Network equipment monitoring method and system and electronic equipment

By normalizing the log data of network equipment in the data center, and combining topological relationships and performance indicator data analysis, the problem of difficulty in monitoring data center network equipment in the existing technology is solved, and rapid fault location and efficient operation and maintenance are achieved.

CN119996175AActive Publication Date: 2025-05-13STATE GRID BEIJING ELECTRIC POWER CO +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202411326611.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-05-13
Estimated Expiration
2044-09-23

AI Technical Summary

Technical Problem

In the prior art, the network management system provided by each manufacturer is carried out in block viewing and management, which makes it difficult to effectively monitor network equipment in the data center, and thus makes it difficult to locate faults.

Method used

By obtaining the log data of each network device in the data center, normalizing the topology relationship of each network device, and updating the topology database. At the same time, performance indicator data is obtained, stored and analyzed, and the log and analysis results are displayed in combination with topological relationships.

Benefits of technology

It realizes rapid fault location of data center network equipment, reduces operation and maintenance difficulties, and improves monitoring efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996175A_ABST
    Figure CN119996175A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network equipment monitoring method and device and electronic equipment, and the method comprises the steps: obtaining log data corresponding to each network equipment in a preset data center, and carrying out the normalization of the log data, so as to obtain the normalized log data corresponding to each network equipment; determining a topological relation corresponding to each network device, and updating the topological relation in a preset topological database; obtaining performance index data corresponding to each network device, and storing the performance index data in a performance index database; analyzing the performance index data corresponding to each network device according to a preset model to obtain an analysis result; and according to a topological relation in a preset topological database, displaying the normalized log data and the analysis result corresponding to each network device. The technical problem that effective monitoring of network equipment in a data center is difficult to realize due to the fact that block viewing management is carried out according to network management systems provided by manufacturers in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a network equipment monitoring method, system and electronic equipment. Background Art

[0002] In recent years, most data centers have adopted a three-level network architecture: access layer, aggregation layer, and core layer; the critical path design is mostly implemented using equal-cost multi-path routing, and a small number of data center modules use SDN technology (Software-Defined Networking) for network deployment. If a network device at a certain layer fails, it will directly lead to link interruption or network oscillation. The network device and surrounding devices will generate a large number of log alarms, and the data center basically has comprehensive indicator monitoring for the equipment. The logs generated by the equipment are collected and stored by configuring the SNMP protocol (Simple Network Management Protocol).

[0003] Due to the differences in alarm logs generated by network devices of multiple manufacturers and types, most of the network management equipment in data centers is now managed in blocks based on the network management systems provided by each manufacturer, making it difficult to quickly and accurately monitor the network equipment in the data center, and thus difficult to locate the resulting faults. Summary of the invention

[0004] The embodiments of the present invention provide a network equipment monitoring method, system and electronic device to at least solve the technical problem that it is difficult to effectively monitor network equipment in a data center due to the block viewing and management based on the network management system provided by each manufacturer in the related technology.

[0005] According to one aspect of an embodiment of the present invention, a network device monitoring method is provided, the method comprising: obtaining log data corresponding to each network device in a preset data center, and normalizing the log data to obtain normalized log data corresponding to each network device; determining the topological relationship corresponding to each network device, and updating the topological relationship in a preset topological database; obtaining performance indicator data corresponding to each network device, and storing the performance indicator data in a performance indicator database; analyzing the performance indicator data corresponding to each network device according to a preset model to obtain an analysis result; and displaying the normalized log data corresponding to each network device and the analysis result according to the topological relationship in the preset topological database.

[0006] Furthermore, the log data corresponding to each network device in the preset data center is obtained, and the log data is normalized to obtain normalized log data corresponding to each network device, including: normalizing the log data corresponding to each network device to obtain preset format data; removing redundancy and noise from the preset format data to obtain the normalized log data.

[0007] Furthermore, the acquisition of log data corresponding to each network device in a preset data center and normalization of the log data to obtain normalized log data corresponding to each network device also includes: modeling a log database according to device documents corresponding to the network devices, wherein the log database includes hit information; matching the normalized log data in the log database according to a preset algorithm to update the hit information corresponding to the normalized log data; and performing early warning analysis on the normalized log data corresponding to each network device based on historical key security logs.

[0008] Furthermore, determining the topological relationship corresponding to each network device and updating the topological relationship in a preset topological database includes: remotely logging into each network device respectively, and obtaining first neighbor relationship data of each network device; and updating second neighbor relationship data of each network device in the preset topological database based on the first neighbor relationship data.

[0009] Furthermore, the obtaining of performance indicator data corresponding to each network device and storing the performance indicator data in a performance indicator database includes: receiving performance indicator data corresponding to each network device sent by a preset monitoring platform; filtering the performance indicator data according to preset rules to obtain standard performance indicator data; storing the standard performance indicator data in the performance indicator database; and updating monitoring items in the preset monitoring platform according to the standard performance indicator data.

[0010] Furthermore, the performance indicator data corresponding to each network device is analyzed according to a preset model to obtain an analysis result, including: obtaining the traffic data corresponding to each network device from the performance indicator database; and analyzing the traffic data corresponding to each network device according to a pre-trained traffic classification anomaly detection model to obtain the analysis result.

[0011] Furthermore, the preset data center includes multiple functional partitions, each of which corresponds to different functions, and each function includes one or more of the network devices, wherein the performance indicator data corresponding to each network device is analyzed according to the preset model to obtain an analysis result, including: obtaining the traffic data corresponding to each network device from the performance indicator database; performing anomaly detection on the traffic data corresponding to the network device according to the network level where the network device is located and the inbound and outbound traffic model corresponding to the functional partition through a pre-trained logical anomaly detection model to obtain the analysis result.

[0012] Furthermore, the display of normalized log data corresponding to each network device and the analysis result based on the topological relationship in the preset topological database includes: displaying a topological map corresponding to the topological relationship in a graphical user interface; and / or, displaying key abnormal logs in the graphical user interface; and / or, displaying indicator data of the network device in the graphical user interface; and / or, if the analysis result includes abnormal events, displaying the abnormal events in the graphical user interface.

[0013] According to one aspect of an embodiment of the present invention, a network device monitoring system is also provided, which includes a log module, a dynamic discovery module, a performance indicator module, a performance analysis module and a front-end display module, and the system includes: through the log module, obtaining log data corresponding to each network device in a preset data center, and normalizing the log data to obtain normalized log data corresponding to each network device; through the dynamic discovery module, determining the topological relationship corresponding to each network device, and updating the topological relationship in a preset topological database; through the performance indicator module, obtaining performance indicator data corresponding to each network device, and storing the performance indicator data in a performance indicator database; through the performance analysis module, analyzing the performance indicator data corresponding to each network device according to a preset model to obtain an analysis result; through the front-end display module, displaying the normalized log data corresponding to each network device and the analysis result according to the topological relationship in the preset topological database.

[0014] According to one aspect of an embodiment of the present invention, there is also provided an electronic device, comprising a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the network device monitoring method as described above.

[0015] In an embodiment of the present invention, the log data corresponding to each network device in the preset data center is obtained, and the log data is normalized to obtain the normalized log data corresponding to each network device; the topological relationship corresponding to each network device is determined, and the topological relationship in the preset topological database is updated; the performance indicator data corresponding to each network device is obtained, and the performance indicator data is stored in the performance indicator database; the performance indicator data corresponding to each network device is analyzed according to the preset model to obtain the analysis result; according to the topological relationship in the preset topological database, the normalized log data corresponding to each network device and the analysis result are displayed. In this embodiment, the log information generated by the network equipment in the preset data center is processed in a normalized format, which reduces the difficulty of operation and maintenance; the log data and performance indicator data generated by the network equipment are sorted and analyzed, and combined with the topological relationship corresponding to the preset data center, the fault location of the network equipment can be quickly realized. In addition, the technical problem that it is difficult to effectively monitor the network equipment in the data center due to the block viewing and management based on the network management system provided by each manufacturer in the related technology is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the accompanying drawings:

[0017] Figure 1 This is a schematic diagram of an optional application scenario in an embodiment of the present invention;

[0018] Figure 2 A schematic diagram of a flow chart of an optional network device monitoring method in an embodiment of the present invention;

[0019] Figure 3 The present invention is an optional framework diagram of a network device monitoring method system in an embodiment of the present invention. DETAILED DESCRIPTION

[0020] The present invention will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that the embodiments and features in the embodiments of the present invention can be combined with each other without conflict.

[0021] The following detailed description is an exemplary description, which is intended to provide further detailed description of the present invention. Unless otherwise specified, all technical terms used in the present invention have the same meaning as those generally understood by those skilled in the art to which the present invention belongs. The terms used in the present invention are only for describing specific embodiments, and are not intended to limit the exemplary embodiments according to the present invention.

[0022] The network device monitoring method proposed in the embodiment of the present invention is applied to Figure 1 In the data center network shown, the network includes multiple network devices 100, a network management device 110, and a management platform 120, wherein the multiple network devices 100 are connected to the network management device 110 through a network, and the network management device 110 is connected to the management platform 120 through a network, and the network management device 110 is used to collect log data of multiple network devices 100. In this embodiment, multiple network devices 100 send their own log data and performance data to the network management device 110 at preset time intervals, and the network management device 110 then uploads and synchronizes the collected log data and performance data to the management platform 120. The management platform 120 is used to monitor the log data and performance data of multiple network devices 100 and locate faults. In actual application scenarios, the network management device includes but is not limited to a monitoring platform, such as a ZABBIX platform. It should be noted that ZABBIX is a network bottom layer data collection and monitoring platform. The network device can send the network device log and device indicator data to the ZABBIX server by configuring SNMP, and ZABBIX provides functions such as monitoring and data collection of remote server / network status.

[0023] The embodiment of the present invention provides a network device monitoring method, which specifically includes the following steps:

[0024] S201, obtaining log data corresponding to each network device in a preset data center, and normalizing the log data to obtain normalized log data corresponding to each network device;

[0025] In this embodiment, data is collected from network devices, security devices, and load balancing devices in a preset data center based on multiple protocols such as system log SYSLOG, TCP (Transmission Control Protocol) / UDP (User Datagram Protocol), FTPFTP (File Transfer Protocol), and SNMP (Simple Network Management Protocol); at the same time, the above data is stored in multiple ways, such as distributed stream processing platform Kafka, OPENTSDB (Open Time Series Database), etc.

[0026] In a specific application scenario, the log data generated by the devices may be uniformly collected through the network management device in the preset data center, or the log data may be reported separately through each network device in the preset data center, which is not limited in this embodiment.

[0027] Then, the logs of different manufacturers and different types of equipment are normalized and unified to facilitate the storage and analysis of log data. After the log data of network equipment in the preset data center is converted into a normalized format, the normalized log data is obtained and input into Syslog and Kafka.

[0028] S202, determining the topological relationship corresponding to each network device, and updating the topological relationship in a preset topological database;

[0029] Specifically, the LLDP protocol (Link Layer Discovery Protocol) SSH (Secure Shell) is used to remotely log in to the network equipment in the preset data center to discover the topological relationship between the key devices in the access layer, aggregation layer and core layer of the preset data center network, where the topological relationship includes the following four information: local device, local port, opposite device, and opposite port.

[0030] At the same time, remote login to the network device is used to ensure that all network devices are in normal status and can be logged in remotely. If the network device cannot be logged in remotely, it means that the network device has a fault and a corresponding alarm message is generated.

[0031] S203, obtaining performance indicator data corresponding to each network device, and storing the performance indicator data in a performance indicator database;

[0032] Specifically, the network device collects performance indicator data by configuring the SNMP protocol, and the performance indicator data includes the network device CPU, memory, inbound and outbound traffic of the network port, CRC (Cyclic Redundancy Check) information, etc. In this embodiment, the network management device stores the above data in the indicator database and sends it to Kafka synchronously.

[0033] S204, analyzing the performance indicator data corresponding to each network device according to the preset model to obtain an analysis result;

[0034] Specifically, the data center network equipment indicator data and port traffic data are obtained to calculate the traffic, display the equipment hardware indicators in real time, and display the neighbor relationship topology and abnormal traffic.

[0035] S205 , displaying normalized log data and analysis results corresponding to each network device according to the topological relationship in the preset topological database.

[0036] Specifically, it displays the performance indicators of network devices, port traffic indicators, topological relationship display functions and dynamic key log information. When the analysis results of network devices are abnormal, the abnormal analysis results are mapped and fed back to the topology map, and emergency shutdown operations can be performed for abnormal conditions on device ports.

[0037] Through this embodiment, the log data corresponding to each network device in the preset data center is obtained, and the log data is normalized to obtain the normalized log data corresponding to each network device; the topological relationship corresponding to each network device is determined, and the topological relationship in the preset topological database is updated; the performance indicator data corresponding to each network device is obtained, and the performance indicator data is stored in the performance indicator database; the performance indicator data corresponding to each network device is analyzed according to the preset model to obtain the analysis result; according to the topological relationship in the preset topological database, the normalized log data and analysis result corresponding to each network device are displayed. In this embodiment, the log information generated by the network equipment in the preset data center is processed in a normalized format, which reduces the difficulty of operation and maintenance; the log data and performance indicator data generated by the network equipment are sorted and analyzed, and combined with the topological relationship corresponding to the preset data center, the fault location of the network equipment can be quickly realized. In addition, the technical problem that it is difficult to effectively monitor the network equipment in the data center due to the block viewing and management based on the network management system provided by each manufacturer in the related technology is solved.

[0038] Optionally, in this embodiment, log data corresponding to each network device in a preset data center is obtained, and the log data is normalized to obtain normalized log data corresponding to each network device, including but not limited to: normalizing the log data corresponding to each network device through a data acquisition module to obtain preset format data; removing redundancy and noise from the preset format data to obtain normalized log data.

[0039] Specifically, the log data is normalized into a preset format through canonical processing, and then redundant and other noise log data are removed to make the data source more regular, so as to obtain normalized log data.

[0040] The logs generated by the network equipment in the preset data center are processed in a normalized format and matched with the database model. They are further classified according to different equipment brands, log levels, log contents, etc., to complete the feature matching and identification of key information in the log model. The specific indicators are shown in Table 1:

[0041] Table 1 Network equipment log indicators

[0042]

[0043] In this embodiment, the logs generated by the device in real time are input into Syslog and Kafka, filtered according to key information (server logs, some non-compliant logs), and the obtained log data is divided and stored according to device name, block name, log level, time, etc., to provide a standardized data source for subsequent log analysis.

[0044] Optionally, in this embodiment, log data corresponding to each network device in a preset data center is obtained, and the log data is normalized to obtain normalized log data corresponding to each network device, also including but not limited to: modeling the log database according to the device documents corresponding to the network devices, wherein the log database includes hit information; matching the normalized log data in the log database according to a preset algorithm to update the hit information corresponding to the normalized log data; and performing early warning analysis on the normalized log data corresponding to each network device based on historical key security logs.

[0045] Specifically, the log data database is modeled according to the equipment documents provided by the network equipment manufacturer, and relationships such as log information levels are established, including timestamp, host name, manufacturer identification, version number, module name, log level, log type and other information; at the same time, a log statistics and association database model is established, including log ID, manufacturer identification, module name, log level, log type, log format, Chinese explanation, solution, number of hits, last occurrence time, key log information identification, etc.

[0046] Furthermore, historical key security logs are identified, the relationship between key security logs and other equipment logs is planned, and key processing and correlation analysis are performed based on the associated logs of different devices that appear at the same time to facilitate fault early warning.

[0047] In actual application scenarios, due to the different manufacturers, types and models of various network devices in the preset data center network, the log display formats are different. It is necessary to perform matching analysis algorithms and classification algorithms based on the logs that appear, so as to better hit the database model in the log analysis module and timely update the database hit information.

[0048] In some application scenarios of the present embodiment, abnormal log items in key information monitoring are performed based on all logs generated within a certain time range. The coverage of these logs can be divided into: abnormal log items in the entire data center network, abnormal log items within a partition, abnormal logs of a single device, and abnormal log items of a single module of a single device. Further filtering and log classification algorithms are performed in combination with specific scenarios to define specific models of failures caused by some abnormal logs.

[0049] In some application scenarios of the present embodiment, the logs generated by the preset data center network devices are divided into many categories, such as device performance, management, port data, routing data, etc. Due to the diversity of logs generated by the devices, the importance of the logs is also different. If a sudden increase in traffic logs is a normal access phenomenon, it does not constitute an abnormal log. If it is a log of other types of devices, it represents a decline in the performance of the network device. Therefore, the filtering rules established according to different logs are different.

[0050] In some application scenarios of this embodiment, the logs generated by the data center network devices are divided into core layer device logs, aggregated device logs, and access layer device logs according to the level. According to the different levels of the network architecture, the abnormal log judgment standards generated are also different. Therefore, the judgment of abnormal logs should be configured with different abnormal log judgment standard models according to the level to which the network device belongs. Compared with the logs generated by the access layer devices, the importance of the logs generated by the core layer devices is far lower than that of the logs generated by the core layer devices. The processing priority of the logs generated by the core layer devices is higher than that of the logs generated by the access layer devices.

[0051] In some application scenarios of this embodiment, the abnormal log detection model device is different according to the functions of the preset data center network equipment. The position in the three-layer architecture of the network is determined by the relationship between some network equipment types, so the judgment model of the abnormal log is determined according to the equipment type (firewall, load balancing). The main function of the switch is to forward data. Under normal circumstances, the flow entering the switch should be roughly equal to the flow forwarded (with a certain delay). Therefore, the abnormal log judgment model of the switch can be determined according to the logs generated by the forwarding mechanism of the device itself or the protocol layer (excluding the specific logs generated by the port).

[0052] Through the above example, the log database is modeled according to the device documents corresponding to the network devices; according to the preset algorithm, the normalized log data is matched in the log database to update the hit information corresponding to the normalized log data; according to the historical key security logs, the normalized log data corresponding to each network device is analyzed for early warning, which realizes the unified monitoring of network devices in the preset data center and can provide timely early warning of network equipment failures.

[0053] Optionally, in this embodiment, the topological relationship corresponding to each network device is determined through a dynamic discovery module, and the topological relationship in a preset topological database is updated, including but not limited to: remotely logging into each network device separately, and obtaining first neighbor relationship data of each network device; based on the first neighbor relationship data, the second neighbor relationship data of each network device in the preset topological database is updated.

[0054] Specifically, in this embodiment, a link relationship and partition relationship table of all network devices in the data center is established. The information includes: the partition to which the device belongs, the configuration item information in the preset topology database CMDB (Configuration Management Database), the local device, the local port, the opposite device, the opposite port, the device manufacturer information, the device type, the device relationship discovery type and other fields. The obtained neighbor relationship data is further cleaned and classified for data standardization, and the standardized device association information is passed to the preset topology database.

[0055] Furthermore, the first neighbor relationship data of the network device topology in the actual production environment is compared with the second neighbor relationship data in the CMDB at preset time intervals, and the above information is pushed to the CMDB in real time through interface calls, and the CMDB is updated with the first neighbor relationship data collected in the actual production environment to ensure the accuracy of the information.

[0056] In addition, the devices that are not monitored in the preset monitoring platform ZABBIX are updated at preset time intervals. By regularly screening and comparing the dynamic topology data with the existing monitoring devices in ZABBIX, the devices for which data has not been collected are updated and feedback is provided to ensure the reliability and accuracy of the underlying data collection.

[0057] Optionally, in this embodiment, performance indicator data corresponding to each network device is obtained through a performance indicator module, and the performance indicator data is stored in a performance indicator database, including but not limited to: receiving performance indicator data corresponding to each network device sent by a network management device through a storage module; filtering the performance indicator data according to preset rules to obtain standard performance indicator data; storing the standard performance indicator data in the performance indicator database; and updating the monitoring items in the preset monitoring platform according to the standard performance indicator data.

[0058] Specifically, based on the advantage of Kafka's high throughput, the above performance indicator data are filtered and processed. The performance indicator data includes network device CPU, device memory, inbound and outbound traffic of network ports, CRC information, etc.

[0059] Furthermore, the data filtered by Kafka is stored in REDIS (Remote Dictionary Server), where the Sort set data type is used. The uniqueness of the Key is ensured by ITEMID (each monitoring item in ZABBIX has a unique ITEMID, a unique identifier of the monitoring item). At the same time, the value and branch score are determined according to the timestamp to ensure the orderliness of the data for easy writing and reading of the data, thereby ensuring the timeliness of data query and calculation.

[0060] Then, by traversing the Key in REDIS and comparing it with the ZABBIX monitoring items, the performance indicators of the data center network equipment can be collected. By regularly updating the report, monitoring items are added to the equipment to ensure the accuracy and effectiveness of all monitoring items in ZABBIX, CMDB, REDIS, and Kafka.

[0061] Optionally, in this embodiment, through the performance analysis module, the performance indicator data corresponding to each network device is analyzed according to a preset model to obtain analysis results, including but not limited to: obtaining the traffic data corresponding to each network device from the performance indicator database; analyzing the traffic data corresponding to each network device according to a pre-trained traffic classification anomaly detection model to obtain analysis results.

[0062] In actual application scenarios, the analysis of anomalies left by network devices includes but is not limited to: obtaining the traffic data of all device ports at the same time, accumulating the inbound and outbound traffic to obtain the device inbound and outbound traffic ratio, setting the anomaly ratio range based on the IP health of the network device, and establishing a traffic anomaly model through redundant denoising to reduce the abnormal traffic caused by device shock and reduce the generation of abnormal traffic alarms.

[0063] Specifically, in this embodiment, for traffic trend graphs of different granularities, statistical algorithms are used to obtain abnormal points in each individual or calculated traffic monitoring item, sort out the abnormal types, add preset filtering rules based on the traffic anomaly model algorithm, and combine the actual application scenarios of the preset data center to modify the traffic anomaly model, analyze the traffic data corresponding to each network device, and obtain the analysis results. Through the above examples, the monitoring of abnormal traffic data of network devices is realized.

[0064] Optionally, in this embodiment, the preset data center includes multiple functional partitions, each of which corresponds to different functions, and each function includes one or more network devices, wherein the performance indicator data corresponding to each network device is analyzed according to a preset model through a performance analysis module to obtain analysis results, including but not limited to: obtaining the traffic data corresponding to each network device from a performance indicator database; performing anomaly detection on the traffic data corresponding to the network device according to the network level where the network device is located and the inbound and outbound traffic model corresponding to the functional partition through a pre-trained logical anomaly detection model to obtain analysis results.

[0065] In this embodiment, for the different functions and traffic data in different directions corresponding to each network device, the traffic trend chart of a single monitoring item is shielded downward. By analyzing the inbound and outbound traffic models of the network hierarchy and functional partitions to which the network device belongs, and the relationship between the north-south and east-west traffic, a more macro logic-based anomaly detection model is abstracted. As a supplement to the traffic classification anomaly detection, anomaly detection is performed on the traffic data corresponding to the network device to discover some problems in the forwarding mechanism or protocol layer of the network device itself.

[0066] Optionally, in this embodiment, the normalized log data and analysis results corresponding to each network device are displayed through the front-end display module according to the topological relationship in the preset topological database, including but not limited to: displaying the topological map corresponding to the topological relationship in the graphical user interface through the front-end display module; and / or, displaying key abnormal logs in the graphical user interface; and / or, displaying the indicator data of the network device in the graphical user interface; and / or, if the analysis results include abnormal events, then displaying the abnormal events in the graphical user interface.

[0067] In this embodiment, the graphical user interface may specifically include the following parts:

[0068] 1. Key log display interface: collect and display key abnormal logs in the model according to the logs generated by the device. The displayed information includes device name, specific log information, log count, time, etc.; according to the specific device page, the number of logs generated by the device, level, specific log content, etc. can also be displayed. Realize the specific front-end display at the log level.

[0069] 2. Network device link relationship topology diagram: After logging in to the device to obtain the LLDP relationship, a link relationship topology diagram is generated, which displays the port and connection information, device connectivity information, port traffic information, etc. in real time. Through CMDB, ZABBIX, and database information linkage, various information of the actual device can be updated in time. At the same time, the operation and maintenance personnel can also intuitively view various link information of the device, which is convenient for emergency isolation of equipment, startup of ports, etc. when a fault occurs.

[0070] 3. Network device information display: Display network device indicator data information, including device CPU, memory, device inbound and outbound traffic ratio, device port traffic, CRC check and other information. Under ideal circumstances, the inbound and outbound traffic of network devices is basically balanced at a ratio of 1 (excluding Span, mirror port, etc.). It can intuitively display the basic information of network devices and make intuitive comparative judgments on abnormal situations.

[0071] 4. Event notification: This part lists the output exceptions, forming event notifications similar to those in the alarm platform, and interacts with the existing monitoring platform, email notifications, etc.

[0072] Through the embodiment of the present invention, the log data corresponding to each network device in the preset data center is obtained, and the log data is normalized to obtain the normalized log data corresponding to each network device; the topological relationship corresponding to each network device is determined, and the topological relationship in the preset topological database is updated; the performance indicator data corresponding to each network device is obtained, and the performance indicator data is stored in the performance indicator database; the performance indicator data corresponding to each network device is analyzed according to the preset model to obtain the analysis result; according to the topological relationship in the preset topological database, the normalized log data and analysis result corresponding to each network device are displayed. In this embodiment, the log information generated by the network equipment in the preset data center is processed in a normalized format, which reduces the difficulty of operation and maintenance; the log data and performance indicator data generated by the network equipment are sorted and analyzed, and combined with the topological relationship corresponding to the preset data center, the fault location of the network equipment can be quickly realized. In addition, the technical problem that it is difficult to effectively monitor the network equipment in the data center due to the block viewing and management based on the network management system provided by each manufacturer in the related technology is solved.

[0073] It is known from common technical knowledge that the present invention can be implemented by other embodiments that do not deviate from its spirit or essential features. Therefore, the above disclosed embodiments are only illustrative in all respects and are not exclusive. All changes within the scope of the present invention or within the scope equivalent to the present invention are included in the present invention.

[0074] In an embodiment of the present invention, a network device monitoring system is also proposed. Figure 3 As shown, the system includes a log module 30, a dynamic discovery module 32, a performance indicator module 34, a performance analysis module 36 and a front-end display module 38. The system includes:

[0075] Obtaining log data corresponding to each network device in a preset data center through the log module 30, and normalizing the log data to obtain normalized log data corresponding to each network device;

[0076] Determine the topological relationship corresponding to each network device through the dynamic discovery module 32, and update the topological relationship in the preset topological database;

[0077] Obtaining the performance indicator data corresponding to each network device through the performance indicator module 34, and storing the performance indicator data in a performance indicator database;

[0078] By means of the performance analysis module 36, the performance indicator data corresponding to each network device is analyzed according to a preset model to obtain an analysis result;

[0079] The front-end display module 38 displays the normalized log data corresponding to each network device and the analysis result according to the topological relationship in the preset topological database.

[0080] Optionally, in this embodiment, the log module 30 is used to obtain log data corresponding to each network device in a preset data center, and the log data is normalized to obtain normalized log data corresponding to each network device, including: normalizing the log data corresponding to each network device to obtain preset format data; removing redundancy and noise from the preset format data to obtain the normalized log data.

[0081] Optionally, in this embodiment, the log module 30 is used to obtain log data corresponding to each network device in a preset data center, and the log data is normalized to obtain normalized log data corresponding to each network device. It also includes: modeling a log database according to device documents corresponding to the network devices, wherein the log database includes hit information; matching the normalized log data in the log database according to a preset algorithm to update the hit information corresponding to the normalized log data; and performing early warning analysis on the normalized log data corresponding to each network device according to historical key security logs.

[0082] Optionally, in this embodiment, the dynamic discovery module 32 is used to determine the topological relationship corresponding to each network device, and the topological relationship in the preset topological database is updated, including: remotely logging into each network device respectively through the dynamic discovery module, and obtaining the first neighbor relationship data of each network device; based on the first neighbor relationship data, the second neighbor relationship data of each network device in the preset topological database is updated.

[0083] Optionally, in this embodiment, the performance indicator data corresponding to each network device is obtained through the performance indicator module 34, and the performance indicator data is stored in a performance indicator database, including: receiving the performance indicator data corresponding to each network device sent by a preset monitoring platform through the storage module; filtering the performance indicator data according to preset rules to obtain standard performance indicator data; storing the standard performance indicator data in the performance indicator database; and updating the monitoring items in the preset monitoring platform according to the standard performance indicator data.

[0084] Optionally, in this embodiment, the performance analysis module 36 analyzes the performance indicator data corresponding to each network device according to a preset model to obtain an analysis result, including: obtaining the traffic data corresponding to each network device from the performance indicator database; analyzing the traffic data corresponding to each network device according to a pre-trained traffic classification anomaly detection model to obtain the analysis result.

[0085] Optionally, in this embodiment, the preset data center includes multiple functional partitions, each of which corresponds to different functions, and each function includes one or more of the network devices, wherein the performance analysis module 36 analyzes the performance indicator data corresponding to each network device according to a preset model to obtain an analysis result, including: obtaining the traffic data corresponding to each network device from the performance indicator database; performing anomaly detection on the traffic data corresponding to the network device according to the network level where the network device is located and the inbound and outbound traffic model corresponding to the functional partition through a pre-trained logical anomaly detection model to obtain the analysis result.

[0086] Optionally, in this embodiment, the front-end display module 38 displays the normalized log data corresponding to each network device and the analysis results according to the topological relationship in the preset topological database, including: displaying a topological map corresponding to the topological relationship in a graphical user interface through the front-end display module; and / or displaying key abnormal logs in the graphical user interface; and / or displaying indicator data of the network device in the graphical user interface; and / or, if the analysis results include abnormal events, displaying the abnormal events in the graphical user interface.

[0087] Obtain the log data corresponding to each network device in the preset data center, and normalize the log data to obtain the normalized log data corresponding to each network device; determine the topological relationship corresponding to each network device, and update the topological relationship in the preset topological database; obtain the performance indicator data corresponding to each network device, and store the performance indicator data in the performance indicator database; analyze the performance indicator data corresponding to each network device according to the preset model to obtain the analysis result; display the normalized log data and analysis result corresponding to each network device according to the topological relationship in the preset topological database. In this embodiment, the log information generated by the network equipment in the preset data center is processed in a normalized format, which reduces the difficulty of operation and maintenance; the log data and performance indicator data generated by the network equipment are sorted and analyzed, and combined with the topological relationship corresponding to the preset data center, the fault location of the network equipment can be quickly realized. This solves the technical problem that it is difficult to effectively monitor the network equipment in the data center due to the block viewing and management based on the network management system provided by each manufacturer in the related technology.

[0088] According to an embodiment of the present invention, an electronic device is also provided, including a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the network device monitoring method described above.

[0089] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0090] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0091] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0092] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A network device monitoring method, characterized in that: The method comprises: Obtaining log data corresponding to each network device in a preset data center, and normalizing the log data to obtain normalized log data corresponding to each network device; Determine the topological relationship corresponding to each of the network devices, and update the topological relationship in a preset topological database; Acquire performance indicator data corresponding to each of the network devices, and store the performance indicator data in a performance indicator database; Analyze the performance indicator data corresponding to each network device according to the preset model to obtain analysis results; Through the front-end display module, the normalized log data corresponding to each network device and the analysis result are displayed according to the topological relationship in the preset topology database.

2. The method according to claim 1, characterized in that The acquiring log data corresponding to each network device in the preset data center and normalizing the log data to obtain normalized log data corresponding to each network device includes: Normalizing the log data corresponding to each network device to obtain data in a preset format; Redundancy and noise are removed from the preset format data to obtain the normalized log data.

3. The method according to claim 1, characterized in that The acquiring log data corresponding to each network device in the preset data center and normalizing the log data to obtain normalized log data corresponding to each network device further includes: Modeling a log database according to a device document corresponding to the network device, wherein the log database includes hit information; According to a preset algorithm, matching the normalized log data in the log database to update hit information corresponding to the normalized log data; According to the historical key security logs, early warning analysis is performed on the normalized log data corresponding to each network device.

4. The method according to claim 1, characterized in that: The determining of the topological relationship corresponding to each of the network devices and updating the topological relationship in a preset topological database includes: Remotely log in to each of the network devices respectively, and obtain first neighbor relationship data of each of the network devices; The second neighbor relationship data of each network device in the preset topology database is updated according to the first neighbor relationship data.

5. The method according to claim 1, characterized in that: The obtaining of the performance indicator data corresponding to each of the network devices and storing the performance indicator data in a performance indicator database includes: Receiving performance indicator data corresponding to each network device sent by a preset monitoring platform; Filtering the performance indicator data according to preset rules to obtain standard performance indicator data; storing the standard performance indicator data in the performance indicator database; and, The monitoring items in the preset monitoring platform are updated according to the standard performance indicator data.

6. The method according to claim 1, characterized in that The analyzing the performance indicator data corresponding to each network device according to the preset model to obtain the analysis result includes: Acquire the flow data corresponding to each of the network devices from the performance indicator database; According to the pre-trained traffic classification anomaly detection model, the traffic data corresponding to each network device is analyzed to obtain the analysis result.

7. The method according to claim 1, characterized in that The preset data center includes a plurality of functional partitions, each of which corresponds to a different function, and each of the functions includes one or more of the network devices, wherein: The analyzing the performance indicator data corresponding to each network device according to the preset model to obtain the analysis result includes: Acquire the flow data corresponding to each of the network devices from the performance indicator database; Through the pre-trained logical anomaly detection model, anomaly detection is performed on the traffic data corresponding to the network device according to the network level where the network device is located and the inbound and outbound traffic model corresponding to the functional partition to obtain the analysis result.

8. The method according to claim 1, characterized in that: The displaying of the normalized log data corresponding to each network device and the analysis result according to the topological relationship in the preset topological database includes: Displaying a topological diagram corresponding to the topological relationship in a graphical user interface; and / or, Displaying key exception logs in the graphical user interface; and / or, Displaying the indicator data of the network device in the graphical user interface; and / or, If the analysis result includes an abnormal event, the abnormal event is displayed in the graphical user interface.

9. A network equipment monitoring system, characterized in that: The network equipment monitoring system includes a log module, a dynamic discovery module, a performance indicator module, a performance analysis module and a front-end display module; The log module is used to obtain log data corresponding to each network device in a preset data center, and normalize the log data to obtain normalized log data corresponding to each network device; The dynamic discovery module is used to determine the topological relationship corresponding to each network device and update the topological relationship in the preset topological database; The performance indicator module is used to obtain the performance indicator data corresponding to each network device and store the performance indicator data in a performance indicator database; The performance analysis module is used to analyze the performance indicator data corresponding to each network device according to a preset model to obtain an analysis result; The front-end display module is used to display the normalized log data corresponding to each network device and the analysis result according to the topological relationship in the preset topological database.

10. An electronic device, characterized in that: It comprises a processor, a memory and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the network device monitoring method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • System, method and server for obtaining network topology

    CN109831318A

  • Security event log acquisition and processing method and system for multiple types of supervision objects

    CN110650038A

  • Network fault positioning method based on network topology and multiple indexes

    CN113542017A

  • Application system performance bottleneck determination method and device, equipment and medium

    CN114553672A

  • System fault monitoring and early warning system and method based on log analysis

    CN116192612A