Alarm information processing method, electronic equipment and computer readable storage medium

By artificial intelligence learning of historical alarm information on the network management platform to generate alarm entry groups, and alarm information matching and screening are solved, the problem of bandwidth occupation and processing pressure when reporting alarm information on network devices is solved, and more efficient fault analysis and processing is achieved.

CN120017483APending Publication Date: 2025-05-16ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311510575.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-14
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When network equipment reports alarm information, it will occupy more bandwidth of the network management platform, increasing the processing pressure of the network management platform.

Method used

By artificial intelligence learning of historical alarm information on the network management platform, multiple alarm entry groups are generated, each alarm entry group corresponds to a type of fault, and these alarm entry groups are sent to network devices. After the network device generates the alarm information, it matches it with the key alarm information in the alarm entry group, and only reports target alarm information that matches the key alarm information.

Benefits of technology

It reduces the number of alarm information reported on network devices, reduces the bandwidth usage and processing pressure on the network management platform, and improves the efficiency of fault analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017483A_ABST
    Figure CN120017483A_ABST
Patent Text Reader

Abstract

The invention provides an alarm information processing method, electronic equipment and a computer readable storage medium. The method comprises the following steps: the network equipment acquires a plurality of pieces of alarm information generated by the network equipment; a plurality of alarm entry groups are obtained, the plurality of alarm entry groups are obtained after a network management platform carries out artificial intelligence learning on a plurality of pieces of historical alarm information, each alarm entry group corresponds to one type of fault, and each alarm entry group comprises key alarm information; matching the plurality of pieces of alarm information with key alarm information in the plurality of alarm entry groups, and determining matched target alarm information from the plurality of pieces of alarm information; and sending the target alarm information to a network management platform. Therefore, when the network equipment reports the alarm information, the alarm information can be screened according to the alarm entry group, so that the number of reported alarm information can be reduced, the bandwidth of a network management platform occupied by the alarm information is reduced, and the processing pressure of the network management platform is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a method for processing alarm information, an electronic device, and a computer-readable storage medium. Background Art

[0002] In the process of providing network services, network equipment will inevitably have anomalies, such as protocol failure, route disconnection, etc. When an abnormality occurs in a network device, the network device will trigger an alarm and generate corresponding alarm information, and then report the alarm information to the network management platform. After receiving the alarm information, the network management platform can analyze the alarm information and display the analysis results to the network maintenance engineer. The operation and maintenance engineer can determine the specific fault situation of the network device based on the analysis results and handle it differently to restore the network device to normal.

[0003] However, in the related art, when network equipment reports alarm information, it usually reports all the alarm information it generates to the network management platform, and then the network management platform summarizes all the alarm information and analyzes it. This not only occupies the bandwidth of the network management platform, but also increases the processing pressure of the network management platform. Summary of the invention

[0004] The present application provides an alarm information processing method, an electronic device and a computer-readable storage medium, which are used to solve the problem that when network devices report alarm information, they occupy more bandwidth of a network management platform, thereby increasing the processing pressure of the network management platform.

[0005] To solve the above technical problems, this application is implemented as follows:

[0006] In a first aspect, a method for processing alarm information is provided, which is applied to a network device, and includes:

[0007] Acquire multiple alarm information generated by the network device;

[0008] Acquire multiple alarm item groups, where the multiple alarm item groups are obtained by the network management platform through artificial intelligence learning of multiple historical alarm information, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0009] Matching the multiple alarm information with the key alarm information in the multiple alarm item groups, and determining matching target alarm information from the multiple alarm information;

[0010] The target alarm information is sent to the network management platform.

[0011] In a second aspect, a method for processing alarm information is provided, which is applied to a network management platform, including:

[0012] Perform artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0013] sending the plurality of alarm item groups to a network device;

[0014] Receive target alarm information sent by the network device, where the target alarm information is generated by the network device and, after matching the multiple alarm information with key alarm information in the multiple alarm item groups, the network device determines matching alarm information from the multiple alarm information.

[0015] According to a third aspect, an electronic device is provided, including:

[0016] processor;

[0017] a memory for storing instructions executable by the processor;

[0018] The processor is configured to execute the instructions to implement the method as described in the first aspect or the second aspect.

[0019] According to a fourth aspect, a computer-readable storage medium is provided. When instructions in the storage medium are executed by a processor of an electronic device, the electronic device can execute the method described in the first aspect or the second aspect.

[0020] In a fifth aspect, a system for processing alarm information is provided, including a network device and a network management platform, wherein:

[0021] The network management platform performs artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0022] The network management platform sends the multiple alarm item groups to the network device;

[0023] The network device acquires a plurality of alarm information generated by the network device;

[0024] The network device matches the multiple alarm information with the key alarm information in the multiple alarm item groups, and determines matching target alarm information from the multiple alarm information;

[0025] The network device sends the target alarm information to the network management platform;

[0026] The network management platform receives the target alarm information sent by the network device.

[0027] In the embodiment of the present application, the network management platform can perform artificial intelligence learning on the historical alarm information reported by the network device, obtain multiple alarm item groups, and send the multiple alarm item groups to the network device, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information. After the network device generates multiple alarm information, when reporting the alarm information, it can first match the multiple alarm information with the key alarm information in the multiple alarm item groups issued by the network management platform, and then report the target alarm information matching the key alarm information. In this way, since the network device can filter the alarm information according to the alarm item group when reporting the alarm information, the number of reported alarm information can be reduced, thereby reducing the bandwidth of the network management platform occupied by the alarm information and reducing the processing pressure of the network management platform. In addition, since the reported alarm information is the key alarm information related to the fault, when performing fault analysis on the network device, the specific fault of the network device can be quickly located according to the key alarm information, thereby improving the analysis efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the present application or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0029] Figure 1 It is a schematic diagram of a schematic system architecture provided in an embodiment of the present application;

[0030] Figure 2 It is a flowchart of a method for processing alarm information according to an embodiment of the present application;

[0031] Figure 3 It is a flowchart of a method for processing alarm information according to an embodiment of the present application;

[0032] Figure 4 is a schematic diagram of a method for processing alarm information according to an embodiment of the present application;

[0033] Figure 5 is a schematic diagram of the structure of an electronic device according to an embodiment of the present application;

[0034] Figure 6 It is a structural diagram of a device for processing alarm information according to an embodiment of the present application;

[0035] Figure 7It is a structural diagram of a device for processing alarm information according to an embodiment of the present application;

[0036] Figure 8 It is a structural diagram of an alarm information processing system according to an embodiment of the present application. DETAILED DESCRIPTION

[0037] The alarm information of network equipment is generally triggered and generated. When an abnormality occurs in a network device, the network device will report the abnormality as an alarm. Usually, the rule followed by the alarm reporting of network equipment is that once an alarm is generated, it must be triggered and reported, regardless of the type of the alarm or the triggering reason of the alarm.

[0038] In the related art, when processing the alarm information of the network equipment, specifically, on the network equipment side, the alarm information can be classified, and the alarms of different levels such as severe alarms and general alarms can be reported by classification, so that the network management platform can distinguish and obtain the alarm contents of different levels. On the network management platform side, the obtained alarm information can be centrally analyzed, and the analysis results can be reported to the network maintenance engineer, so that the network maintenance engineer can judge the specific fault situation of the network equipment according to the analysis results of the network management platform, and handle it differently.

[0039] However, the above-mentioned method of processing alarm information means that when the network device reports an alarm to the network management platform, any alarm will be reported regardless of the reason. The network management platform will analyze and judge after collecting all the alarm information of the network devices. This will not only occupy the bandwidth of the network management channel, but also increase the processing pressure of the network management platform. In particular, when there is a large amount of routing, forwarding entries and other information in the network equipment, the network equipment will experience network oscillation and other behaviors. At this time, the network equipment will generate a large number of related alarms and report them, which will not only occupy the bandwidth of the network management channel, but also increase the processing pressure of the network management platform.

[0040] The embodiments of the present application provide a method for processing alarm information, an electronic device, and a computer-readable storage medium, which can enable the network device to intelligently filter the alarm information on the network device side when reporting the alarm information, and only report the most important alarm information of the current fault, and no longer report other information. This can greatly reduce the number of alarm reports from the network device to the network management platform, improve the overall maintainability of the network, and improve the utilization efficiency of the network.

[0041] The core idea of ​​the technical solution provided by the embodiment of the present application is that the network management platform obtains multiple alarm item groups after performing artificial intelligence learning on historical alarm information, and sends the multiple alarm item groups to the network equipment. After the network equipment generates the alarm information, it can determine the key alarm information in the alarm information according to the alarm item group sent by the network management equipment. When reporting the alarm information, only the key alarm information is reported, and other irrelevant alarms or derivative alarms are filtered, so that the alarm information reported by the network equipment to the network management platform can be greatly reduced, thereby reducing the channel bandwidth occupancy and CPU occupancy of the network management platform and improving network utilization efficiency.

[0042] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in this application will be described clearly and completely below in conjunction with the drawings in one or more embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.

[0043] The terms "first", "second", etc. in the present application and claims are used to distinguish similar objects, and are not used to describe a particular order or precedence. It should be understood that the data used in this way can be interchanged where appropriate so that the present application can be implemented in an order other than those illustrated or described herein. In addition, "and / or" in the present application and claims means at least one of the connected objects, and the character " / " generally means that the objects associated with each other are in an "or" relationship.

[0044] It should be noted that the network device in the embodiment of the present application may be a device that provides network services, such as a switch, a router, etc.

[0045] The technical solution provided in the embodiment of the present application can be applied to scenarios where network devices may generate a large number of alarms, and is particularly suitable for scenarios where network devices have a large amount of forwarding information, routing information, etc. and multiple network shocks occur. Figure 1 A possible application scenario of the technical solution provided in the embodiment of the present application is described.

[0046] Figure 1 It is a schematic diagram of a schematic system architecture provided in an embodiment of the present application. Figure 1 The system framework shown includes a network management platform 11 and multiple network devices 12, 13, ..., 1N. Each network device can provide network services to users, and the network management platform 11 can manage each network device (such as fault management, etc.). The network management platform 11 and each network device can exchange information through the network.

[0047] For any network device, for example, the network device 12 will inevitably fail and generate corresponding alarm information in the process of providing network services to users. After generating the alarm information, the network device 12 can send the alarm information to the network management platform 11, and the network management platform 11 can analyze the alarm information, determine the specific fault of the network device 12, and perform corresponding processing on the network device 12 to restore the network device 12 to normal.

[0048] In the related art, when the network device 12 reports the alarm information, it will report all the generated alarm information to the network management platform 11, which will not only occupy more bandwidth of the network management platform 11, but also increase the processing pressure of the network management platform 11. Based on the technical solution provided in the embodiment of the present application, the network management platform 11 can perform artificial intelligence learning on the historical alarm information reported by the network device 12, obtain multiple alarm item groups, and send the multiple alarm item groups to the network device 12, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information. After the network device 12 generates the alarm information, when reporting the alarm information, it can first match the generated alarm information with the key alarm information in the multiple alarm item groups issued by the network management platform 11, and then report the target alarm information that matches the key alarm information. In this way, since the network device 12 can filter the alarm information according to the alarm item group when reporting the alarm information, the number of reported alarm information can be reduced, thereby reducing the bandwidth of the network management platform 11 occupied by the alarm information and reducing the processing pressure of the network management platform 11. In addition, since the reported alarm information is the key alarm information related to the fault, when performing fault analysis on the network device 12, the specific fault of the network device 12 can be quickly located according to the key alarm information, thereby improving the analysis efficiency.

[0049] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0050] Figure 2 It is a flowchart of a method for processing alarm information according to an embodiment of the present application. Figure 2 The method for processing the warning information shown can be applied to Figure 1 For any of the network devices shown, the method for processing the alarm information specifically includes the following steps.

[0051] S202: Acquire multiple alarm information generated by network devices.

[0052] When a network device fails during the process of providing network services to users, it will generate multiple corresponding alarm information. After the network device generates multiple alarm information, the network device can obtain the multiple alarm information generated by it.

[0053] Optionally, when obtaining alarm information, the network device can obtain the alarm information once at a certain period of time (which can be determined according to actual conditions). Each time the alarm information is obtained, the alarm information within a set time period (which can be determined according to actual conditions) can be obtained. The alarm information within the set time period can correspond to one type of fault or multiple types of faults.

[0054] S204: Acquire multiple alarm item groups. The multiple alarm item groups are obtained by the network management platform through artificial intelligence learning of multiple historical alarm information. Each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information.

[0055] Multiple alarm item groups can be obtained by the network management platform through artificial intelligence learning of historical alarm information reported by network devices. For specific implementation methods, please refer to Figure 3 The embodiment shown is not described in detail here. Each alarm entry group may correspond to a type of fault, and each alarm entry group may include key alarm information of the fault. Each alarm entry group may be obtained by the network management platform through artificial intelligence learning of relevant historical alarm information of a type of fault, and the key alarm information included in the alarm entry group may be important alarm information of the fault.

[0056] When the network device obtains multiple alarm item groups, optionally, in some implementations, the multiple alarm item groups can be obtained from the network management platform. For example, after learning multiple alarm item groups, the network management platform can actively send multiple alarm item groups to the network device, and the network device can obtain multiple alarm item groups actively sent by the network management platform. Alternatively, the network device can also actively obtain multiple alarm item groups from the network management platform. For example, after the network device generates alarm information and before reporting the alarm information, it can send an acquisition request for the alarm item group to the network management platform. The network management platform can send multiple alarm item groups to the network device according to the acquisition request, so that the network device can obtain multiple alarm item groups. Optionally, in some implementations, the network device can also obtain multiple alarm item groups from a third-party platform. The third-party platform can be a server capable of data storage and data forwarding. For example, after learning multiple alarm item groups, the network management platform can send the multiple alarm item groups to the third-party platform, and the third-party platform forwards the multiple alarm item groups to the network device. Alternatively, the network device can actively obtain multiple alarm item groups from the third-party platform after generating alarm information and before reporting the alarm information. The method for the network device to obtain multiple alarm item groups is not specifically limited here.

[0057] S206: Match the multiple alarm information with the key alarm information in the multiple alarm item groups, and determine the matching target alarm information from the multiple alarm information.

[0058] The multiple alarm information includes important alarm information and unimportant alarm information. After matching the multiple alarm information with the key alarm information in the multiple alarm entry groups, the important alarm information can be screened out from the multiple alarm information. The important alarm information is the target alarm information that matches the key alarm information in the multiple alarm entry groups.

[0059] When matching multiple alarm information with key alarm information in multiple alarm item groups, each alarm information may be matched with key alarm information in multiple alarm item groups. Taking any one of the multiple alarm information (hereinafter, for the sake of distinction, it may be represented as the first alarm information) as an example, the following steps may be included:

[0060] Determine characteristic information of the first alarm information and characteristic information of key alarm information in each alarm entry group, the characteristic information including at least one of an alarm type, an alarm keyword, and an alarm code;

[0061] matching the first alarm information with the key alarm information in each alarm entry group according to the characteristic information;

[0062] In the case that there is critical warning information matching the first warning information, the first warning information is determined as the target warning information.

[0063] The characteristic information of the first alarm information can be used to describe the relevant characteristics of the first alarm information. The characteristic information of the first alarm information may include at least one of the alarm type, alarm keyword, and alarm code of the first alarm information, which can be determined by the network device when acquiring the first alarm information. Specifically, when the network device generates the first alarm information, it will first generate an alarm code. The network device can determine the alarm type and the corresponding alarm keyword of the first alarm information by analyzing the alarm code, thereby obtaining the characteristic information of the first alarm information.

[0064] The characteristic information of the key alarm information can be used to describe the relevant characteristics of the key alarm information. The characteristic information of the key alarm information can include at least one of the alarm type, alarm keyword and alarm code of the key alarm information, which can be carried in the alarm item group when the network management platform sends the alarm item group to the network device.

[0065] When the network device matches the first alarm information with the key alarm information in each alarm item group, the characteristic information of the first alarm information can be matched with the characteristic information of the key alarm information in each alarm item group. The matching method can be an exact match or a fuzzy match, which is not specifically limited here. After matching the characteristic information, if there is key alarm information whose characteristic information matches the characteristic information of the first alarm information in the key alarm information of multiple alarm item groups, that is, there is key alarm information matching the first alarm information in multiple alarm item groups, it can be said that the first alarm information is important alarm information, and the first alarm information can be determined as the target alarm information. If there is no key alarm information whose characteristic information matches the characteristic information of the first alarm information in the key alarm information of multiple alarm item groups, that is, there is no key alarm information matching the first alarm information in multiple alarm item groups, it can be said that the first alarm information is not important alarm information, and it can be determined that the first alarm information is not the target alarm information.

[0066] It should be noted that if the characteristic information of the first alarm information and the characteristic information of the key alarm information both include multiple pieces of information, then the first alarm information matches the key alarm information, which may be that the characteristic information of the first alarm information matches one piece of characteristic information in the key alarm information, or that it matches multiple pieces of characteristic information in the key alarm information, or that it matches all the characteristic information in the key alarm information, and no specific limitation is made here. It should also be noted that since each alarm entry group corresponds to a type of fault, and one alarm information usually corresponds to a type of fault, after matching the first alarm information with the key alarm information in multiple alarm entry groups, the matching result usually includes two situations, one is that there is a key alarm information that matches the first alarm information, and the other is that there is no key alarm information that matches the first alarm information.

[0067] For example, assuming that the first alarm information includes alarm keyword a1 and alarm type b1, the network management platform issues two alarm item groups, the key alarm information of the first alarm item group includes alarm keyword a2, alarm type b2 and alarm code c2, and the key alarm information of the second alarm item group includes alarm keyword a3, alarm type b3 and alarm code c3, then when matching, the alarm keyword a1 can be matched with the alarm keyword a2 and the alarm keyword a3 respectively, and the alarm type b1 can be matched with the alarm type b2 and the alarm type b3 respectively. If the alarm keyword a1 matches the alarm keyword a2 and does not match the alarm keyword a3, then the first alarm information can be determined to be the target alarm information, or if the alarm keyword a1 matches the alarm keyword a2 and does not match the alarm keyword a3, and the alarm type b1 matches the alarm type b2 and does not match the alarm type b3, then the first alarm information can be determined to be the target alarm information. If the alarm keyword a1 does not match the alarm keyword a2 and the alarm keyword a3, and the alarm type b1 does not match the alarm type b2 and the alarm type b3, it can be determined that the first alarm information is not the target alarm information.

[0068] Based on the above-described method, by performing matching analysis on each of the multiple alarm information, the target alarm information can be finally determined from the multiple alarm information. The number of the target alarm information can be one or more.

[0069] S208: Send the target alarm information to the network management platform.

[0070] After the network device determines the target alarm information from multiple alarm information, when reporting the alarm information to the network management platform, the target alarm information can be reported to the network management platform. In this way, since the network device can filter the alarm information according to the alarm item group when reporting the alarm information, the number of reported alarm information can be reduced, thereby reducing the bandwidth of the network management platform occupied by the alarm information and reducing the processing pressure of the network management platform. In addition, since the reported alarm information is the key alarm information related to the fault, when performing fault analysis on the network device, the specific fault of the network device can be quickly located according to the key alarm information, thereby improving the analysis efficiency.

[0071] Optionally, in some implementations, each alarm entry group may include non-critical alarm information in addition to critical alarm information. The non-critical alarm information may be negligible alarm information, and the negligible alarm information may not need to be reported to the network management platform. The non-critical alarm information may include at least one of derived alarm information and irrelevant alarm information. Derived alarm information may be alarm information derived from a fault after a network device generates alarm information due to a fault, and irrelevant alarm information may be alarm information that is not related to the fault and may be generated by a network device after the alarm information is generated due to a fault. Generally, derived alarm information and irrelevant alarm information are not important alarm information and may not need to be reported to the network management platform.

[0072] In the case where the multiple alarm entry groups include at least one of the derived alarm information and the irrelevant alarm information, after determining the target alarm information, the network device may further include the following steps:

[0073] determining non-target warning information from a plurality of warning information according to the derived warning information and / or the irrelevant warning information;

[0074] The non-target alarm information is stored in the network device for query by the network management platform.

[0075] Non-target alarm information may be alarm information that does not need to be reported to the network management platform. When determining non-target alarm information, each alarm information except the target alarm information in the multiple alarm information may be matched with the derived alarm information and / or irrelevant alarm information in the multiple alarm item groups, and then the matched alarm information is determined as non-target alarm information. Optionally, in some embodiments, when determining non-target alarm information, the following steps may be included:

[0076] Determine a first alarm entry group where key alarm information matching the target alarm information is located;

[0077] For each second warning information except the target warning information in the multiple warning information, perform the following operations:

[0078] Matching the second alarm information with the derived alarm information and / or irrelevant alarm information in the first alarm entry group;

[0079] When the match is successful, the second warning information is determined as non-target warning information.

[0080] Specifically, when determining non-target alarm information, the alarm item group (here, for the sake of distinction, it can be expressed as the first alarm item group) in which the key alarm information matching the target alarm information is located can be determined first. Wherein, when the number of target alarm information is one, the target alarm information matches one key alarm information, and accordingly, the number of the first alarm item group is also one, and when the number of target alarm information is multiple, each target alarm information matches one key alarm information, and accordingly, the number of the first alarm item group is multiple.

[0081] After obtaining the first alarm item group, for each alarm information except the target alarm information in the multiple alarm information (here for the convenience of distinction, it can be expressed as the second alarm information), when determining whether the second alarm information is non-target alarm information, the second alarm information can be matched with the derived alarm information and / or irrelevant alarm information in the first alarm item group. For example, if the first alarm item group includes the derived alarm information, the second alarm information can be matched with the derived alarm information; if the first alarm item group includes the irrelevant alarm information, the second alarm information can be matched with the irrelevant alarm information; if the first alarm item group includes both the derived alarm information and the irrelevant alarm information, the second alarm information can be matched with the derived alarm information and the irrelevant alarm information, respectively.

[0082] When matching the second alarm information with the derived alarm information and / or irrelevant alarm information in the first alarm item group, it can be specifically matched with the characteristic information of the second alarm information with the characteristic information of the derived alarm information and / or irrelevant alarm information in the first alarm item group. Among them, the characteristic information of the second alarm information, the derived alarm information and the irrelevant alarm information can include at least one of the alarm type, the alarm keyword and the alarm code. For details, please refer to the above description of the characteristic information, which will not be described in detail here. When matching the characteristic information, the matching method can be an exact match or a fuzzy match, which is not specifically limited here.

[0083] After matching the second alarm information with the derived alarm information and / or irrelevant alarm information in the first alarm entry group, if the match is successful, it can be determined that the second alarm information is non-target alarm information, and if the match fails, it can be determined that the second alarm information is not non-target alarm information. For example, taking the first alarm entry group including the derived alarm information and the irrelevant alarm information as an example, if the second alarm information matches the derived alarm information, or the second alarm information matches the irrelevant alarm information, it can be determined that the second alarm information is non-target alarm information, and if the second alarm information does not match the derived alarm information and the irrelevant alarm information, it can be determined that the second alarm information is not non-target alarm information. Among them, the second alarm information matches the derived alarm information, which can be that the characteristic information of the second alarm information matches at least one of the characteristic information of the derived alarm information, the second alarm information matches the irrelevant alarm information, or the characteristic information of the second alarm information matches at least one of the characteristic information of the irrelevant alarm information. For details, please refer to the above description of matching the characteristic information of the first alarm information with the characteristic information of the key alarm information, which will not be described in detail here.

[0084] Based on the above-described method, by performing matching analysis on each of the warning information except the target warning information in the multiple warning information, the non-target warning information can be finally determined from the multiple warning information. The number of the non-target warning information can be one or more.

[0085] Since the second alarm information is matched with the derived alarm information and / or irrelevant alarm information in the first alarm item group when determining the non-target alarm information, there is no need to match the derived alarm information and / or irrelevant alarm information in each alarm item group separately. Therefore, the number of alarm item groups that need to be matched can be reduced, thereby improving the matching efficiency.

[0086] Optionally, in some implementations, when the network device matches multiple alarm information with any alarm item group issued by the network management platform, a matching time threshold may be set, because most of the key alarms of the network devices and the alarm information derived therefrom occur within a time interval, therefore, within a period of time after successfully matching the key alarm information in a certain alarm item group, the alarm information generated by the network device can be matched and screened with the alarm item group, and after this time threshold, the network device can re-match the alarm information with other alarm item groups. The matching time threshold may be configured by the user.

[0087] After determining non-target alarm information from multiple alarm information, since the non-target alarm information is alarm information that is not important relative to the target alarm information, it is not necessary to report the non-target alarm information to the network management platform, thereby reducing the amount of alarm information reported, thereby reducing the bandwidth of the network management platform occupied by the alarm information, and reducing the processing pressure of the network management platform. In the embodiment of the present application, in the case of not reporting the non-target alarm information, the non-target alarm information can also be stored locally in the network device, so that when the network management platform needs to query the non-target alarm information, it can query from the local network device to obtain more alarm information.

[0088] Optionally, in some implementations, for each alarm information, after matching the alarm information with multiple alarm item groups, there may be a situation where the alarm information does not match any of the multiple alarm item groups. For example, if each alarm item group includes critical alarm information and derived alarm information, then the alarm information does not match any of the multiple alarm item groups, which may be that the alarm information does not match any of the critical alarm information and derived alarm information in the multiple alarm item groups. For another example, if each alarm item group includes critical alarm information, derived alarm information, and irrelevant alarm information, then the alarm information does not match any of the multiple alarm item groups, which may be that the alarm information does not match any of the critical alarm information, derived alarm information, and irrelevant alarm information in the multiple alarm item groups.

[0089] If the alarm information does not match multiple alarm entry groups, the network device can perform the following operations:

[0090] Send alarm information to the network management platform;

[0091] A second alarm item group is received, where the second alarm item group is obtained after the network management platform performs artificial intelligence learning on the alarm information.

[0092] Since the alarm information does not match multiple alarm item groups, it can be explained that the alarm information may be a new alarm and does not belong to any of the fault types corresponding to multiple alarm item groups. In this case, the network device can report the alarm information to the network management platform. After receiving the alarm information, the network management platform can perform artificial intelligence learning on the alarm information and obtain a new alarm item group. Here, for easy distinction, the new alarm item group can be represented as the second alarm item group. The specific implementation method of the network device learning the alarm information and obtaining the second alarm item group can be found in Figure 3 The corresponding contents in the illustrated embodiment will not be described in detail here.

[0093] After obtaining the second alarm item group, the network management platform can send the second alarm item group to the network device, and the network device can receive the second alarm item group. In this way, when the network device subsequently screens the alarm information, it can match the alarm information according to the second alarm item group, so that it can match the key alarm information, thereby reducing the number of reported alarm information, reducing the bandwidth occupied by the network management platform and the processing pressure of the network management platform. Among them, when the network management platform sends the second alarm information item group to the forgotten device, it can send it directly to the network device, or forward it to the network device through a third-party platform. Correspondingly, when the network device receives the second alarm item group, it can receive it from the network management platform or from the third-party platform.

[0094] Optionally, in some implementations, the multiple alarm item groups issued by the network management platform may also be dynamically updated by the network management platform. For details, see Figure 3 The corresponding contents in the illustrated embodiment will not be described in detail here. After dynamically updating multiple alarm item groups, the network management platform can send the updated alarm item groups to the network device, and the network device can receive the alarm item groups updated by the network management platform. In this way, when the alarm information is subsequently screened, it can be screened according to the dynamically updated alarm item groups. Since multiple alarm item groups can be dynamically updated by the network management platform and sent to the network device, the target alarm information screened by the network device can be more in line with actual needs. After the target alarm information is reported to the network management platform, it can be convenient for the network management platform to perform fault analysis.

[0095] Figure 3 It is a flowchart of a method for processing alarm information according to an embodiment of the present application. Figure 3 The method for processing the warning information shown can be applied to Figure 1 The network management platform 11 is shown. Figure 3 The method for processing the warning information shown includes the following steps.

[0096] S302: Perform artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information.

[0097] The multiple historical alarm information may be alarm information reported by the network device to the network management platform in the past period of time. The multiple historical alarm information may include alarm information related to multiple types of faults, and the alarm information of each type of fault may include important alarm information and unimportant alarm information. In an embodiment of the present application, the network management platform may collect multiple historical alarm information reported by the network device in the past period of time, and perform artificial intelligence learning on the multiple historical alarm information, and generate multiple alarm item groups according to the learning results. Among them, each alarm item group may correspond to a type of fault, each alarm item group includes key alarm information, and each alarm item group may be obtained by performing artificial intelligence learning on the relevant historical alarm information of a type of fault.

[0098] Optionally, in some implementations, the network management platform performs artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, which may include the following steps:

[0099] Determine multiple fault types corresponding to multiple historical alarm information;

[0100] According to multiple fault types, multiple historical alarm information is divided into multiple alarm information groups, each alarm information group corresponds to one type of fault;

[0101] For each alarm information group, perform the following operations:

[0102] According to the importance index of the alarm information, each historical alarm information in the alarm information group is scored by artificial intelligence to obtain an importance score, where the importance index includes at least one of the type, weight, and degree of impact on the business;

[0103] According to the importance score, key alarm information is determined from the alarm information group;

[0104] According to the key alarm information in the alarm information group, an alarm entry group corresponding to the alarm information group is generated.

[0105] Specifically, after collecting multiple historical alarm information, the network management platform can analyze each historical alarm information to determine which type of fault each historical alarm information corresponds to, thereby obtaining multiple fault types corresponding to the multiple historical alarm information. Among them, one fault type can correspond to one or more historical alarm information. After determining the fault type corresponding to each of the multiple historical alarm information, the multiple historical alarm information can be grouped according to the fault type. When grouping multiple historical alarm information, the historical alarm information corresponding to the same fault type can be divided into a group, thereby obtaining multiple alarm information groups, each alarm information corresponds to a type of fault, and each alarm information group includes one or more historical alarm information.

[0106] After obtaining multiple alarm information groups, artificial intelligence learning can be performed for each alarm information group, and an alarm item group corresponding to each alarm information group can be obtained according to the learning result. Taking one of the alarm information groups as an example, when performing artificial intelligence learning on the alarm information group, the importance index of each historical alarm information in the alarm information group can be obtained first, and then each historical alarm information can be scored by artificial intelligence according to the importance index of each historical alarm information to obtain the importance score of each historical alarm information. Among them, the importance index of the historical alarm information can include at least one of the type of historical alarm information, the weight of the historical alarm information, and the degree of impact of the historical alarm information on the business. The type of historical alarm information is the attribute information of the historical alarm information, which can characterize the type of historical alarm information, such as port class or protocol class. The weight of the historical alarm information can characterize the importance of the historical alarm information. The more important the historical alarm information is, the larger the corresponding weight is. Conversely, the less important the historical alarm information is, the smaller the corresponding weight is. Optionally, the weight of the historical alarm information can be an artificial experience value. The degree of impact of the historical alarm information on the business can be determined according to actual conditions. When performing artificial intelligence scoring on historical alarm information according to the importance index of historical alarm information, if the importance index includes one index, the index value of the one index can be determined as the importance score of the historical alarm information, and if the importance index includes multiple indexes, the sum (or weighted sum, etc.) of the index values ​​of the multiple indexes can be determined as the importance score of the historical alarm information. Among them, the importance of the historical alarm information is directly proportional to the importance score of the historical alarm information.

[0107] After obtaining the importance score of each historical alarm information in the alarm information group, the key alarm information can be determined from the alarm information group according to the importance score. Specifically, the historical alarm information with the largest importance score in the alarm information group can be determined as the key alarm information. After obtaining the key alarm information, an alarm entry group corresponding to the alarm information group can be generated according to the key alarm information, and the alarm entry group includes the key alarm information.

[0108] For example, assuming that the alarm information group includes port class alarm information 1, protocol class alarm information 2 and routing class alarm information 3, after performing artificial intelligence scoring on these three alarm information according to the type, weight and impact of each alarm information on the business, the importance score of port class alarm information 1 is 10 points, the importance score of protocol class alarm information 2 is 8 points, and the importance score of routing class alarm information 3 is 4 points. Then, the port class alarm information 1 with the highest importance score can be determined as the key alarm information, and an alarm entry group corresponding to the alarm information group is generated, and the key alarm information in the alarm entry is the port class alarm information 1.

[0109] Optionally, in some implementations, after determining the critical alarm information in each alarm information group and generating the corresponding alarm entry group based on the above method, non-critical alarm information may also be determined for each alarm entry group, and the non-critical alarm information may include derived alarm information and / or irrelevant alarm information. Derived alarm information may be alarm information derived from a fault after the network device generates alarm information due to a fault, and irrelevant alarm information may be alarm information irrelevant to the fault that may be generated by the network device after the alarm information is generated due to a fault.

[0110] When determining the derived alarm information and / or irrelevant alarm information in each alarm entry group, specifically, for each alarm information group, after obtaining the importance score of each historical alarm information in the alarm information group, the following steps may also be included:

[0111] Determine derived warning information and / or irrelevant warning information from the warning information group according to the importance score;

[0112] When generating an alarm entry group corresponding to the alarm information group according to the key alarm information in the alarm information group, the following may be included:

[0113] An alarm entry group corresponding to the alarm information group is generated according to the derived alarm information and / or irrelevant alarm information in the alarm information group and the key alarm information in the alarm information group.

[0114] When determining derived alarm information and / or irrelevant alarm information from the alarm information group according to the importance score, specifically, corresponding score intervals can be set for the derived alarm information and irrelevant alarm information, the score interval corresponding to the derived alarm information is smaller than the score of the critical alarm information and larger than the score interval corresponding to the irrelevant alarm information, and then the importance scores of the other alarm information in the alarm information group except the critical alarm information are matched with the score area corresponding to the derived alarm information and the score interval corresponding to the irrelevant alarm information, respectively, and the alarm information whose importance score is within the score interval of the derived alarm information is determined as the derived alarm information, and the alarm information whose importance score is within the score interval of the irrelevant alarm information is determined as the derived alarm information. Among them, when setting the score intervals of the derived alarm information and the irrelevant alarm information, it can be set according to actual needs, and no specific limitation is made here.

[0115] After determining the derived alarm information and / or irrelevant alarm information in the alarm information group, when generating the alarm entry group, the alarm entry group may be generated based on the key alarm information, and the derived alarm information and / or irrelevant alarm information.

[0116] Still taking the example that the above alarm information group includes alarm information 1 of the port class, alarm information 2 of the protocol class and alarm information 3 of the routing class, assuming that the score interval corresponding to the derived alarm information is [5,9], and the score interval corresponding to the irrelevant alarm information is [0,5], then the alarm information 2 of the protocol class can be determined as the derived alarm information, and the alarm information 3 of the routing class can be determined as the irrelevant alarm information. When generating an alarm entry group, the entry group includes key alarm information, derived alarm information and irrelevant alarm information, among which the key alarm information is alarm information 1 of the port class, the derived alarm information is alarm information 2 of the protocol class, and the irrelevant alarm information is alarm information 3 of the routing class.

[0117] S304: Send multiple alarm entry groups to the network device.

[0118] After the network management device performs artificial intelligence learning on multiple historical alarm information and obtains multiple alarm item groups, the multiple alarm item groups can be sent to the network device. Each alarm item group includes key alarm information. Optionally, each alarm item group can also include derivative alarm information and / or irrelevant alarm information.

[0119] When the network management platform sends multiple alarm item groups to the network device, the multiple alarm item groups may be sent directly to the network device, or the multiple alarm item groups may be forwarded to the network device through a third-party platform, which is not specifically limited here.

[0120] S306: receiving target alarm information sent by the network device, where the target alarm information is matched alarm information determined from multiple alarm information after matching the multiple alarm information with key alarm information in multiple alarm item groups when the network device generates multiple alarm information.

[0121] After the network management platform sends multiple alarm item groups to the network device, when the network device generates multiple alarm information and reports the alarm information to the network management platform, it can determine the target alarm information from the multiple alarm information according to the multiple alarm item groups, and report the target alarm information to the network management platform. The specific implementation method of the network device determining the target alarm information according to the multiple alarm item groups can be found in Figure 2 The embodiment shown is not described in detail here. After the network device reports the target alarm information to the network management platform, the network management platform can receive the target alarm information reported by the network device. The number of target alarm information can be one or more.

[0122] In this way, since the network equipment can filter the alarm information according to the alarm item group issued by the network management platform when reporting alarm information, the number of reported alarm information can be reduced, thereby reducing the bandwidth of the network management platform occupied by the alarm information and reducing the processing pressure of the network management platform. In addition, since the reported alarm information is key alarm information related to the fault, when performing fault analysis on the network equipment, the specific fault of the network equipment can be quickly located according to the key alarm information, thereby improving the analysis efficiency.

[0123] Optionally, in some implementation modes, after receiving the target alarm information sent by the network device, the network management platform may further include:

[0124] receiving a query request for warning information, the query request being used to request a query for non-target warning information corresponding to the target warning information;

[0125] Sending a query request to a network device;

[0126] The query result sent by the network device is received, and the query result is obtained by the network device after querying the non-target alarm information stored locally according to the query request.

[0127] Specifically, for network devices, after reporting the target alarm information in multiple alarm information to the network management platform, non-target alarm information can also be determined from multiple alarm information according to multiple alarm item groups, and the non-target alarm information is stored locally in the network device. For specific implementation methods, see Figure 2 The corresponding contents in the illustrated embodiments will not be repeated here. For the network management platform, since the network device does not report the non-target alarm information, the network management platform cannot obtain the non-target alarm information. However, in some scenarios, such as scenarios where it is necessary to further analyze the fault in combination with the non-target alarm information, there is a need to query the non-target alarm information. In this case, the network management platform can receive a query request for the non-target alarm information and send the query request to the network device. The query request is used to request to query the non-target alarm information related to the target alarm information. After receiving the query request, the network device can query the non-target alarm information stored locally according to the query request, and send the corresponding query results to the network management platform. The network management platform can receive the query results from the network device, so that the non-target alarm information can still be obtained when the network device does not report the non-target alarm information to meet the actual needs.

[0128] Optionally, in some implementations, the network management platform may also perform the following operations:

[0129] receiving alarm information, where the alarm information is sent by the network device when it is determined that the alarm information does not match any of the multiple alarm entry groups;

[0130] Performing artificial intelligence learning on the alarm information to obtain a second alarm item group;

[0131] The second alarm entry group is sent to the network device.

[0132] Specifically, after the network management platform sends multiple alarm item groups to the network device, when the network device generates multiple alarm messages and matches the alarm information in the multiple alarm item groups, for each alarm message, there may be a situation where the alarm information does not match the multiple alarm item groups. In this case, the network device will send the alarm information to the network management platform, and the network management platform can receive the alarm information sent by the network device.

[0133] After receiving the alarm information, the network management platform can perform artificial intelligence learning on the alarm information, and generate an alarm item group corresponding to the alarm information according to the artificial intelligence learning result, which can be represented as the second alarm item group for easy distinction. The specific implementation method of the network management platform generating the second alarm item group according to the alarm information can refer to the relevant content recorded in the above S302, which will not be repeated here. After generating the second alarm item group, the network management platform can send the second alarm item group to the network device, so that when the network device subsequently screens the alarm information, it can screen according to the second alarm item group to match the key alarm information, thereby reducing the number of reported alarm information and reducing the bandwidth and processing pressure of the network management platform. Among them, when the network management platform sends the second alarm information item group, it can be sent directly to the network device, or it can be forwarded to the network device through a third-party platform. Correspondingly, when the network device receives the second alarm item group, it can be received from the network management platform or from the third-party platform.

[0134] Optionally, in some implementations, after the network management platform generates multiple alarm item groups based on the method described in S302, it can also dynamically update the multiple alarm item groups and send the dynamically updated alarm item groups to the network device, so that the network device can filter the alarm information according to the dynamically updated alarm item groups. The network management platform can dynamically update multiple alarm item groups, taking the dynamic update of one of the alarm item groups as an example, by at least one of the following two methods:

[0135] The first method: receiving an update instruction for the alarm entry group; and updating at least one of the key alarm information, the derived alarm information and the irrelevant alarm information in the alarm entry group according to the update instruction.

[0136] The second method: determine the alarm frequency of the alarm information in the alarm entry group and / or the degree of impact on the business; update the importance of the alarm information in the alarm entry group according to the alarm frequency and / or the degree of impact on the business; update at least one of the key alarm information, derived alarm information and irrelevant alarm information in the alarm entry group according to the updated importance.

[0137] In the first method described above, the update instruction for the alarm item group can be triggered by a network maintenance engineer. For example, when the network maintenance engineer determines that the alarm item group needs to be updated based on actual business needs, the update instruction for the alarm item group can be triggered. The update instruction can include the identification information of the alarm item group that needs to be updated and the specific content of the update of the alarm item group. After receiving the update instruction for the alarm item group, the network management platform can update at least one of the key alarm information, derived alarm information and irrelevant alarm information in the alarm item group according to the instructions of the update instruction. For example, if the update instruction indicates that the key alarm information in alarm item group 1 is modified to information 1, the network management platform can delete the original key alarm information in alarm item group 1 when updating, and use information 1 as the key alarm information of alarm item group 1.

[0138] In the second method described above, the network management platform can realize intelligent updating of the alarm entry group. Specifically, the network management platform can count the alarm frequency of each alarm information received within the time period and / or the degree of impact of each alarm information on the business at regular intervals, and then update the importance of the alarm information in the alarm entry group according to the alarm frequency and / or the degree of impact on the business. Among them, the higher the alarm frequency of the alarm information, the more important the alarm information, the greater the impact of the alarm information on the business, the more important the alarm information, and vice versa. The less important the alarm information is. After the importance of the alarm information is updated, at least one of the key alarm information, derived alarm information, and irrelevant alarm information in the alarm entry group can be redefined according to the updated importance, thereby realizing the update of the alarm entry group.

[0139] In actual application scenarios, the alarm entry group may be updated by at least one of the two updating methods mentioned above.

[0140] It should be noted that in the process of processing alarm information in the embodiment of the present application, the network device can perform new matching and alarm reporting according to the updated alarm item group issued by the network management platform, and the network maintenance engineer can also update the fault-related alarm information of the network management platform according to the newly generated fault and the fault alarm information related thereto. In the process of artificial intelligence learning of alarm information, the network management device can also dynamically adjust the importance score of the alarm information according to the alarm frequency of the alarm information reported by the network device and the degree of impact on the business (the network management platform can monitor the degree of damage to the business caused by the alarm reported by the network device) (for example, the protocol link break score is increased, and the subsequent protocol link break caused by the port abnormality only reports the alarm information of the protocol link break, ignoring the port abnormality information), and finally dynamically forms a constantly updated alarm item group and sends it to the network device. Therefore, the network management platform can achieve the optimal effect of dynamic update and learning of the alarm item group by interacting and learning with the network device multiple times.

[0141] To facilitate understanding of the method for processing alarm information provided in the embodiment of the present application, please refer to Figure 4 The embodiment shown. Figure 4 It is a schematic diagram of a method for processing alarm information according to an embodiment of the present application. Figure 4 The illustrated embodiment may include the following steps when processing the alarm information.

[0142] Step 1: The network management platform obtains alarm item group 1 to alarm item group N (N is an integer greater than 1) by artificial intelligence learning of the historical alarm information reported by the network device, and sends these N alarm item groups to the network device. The network device saves the N alarm item groups in the local alarm comparison table. Among them, alarm item group 1 is the ospf routing protocol failure alarm group, in which the key alarm information is the ospf protocol disconnection, and the alarm information that can be ignored is the route deletion alarm.

[0143] Step 2: The network device generates alarm information 1 / 2 / 3 / 4, wherein alarm information 1 is an ospf protocol disconnection alarm, and alarm information 2 / 3 / 4 is an alarm of deletion of three routes caused by the ospf protocol disconnection.

[0144] Step 3: The network device matches the alarm information 1 / 2 / 3 / 4 with the N alarm entry groups in the alarm comparison table.

[0145] Step 4: Alarm information 1 generated by the network device matches the key alarm information of alarm entry group 1, namely, ospf protocol disconnection.

[0146] Step 5: The network device continues to compare alarm information 2 / 3 / 4 with the alarm information in alarm entry group 1, and matches the route deletion alarm type in the ignorable alarm.

[0147] Step 6: The network device reports alarm information 1, namely the OSPF protocol disconnection alarm, to the network management platform, and stores other alarm information 2 / 3 / 4 in the alarm log file of the network device.

[0148] Step 7: The network management platform prompts the network maintenance engineer that a critical fault has occurred in the network equipment, an OSPF protocol disconnection event, and prompts the engineer to continue to obtain other alarm information.

[0149] Step 8: If the network maintenance engineer wants to obtain other alarm information of this critical alarm, the network management platform can obtain the ignored alarm entries route deletion alarm 2 / 3 / 4 related to this critical alarm information 1, namely the ospf protocol disconnection alarm, in the alarm log file of the network device.

[0150] Afterwards, the network device generates alarm information 5 / 6 / 7 / 8, wherein alarm information 5 is a BGP protocol disconnection alarm, and alarm information 6 / 7 / 8 is a 3-route deletion alarm caused by the BGP protocol disconnection. When processing alarm information 5 / 6 / 7 / 8, the following steps may be included:

[0151] Step 1: The network device matches the generated alarm information 5 / 6 / 7 / 8 with the N alarm entry groups in the alarm comparison table.

[0152] Step 2: The network device does not match the alarm information corresponding to the alarm information 5 / 6 / 7 / 8 in the N alarm entry groups.

[0153] Step 3: The network device reports alarm information 5 / 6 / 7 / 8 to the network management platform.

[0154] Step 4: The network management platform performs artificial intelligence learning on alarm information 5 / 6 / 7 / 8, and determines that alarm information 5 BGP protocol disconnection alarm is a critical alarm information and alarm information 6 / 7 / 8 route deletion alarm is an ignorable alarm information based on the learning results, and generates a new alarm entry group 11. The critical alarm information in alarm entry group 11 is alarm information 5, and the ignorable alarm information is alarm information 6 / 7 / 8.

[0155] Step 5: The network management platform sends the alarm item group 11 to the network device, and the network device can save the alarm item group 11 into the alarm comparison table.

[0156] Step 6: When the network device subsequently generates a BGP-related protocol disconnection alarm, by matching with the alarm entry group 11, only the BGP protocol disconnection alarm can be reported, and the route deletion alarm information related thereto can be ignored.

[0157] Through the above processing, the network device can generate more alarm item groups after multiple interactions with the network management platform. The network device can complete the matching of most alarm information based on these alarm item groups, so that the negligible alarm information can be automatically processed on the network device side, and only the key alarm information is reported to reduce the number of reported alarm information.

[0158] Based on the technical solution provided by the embodiment of the present application, the network management platform can perform artificial intelligence learning on the historical alarm information reported by the network device, obtain multiple alarm item groups, and send the multiple alarm item groups to the network device, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information. After the network device generates multiple alarm information, when reporting the alarm information, it can first match the multiple alarm information with the key alarm information in the multiple alarm item groups issued by the network management platform, and then report the target alarm information matching the key alarm information. In this way, since the network device can filter the alarm information according to the alarm item group when reporting the alarm information, the number of alarm information reported can be reduced, thereby reducing the bandwidth of the network management platform occupied by the alarm information and reducing the processing pressure of the network management platform. In addition, since the reported alarm information is the key alarm information related to the fault, when performing fault analysis on the network device, the specific fault of the network device can be quickly located according to the key alarm information, thereby improving the analysis efficiency.

[0159] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0160] Figure 5 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 5At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include a memory, such as a high-speed random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage. Of course, the electronic device may also include hardware required for other services.

[0161] The processor, network interface and memory can be interconnected through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0162] The memory is used to store the program. Specifically, the program may include a program code, and the program code includes a computer operation instruction. The memory may include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0163] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a processing device for alarm information at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:

[0164] Get multiple alarm information generated by network devices;

[0165] Acquire multiple alarm item groups, where the multiple alarm item groups are obtained by the network management platform through artificial intelligence learning of multiple historical alarm information, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0166] Matching the multiple alarm information with the key alarm information in the multiple alarm item groups, and determining matching target alarm information from the multiple alarm information;

[0167] The target alarm information is sent to the network management platform.

[0168] Or, to do the following:

[0169] Perform artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0170] sending the plurality of alarm item groups to a network device;

[0171] Receive target alarm information sent by the network device, where the target alarm information is generated by the network device and, after matching the multiple alarm information with key alarm information in the multiple alarm item groups, the network device determines matching alarm information from the multiple alarm information.

[0172] The above application Figure 5 The method performed by the alarm information processing device disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in software form. The above processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in this application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in this application can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0173] The electronic device may also perform Figure 2 or Figure 3 The method and the device for processing the alarm information are implemented in Figure 2 or Figure 3 The functions in the illustrated embodiments will not be described in detail in this application.

[0174] Of course, in addition to software implementation methods, the electronic device of the present application does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0175] The present application also proposes a computer-readable storage medium, which stores one or more programs, wherein the one or more programs include instructions, which, when executed by a portable electronic device including a plurality of application programs, enable the portable electronic device to execute Figure 2 or Figure 3 The method of the embodiment shown is specifically used to perform the following operations:

[0176] Get multiple alarm information generated by network devices;

[0177] Acquire multiple alarm item groups, where the multiple alarm item groups are obtained by the network management platform through artificial intelligence learning of multiple historical alarm information, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0178] Matching the multiple alarm information with the key alarm information in the multiple alarm item groups, and determining matching target alarm information from the multiple alarm information;

[0179] The target alarm information is sent to the network management platform.

[0180] Or, to do the following:

[0181] Perform artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0182] sending the plurality of alarm item groups to a network device;

[0183] Receive target alarm information sent by the network device, where the target alarm information is generated by the network device and, after matching the multiple alarm information with key alarm information in the multiple alarm item groups, the network device determines matching alarm information from the multiple alarm information.

[0184] Figure 6 This is a schematic diagram of the structure of an alarm information processing device 60 according to an embodiment of the present application. Figure 6 In a software implementation, the warning information processing device 60 may include: a first acquisition module 61, a second acquisition module 62, a matching module 63 and a sending module 64, wherein:

[0185] A first acquisition module 61 acquires a plurality of alarm information generated by the network device;

[0186] A second acquisition module 62 acquires a plurality of alarm item groups, wherein the plurality of alarm item groups are obtained by the network management platform through artificial intelligence learning of a plurality of historical alarm information, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0187] A matching module 63 matches the multiple alarm information with the key alarm information in the multiple alarm item groups, and determines matching target alarm information from the multiple alarm information;

[0188] The sending module 64 sends the target alarm information to the network management platform.

[0189] Optionally, in some implementations, the matching module 63 matches the multiple alarm information with the key alarm information in the multiple alarm item groups, and determines the matching target alarm information from the multiple alarm information, including:

[0190] For each first warning information in the plurality of warning information, perform the following operations:

[0191] Determine characteristic information of the first alarm information and characteristic information of key alarm information in each alarm entry group, wherein the characteristic information includes at least one of an alarm type, an alarm keyword, and an alarm code;

[0192] According to the characteristic information, matching the first alarm information with key alarm information in each alarm entry group;

[0193] In a case where there is critical warning information matching the first warning information, the first warning information is determined as the target warning information.

[0194] Optionally, in some implementations, each alarm entry group further includes derived alarm information and / or irrelevant alarm information; after determining the target alarm information, the matching module 63 further includes:

[0195] Determining non-target warning information from the plurality of warning information according to the derived warning information and / or the irrelevant warning information;

[0196] The non-target alarm information is stored in the network device for query by the network management platform.

[0197] Optionally, in some implementations, the matching module 63 determines the non-target warning information from the multiple warning information according to the derived warning information and / or the irrelevant warning information, including:

[0198] Determine a first alarm entry group where key alarm information matching the target alarm information is located;

[0199] For each second warning information in the plurality of warning information except the target warning information, perform the following operations:

[0200] Matching the second alarm information with the derived alarm information and / or irrelevant alarm information in the first alarm entry group;

[0201] If the match is successful, the second warning information is determined as non-target warning information.

[0202] Optionally, in some implementations, the apparatus 60 further includes a receiving module, which, for each alarm information, when the alarm information does not match any of the multiple alarm item groups:

[0203] The sending module 64 sends the alarm information to the network management platform;

[0204] The receiving module receives a second alarm item group, where the second alarm item group is obtained after the network management platform performs artificial intelligence learning on the alarm information.

[0205] Optionally, in some implementations, the plurality of alarm item groups are dynamically updated by the network management platform; and the receiving module further includes:

[0206] Receive the alarm item group updated by the network management platform.

[0207] The alarm information processing device 60 provided in the present application can also execute Figure 2 The method is implemented by the alarm information processing device 60. Figure 2 The functions of the illustrated embodiments will not be described in detail in this application.

[0208] Figure 7 This is a schematic diagram of the structure of an alarm information processing device 70 according to an embodiment of the present application. Figure 7 In a software implementation, the alarm information processing device 70 may include: an intelligent learning module 71, a sending module 72 and a receiving module 73, wherein:

[0209] An intelligent learning module 71 performs artificial intelligence learning on a plurality of historical alarm information to obtain a plurality of alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0210] A sending module 72, sending the plurality of alarm item groups to a network device;

[0211] The receiving module 73 receives the target alarm information sent by the network device. The target alarm information is generated by the network device, and after matching the multiple alarm information with the key alarm information in the multiple alarm item groups, the matching alarm information is determined from the multiple alarm information.

[0212] Optionally, in some implementations, the intelligent learning module 71 performs artificial intelligence learning on a plurality of historical alarm information to obtain a plurality of alarm item groups, including:

[0213] Determine multiple fault types corresponding to the multiple historical alarm information;

[0214] According to the multiple fault types, the multiple historical alarm information is divided into multiple alarm information groups, each alarm information group corresponds to a type of fault;

[0215] For each alarm information group, perform the following operations:

[0216] According to the importance index of the alarm information, each historical alarm information in the alarm information group is scored by artificial intelligence to obtain an importance score, wherein the importance index includes at least one of the type, the weight, and the degree of impact on the business;

[0217] Determining key warning information from the warning information group according to the importance score;

[0218] An alarm entry group corresponding to the alarm information group is generated according to the key alarm information in the alarm information group.

[0219] Optionally, in some implementations, after obtaining the importance score, the intelligent learning module 71 further includes:

[0220] Determining derived warning information and / or irrelevant warning information from the warning information group according to the importance score;

[0221] The step of generating an alarm entry group corresponding to the alarm information group according to the key alarm information in the alarm information group includes:

[0222] An alarm entry group corresponding to the alarm information group is generated according to the derived alarm information and / or irrelevant alarm information in the alarm information group and the key alarm information in the alarm information group.

[0223] Optionally, in some implementations, the receiving module 73, after receiving the target alarm information sent by the network device, receives a query request for alarm information, wherein the query request is used to request to query non-target alarm information corresponding to the target alarm information;

[0224] The sending module 72 sends the query request to the network device;

[0225] The receiving module 73 receives the query result sent by the network device, and the query result is obtained by the network device after querying the non-target alarm information stored locally according to the query request.

[0226] Optionally, in some implementations, the receiving module 73 receives alarm information, where the alarm information is sent by the network device when it is determined that the alarm information does not match any of the multiple alarm item groups;

[0227] The intelligent learning module 71 performs artificial intelligence learning on the alarm information to obtain a second alarm item group;

[0228] The sending module 72 sends the second alarm item group to the network device.

[0229] Optionally, in some implementations, the intelligent learning module 71, after obtaining the multiple alarm item groups, dynamically updates the multiple alarm item groups;

[0230] The sending module 72 sends the updated alarm item group to the network device;

[0231] Wherein, for each alarm item group, the intelligent learning module 71 dynamically updates the alarm item group, including at least one of the following:

[0232] Receiving an update instruction for the alarm entry group; updating at least one of the key alarm information, the derived alarm information, and the irrelevant alarm information in the alarm entry group according to the update instruction;

[0233] Determine the alarm frequency and / or the degree of impact on the business of the alarm information in the alarm entry group; update the importance of the alarm information in the alarm entry group according to the alarm frequency and / or the degree of impact on the business; update at least one of the key alarm information, derived alarm information and irrelevant alarm information in the alarm entry group according to the updated importance.

[0234] The alarm information processing device 70 provided in the present application can also execute Figure 3 The method and the alarm information processing device 70 are implemented in Figure 3 The functions of the illustrated embodiments will not be described in detail in this application.

[0235] Figure 8 This is a schematic diagram of the structure of an alarm information processing system 80 according to an embodiment of the present application. Figure 8 , Figure 8 The alarm information processing system 80 shown includes a network device 81 and a network management platform 82, wherein:

[0236] The network management platform 82 performs artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information;

[0237] The network management platform 82 sends the plurality of alarm item groups to the network device 81;

[0238] The network device 81 obtains a plurality of alarm information generated by the network device 81;

[0239] The network device 81 matches the multiple alarm information with the key alarm information in the multiple alarm item groups, and determines the matching target alarm information from the multiple alarm information;

[0240] The network device 81 sends the target alarm information to the network management platform 82;

[0241] The network management platform 82 receives the target alarm information sent by the network device 81 .

[0242] In the embodiment of the present application, the network device 81 can implement the above Figures 1 to 4 In the embodiment shown, the network equipment implements the functions, and the network management platform 82 can implement the above Figures 1 to 4 The functions implemented by the network management platform in the embodiment shown in the figure can be specifically implemented by referring to the above Figures 1 to 4 The specific implementation of the corresponding steps in the illustrated embodiment will not be repeated here.

[0243] In short, the above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0244] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0245] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0246] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0247] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

Claims

1. A method for processing alarm information, applied to a network device, comprising: Acquire multiple alarm information generated by the network device; Acquire multiple alarm item groups, where the multiple alarm item groups are obtained by the network management platform through artificial intelligence learning of multiple historical alarm information, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information; Matching the multiple alarm information with the key alarm information in the multiple alarm item groups, and determining matching target alarm information from the multiple alarm information; The target alarm information is sent to the network management platform.

2. The method according to claim 1, wherein the matching the plurality of alarm information with the key alarm information in the plurality of alarm item groups and determining the matching target alarm information from the plurality of alarm information comprises: For each first warning information in the plurality of warning information, perform the following operations: Determine characteristic information of the first alarm information and characteristic information of key alarm information in each alarm entry group, wherein the characteristic information includes at least one of an alarm type, an alarm keyword, and an alarm code; According to the characteristic information, matching the first alarm information with key alarm information in each alarm entry group; In a case where there is critical warning information matching the first warning information, the first warning information is determined as the target warning information.

3. The method according to claim 1, wherein each alarm entry group further includes derived alarm information and / or irrelevant alarm information; After determining the target warning information, the method further includes: Determining non-target warning information from the plurality of warning information according to the derived warning information and / or the irrelevant warning information; The non-target alarm information is stored in the network device for query by the network management platform.

4. The method according to claim 3, wherein determining non-target warning information from the plurality of warning information according to the derived warning information and / or the irrelevant warning information comprises: Determine a first alarm entry group where key alarm information matching the target alarm information is located; For each second warning information in the plurality of warning information except the target warning information, perform the following operations: Matching the second alarm information with the derived alarm information and / or irrelevant alarm information in the first alarm entry group; If the match is successful, the second warning information is determined as non-target warning information.

5. The method according to claim 1, for each alarm information, when the alarm information does not match any of the plurality of alarm item groups, the method further comprises: Sending the alarm information to the network management platform; A second alarm item group is received, where the second alarm item group is obtained by the network management platform after performing artificial intelligence learning on the alarm information.

6. The method according to claim 1, wherein the plurality of alarm item groups are dynamically updated by the network management platform; the method further comprising: Receive the alarm item group updated by the network management platform.

7. A method for processing alarm information, applied to a network management platform, comprising: Perform artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information; sending the plurality of alarm item groups to a network device; Receive target alarm information sent by the network device, where the target alarm information is generated by the network device and, after matching the multiple alarm information with key alarm information in the multiple alarm item groups, the network device determines matching alarm information from the multiple alarm information.

8. The method according to claim 7, wherein the performing artificial intelligence learning on a plurality of historical alarm information to obtain a plurality of alarm item groups comprises: Determine multiple fault types corresponding to the multiple historical alarm information; According to the multiple fault types, the multiple historical alarm information is divided into multiple alarm information groups, each alarm information group corresponds to a type of fault; For each alarm information group, perform the following operations: According to the importance index of the alarm information, each historical alarm information in the alarm information group is scored by artificial intelligence to obtain an importance score, wherein the importance index includes at least one of the type, the weight, and the degree of impact on the business; Determining key warning information from the warning information group according to the importance score; An alarm entry group corresponding to the alarm information group is generated according to the key alarm information in the alarm information group.

9. The method according to claim 8, after obtaining the importance score, further comprising: Determining derived warning information and / or irrelevant warning information from the warning information group according to the importance score; The step of generating an alarm entry group corresponding to the alarm information group according to the key alarm information in the alarm information group includes: An alarm entry group corresponding to the alarm information group is generated according to the derived alarm information and / or irrelevant alarm information in the alarm information group and the key alarm information in the alarm information group.

10. The method according to claim 7, after receiving the target alarm information sent by the network device, the method further comprises: receiving a query request for warning information, the query request being used to request a query for non-target warning information corresponding to the target warning information; Sending the query request to the network device; The query result sent by the network device is received, where the query result is obtained by the network device after querying the non-target alarm information stored locally according to the query request.

11. The method of claim 7, further comprising: receiving alarm information, wherein the alarm information is sent by the network device when it is determined that the alarm information does not match any of the plurality of alarm entry groups; Performing artificial intelligence learning on the alarm information to obtain a second alarm item group; The second alarm entry group is sent to the network device.

12. The method according to any one of claims 7 to 9, after obtaining the plurality of alarm item groups, the method further comprises: Dynamically updating the multiple alarm entry groups; Sending the updated alarm entry group to the network device; For each alarm entry group, dynamically updating the alarm entry group includes at least one of the following: Receiving an update instruction for the alarm entry group; updating at least one of the key alarm information, the derived alarm information, and the irrelevant alarm information in the alarm entry group according to the update instruction; Determine the alarm frequency and / or the degree of impact on the business of the alarm information in the alarm entry group; update the importance of the alarm information in the alarm entry group according to the alarm frequency and / or the degree of impact on the business; update at least one of the key alarm information, derived alarm information and irrelevant alarm information in the alarm entry group according to the updated importance.

13. An electronic device, comprising: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the method according to any one of claims 1 to 12.

14. A computer-readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method according to any one of claims 1 to 12.

15. A system for processing alarm information, comprising network equipment and a network management platform, wherein: The network management platform performs artificial intelligence learning on multiple historical alarm information to obtain multiple alarm item groups, each alarm item group corresponds to a type of fault, and each alarm item group includes key alarm information; The network management platform sends the multiple alarm item groups to the network device; The network device acquires a plurality of alarm information generated by the network device; The network device matches the multiple alarm information with the key alarm information in the multiple alarm item groups, and determines matching target alarm information from the multiple alarm information; The network device sends the target alarm information to the network management platform; The network management platform receives the target alarm information sent by the network device.