Alarm root cause analysis method, device, equipment and medium
By using the preset classification model and the alarm hierarchical classification library to analyze the alarm data in the absence of CMDB information, the root cause analysis problem of alarm root cause is solved, and effective fault propagation relationship and the provision of alarm root cause results are achieved.
Patent Information
- Application Number
- CN202510122670.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-23
AI Technical Summary
Without CMDB information, it is difficult to realize the root cause analysis of the alarm, and it is impossible to effectively determine the fault propagation relationship and the root cause results of the alarm.
By obtaining the target alarm data of the target business system, the target alarm tag of the target alarm data is determined using the preset classification model, and the root cause analysis of the alarm data in each fault scenario is performed based on the preset alarm hierarchical classification library.
In the absence of CMDB information, the root cause analysis of alarms can be effectively carried out, and possible fault propagation relationships and root cause results can be provided, and the operation and maintenance personnel can quickly locate and resolve problems.
Smart Images

Figure CN120029806A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to an alarm root cause analysis method, device, equipment and medium. Background Art
[0002] In monitoring and management systems, alarm data is often used to indicate abnormal situations or potential problems. When a fault occurs, the root cause can be determined by analyzing the alarm data. Usually, root cause analysis relies heavily on CMDB (Configuration Management Database) relationships, that is, the dependencies between configuration items. However, it is currently difficult to perform alarm root cause analysis without CMDB information. Summary of the invention
[0003] The present invention provides an alarm root cause analysis method, device, equipment and medium, which can perform root cause analysis on the alarm data of each fault scenario based on alarm tags in the absence of CMDB information, so as to provide possible fault propagation relationships and alarm root cause results for the fault scenario.
[0004] According to one aspect of the present invention, a method for analyzing an alarm root cause is provided, the method comprising:
[0005] Obtain target alarm data of a target business system, and determine a target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification label information, and root cause sorting results of the alarm hierarchical information and alarm classification label information;
[0006] Determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data;
[0007] A root cause analysis is performed on the target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm label.
[0008] According to another aspect of the present invention, there is provided an alarm root cause analysis device, the device comprising:
[0009] A target alarm label determination module is used to obtain target alarm data of a target business system, and determine the target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification label information, and root cause sorting results of the alarm hierarchical information and alarm classification label information;
[0010] A target fault scenario determination module, configured to determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data;
[0011] The target alarm data root cause analysis module is used to perform root cause analysis on the target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm label.
[0012] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0013] at least one processor; and,
[0014] a memory communicatively connected to the at least one processor; wherein,
[0015] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the alarm root cause analysis method described in any embodiment of the present invention.
[0016] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the alarm root cause analysis method described in any embodiment of the present invention when executed.
[0017] The technical solution of the embodiment of the present invention obtains the target alarm data of the target business system, and determines the target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe the alarm hierarchical information, alarm classification label information, and the root cause ranking results of the alarm hierarchical information and the alarm classification label information; one or more target fault scenarios are determined according to the generation time of the target alarm data and the target business system corresponding to the target alarm data; and the target alarm data in each target fault scenario is subjected to root cause analysis based on the preset alarm hierarchical classification library and the target alarm label. This technical solution can perform root cause analysis on the alarm data of each fault scenario based on the alarm label in the absence of CMDB information, so as to provide possible fault propagation relationships and alarm root cause results for the fault scenario.
[0018] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0020] Figure 1 is a flow chart of an alarm root cause analysis method provided according to Embodiment 1 of the present invention;
[0021] Figure 2 is a schematic diagram of an alarm root cause analysis result provided according to Embodiment 1 of the present invention;
[0022] Figure 3 is a flow chart of an alarm root cause analysis method provided according to Embodiment 2 of the present invention;
[0023] Figure 4 is a schematic diagram of an alarm root cause analysis method provided according to Embodiment 2 of the present invention;
[0024] Figure 5 is a structural diagram of an alarm root cause analysis device provided according to Embodiment 3 of the present invention;
[0025] Figure 6 The present invention is a schematic diagram of the structure of an electronic device for implementing an alarm root cause analysis method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0026] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first", "second", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0028] Embodiment 1
[0029] Figure 1 This is a flowchart of an alarm root cause analysis method provided in the first embodiment of the present invention. This embodiment is applicable to the case where the root cause analysis of alarm data is performed without CMDB information. The method can be executed by an alarm root cause analysis device, which can be implemented in the form of hardware and / or software. The alarm root cause analysis device can be configured in an electronic device with data processing capabilities. Figure 1 As shown, the method includes:
[0030] S110, acquiring target alarm data of a target business system, and determining a target alarm label of the target alarm data through a preset classification model.
[0031] Among them, the target business system can be used to characterize the source of the target alarm data, which can be one or more business systems. Exemplarily, the target business system may include an image content management system, a core business system, and a payment system, etc., which need to be determined according to actual conditions. Alarm data may refer to data used to prompt abnormal conditions or potential problems in a monitoring and management system. The target alarm data may refer to real-time alarm data from the target business system, which may be one or more alarm data. The preset classification model may refer to a pre-set machine learning model that can realize the function of labeling alarm data, which is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library.
[0032] Among them, the preset alarm hierarchical classification library can refer to a pre-established database for describing alarm hierarchical information, alarm classification label information, and the root cause sorting results of alarm hierarchical information and alarm classification label information. Among them, the alarm hierarchical information can be used to characterize the layer to which the alarm information belongs (such as transaction layer, database layer, hardware device layer, network layer, computer room, etc.), and the alarm classification label information can be used to characterize the classification label corresponding to the alarm information (such as reduced transaction volume, high CPU usage, device hard disk failure, high network transmission delay, abnormal computer room air conditioning, etc.). Among them, the relationship between layers and classification labels is one-to-many, and each alarm data can be marked with appropriate classification labels and layers.
[0033] In this embodiment, it is necessary to establish an alarm hierarchical classification library (i.e., a preset alarm hierarchical classification library) in advance based on historical alarm data. The operation and maintenance experts are required to participate in this process. Based on the operation and maintenance experience of key fault labels and hierarchical classification in the financial industry, a set of generally applicable preset alarm hierarchical classification libraries is summarized, and the alarm hierarchical information and the alarm classification label information corresponding to each alarm hierarchical information are sorted by root cause possibility (from large to small or from small to large) to obtain the corresponding root cause sorting results. In addition, the preset alarm hierarchical classification library can be continuously updated and optimized according to the alarm data encountered later.
[0034] In this embodiment, optionally, the training process of the preset classification model includes: obtaining historical alarm data of the candidate business system, performing data cleaning and clustering processing on the historical alarm data to obtain historical alarm templates; determining a historical alarm data from each historical alarm template as reference alarm data, and using a large language model to determine alarm classification label information matching the reference alarm data from a preset alarm hierarchical classification library as a reference alarm label; determining the reference alarm label as the alarm label of all historical alarm data in the historical alarm template where the reference alarm data is located; using the historical alarm data carrying the alarm label as training sample data, and training the basic classification model according to the training sample data to obtain a preset classification model.
[0035] Specifically, when training the preset classification model, first obtain multiple historical alarm data from the candidate business system, and perform data cleaning and clustering processing on the historical alarm data to obtain the corresponding historical alarm template. Among them, data cleaning may include deduplication of alarm data content and deletion of empty content. Clustering processing is the process of structuring alarm data, and the variable position in the log can be replaced with <*>. Exemplarily, when the alarm data content is that the CPU usage rate is higher than 80%, the alarm template obtained is that the CPU usage rate is higher than <*>; when the alarm data content is that the CPU idle rate is lower than 5%, the alarm template obtained is that the CPU idle rate is lower than <*>. Assuming that there are 1 million historical alarm data, the amount of historical alarm data can be greatly compressed through clustering processing. For example, 1,000 historical alarm templates may be obtained, and each historical alarm template corresponds to one or more historical alarm data. After obtaining the historical alarm template, a historical alarm data can be randomly determined from each historical alarm template as the reference alarm data, and a prompt word can be set for the large language model, so that the large language model can select the alarm classification label information that is most suitable (i.e., matching) for the reference alarm data from the preset alarm hierarchical classification library as the reference alarm label. Then, the reference alarm label is mapped to all historical alarm data corresponding to the historical alarm template through the historical alarm template, that is, the alarm labels of all historical alarm data in the historical alarm template where the reference alarm data is located are set as the reference alarm label. Exemplarily, assuming that the reference alarm data selected in the historical alarm template 1 is labeled with [CPU usage is too high], then all historical alarm data corresponding to the historical alarm template 1 will be labeled with [CPU usage is too high]. Then, the historical alarm data carrying the alarm label is used as the training sample data to fine-tune the basic classification model (such as the Bert model), freeze the first 6 layers of parameters of the Bert model, train and fine-tune the parameters of the last 6 layers, and add a fully connected layer for label classification, and finally obtain the preset classification model.
[0036] This solution adopts such a setting, which can use a large language model to label historical alarm data based on a preset alarm hierarchical classification library and historical alarm templates, thereby improving the accuracy and efficiency of labeling.
[0037] In this embodiment, after the target alarm data of the target business system is acquired, the target alarm data may be input into a preset classification model in batches, and the target alarm labels corresponding to the target alarm data may be obtained according to the output results of the preset classification model.
[0038] S120: Determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data.
[0039] In this embodiment, for the target alarm data generated in real time by the target business system, a target fault scenario can be generated by setting a time window, so that the root cause analysis of the alarm data can be performed based on the fault scenario later. It should be noted that all the alarm data generated when a fault occurs in a business system constitute a fault scenario, which can be specifically manifested as the alarms that occur continuously in a business system within a period of time constitute a fault scenario. Optionally, one or more target fault scenarios are determined according to the generation time of the target alarm data and the target business system corresponding to the target alarm data, including: taking the generation time of the initial target alarm data as the scenario start time, determining the scenario end time according to the scenario start time and the preset fixed time window; determining the target time period according to the scenario start time and the scenario end time; if the generation time interval of adjacent target alarm data in the target time period is within the preset sliding time window, and the target business system corresponding to each target alarm data is the same, then each target alarm data in the target time period is determined as a target fault scenario.
[0040] Among them, the initial target alarm data may refer to the first target alarm data generated in each target fault scenario. The preset fixed time window may refer to a time window pre-set according to actual application requirements, which can be used to limit the time interval between the first alarm data and other alarm data in a fault scenario, that is, the time interval between the first alarm data and other alarm data in a fault scenario shall not exceed the preset fixed time window. The scene start time and the scene end time may refer to the start time and end time of the fault scenario, respectively. The target time period may refer to the time period between the scene start time and the scene end time. The preset sliding time window may refer to another time window pre-set according to actual application requirements, which can be used to limit the time interval between adjacent alarm data in a fault scenario, that is, the time interval between adjacent alarm data in a fault scenario shall not exceed the preset sliding time window.
[0041] Specifically, firstly, the first target alarm data generated is used as the initial target alarm data, and the corresponding generation time is used as the scenario start time of the first target fault scenario. Then the scenario start time is added to the time length corresponding to the preset fixed time window to obtain the scenario end time of the first target fault scenario. The time period between the scenario start time and the scenario end time is used as the first target time period. If the generation time interval of adjacent target alarm data in the first target time period is within the preset sliding time window, and each target alarm data comes from the same target business system, then each target alarm data in the first target time period can be divided into the first target fault scenario; otherwise, the next target fault scenario is started, and the first target alarm data generated in the next target fault scenario is used as the initial target alarm data, and the above process is repeated, thereby obtaining one or more target fault scenarios.
[0042] S130, performing root cause analysis on target alarm data in each target fault scenario based on a preset alarm hierarchical classification library and target alarm tags.
[0043] In this embodiment, after determining the target alarm label and the target fault scenario, the target alarm data in each target fault scenario can be subjected to root cause analysis based on the fault scenario, the preset alarm hierarchical classification library and the target alarm label. Exemplarily, the alarm root cause analysis can be performed by first stratifying and then classifying, thereby improving the efficiency of the alarm root cause analysis. Optionally, the target alarm data in each target fault scenario is subjected to root cause analysis based on the preset alarm hierarchical classification library and the target alarm label, including: based on the root cause sorting result of the alarm hierarchical information in the preset alarm hierarchical classification library, the target alarm hierarchical of the target alarm data in each target fault scenario is subjected to root cause sorting to obtain a first sorting result; wherein the target alarm hierarchical is the alarm hierarchical information corresponding to the target alarm label in the target fault scenario in the preset alarm hierarchical classification library; based on the root cause sorting result of the alarm classification label information in the preset alarm hierarchical classification library, the target alarm labels under each target alarm hierarchical in each target fault scenario are subjected to root cause sorting to obtain a second sorting result; and the target alarm data in each target fault scenario is subjected to root cause analysis according to the first sorting result and the second sorting result.
[0044] Specifically, after determining the first sorting result and the second sorting result respectively according to the root cause sorting results of the alarm hierarchical information and the root cause sorting results of the alarm classification label information in the preset alarm hierarchical classification library, the first sorting result and the second sorting result can be integrated to obtain the final sorting result of all target alarm labels in each target fault scenario. The result shows the fault propagation relationship, and gives the fault phenomenon label and the recommended root cause label, so that the operation and maintenance personnel can quickly locate where the problem occurs and give priority to solving the root cause problem, and support querying the corresponding target alarm information, thereby realizing the root cause analysis of the target alarm data in each target fault scenario.
[0045] Figure 2 A schematic diagram of an alarm root cause analysis result provided in the first embodiment of the present invention. Among them, application, server performance, middleware and database represent different layers, and F5 member monitoring alarm, high CPU usage, application process offline, high database connection pool usage, high thread pool usage and too many database cursors open represent different classification tags. Figure 2 As shown in the figure, through the alarm root cause analysis, it is finally determined that too many database cursors are opened as the root cause.
[0046] The technical solution of the embodiment of the present invention obtains the target alarm data of the target business system, and determines the target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe the alarm hierarchical information, alarm classification label information, and the root cause ranking results of the alarm hierarchical information and the alarm classification label information; one or more target fault scenarios are determined according to the generation time of the target alarm data and the target business system corresponding to the target alarm data; and the target alarm data in each target fault scenario is subjected to root cause analysis based on the preset alarm hierarchical classification library and the target alarm label. This technical solution can perform root cause analysis on the alarm data of each fault scenario based on the alarm label in the absence of CMDB information, so as to provide possible fault propagation relationships and alarm root cause results for the fault scenario.
[0047] In this embodiment, optionally, after determining a historical alarm data from each historical alarm template as reference alarm data, it also includes: if the large language model cannot determine the alarm classification label information that matches the reference alarm data from the preset alarm hierarchical classification library, then determining the candidate alarm labels of the reference alarm data through the large language model; performing expert review on the candidate alarm labels of the reference alarm data to obtain a review result; if the review result is passed, the candidate alarm label is used as the reference alarm label; if the review result is failed, the alarm label determined by the expert is used as the reference alarm label.
[0048] It should be noted that, due to the limited alarm classification label information in the preset alarm hierarchical classification library, when using the large language model to determine the alarm classification label information that matches the reference alarm data from the preset alarm hierarchical classification library, there may be a situation where a suitable label cannot be matched. At this time, the large language model can automatically label the reference alarm data with a label as a candidate alarm label. In order to ensure the accuracy of the candidate alarm labels, the candidate alarm labels need to be reviewed by experts. If the review result is passed, it means that the candidate alarm label is accurate. At this time, the candidate alarm label can be directly used as a reference alarm label; if the review result is failed, it means that the candidate alarm label is inaccurate. At this time, experts are required to make corresponding modifications to the candidate alarm label and use the modified candidate alarm label (that is, the alarm label determined by the expert) as the reference alarm label.
[0049] Through such a setting, this solution can effectively handle the situation where the large language model cannot match the alarm classification label information, thereby ensuring the accuracy of the reference alarm label.
[0050] In this embodiment, optionally, after using the historical alarm data carrying the alarm label as the training sample data, it also includes: performing data enhancement processing on the training sample data to obtain the target sample data, and updating the training sample data based on the target sample data; wherein the data enhancement processing includes one or more of upsampling, downsampling, random deletion, random exchange and random noise; accordingly, training the basic classification model according to the training sample data to obtain the preset classification model, including: training the basic classification model according to the updated training sample data to obtain the preset classification model.
[0051] It should be noted that if the historical alarm data with alarm labels is directly used as the training sample data of the preset classification model, the label distribution may be uneven, and the sample imbalance will affect the effect of model training. Therefore, it is necessary to perform data enhancement processing on the training sample data to achieve data balance and make the training sample data have a certain degree of generalization. Among them, data enhancement processing includes data enhancement processing of alarm labels and data enhancement processing of historical alarm data.
[0052] Through such a setting, this solution can achieve data balance for the training sample data and improve the generalization of the training sample data by data enhancement processing, which helps to improve the accuracy and applicability of the preset classification model.
[0053] Embodiment 2
[0054] Figure 3 This is a flow chart of an alarm root cause analysis method provided in Embodiment 2 of the present invention. This embodiment is optimized based on the above embodiment.
[0055] As Figure 3 shown, the method of this embodiment specifically includes the following steps:
[0056] S210. Obtain the target alarm data of the target business system, and determine the target alarm label of the target alarm data through a preset classification model.
[0057] Among them, the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification label information, and the root cause sorting result of alarm hierarchical information and alarm classification label information.
[0058] S220. Use the generation time of the initial target alarm data as the start time of the scenario, and determine the end time of the scenario according to the start time of the scenario and a preset fixed time window.
[0059] S230. Determine the target time period according to the start time of the scenario and the end time of the scenario.
[0060] S240. If the generation time interval of adjacent target alarm data within the target time period is within a preset sliding time window and the target business systems corresponding to each target alarm data are the same, then determine each target alarm data within the target time period as a target fault scenario.
[0061] S250. Determine the total number of alarm labels according to the content of each target alarm label in the target fault scenario.
[0062] It should be noted that considering that the alarms generated when a fault occurs are not of a single type, in order to ensure the rationality and accuracy of the fault scenario, it is necessary to filter out fault scenarios with fewer hierarchical levels or fewer classification labels (here considered as false fault scenarios), and the remaining ones are real fault scenarios.
[0063] In this embodiment, first determine the total number of alarm labels according to the content of each target alarm label in the target fault scenario. Among them, target alarm labels with the same content are recorded as 1, and different target alarm labels are counted according to the label quantity.
[0064] S260. Determine the alarm hierarchical information corresponding to each target alarm label in the target fault scenario from the preset alarm hierarchical classification library as the target alarm hierarchy, and determine the total number of alarm hierarchies according to the content of the target alarm hierarchy.
[0065] In this embodiment, find the alarm hierarchical information corresponding to each target alarm label in the target fault scenario from the preset alarm hierarchical classification library as the target alarm hierarchy, and determine the total number of alarm hierarchies according to the content of the target alarm hierarchy. Among them, target alarm hierarchies with the same content are recorded as 1, and different target alarm hierarchies are counted according to the hierarchical quantity.
[0066] S270: If the total number of alarm tags is less than a first preset number or the total number of alarm layers is less than a second preset number, the target fault scenario is determined to be a false fault scenario.
[0067] In this embodiment, if it is determined that the total number of alarm tags is less than the first preset number or the total number of alarm layers is less than the second preset number, the corresponding target fault scenario can be determined as a false fault scenario for elimination. The first preset number and the second preset number can refer to the reference value of the total number of alarm tags and the reference value of the total number of alarm layers pre-set according to actual application requirements, respectively.
[0068] S280: Perform root cause analysis on target alarm data in each target fault scenario based on a preset alarm hierarchical classification library and target alarm tags.
[0069] Figure 4 The schematic diagram of an alarm root cause analysis method provided in the second embodiment of the present invention specifically includes two parts: a real-time process and an offline process. Figure 4 As shown, a set of alarm hierarchical classification libraries (i.e., preset alarm hierarchical classification libraries) is maintained in advance by operation and maintenance experts, and the alarm hierarchical information and alarm classification label information in the alarm hierarchical classification library are sorted by root causes. In the offline process, a batch of historical alarm data is first obtained, and data cleaning and clustering processing are performed on them to obtain multiple historical alarm templates; then a historical alarm data is randomly selected from each historical alarm template as reference alarm data, and a large model (i.e., a large language model) is used to determine the alarm classification label information matching the reference alarm data from the alarm hierarchical classification library for labeling. At the same time, for situations where the match cannot be successfully made, the labels automatically given by the large language model need to be reviewed by experts, and manually modified if the review fails; then the alarm labels corresponding to the reference alarm data are mapped to all alarm data in the historical alarm template to which the reference alarm data belongs, and the labeled historical alarm data are subjected to data enhancement processing, and the data after data enhancement is used to train the Bert classification model to obtain the preset classification model. In the real-time process, first obtain the alarm data generated in real time (i.e., target alarm data), and label the target alarm data through the preset classification model (i.e., the classification model in the figure); then determine the target fault scenario by setting a fixed window (i.e., the preset fixed time window) and a sliding window (i.e., the preset sliding time window), and filter out the false fault scenarios to obtain the real fault scenarios; then, based on the root cause sorting results in the alarm hierarchical classification library, sort the alarm labels in each real fault scenario by root cause, thereby realizing the alarm root cause analysis of the fault scenario.
[0070] The technical solution of the embodiment of the present invention performs root cause analysis on the alarm data in each fault scenario based on alarm tags in the absence of CMDB information, so as to provide possible fault propagation relationships and alarm root cause results for the fault scenario; at the same time, considering the actual alarm situation when the fault occurs, the fault scenarios determined based on the time window are screened, and the false fault scenarios are excluded from them, thereby ensuring the accuracy and reasonableness of the fault scenario.
[0071] Embodiment III
[0072] Figure 5 FIG. is a schematic structural diagram of an alarm root cause analysis device provided in Embodiment III of the present invention. The device can execute the alarm root cause analysis method provided in any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method. As Figure 5 shown, the device includes:
[0073] A target alarm tag determination module 310, configured to obtain target alarm data of a target business system, and determine a target alarm tag of the target alarm data through a preset classification model; wherein, the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification tag information, and root cause sorting results of the alarm hierarchical information and alarm classification tag information;
[0074] A target fault scenario determination module 320, configured to determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data;
[0075] A target alarm data root cause analysis module 330, configured to perform root cause analysis on the target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm tag.
[0076] Optionally, the device further includes: a model training module, configured to:
[0077] Obtain historical alarm data of a candidate business system, and perform data cleaning and clustering processing on the historical alarm data to obtain a historical alarm template;
[0078] Determine a piece of historical alarm data from each historical alarm template as reference alarm data, and use a large language model to determine alarm classification tag information matching the reference alarm data from the preset alarm hierarchical classification library as a reference alarm tag;
[0079] Determine the reference alarm tag as the alarm tag of all historical alarm data in the historical alarm template where the reference alarm data is located;
[0080] The historical alarm data carrying the alarm label is used as the training sample data, and the basic classification model is trained according to the training sample data to obtain the preset classification model.
[0081] Optionally, the model training module is further used to:
[0082] After using the historical alarm data carrying the alarm label as training sample data, performing data enhancement processing on the training sample data to obtain target sample data, and updating the training sample data based on the target sample data;
[0083] The data enhancement processing includes one or more of upsampling, downsampling, random deletion, random exchange and random noise;
[0084] Accordingly, the model training module is also used for:
[0085] The basic classification model is trained according to the updated training sample data to obtain a preset classification model.
[0086] Optionally, the model training module is further used to:
[0087] After determining a historical alarm data as reference alarm data from each of the historical alarm templates, if the large language model cannot be used to determine the alarm classification label information matching the reference alarm data from the preset alarm hierarchical classification library, then determining the candidate alarm labels of the reference alarm data by using the large language model;
[0088] Performing expert review on the candidate alarm labels of the reference alarm data to obtain a review result;
[0089] If the audit result is passed, the candidate alarm label is used as a reference alarm label;
[0090] If the audit result is failure, the warning label determined by the expert will be used as a reference warning label.
[0091] Optionally, the target fault scenario determination module 320 is used to:
[0092] The generation time of the initial target alarm data is used as the scene start time, and the scene end time is determined according to the scene start time and the preset fixed time window;
[0093] Determine the target time period according to the scene start time and the scene end time;
[0094] If the time interval between adjacent target alarm data within the target time period is within a preset sliding time window, and the target business system corresponding to each target alarm data is the same, each target alarm data within the target time period is determined as a target fault scenario.
[0095] Optionally, the target fault scenario determination module 320 is further configured to:
[0096] After determining each target alarm data within the target time period as a target fault scenario, determining the total number of alarm tags according to the content of each target alarm tag in the target fault scenario;
[0097] Determine the alarm layer information corresponding to each target alarm label in the target fault scenario from the preset alarm layer classification library as the target alarm layer, and determine the total number of alarm layers according to the content of the target alarm layer;
[0098] If the total number of alarm tags is less than a first preset number or the total number of alarm layers is less than a second preset number, the target fault scenario is determined to be a false fault scenario.
[0099] Optionally, the target alarm data root cause analysis module 330 is used to:
[0100] Based on the root cause sorting result of the alarm layer information in the preset alarm layer classification library, the target alarm layer of the target alarm data in each target fault scenario is sorted by root cause to obtain a first sorting result; wherein the target alarm layer is the alarm layer information corresponding to the target alarm label in the target fault scenario in the preset alarm layer classification library;
[0101] Based on the root cause sorting result of the alarm classification label information in the preset alarm hierarchical classification library, the target alarm labels under each target alarm layer in each target fault scenario are sorted by root cause to obtain a second sorting result;
[0102] A root cause analysis is performed on the target alarm data in each of the target fault scenarios according to the first sorting result and the second sorting result.
[0103] An alarm root cause analysis device provided in an embodiment of the present invention can execute an alarm root cause analysis method provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0104] Embodiment 4
[0105] Figure 6A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0106] like Figure 6 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0107] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0108] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the alarm root cause analysis method.
[0109] In some embodiments, the alarm root cause analysis method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the alarm root cause analysis method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the alarm root cause analysis method in any other appropriate manner (e.g., by means of firmware).
[0110] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0111] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0112] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0113] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0114] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0115] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0116] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0117] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for analyzing the root cause of an alarm, characterized in that: The method comprises: Obtain target alarm data of a target business system, and determine a target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification label information, and root cause sorting results of the alarm hierarchical information and alarm classification label information; Determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data; A root cause analysis is performed on the target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm label.
2. The method according to claim 1, characterized in that The training process of the preset classification model includes: Acquire historical alarm data of the candidate business system, and perform data cleaning and clustering processing on the historical alarm data to obtain a historical alarm template; Determine a historical alarm data from each of the historical alarm templates as reference alarm data, and use a large language model to determine alarm classification label information matching the reference alarm data from the preset alarm hierarchical classification library as a reference alarm label; Determine the reference alarm tag as the alarm tag of all historical alarm data in the historical alarm template where the reference alarm data is located; The historical alarm data carrying the alarm label is used as the training sample data, and the basic classification model is trained according to the training sample data to obtain the preset classification model.
3. The method according to claim 2, characterized in that After using the historical alarm data with alarm labels as training sample data, it also includes: Performing data enhancement processing on the training sample data to obtain target sample data, and updating the training sample data based on the target sample data; The data enhancement processing includes one or more of upsampling, downsampling, random deletion, random exchange and random noise; Accordingly, the basic classification model is trained according to the training sample data to obtain a preset classification model, including: The basic classification model is trained according to the updated training sample data to obtain a preset classification model.
4. The method according to claim 2 or 3, characterized in that: After determining a piece of historical alarm data from each of the historical alarm templates as reference alarm data, the method further includes: If the large language model cannot be used to determine the alarm classification label information matching the reference alarm data from the preset alarm hierarchical classification library, determining the candidate alarm labels of the reference alarm data by using the large language model; Performing expert review on the candidate alarm labels of the reference alarm data to obtain a review result; If the audit result is passed, the candidate alarm label is used as a reference alarm label; If the audit result is failure, the warning label determined by the expert will be used as a reference warning label.
5. The method according to claim 1, characterized in that Determining one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data includes: The generation time of the initial target alarm data is used as the scene start time, and the scene end time is determined according to the scene start time and the preset fixed time window; Determine the target time period according to the scene start time and the scene end time; If the time interval between adjacent target alarm data within the target time period is within a preset sliding time window, and the target business system corresponding to each target alarm data is the same, each target alarm data within the target time period is determined as a target fault scenario.
6. The method according to claim 5, characterized in that After determining each target alarm data within the target time period as a target fault scenario, the method further includes: Determine the total number of alarm tags according to the content of each target alarm tag in the target fault scenario; Determine the alarm layer information corresponding to each target alarm label in the target fault scenario from the preset alarm layer classification library as the target alarm layer, and determine the total number of alarm layers according to the content of the target alarm layer; If the total number of alarm tags is less than a first preset number or the total number of alarm layers is less than a second preset number, the target fault scenario is determined to be a false fault scenario.
7. The method according to claim 1, characterized in that Performing root cause analysis on target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm label includes: Based on the root cause sorting result of the alarm layer information in the preset alarm layer classification library, the target alarm layer of the target alarm data in each target fault scenario is sorted by root cause to obtain a first sorting result; wherein the target alarm layer is the alarm layer information corresponding to the target alarm label in the target fault scenario in the preset alarm layer classification library; Based on the root cause sorting result of the alarm classification label information in the preset alarm hierarchical classification library, the target alarm labels under each target alarm layer in each target fault scenario are sorted by root cause to obtain a second sorting result; A root cause analysis is performed on the target alarm data in each of the target fault scenarios according to the first sorting result and the second sorting result.
8. An alarm root cause analysis device, characterized in that: The device comprises: A target alarm label determination module is used to obtain target alarm data of a target business system, and determine the target alarm label of the target alarm data through a preset classification model; wherein the preset classification model is obtained through model training based on historical alarm data and a preset alarm hierarchical classification library, and the preset alarm hierarchical classification library is used to describe alarm hierarchical information, alarm classification label information, and root cause sorting results of the alarm hierarchical information and alarm classification label information; A target fault scenario determination module, configured to determine one or more target fault scenarios according to the generation time of the target alarm data and the target business system corresponding to the target alarm data; The target alarm data root cause analysis module is used to perform root cause analysis on the target alarm data in each target fault scenario based on the preset alarm hierarchical classification library and the target alarm label.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the alarm root cause analysis method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the alarm root cause analysis method according to any one of claims 1 to 7 when executed.
Citation Information
Cited By
Root cause alarm determination method and device, electronic equipment and readable storage medium
CN120750729A