Method and system for intelligently identifying abnormal items and distributing work orders based on real-time logs

By adopting a smart identification method based on real-time logs in complex application deployment environments, using machine learning models and intelligent matching algorithms to automatically identify exceptions and allocate work orders, the problems of low efficiency and poor accuracy of log exception handling in the existing technology are solved, and efficient and accurate log management and operation and maintenance automation are achieved.

CN120029849APending Publication Date: 2025-05-23SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510105569.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the complex application deployment environment, it is difficult to efficiently identify and handle abnormal items in the log, resulting in high operation and maintenance costs and low accuracy. The fixed rules and methods in the early stage are difficult to adapt to when business changes, which may generate a large number of false alarms or missed reports.

Method used

Using an intelligent identification method based on real-time logs, through the steps of log collection and preprocessing, feature extraction and standardization, intelligent log exception detection, intelligent work order intelligent allocation, work order processing and feedback, machine learning model and intelligent matching algorithm are used to automatically identify abnormal items and assign work orders.

Benefits of technology

It improves the efficiency, accuracy and automation level of log management, and can promptly detect and deal with potential problems and faults in large-scale distributed systems, reduce operation and maintenance costs, and improve operation and maintenance quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120029849A_ABST
    Figure CN120029849A_ABST
Patent Text Reader

Abstract

The invention discloses a method and system for intelligently identifying abnormal items and distributing work orders based on real-time logs, and belongs to the technical field of cloud platforms and tobacco industry business application management. The method comprises the steps of log collection and preprocessing, feature extraction and standardization, intelligent log anomaly detection, intelligent work order distribution and work order processing and feedback, real-time extraction of application service logs, and matching of an algorithm conforming to an actual scene through construction, training and testing of a machine learning model. The used machine learning model can be constructed based on unsupervised learning or supervised learning; and the abnormal items in the application logs are intelligently identified through the algorithm model monitoring indexes, an exception handling work order is automatically created according to the abnormal items and the person in charge, the corresponding person in charge is pushed for handling, and the exception handling condition is tracked and fed back. According to the method, the log management efficiency, accuracy and automation level can be improved, and particularly, potential problems and faults in a large-scale distributed system can be found and processed in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud platform and tobacco industry business application management, and in particular to a method and system for intelligently identifying abnormal items and allocating work orders based on real-time logs. Background Art

[0002] With the popularization of "cloud + middle platform + microservice" technology, the cloud platform provides high-performance and scalable container application management capabilities to manage the entire life cycle of applications. Operation and maintenance personnel can use log service tools to manually inspect the operation of applications. After problems are found during the inspection, work orders are created for processing. However, for the location of complex abnormal scenes, various rules need to be manually configured to capture abnormalities, and the corresponding difficulty is also increasing. At the same time, as the business continues to change dynamically, the rules and methods that have been fixed in the early stage are difficult to work under new businesses, and may generate a large number of false alarms or missed alarms. Not only is the operation and maintenance difficult and costly, but the accuracy is also low. Summary of the invention

[0003] The technical task of the present invention is to address the above shortcomings and provide a method and system for intelligently identifying abnormal items and assigning work orders based on real-time logs, which can improve the efficiency, accuracy and automation level of log management, especially the timely discovery and processing of potential problems and faults in large-scale distributed systems.

[0004] The technical solution adopted by the present invention to solve the technical problem is:

[0005] A method for intelligently identifying abnormal items and assigning work orders based on real-time logs. The implementation of this method includes log collection and preprocessing, feature extraction and normalization, intelligent log anomaly detection, intelligent work order allocation, and work order processing and feedback.

[0006] Extract application service logs in real time, and match algorithms that meet actual scenarios through the construction, training, and testing of machine learning models. The machine learning models used can be based on unsupervised learning or supervised learning. Intelligently identify abnormal items in application logs through algorithm model monitoring indicators, automatically create exception handling work orders based on abnormal items and responsible persons, push them to the corresponding responsible persons for processing, and track and feedback the exception handling status.

[0007] The basic condition for implementing this method is that the user already has tools for deploying the application system, and the application system logs have been output as required. This method establishes a log recognition algorithm model and continuously optimizes the algorithm through machine learning, so that users can automatically inspect the application system after simply configuring the task items, identify the risk points of the application system, and create processing work orders to eliminate abnormal items in the application system in a timely manner. The implementation method includes the use of key technologies such as microservice architecture, front-end and back-end separation, machine learning, and algorithm models.

[0008] Furthermore, the log collection and preprocessing,

[0009] Configure the log collection task of the application system to capture system logs, application logs, and network logs in real time; the collected log data includes timestamp, event type, source address, target address, operation results, etc.

[0010] Ensure comprehensive collection of system-generated logs through a distributed collection mechanism to avoid data loss;

[0011] Perform preliminary formatting on the collected log data to unify the data format, including removing useless information (such as timestamps, IP addresses, etc.), structuring data, including converting semi-structured or unstructured logs into structured formats, and formatting timestamps from different sources into a unified standard time format.

[0012] Furthermore, the feature extraction and normalization,

[0013] Establish an abnormal pattern knowledge base, which contains known abnormal patterns and corresponding features; the abnormal patterns can be determined based on historical failure data, industry experience, and in-depth understanding of system architecture; for example, a service frequently restarts in a short period of time, a large number of specific error codes, etc.;

[0014] Extract key information from log data in real time, including event type, error code and other data, standardize the collected key information according to the standard log output format, unify the data format, and facilitate subsequent abnormal problem identification.

[0015] Furthermore, the intelligent log anomaly detection inputs the preprocessed log data into a pre-built machine learning model to perform anomaly detection:

[0016] First, use unsupervised learning algorithms, such as clustering algorithms, to group log data and identify groups that deviate from normal patterns by more than a threshold. Then, combine supervised learning algorithms to train the labeled abnormal log data to further improve the accuracy of anomaly identification.

[0017] Based on the results of the abnormal pattern knowledge base and machine learning algorithms, abnormal items in the log data are judged in real time; when an anomaly is detected, detailed information related to the anomaly is extracted, including the severity of the anomaly, the scope of impact, etc., and an abnormality report is generated based on the real-time identification of abnormal items in the log data.

[0018] Furthermore, the work order is intelligently allocated.

[0019] Establish an operation and maintenance personnel information database, which contains information such as the skills, responsible system modules, workload, etc. of each operation and maintenance personnel. According to the type and severity of abnormal items identified in the log and the operation and maintenance personnel information database, use the intelligent matching algorithm to determine the assignment object of the work order to ensure that the work order can be assigned to the right person to handle, avoiding the problem of abnormal risk expansion due to allocation errors.

[0020] Furthermore, the work order is intelligently allocated.

[0021] Record the exception information in detail in the assigned work order, including the description of the exception, the time of discovery, the possible scope of impact, etc., so that the operation and maintenance personnel can quickly understand the situation and take effective measures;

[0022] If the exception is related to the database and there is a person who is responsible for database maintenance and has a low current workload, the work order will be assigned to that person. The work order should include the database instance name, database type, access address, username and password, error code, name of the database access system, and recommended repair methods.

[0023] Furthermore, the work order processing and feedback,

[0024] After receiving the pushed work order, the operation and maintenance personnel will handle the exception. After the maintenance personnel have processed the work order, they will collect their feedback on the accuracy of the work order information, the effect of abnormal identification, etc., and generate a work order tracking report in real time, including the processing results, processing time and other information.

[0025] Based on the feedback information, the abnormal pattern knowledge base, machine learning algorithm and work order allocation algorithm are optimized. For example, if a new abnormal pattern is not identified, it is added to the knowledge base and the machine learning model is retrained; if work orders are often assigned to inappropriate personnel, the weight of the work order allocation algorithm is adjusted to improve the accuracy of subsequent abnormality detection.

[0026] The present invention also claims a system for intelligently identifying abnormal items based on real-time logs and assigning work orders, including an access terminal, a server terminal and a platform support; the server terminal includes a workbench, a log management module, an algorithm management module, a work order management module and a knowledge base management module, wherein the log management module can realize log collection and preprocessing, feature extraction and normalization; the algorithm management module can realize intelligent log anomaly detection, the work order management module can realize work order processing and feedback; the knowledge base management module can be optimized according to feedback information;

[0027] The system specifically uses the above method to intelligently identify abnormal items based on real-time logs and assign work orders.

[0028] The present invention also claims protection for a device for intelligently identifying abnormal items and allocating work orders based on real-time logs, including: at least one memory and at least one processor;

[0029] The at least one memory is used for storing machine-readable programs;

[0030] The at least one processor is used for calling the machine-readable program to implement the above-mentioned method.

[0031] The present invention also claims protection for a computer-readable medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the above-mentioned method can be implemented.

[0032] Compared with the prior art, the method and system for intelligently identifying abnormal items and allocating work orders based on real-time logs of the present invention have the following beneficial effects:

[0033] For the complex application deployment environment within an enterprise, it can realize self-service inspection by simple configuration, identify abnormal items through intelligent algorithms, and create corresponding processing work orders according to personnel division of labor. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 is a flowchart of a method for intelligently identifying abnormal items and allocating work orders based on real-time logs provided by an embodiment of the present invention;

[0035] Figure 2 is a system architecture diagram of a method for intelligently identifying abnormal items and allocating work orders based on real-time logs provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] The present invention will be further described below in conjunction with specific embodiments.

[0037] The embodiment of the present invention provides a method for intelligently identifying abnormal items and allocating work orders based on real-time logs. The implementation of this method includes log collection and preprocessing, feature extraction and normalization, intelligent log anomaly detection, intelligent work order allocation, and work order processing and feedback.

[0038] Real-time extraction of application service logs, through the construction, training, and testing of machine learning models, matching algorithms that conform to the actual scenario. The machine learning models used can be constructed based on unsupervised learning or supervised learning; through the algorithm model monitoring metrics, intelligently identify abnormal items in the application logs, automatically create abnormal handling work orders according to the abnormal items and the person in charge, push them to the corresponding person in charge for processing, and track and feedback the abnormal handling situation.

[0039] In response to the problems of low efficiency and poor timeliness faced when manually inspecting system abnormalities and creating work orders, this method mainly uses a self-developed machine learning algorithm model to perform one-stop integration and inspection of streaming data such as indicators and logs, automatically identify abnormal items, and automatically assign work orders according to task roles, so as to reduce operation and maintenance costs and improve operation and maintenance quality. The algorithm model of this method automatically completes abnormality detection, business logic adaptation, and fine alarms for operation and maintenance personnel and customers, freeing customers and operation and maintenance personnel from the complex and cumbersome rule configuration of manual inspection configuration, while improving the abnormal repair rate and reducing the system abnormality rate.

[0040] The basic condition for implementing this method is that the user already has tools for deploying the application system, and the application system logs have been output as required. This method establishes a log recognition algorithm model and continuously optimizes the algorithm through machine learning, so that users can automatically inspect the application system after simply configuring the task items, identify the risk points of the application system, and create processing work orders to eliminate abnormal items in the application system in a timely manner. The implementation method includes the use of key technologies such as microservice architecture, front-end and back-end separation, machine learning, and algorithm models.

[0041] like Figure 1 As shown, the specific implementation of this method includes the following steps:

[0042] 1. Environmental preparation.

[0043] The implementation of this technical solution requires the user to standardize the business system log output format so that the machine learning algorithm can better identify the log data. At the same time, it is necessary to provide corresponding big data computing resources for normalizing and standardizing the log data, and to train the log recognition algorithm to improve the accuracy of identifying log anomalies.

[0044] 2. Log collection and formatting.

[0045] Configure the log collection task of the application system to capture system logs, application logs, and network logs in real time. The collected log data includes timestamp, event type, source address, target address, operation results, etc.

[0046] The distributed collection mechanism ensures that the logs generated by the system are fully collected to avoid data loss. The collected log data is initially formatted to unify the data format, including removing useless information (such as timestamps, IP addresses, etc.), structuring data (converting semi-structured or unstructured logs into structured formats, and formatting timestamps from different sources into a unified standard time format), etc.

[0047] 3. Feature extraction and normalization.

[0048] Establish an abnormal pattern knowledge base, which contains known abnormal patterns and corresponding features. The abnormal pattern can be determined based on historical failure data, industry experience, and in-depth understanding of system architecture. For example, a service frequently restarts in a short period of time, a large number of specific error codes, etc.

[0049] Extract key information from log data in real time, including event type, error code and other data, standardize the collected key information according to the standard log output format, unify the data format, and facilitate subsequent abnormal problem identification.

[0050] 4. Intelligent log anomaly detection.

[0051] The preprocessed log data is fed into a pre-built machine learning model for anomaly detection.

[0052] First, use unsupervised learning algorithms, such as clustering algorithms, to group log data and identify groups that deviate greatly from normal patterns. Then, combine supervised learning algorithms to train the already labeled abnormal log data to further improve the accuracy of anomaly identification.

[0053] Based on the results of the abnormal pattern knowledge base and machine learning algorithms, abnormal items in log data are judged in real time. When an abnormality is detected, detailed information related to the abnormality is extracted, such as the severity of the abnormality, the scope of impact, etc., and an abnormality report is generated based on the real-time identification of abnormal items in log data.

[0054] 5. Intelligent allocation of work orders.

[0055] Establish an operation and maintenance personnel information database, which contains information such as the skills, responsible system modules, workload, etc. of each operation and maintenance personnel. According to the type and severity of abnormal items identified in the log and the operation and maintenance personnel information database, use the intelligent matching algorithm to determine the assignment object of the work order to ensure that the work order can be assigned to the right person to handle, avoiding the problem of abnormal risk expansion due to allocation errors.

[0056] Record the exception information in detail in the assigned work order, including the description of the exception, the time of discovery, the possible scope of impact, etc., so that the operation and maintenance personnel can quickly understand the situation and take effective measures. For example: if it is a database-related exception, and there is a person who is responsible for database maintenance and has a low current workload, the work order will be assigned to that person. The work order should include the database instance name, database type, access address, username and password, error code, name of the database access system, and recommended repair methods.

[0057] 6. Work order processing and feedback.

[0058] After receiving the pushed work order, the operation and maintenance personnel will handle the exception. After the maintenance personnel have processed the work order, they will collect their feedback on aspects including the accuracy of the work order information and the effectiveness of the exception identification, and generate a work order tracking report in real time, including processing results, processing time and other information.

[0059] Based on the feedback information, the abnormal pattern knowledge base, machine learning algorithm and work order allocation algorithm are optimized. For example, if a new abnormal pattern is not identified, it is added to the knowledge base and the machine learning model is retrained; if work orders are often assigned to inappropriate personnel, the weight of the work order allocation algorithm is adjusted to improve the accuracy of subsequent abnormality detection.

[0060] The application cases of this method are as follows: A provincial tobacco business bureau has purchased a cloud platform and uses cloud components to manage the entire life cycle of application operations. In order to improve the stability of application operations and promptly discover and eliminate potential application abnormality risks, the information center configures application monitoring items and system managers. The built-in log recognition algorithm model will automatically complete anomaly detection, identify abnormal risk points, and create processing work orders based on different business systems. The work orders are pushed to the system managers in a timely manner, and the managers handle the abnormal items according to the work order content and provide feedback on the processing status.

[0061] The embodiment of the present invention also provides a system for intelligently identifying abnormal items and assigning work orders based on real-time logs, such as Figure 2 As shown, it includes access end, server end and platform support. Among them, the server end includes workbench, log management module, algorithm management module, work order management module and knowledge base management module. Among them, the log management module can realize log collection and preprocessing, feature extraction and normalization; the algorithm management module can realize intelligent log anomaly detection, the work order management module can realize work order processing and feedback; the knowledge base management module can optimize according to the feedback information.

[0062] The system specifically realizes intelligent identification of abnormal items and allocation of work orders through the method for intelligent identification of abnormal items based on real-time logs and allocation of work orders described in the above embodiments.

[0063] The log collection and preprocessing:

[0064] Configure the log collection task of the application system to capture system logs, application logs, and network logs in real time. The collected log data includes timestamp, event type, source address, target address, operation results, etc.

[0065] The distributed collection mechanism ensures that the logs generated by the system are fully collected to avoid data loss. The collected log data is initially formatted to unify the data format, including removing useless information (such as timestamps, IP addresses, etc.), structuring data (converting semi-structured or unstructured logs into structured formats, and formatting timestamps from different sources into a unified standard time format), etc.

[0066] Feature extraction and normalization:

[0067] Establish an abnormal pattern knowledge base, which contains known abnormal patterns and corresponding features. The abnormal pattern can be determined based on historical failure data, industry experience, and in-depth understanding of system architecture. For example, a service frequently restarts in a short period of time, a large number of specific error codes, etc.

[0068] Extract key information from log data in real time, including event type, error code and other data, standardize the collected key information according to the standard log output format, unify the data format, and facilitate subsequent abnormal problem identification.

[0069] The intelligent log anomaly detection:

[0070] The preprocessed log data is fed into a pre-built machine learning model for anomaly detection.

[0071] First, use unsupervised learning algorithms, such as clustering algorithms, to group log data and identify groups that deviate greatly from normal patterns. Then, combine supervised learning algorithms to train the already labeled abnormal log data to further improve the accuracy of anomaly identification.

[0072] Based on the results of the abnormal pattern knowledge base and machine learning algorithms, abnormal items in log data are judged in real time. When an abnormality is detected, detailed information related to the abnormality is extracted, such as the severity of the abnormality, the scope of impact, etc., and an abnormality report is generated based on the real-time identification of abnormal items in log data.

[0073] The work order intelligent allocation:

[0074] Establish an operation and maintenance personnel information database, which contains information such as the skills, responsible system modules, workload, etc. of each operation and maintenance personnel. According to the type and severity of abnormal items identified in the log and the operation and maintenance personnel information database, use the intelligent matching algorithm to determine the assignment object of the work order to ensure that the work order can be assigned to the right person to handle, avoiding the problem of abnormal risk expansion due to allocation errors.

[0075] Record the exception information in detail in the assigned work order, including the description of the exception, the time of discovery, the possible scope of impact, etc., so that the operation and maintenance personnel can quickly understand the situation and take effective measures. For example: if it is a database-related exception, and there is a person who is responsible for database maintenance and has a low current workload, the work order will be assigned to that person. The work order should include the database instance name, database type, access address, username and password, error code, name of the database access system, and recommended repair methods.

[0076] The work order processing and feedback:

[0077] After receiving the pushed work order, the operation and maintenance personnel will handle the exception. After the maintenance personnel have processed the work order, they will collect their feedback on aspects including the accuracy of the work order information and the effectiveness of the exception identification, and generate a work order tracking report in real time, including processing results, processing time and other information.

[0078] Based on the feedback information, the abnormal pattern knowledge base, machine learning algorithm and work order allocation algorithm are optimized.

[0079] For example: if a new abnormal pattern is not recognized, add it to the knowledge base and retrain the machine learning model; if work orders are often assigned to inappropriate personnel, adjust the weight of the work order assignment algorithm to improve the accuracy of subsequent anomaly detection.

[0080] An embodiment of the present invention also provides a device for intelligently identifying abnormal items and allocating work orders based on real-time logs, comprising: at least one memory and at least one processor;

[0081] The at least one memory is used to store a machine-readable program;

[0082] The at least one processor is used to call the machine-readable program to implement the method described in the above embodiment for intelligently identifying abnormal items based on real-time logs and allocating work orders.

[0083] The embodiment of the present invention also provides a computer-readable medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the processor executes the method for intelligently identifying abnormal items based on real-time logs and assigning work orders as described in the above embodiment. Specifically, a system or device equipped with a storage medium can be provided, on which software program codes that implement the functions of any of the above embodiments are stored, and a computer (or CPU or MPU) of the system or device reads and executes the program code stored in the storage medium.

[0084] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute a part of the present invention.

[0085] The storage medium embodiments for providing the program code include a floppy disk, a hard disk, a magneto-optical disk, an optical disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), a magnetic tape, a non-volatile memory card, and a ROM. Alternatively, the program code can be downloaded from a server computer by a communication network.

[0086] In addition, it should be clear that the functions of any of the above embodiments can be implemented not only by executing the program code read by the computer, but also by enabling an operating system operating on the computer to complete part or all of the actual operations based on instructions from the program code.

[0087] In addition, it can be understood that the program code read from the storage medium is written to a memory provided in an expansion board inserted into the computer or written to a memory provided in an expansion unit connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or the expansion unit is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above-mentioned embodiments.

[0088] The present invention is shown and described in detail above through the accompanying drawings and preferred embodiments. However, the present invention is not limited to these disclosed embodiments. Based on the above multiple embodiments, those skilled in the art can know that the code review methods in the above different embodiments can be combined to obtain more embodiments of the present invention, and these embodiments are also within the protection scope of the present invention.

Claims

1. A method for intelligently identifying abnormal items and assigning work orders based on real-time logs, characterized in that: The implementation of this method includes log collection and preprocessing, feature extraction and normalization, intelligent log anomaly detection, intelligent work order allocation, and work order processing and feedback. Extract application service logs in real time, and match algorithms that meet actual scenarios through the construction, training, and testing of machine learning models. The machine learning models used can be based on unsupervised learning or supervised learning. Intelligently identify abnormal items in application logs through algorithm model monitoring indicators, automatically create exception handling work orders based on abnormal items and responsible persons, push them to the corresponding responsible persons for processing, and track and feedback the exception handling status.

2. According to claim 1, a method for intelligently identifying abnormal items and assigning work orders based on real-time logs is characterized in that: The log collection and preprocessing, Configure the log collection task of the application system to capture system logs, application logs, and network logs in real time; the collected log data includes timestamp, event type, source address, target address, and operation results; Ensure comprehensive collection of system-generated logs through a distributed collection mechanism; Perform preliminary formatting on the collected log data to unify the data format, including removing useless information and structured data, including converting semi-structured or unstructured logs into structured formats, and formatting timestamps from different sources into a unified standard time format.

3. According to claim 1, a method for intelligently identifying abnormal items and assigning work orders based on real-time logs is characterized in that: The feature extraction and normalization, Establish an abnormal pattern knowledge base, which contains known abnormal patterns and corresponding features; the abnormal patterns can be determined based on historical failure data, industry experience and in-depth understanding of system architecture; Extract key information from log data in real time, including event type and error code data, and standardize the collected key information according to the standard log output format to unify the data format.

4. According to claim 1, a method for intelligently identifying abnormal items and assigning work orders based on real-time logs is characterized in that: The intelligent log anomaly detection inputs the preprocessed log data into a pre-built machine learning model to perform anomaly detection: First, an unsupervised learning algorithm is used to group the log data and identify the groups that deviate from the normal pattern by more than a threshold. Then, a supervised learning algorithm is combined to train the labeled abnormal log data to further improve the accuracy of anomaly identification. Based on the results of the abnormal pattern knowledge base and machine learning algorithms, abnormal items in the log data are judged in real time; when an anomaly is detected, detailed information related to the anomaly is extracted, including the severity of the anomaly and the scope of impact, and an abnormality report is generated based on the real-time identification of abnormal items in the log data.

5. The method for intelligently identifying abnormal items and assigning work orders based on real-time logs according to claim 1 is characterized in that: The work order is intelligently allocated, Establish an operation and maintenance personnel information database that contains each operation and maintenance personnel's skills, responsible system modules, and workload information. Based on the type and severity of abnormal items identified in the log and the operation and maintenance personnel information database, use an intelligent matching algorithm to determine the assignment object of the work order to ensure that the work order can be assigned to the right person for processing.

6. A method for intelligently identifying abnormal items and allocating work orders based on real-time logs according to claim 1 or 5, characterized in that: The work order is intelligently allocated, Record the exception information in detail in the assigned work order, including the description of the exception, the time of discovery, and the possible scope of impact, so that the operation and maintenance personnel can quickly understand the situation and take effective measures; If the exception is related to the database and there is a person who is responsible for database maintenance and has a low current workload, the work order will be assigned to that person. The work order should include the database instance name, database type, access address, username and password, error code, name of the database access system, and recommended repair methods.

7. The method for intelligently identifying abnormal items and assigning work orders based on real-time logs according to claim 1 is characterized in that: The work order processing and feedback, After receiving the pushed work order, the operation and maintenance personnel will handle the exception. After the maintenance personnel have processed the work order, they will collect their feedback on the accuracy of the work order information and the effect of exception identification, and generate a work order tracking report in real time, including the processing results and processing time information. Based on the feedback information, the abnormal pattern knowledge base, machine learning algorithm and work order allocation algorithm are optimized.

8. A system for intelligently identifying abnormal items and assigning work orders based on real-time logs, characterized in that: It includes access end, server end and platform support; the server end includes workbench, log management module, algorithm management module, work order management module and knowledge base management module. Among them, the log management module can realize log collection and preprocessing, feature extraction and normalization; the algorithm management module can realize intelligent log anomaly detection, the work order management module can realize work order processing and feedback; the knowledge base management module can optimize according to feedback information; The system specifically implements intelligent identification of abnormal items based on real-time logs and allocation of work orders through the method described in any one of claims 1 to 7.

9. A device for intelligently identifying abnormal items and assigning work orders based on real-time logs, characterized in that: include: at least one memory and at least one processor; The at least one memory is used to store a machine-readable program; The at least one processor is used to call the machine-readable program to implement the method described in any one of claims 1 to 7.

10. A computer-readable medium, characterized in that The computer readable medium stores computer instructions, which, when executed by a processor, can implement the method described in any one of claims 1 to 7.

Citation Information

Cited By

  • Logistics task intelligent distribution method and system oriented to multi-source demand

    CN120706815A

  • A multi-source demand-oriented logistics task intelligent allocation method and system

    CN120706815B