiment of the present invention does not limit the system type to which the fault root cause location method is applicable.

[0043] Correspondingly, after detecting that the system triggers the generation of a target alarm event, the target alarm event can be used as a benchmark to obtain relevant data of the target alarm event, and then all related entities of the target alarm event can be determined based on the relevant data of the target alarm event, and the associated events of all related entities can be obtained, thereby generating a full entity event graph of the target alarm event based on all related entities and associated events of the target alarm event.

[0044] Among them, the entity represents the object defined in the system, which can be determined by relevant information such as entity type, entity ID (Identity, identity number), entity name and entity first appearance time. Exemplarily, taking a distributed system as an example, the entity type can include but is not limited to resource type entities within the system, such as hosts or containers, and can also be business type entities within the system, such as services or businesses. The entity ID is the corresponding ID, and the entity name is the readable name of the entity. An event is an event that occurs on an entity. It can be a logical structure that describes an event that occurred on an entity within a certain period of time. It can usually be generated by indicator anomaly detection, log anomaly detection, and version change records. An event may include but is not limited to fields such as event type, event ID, event name, entity, start time, and end time. Exemplarily, taking a distributed system as an example, the event type may include but is not limited to a spike in machine memory usage, excessive CPU usage, and insufficient memory resources.

[0045] Optionally, in the full entity event graph, the association relationship between entities and the association relationship between entities and events can be represented by undirected edges. That is, when there is an undirected edge between two entities, it indicates that there is an association relationship between the two entities; when there is an undirected edge between an entity and an event, it indicates that there is an association relationship between the entity and the event.

[0046] It should be noted that in the full entity event graph, the associated entity can be an entity directly associated with the target alarm event, or it can also be an entity indirectly associated with the target alarm event. The so-called direct association can be understood as the target alarm event occurring on the associated entity. The so-called indirect association can be understood as the existence of an association relationship between entities directly associated with the target alarm event. Exemplarily, assuming that the entity directly associated with the target alarm event is entity A, if entity B has an association relationship with entity A, then entity B can be used as an entity indirectly associated with the target alarm event; if entity C has an association relationship with entity B, then entity C can also be used as an entity indirectly associated with the target alarm event.

[0047] It can be seen that after detecting that the system generates a target alarm event, by creating a full entity event graph of the target alarm event, the data of all entities and events associated with the target alarm event can be clearly grasped, which can be used as the basic data source for the subsequent fault root cause location process.

[0048] S120: Generate an entity event subgraph corresponding to a target reference event according to the full entity event graph.

[0049] The target reference event may be an event used to generate an entity event subgraph, and the number of target reference events may be multiple. The entity event subgraph may be a subgraph of a local area selected from the full entity event graph, and the subgraph includes entities associated with the target reference event.

[0050] When it is necessary to determine the root cause of the target alarm event, it is often necessary to analyze the causal relationship between different events. In an embodiment of the present invention, in order to determine the causal relationship between different events, the event that needs to analyze the causal relationship in the full entity event graph can be determined as the target reference event, and an entity event subgraph corresponding to the target reference event is generated based on the full entity event graph. In the entity event subgraph, only entities and events associated with the target reference event are included. That is, the entities included in the entity event subgraph are part of the entities in the full entity event graph, and the events included in the entity event subgraph are part of the events in the full entity event graph.

[0051] Exemplarily, event A and event B in the full entity event graph can be used as target reference events, and the entities and events associated with event A and event B can be determined based on the full entity event graph, and then the association relationship between the entities and events associated with event A and event B can be determined based on the full entity event graph to obtain the entity event subgraph corresponding to event A and event B.

[0052] Optionally, the number of target reference events may be 2, 3 or other values, and the embodiment of the present invention does not limit the number of target reference events. It is understandable that when the type and / or number of target reference events are different, the structure and content of the corresponding generated entity event subgraphs may be the same or different.

[0053] In order to obtain the causal relationship between all events, all events included in the full entity event graph can be traversed to construct multiple sets of target reference events, thereby generating multiple entity event subgraphs based on the multiple sets of target reference events. Since the edges in the full entity event graph and the entity event subgraph are undirected edges, attribute information can be configured for the edges in the full entity event graph, such as determining the relationship type to which the edge belongs, to enrich the edge information.

[0054] S130, inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network.

[0055] Among them, Heterogeneous Graph Neural Networks is a deep learning model for processing heterogeneous graph data. In heterogeneous graphs, nodes and edges can be of different types, which makes it difficult for traditional graph neural network models to be directly applied to such complex graph structures. Heterogeneous graph neural networks are designed to effectively learn and represent such complex heterogeneous graph data. They usually include multiple different types of nodes and edges, each type of node and edge may have different features and semantic meanings.

[0056] Since the nodes in the entity event subgraph are entities and events, and the edges are the relationships between entities and between entities and events, the entity event subgraph is a heterogeneous graph. Therefore, after obtaining each entity event subgraph, the entity event subgraph can be used as input data and input into the pre-trained heterogeneous graph neural network, so that the heterogeneous graph neural network can predict the causal relationship between the target reference events based on the entity event subgraph.

[0057] The causal relationship between events in the entity event subgraph is predicted by using a heterogeneous graph neural network. First, it is assumed that all the edges that can be associated with a causal relationship must also have associated entities. This assumption comes from the fact that the causal relationship of events must be restricted by their entity relationships. Specifically, for example, it is necessary to determine whether event 1 and event 2 are causally related. The input is the entity where event a and event b are located, the connected entity of the entity, and all events on the entity. The output is whether event a and event b are related. Heterogeneous graph neural networks use surrounding events and entity information as conditions to judge event causality, which can improve the accuracy and efficiency of event causal relationship positioning.

[0058] S140: Generate a target event causal graph of the target alarm event according to the causal relationship between the target reference events.

[0059] The target event causal graph may refer to a graph including associated events corresponding to the target alarm event and the causal relationship between the events.

[0060] Since the full entity event graph can generate multiple entity event subgraphs, each entity event subgraph can predict the causal relationship between the corresponding target reference events. Therefore, after the prediction of all entity event subgraphs is completed using a heterogeneous graph neural network, the causal relationship between the events in the full entity event graph can be obtained. It can be understood that among the events in the full entity event graph, some events have a causal relationship, and some events may not have a causal relationship. The causal relationship between events is related to the actual failure of the system, and the embodiments of the present invention do not limit this.

[0061] Therefore, a target event causal graph for generating target alarm events can be constructed based on the causal relationship between all target reference events. In the target event causal graph, events are nodes, causal relationships between events are edges, and causal relationships between events can be labeled. Optionally, the edges between events in the target event causal graph can be directed edges. Exemplarily, on the target event causal graph, if event a points to event b, it means that event a is the cause event of event b. Optionally, the edges of the target event causal graph can also be configured with other attribute data, such as association weights.

[0062] S150: Determine a target fault root cause of the target alarm event according to a target event cause-effect graph of the target alarm event.

[0063] The target fault root cause may refer to a root cause event with a high probability of generating a target alarm event. Optionally, the target fault root cause may be of one or more types. The root cause event may be understood as an event type that causes the target alarm event.

[0064] Since the target event causal graph of the target alarm event establishes a causal relationship with all associated events of the target alarm event, the target event causal graph can be used as a benchmark, the target alarm event can be used as an entry event, and the events that cause the target alarm event can be searched and determined in sequence as the root cause events of the target alarm event, and the target fault root cause of the target alarm event can be determined according to the degree of influence of the root cause events. Exemplarily, one or more root cause events that have a high probability of causing the target alarm event can be determined as the target fault root cause. In this way, the target event causal graph can help find the most fundamental reason for the occurrence of the target alarm event in the system.

[0065] The embodiment of the present invention creates a full entity event graph of the target alarm event, so as to obtain the associated events and associated entities of the target alarm event, as well as the association relationship between the event and the corresponding entity through the full entity event graph. Furthermore, an entity event subgraph corresponding to the target reference event is generated according to the full entity event graph, so that each entity event subgraph is input into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraph through the heterogeneous graph neural network, and then generate a target event causal graph of the target alarm event according to the causal relationship between each target reference event, and finally determine the target fault root cause of the target alarm event according to the target event causal graph of the target alarm event. The above technical scheme can solve the problems of low extraction rate and positioning accuracy of the root cause of the fault in the existing system when locating the root cause of the fault, and can accurately extract the root cause of the fault of the system, reduce the fault time, and improve the stability and efficiency of the system.

[0066] Embodiment 2

[0067] Figure 2It is a flow chart of a method for locating the root cause of a fault provided in the second embodiment of the present invention. This embodiment is concretized based on the above embodiment. In this embodiment, a variety of specific optional implementation methods are provided for obtaining a full entity event graph, generating an entity event subgraph, training a heterogeneous graph neural network, generating a target event causal graph, and determining the target fault root cause.

[0068] Correspondingly, such as Figure 2 As shown, the method of this embodiment may include:

[0069] S210: Create a full entity event graph of the target alarm event.

[0070] In an optional embodiment of the present invention, the creation of a full entity event graph of the target alarm event may include: determining the corresponding target call chain data based on the key fields of the target alarm event; determining the associated entities included in the target call chain data based on preset associated fields, and constructing an entity relationship graph containing each of the associated entities based on preset entity relationships; determining the associated events of each of the associated entities in the entity relationship graph; establishing an association relationship between the associated events and the corresponding associated entities to obtain the full entity event graph.

[0071] Among them, the key field can be a field in the target alarm event that identifies the service where the current call is located. Exemplarily, the key field can be a business field, etc. The target call chain data can be the call chain data corresponding to the target alarm event. The call chain data can include detailed execution status of each component on the query request path. The preset association field can be a pre-set field for identifying the associated entities contained in the target call chain data. The preset entity relationship can refer to the information transfer relationship between various entities preset in the system. The entity relationship diagram can be a diagram including various associated entities in the target call chain data, and the entity relationship between various associated entities.

[0072] In an embodiment of the present invention, when creating a full entity event graph of a target alarm event, the corresponding target call chain data can be specifically determined first according to the key fields of the target alarm event to obtain the relevant data called by the target alarm event. Further, a preset association field is determined. For example, the preset association field can be a service name, i.e., service_name, to determine the entity corresponding to the service in the business type; the preset association field can also be a host address, i.e., host.ip, to determine the entity corresponding to the host in the resource type. After determining the preset association field, the associated entities included in the target call chain data can be determined according to the preset association field, so as to construct an entity relationship graph including each associated entity according to the preset entity relationship. For example, the preset entity relationship can be a topological relationship between hosts, a call relationship between services, a deployment relationship between services and hosts, etc. In the entity relationship graph, entities are nodes and the relationships between entities are edges. For example, if the entity corresponding to host 1 is taken as a node, service 1 is taken as another node, and service 1 is deployed on host 1, then the two nodes have an edge of the "deployment" type. After establishing the entity relationship graph corresponding to each associated entity, the associated events of each associated entity in the generated entity relationship graph can be further determined, and the association relationship between the associated events and the corresponding associated entities can be established to obtain the full entity event graph.

[0073] Optionally, when determining the corresponding target call chain data according to the key fields of the target alarm event, the key fields such as the business field, alarm start time and alarm end time of the target alarm event can be obtained, wherein the business field can refer to the field indicating the service entry. Exemplarily, the business field can be service_name. The alarm start time can refer to the time when the alarm event starts to be generated. The alarm end time can refer to the time when the alarm event ends. Further, the preset time range is determined according to the alarm start time and the alarm end time, such as taking the time period from half an hour before the alarm start time to half an hour after the alarm end time as the preset time range, so as to determine the target call chain data that meets the preset time range from the target database according to the business field. Thus, through the business field, alarm start time and alarm end time in the target alarm event, the target call chain data that meets the preset time range can be screened out in the target database.

[0074] Optionally, when constructing an entity relationship graph including the associated entities according to a preset entity relationship, an entity relationship between two associated entities may be determined according to the preset entity relationship as a connecting edge between the two entity nodes. Figure 3 is a schematic diagram of the structure of an entity relationship diagram provided by the second embodiment of the present invention. In a specific example, Figure 3As shown in the figure, it is assumed that entity 1 is service a, entity 2 is service b, entity 3 is host 1, and entity 4 is host 2. If service a is deployed on host 1, service b is deployed on host 2, service a calls service b, and data is shared between host 1 and host 2, then Figure 3 In the attribute information of the edge between entity 1 and entity 3, the preset entity relationship can be configured as "deployed on", the attribute information of the edge between entity 2 and entity 4 can be configured as "deployed on", the attribute information of the edge between entity 1 and entity 2 can be configured as "call", and the attribute information of the edge between entity 3 and entity 4 can be configured as "data sharing".

[0075] Optionally, when establishing an association relationship between an associated event and a corresponding associated entity, the indicator data corresponding to each associated entity can be determined according to the matching field, and the entity relationship diagram can be filled according to each indicator data and the corresponding event rule. For example, the indicator data that meets the preset time range can be determined from the target database according to the matching field corresponding to each associated entity. In a specific example, if it is necessary to determine the indicator data of the host in the associated entity contained in the target call chain data, and the address of the host is 192.168.1.1. Then the matching field host.ip:192.168.1.1 can be used to determine all the host.ip:192.168.1.1 indicator data within the corresponding time short from the target database. Assume that service a obtains indicator data of average time consumption and call volume type, service b obtains indicator data of call volume type, and host 192.168.1.1 and host 192.168.1.2 both obtain indicator data of CPU usage type. Then, according to each indicator data and the corresponding event rules, an associated event is generated. For example, if the indicator data of host 192.168.1.1 is that the CPU usage is equal to 0.96, and the corresponding event rule is a static threshold detection of excessive CPU usage, the threshold is 0.95. Therefore, an associated event of excessive CPU usage can be generated on the entity host 192.168.1.1. Taking this as an example, the indicator data and event rules corresponding to the remaining associated entities are used to generate corresponding associated events, such as an associated event of high average time consumption and decreased call volume on service a; an associated event of decreased call volume on service b; and no associated event is logged on host 192.168.1.2. Finally, the generated associated events are added to the corresponding entity relationship graph according to the association relationship with the associated entity, and the association relationship between the associated events and the corresponding associated entities is reflected in the entity relationship graph in the form of edges to obtain a full entity event graph.

[0076] Figure 4 is a schematic diagram of the structure of a full entity event graph provided by the second embodiment of the present invention. In a specific example, Figure 4As shown, a corresponding association relationship is established for each associated event corresponding to an associated entity, such as establishing an edge between event 1 and entity 1, an edge between event 3 and entity 1, an edge between event 2 and entity 2, and an edge between event 4 and entity 6, to obtain the final full entity event graph. In the full entity event graph, the relationship between an associated event and the corresponding associated entity can be "occurred in". For example, event 1 occurs in entity 1, event 2 occurs in entity 2, and so on.

[0077] S220 , selecting two events from all events included in the full entity event graph in sequence as current target reference events.

[0078] It is understandable that the events in the full entity event graph include the target alarm event and the associated events of the target alarm event. In order to accurately predict the causal relationship between the events, two events can be selected from all the events included in the full entity event graph as the current target reference events.

[0079] For example, Figure 4 As shown, event 1 and event 3 can be selected as the current target reference events. After event 1 and event 3 are processed, event 1 and event 2 can be selected as the current target reference events, and so on, until all combinations of two events are traversed.

[0080] S230: Determine, according to the full entity event graph, a current associated entity corresponding to the current target reference event and a directly associated entity of the current associated entity.

[0081] The current associated entity may be an associated entity directly associated with the current target reference event, that is, there is an associated relationship between the current associated entity and the current target reference event. The directly associated entity may be an associated entity directly associated with the current associated entity, that is, there is a preset entity relationship between the current associated entity and the directly associated entity.

[0082] S240: Determine, according to the full entity event graph, associated events of the current associated entity and the directly associated entity as current subgraph associated events.

[0083] In a specific example, Figure 4 As shown, assuming that event 1 and event 2 are the current target reference events, then according to Figure 4The full entity event graph shown can determine that the current associated entities corresponding to the current target reference event are entity 1 and entity 2, and the directly associated entities of entity 1 are entity 2 and entity 3, and the directly associated entities of entity 2 are entity 1 and entity 4. Further, the associated events of entity 1 are event 1 and event 3, the associated event of entity 2 is event 2, entity 3 has no associated event, and the associated event of entity 4 is event 5. Then the current subgraph associated events can include event 1, event 3, event 2, and event 5.

[0084] S250: Generate an entity event subgraph corresponding to the current target reference event according to the association relationship between the current associated entity, the directly associated entity, and the current subgraph associated event.

[0085] Figure 5 is a schematic diagram of the structure of an entity event subgraph provided by the second embodiment of the present invention. In a specific example, Figure 4 and Figure 5 As shown, continuing with the above example, assuming that event 1 and event 2 are selected as the current target reference events, the current associated entities corresponding to the current target reference events, namely entity 1 and entity 2, and the directly associated entities of the current associated entities, namely entity 1, entity 2, entity 3 and entity 4, are determined based on the full entity event graph, and then the specific association relationship between the current subgraph associated events such as event 1, event 3, event 2 and event 5 and the corresponding associated entities is combined to filter out the following from the full entity event graph: Figure 5 The entity event subgraph corresponding to the target reference event shown.

[0086] In an optional embodiment of the present invention, generating the entity event subgraph corresponding to the current target reference event based on the association relationship between the current associated entity, the directly associated entity and the current subgraph associated event may include: generating a first undirected edge between entities in the entity event subgraph based on the entity relationship between the current associated entity and the directly associated entity; generating a second undirected edge between entities and events in the entity event subgraph based on the association relationship between the current subgraph associated event and the corresponding entity; and configuring edge attribute data for the first undirected edge and the second undirected edge.

[0087] The entity relationship is also the association relationship between entities. The first undirected edge may be an edge connecting two entities in the entity event subgraph. The second undirected edge may be an edge connecting an entity and an event in the entity event subgraph.

[0088] Specifically, the first undirected edge between entities in the entity event subgraph can be generated based on the entity relationship between the current associated entity and the directly associated entity, and the second undirected edge between the entity and the event in the entity event subgraph can be generated based on the association relationship between the current subgraph associated event and the corresponding entity, thereby obtaining the benchmark architecture of the entity event subgraph corresponding to the current target reference event. Furthermore, the attribute data of the first undirected edge and the second undirected edge in the entity event subgraph can be configured. For example, Figure 5 As shown, the attribute data of the second undirected edge between event 1 and entity 1 can be configured as “occurs at”, and the attribute data of the first undirected edge between entity 1 and entity 3 can be configured as “deployed at”.

[0089] Optionally, based on the determined current associated entity and directly associated entity, a partial graph including the current associated entity, the directly associated entity and the current subgraph associated event can be directly intercepted from the full entity event graph as the entity event subgraph corresponding to the current target reference event.

[0090] S260, inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network.

[0091] After each entity event subgraph is input into the heterogeneous graph neural network, the heterogeneous graph neural network can generate a vector encoding of the target reference event in the entity event subgraph. The generated vector encoding can generate a binary classification result through the linear layer and logit (Logit regression, evaluation model) of the heterogeneous graph neural network. In this way, the causal relationship between events can be judged through the entity event subgraph composed of the relationship between events and entities through the heterogeneous graph neural network model.

[0092] In an optional embodiment of the present invention, before creating the full entity event graph of the target alarm event, it may also include: collecting subgraph positive sample data and subgraph negative sample data based on the event causal graph sample data; wherein, there is a causal relationship between the event and the corresponding entity in the subgraph positive sample data, and there is no causal relationship between the event and the corresponding entity in the subgraph negative sample data; and training the heterogeneous graph neural network based on the subgraph positive sample data and the subgraph negative sample data.

[0093] Among them, the event causal graph sample data can be an optional sample data source for training heterogeneous graph neural networks, and the event causal graph sample data can include entity relationship graphs and event causal graphs with causal relationships. Subgraph positive sample data can be positive sample data generated by event causal graph sample data, and subgraph negative sample data can be negative sample data generated by event causal graph sample data. Both subgraph positive sample data and subgraph negative sample data can be sample data composed of entity event subgraphs. Reference sample events can be event samples used to reference the generation of subgraph positive sample data or subgraph negative sample data.

[0094] Figure 6 FIG. 1 is a schematic diagram of an overall process of locating the root cause of a system failure provided by Embodiment 2 of the present invention. In a specific example, Figure 6 As shown, before using a heterogeneous graph neural network to predict the causal relationship between events, it is first necessary to collect training data to perform a model training process on the heterogeneous graph neural network until it is determined that the prediction accuracy of the heterogeneous graph neural network meets the requirements. In an embodiment of the present invention, when training a heterogeneous graph neural network, an entity relationship graph and an event causal graph with a causal relationship can be used as event causal graph sample data. Among them, the event causal graph also takes events as nodes and samples a graph structure composed of directed edges connecting events. After obtaining the event causal graph sample data, data collection can be performed on the event causal graph sample data, and the corresponding type of entity event subgraphs can be extracted to generate subgraph positive sample data and subgraph negative sample data. Among them, there is a causal relationship between the reference sample events in the subgraph positive sample data, and there is no causal relationship between the reference sample events in the subgraph negative sample data. Accordingly, after collecting and generating the subgraph positive sample data and the subgraph negative sample data, the heterogeneous graph neural network can be trained according to the subgraph positive sample data and the subgraph negative sample data.

[0095] Specifically, when collecting subgraph positive sample data based on event causal graph sample data, all causally related events can be extracted from the known event causal graph, and two causally related events can be selected from the extracted causally related events in turn as reference sample events for the subgraph positive sample data. Furthermore, the selected reference sample events and the entity relationship graph are used to determine the entities that have an association relationship with the reference sample events, and corresponding connection edges are generated between the reference sample events and the entities based on the entity relationship graph, thereby generating an entity event subgraph corresponding to the reference sample events as the subgraph positive sample data. When collecting subgraph positive sample data, it is necessary to ensure that the reference sample events corresponding to the subgraph positive sample data can cover a variety of event types and entity types to ensure that the heterogeneous graph neural network can learn the causal relationship between different types of events.

[0096] Specifically, when collecting subgraph negative sample data based on event causal graph sample data, all events without causal relationships can be extracted from the known event causal graph, and two events without causal relationships can be selected from the extracted events without causal relationships in turn as reference sample events of the subgraph negative sample data. Further, the selected reference sample events and the entity relationship graph determine the entities that have an association relationship with the reference sample events, and the corresponding connection edges are generated between the reference sample events and the entities according to the entity relationship graph, so as to generate the entity event subgraph corresponding to the reference sample events as the subgraph negative sample data. When collecting subgraph negative sample data, event pairs without causal relationships can be randomly selected as reference sample events to ensure that these event pairs have no causal relationships in the known causal graph. It is also possible to use the subgraph positive sample data as a benchmark and exchange the reference sample events in the subgraph positive sample data to generate subgraph negative sample data. Event exchange mainly affects the subsequent linear layer input of the heterogeneous graph neural network. For example, after embedding, event 1 and event 2 are h1 and h2 respectively. After event exchange, h1 and h2 should remain unchanged because the entity event subgraphs corresponding to event 1 and event 2 have not changed. However, the linear layer input to the heterogeneous graph neural network becomes [h2, h1], and the heterogeneous graph neural network needs to output the opposite judgment because the causality of event 1 and event 2 cannot be bidirectional. At the same time, when collecting subgraph negative sample data, it is necessary to ensure that there is a certain correlation between the entities of the reference sample events, that is, they are connected in the entity relationship graph, because only events associated with entities can have a causal relationship. At the same time, it is also necessary to ensure that the combination of different event types and entity types in the subgraph negative sample data is evenly sampled to avoid the heterogeneous graph neural network model being biased towards a certain type.

[0097] Figure 7 is a schematic diagram of the structure of a sub-graph sample data provided by the second embodiment of the present invention. In a specific example, if Figure 7 The subgraph sample data shown is the subgraph positive sample data. Event 1 and event 2 in the subgraph positive sample data are reference sample events. Therefore, the subgraph positive sample data should have a true causal relationship between event 1 and event 2. Figure 7 The sub-graph sample data shown is sub-graph negative sample data, in which event 1 and event 2 are reference sample events, and there is no causal relationship between event 1 and event 2 in the sub-graph negative sample data.

[0098] S270, predicting the association weights between the events in the entity event subgraph through the heterogeneous graph neural network.

[0099] The association weight of the edge between events can evaluate whether there is a causal relationship between the two events. Exemplarily, the association weight can be a measure of the credibility of whether there is a causal relationship between the two events.

[0100] In an embodiment of the present invention, in addition to predicting the causal relationship between target reference events based on the entity event subgraph through a heterogeneous graph neural network, the heterogeneous graph neural network can also be used to predict the association weights between events with causal relationships in the entity event subgraph. Automatically predicting the association weights between events with causal relationships through a heterogeneous graph neural network can improve the accuracy and reliability of the association weight values ​​between events.

[0101] S280: Generate a target event causal graph of the target alarm event according to each event type, the causal relationship between the target reference events, and the association weights between the events.

[0102] After predicting the causal relationship between events in the entity event subgraph and the association weights between causally related events through heterogeneous graph neural networks, the target event causal graph of the target alarm event can be constructed with events as nodes and causal relationships between events as edges. After the target event causal graph is constructed, the event type of each event in the target event causal graph can be annotated, and the corresponding weight values ​​can be configured for the edges in the target event causal graph according to the association weights between events.

[0103] In the target event causal graph, attribute information may be configured for the node, such as the type of event, the associated entity corresponding to the event, and the associated time of the event. The associated time of the event node in the target event causal graph may be the timestamp of the event or the duration range of the event, which is not limited in the embodiment of the present invention.

[0104] Figure 8 is a schematic diagram of the structure of a target event causal graph provided by the second embodiment of the present invention. In a specific example, Figure 8 As shown in FIG. 1 , assuming that event 2 is a target alarm event, and the event type of event 2 is the duration of the call of service a, the associated events determined based on event 2 are event 1, event 3, event 4, event 5, event 6, and event 7, and the causal relationship and associated weights are determined between each event. According to the event types of events 1 to 7, the causal relationship between each event, and the associated weights between events, the following can be generated: Figure 8 The target event causal diagram is shown in Figure 1. Figure 8 As shown in the figure, when there is no association weight value between the edges of events, the default association weight value of the edge is 1. The association weight of the edge between event 1 and event 2 is 0.8, indicating that event 2 has an 80% probability of being caused by event 1. The association weight of the edge between event 4 and event 2 is 0.2, indicating that event 2 has a 20% probability of being caused by event 4. It can be understood that events 2 to 7 all have corresponding event types, such as a decrease in service call volume, a high average service time, and a high CPU usage rate.

[0105] S290: Determine a target fault root cause of the target alarm event according to a target event cause-effect graph of the target alarm event.

[0106] In an optional embodiment of the present invention, determining the target fault root cause of the target alarm event based on the target event causal graph of the target alarm event may include: calculating the root cause correlation score of each event in the target event causal graph of the target alarm event; sorting each event in the target event causal graph according to the root cause correlation score of each event in the target event causal graph of the target alarm event; and obtaining a preset number of root cause events in the sorting result as the target fault root cause.

[0107] The root cause correlation score may be a score calculated for each event in the target event cause-effect graph, and may be used to evaluate the degree of influence of the event on the target alarm event. The preset number may be set according to actual needs, for example, 2 or 3, etc. The embodiment of the present invention does not limit the specific value of the preset number.

[0108] Optionally, any available ranking algorithm can be used to calculate the root cause correlation score of each event in the target event causal graph of the target alarm event based on the target event causal graph of the target alarm event. It is understandable that the higher the root cause correlation score calculated for the event, the greater the probability that the event is the cause event of the target alarm event. After calculating the root cause correlation score of each event in the target event causal graph, the events in the target event causal graph can be sorted in descending order of the root cause correlation score, and a preset number of root cause events in the sorting result are obtained as the target fault root cause.

[0109] The above technical solution can enhance the extraction effect of event causal relationships and the accuracy of causal relationship positioning by generating a heterogeneous entity event subgraph corresponding to the target reference event based on the full entity event graph of the target alarm event, and using a heterogeneous graph neural network to predict the causal relationship between each event in the full entity event graph based on the generated multiple entity event subgraphs. Furthermore, a target event causal graph of the target alarm event is generated based on the causal relationship between each event in the full entity event graph. The target event causal graph is interpretable, depends on the causal relationship, and can also be manually intervened and modified. Finally, the target fault root cause of the target alarm event can be quickly determined based on the target event causal graph of the target alarm event. It can be seen that the above fault root cause positioning method can automatically extract causal relationships using existing data, and the judgment of causal relationships only depends on the nature of the event and the entity in which the event is located. The root cause of the system fault can be accurately extracted, the fault time is reduced, and the stability and efficiency of the system are improved.

[0110] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data comply with relevant laws, regulations and standards in relevant regions.

[0111] It should be noted that any arrangement and combination of the technical features in the above embodiments also falls within the protection scope of the present invention.

[0112] Embodiment 3

[0113] Fig. 9 is a schematic diagram of a fault root cause locating device provided in Embodiment 3 of the present invention, such as Fig. 9 As shown, the device includes: a full entity event graph creation module 310, an entity event subgraph generation module 320, a causal relationship prediction module 330, a target event causal graph generation module 340 and a target fault root cause determination module 350, wherein:

[0114] A full entity event graph creation module 310 is used to create a full entity event graph of a target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between an event and a corresponding entity;

[0115] An entity event subgraph generation module 320 is used to generate an entity event subgraph corresponding to a target reference event according to the full entity event graph;

[0116] A causal relationship prediction module 330, used for inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network;

[0117] A target event cause-effect graph generation module 340 is used to generate a target event cause-effect graph of the target alarm event according to the cause-effect relationship between the target reference events;

[0118] The target fault root cause determination module 350 is used to determine the target fault root cause of the target alarm event according to the target event cause-effect graph of the target alarm event.

[0119] The embodiment of the present invention creates a full entity event graph of the target alarm event, so as to obtain the associated events and associated entities of the target alarm event, as well as the association relationship between the event and the corresponding entity through the full entity event graph. Furthermore, an entity event subgraph corresponding to the target reference event is generated according to the full entity event graph, so that each entity event subgraph is input into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraph through the heterogeneous graph neural network, and then generate a target event causal graph of the target alarm event according to the causal relationship between each target reference event, and finally determine the target fault root cause of the target alarm event according to the target event causal graph of the target alarm event. The above technical scheme can solve the problems of low extraction rate and positioning accuracy of the root cause of the fault in the existing system when locating the root cause of the fault, and can accurately extract the root cause of the fault of the system, reduce the fault time, and improve the stability and efficiency of the system.

[0120] Optionally, the full entity event graph creation module 310 is also used to: determine the corresponding target call chain data based on the key fields of the target alarm event; determine the associated entities included in the target call chain data based on the preset associated fields, and construct an entity relationship graph including each of the associated entities based on the preset entity relationship; determine the associated events of each of the associated entities in the entity relationship graph; establish an association relationship between the associated events and the corresponding associated entities to obtain the full entity event graph.

[0121] Optionally, the entity event subgraph generation module 320 is also used to: select two events in turn from all events included in the full entity event graph as current target reference events; determine the current associated entity corresponding to the current target reference event and the directly associated entity of the current associated entity according to the full entity event graph; determine the associated events of the current associated entity and the directly associated entity as current subgraph associated events according to the full entity event graph; and generate an entity event subgraph corresponding to the current target reference event according to the association relationship between the current associated entity, the directly associated entity and the current subgraph associated events.

[0122] Optionally, the entity event subgraph generation module 320 is also used to: generate a first undirected edge between entities in the entity event subgraph based on the entity relationship between the current associated entity and the directly associated entity; generate a second undirected edge between entities and events in the entity event subgraph based on the association relationship between the current subgraph associated event and the corresponding entity; and configure edge attribute data for the first undirected edge and the second undirected edge.

[0123] Optionally, the above-mentioned device also includes a heterogeneous graph neural network training module, which is used to: collect sub-graph positive sample data and sub-graph negative sample data according to event causal graph sample data; wherein there is a causal relationship between the reference sample events in the sub-graph positive sample data, and there is no causal relationship between the reference sample events in the sub-graph negative sample data; and train the heterogeneous graph neural network according to the sub-graph positive sample data and the sub-graph negative sample data.

[0124] Optionally, the target event causal graph generation module 340 is also used to: predict the association weights between the events in the entity event subgraph through the heterogeneous graph neural network; and generate a target event causal graph of the target alarm event based on the event type, the causal relationship between the target reference events, and the association weights between the events.

[0125] Optionally, the target fault root cause determination module 350 is also used to: calculate the root cause correlation score of each event in the target event causal graph of the target alarm event; sort the events in the target event causal graph according to the root cause correlation score of each event in the target event causal graph of the target alarm event; and obtain a preset number of root cause events in the sorting result as the target fault root cause.

[0126] The above-mentioned fault root cause location device can execute the fault root cause location method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method. For technical details not fully described in this embodiment, please refer to the fault root cause location method provided by any embodiment of the present invention.

[0127] Since the fault root cause locating device described above is a device that can execute the fault root cause locating method in the embodiment of the present invention, based on the fault root cause locating method described in the embodiment of the present invention, a person skilled in the art can understand the specific implementation of the fault root cause locating device in the present embodiment and its various variations, so how the fault root cause locating device implements the fault root cause locating method in the embodiment of the present invention is not described in detail here. As long as a person skilled in the art implements the device used by the fault root cause locating method in the embodiment of the present invention, it belongs to the scope of protection of this application.

[0128] Embodiment 4

[0129] Fig.10A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0130] like Fig.10 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0131] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0132] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a fault root cause location method.

[0133] Optionally, the method for locating the root cause of a fault may include: creating a full entity event graph of a target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and the association relationship between events and corresponding entities; generating an entity event subgraph corresponding to a target reference event based on the full entity event graph; inputting each of the entity event subgraphs into a heterogeneous graph neural network to predict the causal relationship between the target reference events based on the entity event subgraph through the heterogeneous graph neural network; generating a target event causal graph of the target alarm event based on the causal relationship between each of the target reference events; and determining the target fault root cause of the target alarm event based on the target event causal graph of the target alarm event.

[0134] In some embodiments, the fault root cause location method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the fault root cause location method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the fault root cause location method in any other appropriate manner (e.g., by means of firmware).

[0135] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0136] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0137] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0138] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0139] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0140] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0141] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0142] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A method for locating the root cause of a fault, characterized in that: include: Creating a full entity event graph of the target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between the event and the corresponding entity; Generate an entity event subgraph corresponding to a target reference event according to the full entity event graph; Inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network; Generate a target event causal graph of the target alarm event according to the causal relationship between each of the target reference events; A target fault root cause of the target alarm event is determined according to a target event cause-effect graph of the target alarm event.

2. The method according to claim 1, characterized in that: The creation of a full entity event graph of the target alarm event includes: Determine the corresponding target call chain data according to the key field of the target alarm event; Determine the associated entities included in the target call chain data according to the preset associated fields, and construct an entity relationship graph including each of the associated entities according to the preset entity relationship; Determine the associated events of each of the associated entities in the entity relationship diagram; An association relationship is established between the associated event and the corresponding associated entity to obtain the full entity event graph.

3. The method according to claim 1, characterized in that The generating an entity event subgraph corresponding to a target reference event according to the full entity event graph includes: Selecting two events from all events included in the full entity event graph in sequence as current target reference events; Determine, according to the full entity event graph, a current associated entity corresponding to the current target reference event, and a directly associated entity of the current associated entity; Determine, according to the full entity event graph, the associated events of the current associated entity and the directly associated entity as the current subgraph associated events; An entity event subgraph corresponding to the current target reference event is generated according to the association relationship between the current associated entity, the directly associated entity and the current subgraph associated event.

4. The method according to claim 3, characterized in that The generating, according to the association relationship among the current associated entity, the directly associated entity and the current subgraph associated event, an entity event subgraph corresponding to the current target reference event comprises: Generate a first undirected edge between entities in the entity event subgraph according to the entity relationship between the current associated entity and the directly associated entity; Generate a second undirected edge between the entity and the event in the entity event subgraph according to the association relationship between the current subgraph associated event and the corresponding entity; Edge attribute data is configured for the first undirected edge and the second undirected edge.

5. The method according to claim 1, characterized in that Before creating the full entity event graph of the target alarm event, the method further includes: Collect subgraph positive sample data and subgraph negative sample data according to event causal graph sample data; wherein the reference sample events in the subgraph positive sample data have a causal relationship, and the reference sample events in the subgraph negative sample data do not have a causal relationship; The heterogeneous graph neural network is trained according to the subgraph positive sample data and the subgraph negative sample data.

6. The method according to claim 1, characterized in that The step of generating a target event causal graph of the target alarm event according to the causal relationship between the target reference events includes: Predicting the association weights between events in the entity event subgraph by using the heterogeneous graph neural network; A target event causal graph of the target alarm event is generated according to each event type, the causal relationship between the target reference events and the association weights between the events.

7. A fault root cause location device, characterized in that: include: A full entity event graph creation module, used to create a full entity event graph of a target alarm event; wherein the full entity event graph includes associated events and associated entities of the target alarm event, and an association relationship between events and corresponding entities; An entity event subgraph generation module, used to generate an entity event subgraph corresponding to a target reference event according to the full entity event graph; A causal relationship prediction module, used for inputting each of the entity event subgraphs into a heterogeneous graph neural network, so as to predict the causal relationship between the target reference events according to the entity event subgraphs through the heterogeneous graph neural network; A target event causal graph generation module, used to generate a target event causal graph of the target alarm event according to the causal relationship between the target reference events; The target fault root cause determination module is used to determine the target fault root cause of the target alarm event according to the target event cause-effect graph of the target alarm event.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the fault root cause locating method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the fault root cause locating method described in any one of claims 1-7 when executed.

10. A computer program product comprising a computer program / instructions, wherein: When the computer program / instructions are executed by a processor, the fault root cause locating method according to any one of claims 1 to 7 is implemented.