Service alarm processing method and device, electronic equipment and medium
Through the large language model, the link between the alarm system and the service change system is established, and the information processing problems under different naming systems are solved, and the alarm information of abnormal services is automatically processed, which improves efficiency and reduces costs.
Patent Information
- Application Number
- CN202510110167.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the alarm system and the service change system use different naming systems, which makes it a difficult problem to process the alarm information based on the information of the service change system when an alarm is received.
The large language model establishes an association based on alarm information and service change information, and uses the named mapping relationship to generate processing results to indicate whether the service changes occurred during the exception occurrence time.
It realizes the establishment of association between the alarm system and the change system, and automatically handles the alarm information of abnormal services, reducing manual intervention, improving processing efficiency and saving labor costs.
Smart Images

Figure CN120045424A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and more particularly to large language models and service management. Specifically, the present disclosure relates to a method, apparatus, electronic device, computer-readable storage medium, and computer program product for service alarm processing. Background Art
[0002] In related fields, alarm systems and service change systems often adopt different naming systems. Therefore, when receiving an alarm, how to process the alarm information based on the information of the service change system becomes a difficult problem.
[0003] The methods described in this section are not necessarily methods that have been previously conceived or adopted. Unless otherwise specified, no method described in this section should be considered prior art merely because it is included in this section. Similarly, unless otherwise specified, the problems mentioned in this section should not be considered to have been recognized in any prior art. Summary of the Invention
[0004] The present disclosure provides a method, apparatus, electronic device, computer-readable storage medium, and computer program product for service alarm processing.
[0005] According to one aspect of the present disclosure, there is provided a method for service alarm processing, including: obtaining alarm information for an abnormal service, the alarm information including a first name of the abnormal service mapped according to a first naming mapping and an abnormal occurrence time of the abnormal service, the first naming mapping being used to map a service set including the abnormal service to a first naming set including the first name; obtaining service change information, the service change information including corresponding names of at least one service in the service set mapped according to a second naming mapping and corresponding service change histories of the at least one service, the second naming mapping being used to map the service set to a second naming set different from the first naming set; and obtaining a processing result based on the alarm information and the service change information through a large language model, the processing result being capable of indicating whether a service change has occurred for the abnormal service at the abnormal occurrence time.
[0006] According to another aspect of the present disclosure, there is provided a service alarm processing device, including: an alarm obtaining unit configured to obtain alarm information for an abnormal service, where the alarm information includes a first name of the abnormal service mapped according to a first naming and an abnormal occurrence time of the abnormal service, and the first naming is used to map a service set including the abnormal service to a first naming set; a change obtaining unit configured to obtain service change information, where the service change information includes corresponding names of at least one service in the service set mapped according to a second naming and corresponding service change histories of the at least one service, and the second naming is used to map the service set to a second naming set different from the first naming set; and a processing obtaining unit configured to obtain a processing result based on the alarm information and the service change information through a large language model, and the processing result can indicate whether a service change occurs for the abnormal service at the abnormal occurrence time.
[0007] According to another aspect of the present disclosure, there is provided an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; where the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the service alarm processing method according to one or more embodiments of the present disclosure.
[0008] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause the computer to execute the service alarm processing method according to one or more embodiments of the present disclosure.
[0009] According to another aspect of the present disclosure, there is provided a computer program product, including a computer program, where the computer program, when executed by a processor, implements the service alarm processing method according to one or more embodiments of the present disclosure.
[0010] According to one or more embodiments of the present disclosure, it is possible to effectively assist in processing abnormalities.
[0011] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The drawings exemplarily show embodiments and constitute a part of the specification, and are used together with the textual description of the specification to explain the exemplary implementation manners of the embodiments. The shown embodiments are only for illustrative purposes and do not limit the scope of the claims. In all the drawings, the same reference numerals refer to similar but not necessarily identical elements.
[0013] Figure 1 A schematic diagram showing an exemplary system in which various methods described herein can be implemented according to an embodiment of the present disclosure;
[0014] Figure 2 A flowchart showing a service alarm processing method according to an embodiment of the present disclosure;
[0015] Figures 3A - 3E A schematic diagram showing a schematic scenario of a service alarm processing method according to an embodiment of the present disclosure;
[0016] Figure 4 A structural block diagram showing a service alarm processing device according to an embodiment of the present disclosure;
[0017] Figure 5 A structural block diagram showing an exemplary electronic device capable of implementing an embodiment of the present disclosure. Detailed implementation manners
[0018] The following describes exemplary embodiments of the present disclosure in conjunction with the accompanying drawings. Various details of the embodiments of the present disclosure are included to assist in understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0019] In the present disclosure, unless otherwise specified, the terms "first", "second", etc. are used to describe various elements and are not intended to limit the positional relationship, timing relationship, or importance relationship of these elements. Such terms are only used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of the element, and in certain cases, based on the context description, they may also refer to different instances.
[0020] In the description of various examples in the present disclosure, the terms used are only for the purpose of describing specific examples and are not intended to be limiting. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element may be one or more. In addition, the term "and / or" used in the present disclosure covers any one of the listed items and all possible combinations.
[0021] Embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings.
[0022] Figure 1 A schematic diagram showing an exemplary system 100 in which various methods and devices described herein can be implemented according to an embodiment of the present disclosure. Refer toFigure 1 , the system 100 includes one or more client devices 101, 102, 103, 104, 105, and 106, a server 120, and one or more communication networks 110 that couple the one or more client devices to the server 120. The client devices 101, 102, 103, 104, 105, and 106 can be configured to execute one or more applications.
[0023] In an embodiment of the present disclosure, the server 120 can run one or more services or software applications that enable the execution of the service alarm processing method according to the present disclosure.
[0024] In certain embodiments, the server 120 can also provide other services or software applications, which can include non-virtual environments and virtual environments. In certain embodiments, these services can be provided as web-based services or cloud services, for example, provided to users of the client devices 101, 102, 103, 104, 105, and / or 106 under a software as a service (SaaS) model.
[0025] In Figure 1 the configuration shown, the server 120 can include one or more components that implement the functions performed by the server 120. These components can include software components, hardware components, or a combination thereof that can be executed by one or more processors. Users operating the client devices 101, 102, 103, 104, 105, and / or 106 can in turn utilize one or more client applications to interact with the server 120 to utilize the services provided by these components. It should be understood that various different system configurations are possible, which can be different from the system 100. Therefore, Figure 1 is an example of a system for implementing the various methods described herein and is not intended to be limiting.
[0026] Users can use the client devices 101, 102, 103, 104, 105, and / or 106 to receive, view, process service alarms, etc. The client device can provide an interface that enables the user of the client device to interact with the client device. The client device can also output information to the user via this interface. Although Figure 1 only six client devices are depicted, those skilled in the art will be able to understand that the present disclosure can support any number of client devices.
[0027] Client devices 101, 102, 103, 104, 105, and / or 106 can include various types of computing devices, such as portable handheld devices, general-purpose computers (such as personal computers and laptop computers), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors, or other sensing devices, etc. These computing devices can run various types and versions of software applications and operating systems, such as MICROSOFT Windows, APPLE iOS, UNIX-like operating systems, Linux, or Linux-like operating systems (such as GOOGLE Chrome OS); or include various mobile operating systems, such as MICROSOFT WindowsMobile OS, iOS, Windows Phone, Android. Portable handheld devices can include cellular phones, smartphones, tablets, personal digital assistants (PDAs), etc. Wearable devices can include head-mounted displays (such as smart glasses) and other devices. Gaming systems can include various handheld gaming devices, Internet-enabled gaming devices, etc. Client devices are capable of executing various different applications, such as various Internet-related applications, communication applications (such as email applications), short message service (SMS) applications, and can use various communication protocols.
[0028] Network 110 can be any type of network known to those skilled in the art, which can support data communication using any of a variety of available protocols (including but not limited to TCP / IP, SNA, IPX, etc.). By way of example only, one or more networks 110 can be a local area network (LAN), an Ethernet-based network, token ring, wide area network (WAN), the Internet, a virtual network, a virtual private network (VPN), an intranet, an extranet, a blockchain network, a public switched telephone network (PSTN), an infrared network, a wireless network (such as Bluetooth, WIFI), and / or any combination of these and / or other networks.
[0029] Server 120 can include one or more general-purpose computers, dedicated server computers (such as PC (personal computer) servers, UNIX servers, midrange servers), blade servers, mainframes, server clusters, or any other suitable arrangement and / or combination. Server 120 can include one or more virtual machines running a virtual operating system, or other computing architectures involving virtualization (such as one or more flexible pools of logical storage devices that can be virtualized to maintain virtual storage devices for the server). In various embodiments, server 120 can run one or more services or software applications that provide the functions described below.
[0030] The computing units in server 120 can run one or more operating systems including any of the above-mentioned operating systems and any commercially available server operating systems. Server 120 can also run any one of a variety of additional server applications and / or middleware applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, etc.
[0031] In some embodiments, server 120 can include one or more applications to analyze and merge data feeds and / or event updates received from users of client devices 101, 102, 103, 104, 105, and 106. Server 120 can also include one or more applications to display data feeds and / or real-time events via one or more display devices of client devices 101, 102, 103, 104, 105, and 106.
[0032] In some embodiments, server 120 can be a server of a distributed system, or a server incorporating a blockchain. Server 120 can also be a cloud server, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology. A cloud server is a host product in the cloud computing service system to address the defects of high management difficulty and weak business scalability existing in traditional physical hosts and virtual private server (VPS) services.
[0033] System 100 can also include one or more databases 130. In certain embodiments, these databases can be used to store data and other information. For example, one or more of databases 130 can be used to store information such as audio files and video files. Databases 130 can reside in various locations. For example, the databases used by server 120 can be local to server 120, or can be remote from server 120 and can communicate with server 120 via a network-based or dedicated connection. Databases 130 can be of different types. In certain embodiments, the databases used by server 120 can be relational databases, for example. One or more of these databases can store, update, and retrieve data to and from the databases in response to commands.
[0034] In certain embodiments, one or more of databases 130 can also be used by applications to store application data. The databases used by applications can be different types of databases, such as key-value repositories, object repositories, or conventional repositories supported by a file system. Figure 1 System 100 can be configured and operated in various ways to enable the application of the various methods and apparatuses described according to the present disclosure.
[0035] Reference is made below to Figure 2 describe a service alarm processing method 200 according to an exemplary embodiment of the present disclosure.
[0036] At step S201, alarm information for an abnormal service is obtained, the alarm information including a first name of the abnormal service mapped according to a first naming mapping and an abnormal occurrence time of the abnormal service, the first naming mapping being used to map a service set including the abnormal service to a first naming set including the first name.
[0037] At step S202, service change information is obtained, the service change information including corresponding names of at least one service in the service set mapped according to a second naming mapping and corresponding service change histories of the at least one service, the second naming mapping being used to map the service set to a second naming set different from the first naming set.
[0038] At step S203, a processing result is obtained by a large language model based on the alarm information and the service change information, the processing result being capable of indicating whether a service change has occurred for the abnormal service at the abnormal occurrence time.
[0039] The method according to an embodiment of the present disclosure can effectively assist in processing anomalies.
[0040] When receiving alarm information, it is necessary to view the corresponding change information for processing. In the prior art, alarm information and service change information often use different naming systems, and thus, it is necessary to manually associate between the two systems. According to an embodiment of the present disclosure, an association is established between the two naming systems by a large language model, so that effective processing can be performed.
[0041] Specifically, the alarm information is alarm information for an abnormal service generated by an alarm system based on a first naming mapping set, and the service change information is version iteration information generated based on a second naming mapping set, including a second name of the abnormal service mapped according to the second naming mapping and the version iteration history of the abnormal service. These two systems have different naming systems, but through an embodiment of the present disclosure, these two systems can be associated without having to manually change the naming system.
[0042] According to some embodiments, the obtaining of the processing result by the large language model based on the alarm information and the service change information may include: obtaining the processing result based on a naming mapping relationship, the naming mapping relationship including natural language describing the relationship between the first naming mapping and the second naming mapping.
[0043] According to such an example, the processing result can be obtained based on the relationship between the two naming mappings by utilizing the natural language understanding ability of the large language model.
[0044] According to some embodiments, the naming mapping relationship may include the corresponding relationship between the proper subset of the first naming set and the proper subset of the second naming set.
[0045] According to such an example, a part of the corresponding relationship between the namings can be provided to the large language model, making full use of the understanding ability of the large model to let the large language model deduce other corresponding relationships.
[0046] According to some embodiments, the obtaining of the processing result by the large language model based on the alarm information and the service change information may include obtaining the second name by the large language model based on the naming mapping relationship and the first name in the alarm information.
[0047] The name of the alarm information in the service change system, i.e., the second name, can be obtained, thus facilitating recording and personnel maintenance.
[0048] According to some embodiments, the processing result may include the second name and the machine room name of the service change information corresponding to the alarm information.
[0049] According to such an example, by using the large language model to output both the second name and the machine room name, the summarization and extraction ability of the large language model can be utilized to extract the associated information together, facilitating subsequent processing and reducing labor costs.
[0050] According to some embodiments, the service change information may be obtained from a service change event library, and the service change event library is a relational database maintained by a poller.
[0051] According to such an example, the relational database can be maintained by the poller, so that the change information can be queried, and it is no longer necessary to read the service log, which is more convenient for querying.
[0052] According to some embodiments, the poller can maintain the service change event library by periodically polling the change system to obtain the status of all service changes being executed currently.
[0053] By maintaining the service change event library through the polling system, it is possible to more conveniently obtain the service status information corresponding to the abnormal moment.
[0054] According to one or more embodiments of the present disclosure, in the case where the alarm system and the change system have different names for the same service, a naming mapping relationship table that is a subset of the entire service set is maintained and input to the agent, allowing the agent to deduce the naming relationship, thereby generating the service name, computer room name, and abnormal time for query in the change system. In addition, the change event library is maintained by polling, and an interface is provided through the retrieval tool so that the change event can be queried.
[0055] After a very long period of iteration of large-scale distributed systems and the contributions of multiple teams, the peripheral support systems of the business system are independently built and different standards are used during the construction process. For example, for Service A, the change system uses a naming system and calls this service A, while the abnormal alarm system calls this service a. This difference is relatively easy to understand for humans. However, when processing information output by different systems, it can only rely on human participation, which is relatively inefficient and consumes labor costs.
[0056] Figure 3A An exemplary application scenario in the related art is shown. In the complex business system developed in the above background, the service change system and the service abnormal alarm are independent, and different naming systems are used for the names of services. When the service abnormal alarm system discovers a service anomaly and issues an alarm (such as an anomaly occurs in Service a), it needs to be received by a human first. If the human knows the name of this service in the service change system, then use this name to search for suspicious changes. Otherwise, browse the change list of the relevant time in the service change system and visually search for whether there is a service similar to A. The entire process is relatively inefficient and consumes a lot of labor costs.
[0057] When the business system is very complex, the number of services is very large, and it is difficult for humans to fully understand the mapping of the two names. As a result, when an alarm occurs, searching for suspicious changes becomes even more inefficient. Since the alarm system and the change system are often maintained by different teams, the corresponding collaboration cost for transformation is very high. Even if they are maintained by the same team, changing the naming system will affect the current usage. The overall process not only has a low ROI, but also the transformation itself is an invasive task. Building a zero-invasive, automated, intelligent analysis system with the ability to generalize names has a very important role in improving the efficiency of anomaly handling and saving labor costs.
[0058] Figure 3B A timing diagram of service change is shown. Large-scale distributed systems are often distributed across multiple computer rooms, and in order to ensure safety in each computer room, the change is divided into multiple stages. Generally, it is divided into the canary stage and the all stage, which correspond to different instance sets in a computer room respectively. After each stage is completed, there will be a short pause to observe the service stability. Massive changes occur simultaneously for multiple services in large-scale distributed systems every day.
[0059] Figure 3C A schematic diagram of a system architecture according to one or more embodiments of the present disclosure is shown. By polling the change system, the status of all service changes currently being executed is periodically obtained and written into the change database. By constructing a knowledge base to map the mapping relationships of a small number of service names in the alarm system and the change system to achieve generalization capabilities. By building an agent, based on the knowledge base, it receives alarms from the alarm system, and based on the guidance of the prompt, converts the service names in the alarm system into service names in the change system, and calls the retrieval tool to retrieve the change orders that meet the conditions from the change database.
[0060] Exemplarily, the poller can periodically call the full-status query API of the change system to obtain the change status of each service at the current moment and write it into the change event library. The polling period is generally set to the minute level so that it is sufficient to capture the time at any stage. Using the poller, the change status of each service can be obtained without modifying the change system itself, thereby achieving the purpose of non-invasion.
[0061] Exemplarily, a change event library can be maintained. The change event library can be a relational database. The change event library can include service name, computer room, stage, change number, start time, and end time. Among them, the service name is the service name system adopted by the change system. The change number is an identifier for a single change of a service. Exemplarily, data can be written in the form of SQL or API.
[0062] As Figure 3C shown, a retrieval tool can be provided. Exemplarily, the retrieval tool can provide two interfaces.
[0063] Interface 1 can obtain all service names from the change event library. Interface 2 can obtain the corresponding change orders according to the specified service name, abnormal time, and computer room parameters.
[0064] Interface 2 is described in detail below.
[0065] The retrieval tool is used to query relevant change data from the change event library through SQL. As a specific non-limiting example, the retrieval tool can externally receive the following parameters:
[0066] ● Service name: service_name
[0067] ● Abnormal time: timestamp
[0068] ● Computer room: idc
[0069] For these three parameters, the retrieval tool can construct the following two SQL statements.
[0070]
[0071] In this way, all change sets that meet the conditions can be found. As a specific non-limiting example, Figure 3D shows an example scenario where service A fails in computer room 2.
[0072] Return reference Figure 3C , a knowledge base can be maintained. The knowledge base can be used to maintain a name mapping table, which records the service names in the alarm system and the service names in the change system for a part of the services.
[0073]
[0074] This knowledge base can be conveniently entered manually.
[0075] Return reference Figure 3C , the agent can utilize dynamic prompt statements (prompts). As those skilled in the art can understand, throughout this document, the terms agent, large language model, large model, and LLM can be used interchangeably. An exemplary agent structure can be as Figure 3E shown. Exemplarily, the name mapping relationship can be obtained from the knowledge base, and the principle content can be obtained from interface 1 of the retrieval tool.
[0076] As a specific non-limiting example, an exemplary prompt statement can be as follows:
[0077]
[0078]
[0079]
[0080] Based on this dynamically generated prompt, the agent can convert the input of the alarm system into three parameters required by the retrieval tool. Furthermore, the agent calls the retrieval tool to obtain the retrieval result and present it.
[0081] According to one or more embodiments of the present disclosure, instead of modifying the change system and the alarm system, means such as a poller, a change database, and a knowledge base are constructed externally, and the goal can be achieved in a non-intrusive manner.
[0082] According to one or more embodiments of the present disclosure, by introducing an incomplete service name mapping of the knowledge base and with the assistance of the LLM, the similarity of names can be discovered; under the condition of knowing the full set of change service names, in the face of an alarm service name that has not appeared before, the matching change service name can also be well generalized. The name generalization ability is achieved.
[0083] According to one or more embodiments of the present disclosure, automation is achieved, thus saving a large amount of time for manual positioning of fault changes.
[0084] According to one or more embodiments of the present disclosure, through a poller and a change event library, retrievable change events are maintained, replacing the unconditional query ability of the current change system and the pure log system.
[0085] According to one or more embodiments of the present disclosure, a name mapping table is maintained through a knowledge base, enabling AI to learn the service name associations between the two systems, thereby saving manpower.
[0086] According to one or more embodiments of the present disclosure, a low-cost automation link between two systems is provided, capable of reading change system records when the alarm system alarms, thereby determining whether the alarm is caused by a change in the change system.
[0087] Now refer to Figure 4 Describe a service alarm processing device 400 according to an embodiment of the present disclosure. The service alarm processing device 400 may include an alarm acquisition unit 401, a change acquisition unit 402, and a processing acquisition unit 403.
[0088] The alarm acquisition unit 401 may be used to acquire alarm information for an abnormal service, where the alarm information includes a first name of the abnormal service according to a first naming mapping and the abnormal occurrence time of the abnormal service, and the first naming mapping is used to map a service set including the abnormal service to a first naming set.
[0089] The change acquisition unit 402 may be used to acquire service change information, where the service change information includes the corresponding naming of at least one service in the service set according to a second naming mapping and the corresponding service change history of the at least one service, and the second naming mapping is used to map the service set to a second naming set different from the first naming set.
[0090] The processing acquisition unit 403 may be used to obtain a processing result based on the alarm information and the service change information through a large language model, and the processing result can indicate whether a service change occurs for the abnormal service at the abnormal occurrence time.
[0091] The device according to the embodiment of the present disclosure can effectively assist in processing abnormalities.
[0092] According to some embodiments, the processing acquisition unit may include a unit for obtaining the processing result based on a naming mapping relationship, and the naming mapping relationship includes natural language describing the relationship between the first naming mapping and the second naming mapping.
[0093] According to some embodiments, the naming mapping relationship may include a correspondence relationship between a proper subset of the first naming set and a proper subset of the second naming set.
[0094] According to some embodiments, the processing and obtaining unit may include a unit for obtaining a second name based on the naming mapping relationship and the first name in the alarm information through the large language model.
[0095] According to some embodiments, the processing result may include the second name and the machine room name of the service change information corresponding to the alarm information.
[0096] According to some embodiments, the service change information may be obtained from a service change event library, which is a relational database maintained by a poller.
[0097] According to some embodiments, the poller may maintain the service change event library by periodically polling the change system to obtain the status of all service changes currently being executed.
[0098] In the technical solution of the present disclosure, the collection, acquisition, storage, use, processing, transmission, provision, and public application of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0099] According to an embodiment of the present disclosure, an electronic device, a readable storage medium, and a computer program product are also provided.
[0100] Reference Figure 5 , the structural block diagram of the electronic device 500 that can be used as the server or client of the present disclosure will now be described. It is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or required herein.
[0101] As Figure 5As shown, the electronic device 500 includes a computing unit 501, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0102] A plurality of components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, an output unit 507, a storage unit 508, and a communication unit 509. The input unit 506 can be any type of device capable of inputting information into the electronic device 500. The input unit 506 can receive input digital or character information and generate key signal inputs related to user settings and / or function controls of the electronic device, and can include, but is not limited to, a mouse, a keyboard, a touch screen, a trackpad, a trackball, a joystick, a microphone, and / or a remote control. The output unit 507 can be any type of device capable of presenting information and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 508 can include, but is not limited to, a magnetic disk, an optical disk. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks, and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, an 802.11 device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0103] The computing unit 501 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above, such as method 200 and its variants. For example, in some embodiments, method 200 and its variants can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of method 200 and its variants described above can be executed. Alternatively, in other embodiments, the computing unit 501 can be configured to execute method 200 and its variants in any other suitable manner (e.g., by means of firmware).
[0104] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general-purpose programmable processor, receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0105] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0106] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0107] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).
[0108] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0109] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is generated by computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0110] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitations are imposed herein.
[0111] Although embodiments or examples of the present disclosure have been described with reference to the accompanying drawings, it should be understood that the above methods, systems, and devices are merely exemplary embodiments or examples, and the scope of the present invention is not limited by these embodiments or examples, but is only defined by the authorized claims and their equivalent scope. Various elements in the embodiments or examples can be omitted or replaced by their equivalent elements. In addition, the steps can be executed in an order different from that described in the present disclosure. Further, the various elements in the embodiments or examples can be combined in various ways. Importantly, with the evolution of technology, many of the elements described herein can be replaced by equivalent elements that emerge after the present disclosure.
Claims
1. A service alarm processing method, comprising: Obtaining alarm information for an abnormal service, the alarm information including a first name of the abnormal service according to a first naming mapping and an abnormal occurrence time of the abnormal service, wherein the first naming mapping is used to map a service set including the abnormal service to a first naming set including the first name; obtaining service change information, the service change information including corresponding names of at least one service in the service set and corresponding service change history of the at least one service according to a second naming mapping, wherein the second naming mapping is used to map the service set to a second naming set different from the first naming set; as well as A processing result is obtained based on the alarm information and the service change information through a large language model, and the processing result can indicate whether a service change occurs to the abnormal service at the time when the abnormality occurs.
2. The method according to claim 1, wherein: The obtaining of the processing result based on the alarm information and the service change information by using the large language model includes: The processing result is obtained based on a naming mapping relationship, where the naming mapping relationship includes a natural language describing a relationship between the first naming mapping and the second naming mapping.
3. The method according to claim 2, wherein: The naming mapping relationship includes a correspondence relationship between a proper subset of the first naming set and a proper subset of the second naming set.
4. The method according to claim 2 or 3, wherein: The obtaining of the processing result based on the alarm information and the service change information by using the large language model includes: A second name is obtained through the large language model based on the naming mapping relationship and the first name in the alarm information.
5. The method according to claim 4, wherein: The processing result includes the second name and the computer room name of the service change information corresponding to the alarm information.
6. The method according to any one of claims 1 to 5, wherein: The service change information is obtained from a service change event library, and the service change event library is a relational database maintained by a poller.
7. The method according to claim 6, wherein: The poller maintains the service change event library by periodically polling the change system to obtain the status of all service changes currently being executed.
8. A service alarm processing device, comprising: an alarm obtaining unit, configured to obtain alarm information for an abnormal service, the alarm information including a first name of the abnormal service according to a first naming mapping and an abnormal occurrence time of the abnormal service, wherein the first naming mapping is used to map a service set including the abnormal service to a first naming set; a change obtaining unit, configured to obtain service change information, the service change information including a corresponding name of at least one service in the service set and a corresponding service change history of the at least one service according to a second naming mapping, wherein the second naming mapping is used to map the service set to a second naming set different from the first naming set; as well as A processing obtaining unit is used to obtain a processing result based on the alarm information and the service change information through a large language model, and the processing result can indicate whether the abnormal service has a service change at the time when the abnormality occurs.
9. The device according to claim 8, wherein: The processing obtaining unit includes a unit for obtaining the processing result based on a naming mapping relationship, wherein the naming mapping relationship includes a natural language describing a relationship between the first naming mapping and the second naming mapping.
10. The device according to claim 9, wherein: The naming mapping relationship includes a correspondence between a proper subset of the first naming set and a proper subset of the second naming set.
11. The device according to claim 9 or 10, wherein: The processing obtaining unit includes a unit for obtaining a second name based on the naming mapping relationship and the first name in the alarm information through the large language model.
12. The device according to claim 11, wherein The processing result includes the second name and the computer room name of the service change information corresponding to the alarm information.
13. The device according to any one of claims 8 to 12, wherein: The service change information is obtained from a service change event library, and the service change event library is a relational database maintained by a poller.
14. The device according to claim 13, wherein: The poller maintains the service change event library by periodically polling the change system to obtain the status of all service changes currently being executed.
15. An electronic device, comprising: at least one processor; as well as a memory communicatively coupled to the at least one processor; in The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.
16. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-7.
17. A computer program product comprising a computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.