Alarm root cause information determination method and device and electronic equipment
By aggregating the target alarm data under 5G base stations and building the alarm knowledge graph, the problems of low alarm information processing efficiency and high operation and maintenance costs are solved, and efficient alarm root cause positioning is achieved.
Patent Information
- Application Number
- CN202311579303.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
The alarm information processing efficiency under 5G base stations is low, the network operation and maintenance cost is high, and it is difficult to locate the root cause of the alarm in the alarm storm.
By aggregating the alarm data in the target alarm data group, a target class cluster set is generated, and an alarm propagation sub-graph set is constructed based on the alarm knowledge graph to determine the alarm root cause information.
The compression of alarm data is achieved, maintenance costs are reduced, and the determination efficiency and accuracy of the root cause information of alarms is improved, thereby improving the efficiency and accuracy of fault location.
Smart Images

Figure CN120050155A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of the combination of communication technology and network intelligent operation and maintenance technology, and particularly relates to a method, apparatus, and electronic device for determining alarm root cause information. Background Art
[0002] With the advent of the information era of the fifth-generation mobile communication technology (5G), the scale of its communication network has become quite large. Alarm messages are generated every day in the network, and the amount of these message data is huge, with many sudden failures. When a network device fails and triggers an alarm, related alarm information will be sent out by the associated devices and business processes. At the same time, alarm information caused by multiple failures will be superimposed together, drowning the real alarm information and making it very difficult to identify faults.
[0003] Currently, the network operation and maintenance under 5G pico base stations mainly rely on manual work. In the event of a large number of fault alarms, it basically cannot meet the real-time requirements of alarm processing, and the processing efficiency of alarm information is low. At the same time, due to the existence of a lot of redundant and repeated fault alarms in a large number of fault alarms, the network operation and maintenance cost is very high, and it is difficult to locate the alarm root cause (Root Cause) in the alarm storm. Summary of the Invention
[0004] This application provides a method, apparatus, and electronic device for determining alarm root cause information, which can solve the problems of low processing efficiency of alarm information, high network operation and maintenance cost, and difficulty in locating the alarm root cause in the alarm storm under current 5G pico base stations.
[0005] In a first aspect, this application provides a method for determining alarm root cause information, and the method includes:
[0006] Performing aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group;
[0007] Constructing an alarm propagation subgraph set corresponding to the target cluster set based on an alarm knowledge graph, where the alarm knowledge graph is constructed according to original alarm data, and the alarm propagation subgraph characterizes the correlation between alarm data;
[0008] Determining the alarm root cause information of the target alarm data group based on the alarm propagation subgraph set.
[0009] By the above method, the alarm data in the obtained target alarm data group is aggregated to compress the alarm data, which can avoid the increase in maintenance costs caused by out-of-control alarms. At the same time, based on the alarm knowledge graph, the automatic tracing of the root cause of the alarm is carried out. Not only can the direct root cause be found, but also the indirect root cause can be inferred, improving the determination efficiency and accuracy of the alarm root cause information, and further improving the efficiency and accuracy of fault location.
[0010] In a possible design, before aggregating the alarm data in the obtained target alarm data group to generate the target cluster set corresponding to the target alarm data group, it further includes:
[0011] Determine the alarm causality pairs based on historical alarm data and the network topology structure, where the alarm causality pair refers to two alarm data with a causal sequence;
[0012] Based on the correspondence between alarm data and alarm causes and repair suggestions, determine the target alarm cause and target repair suggestion corresponding to the alarm data in the alarm causality pair;
[0013] Use the alarm causality pair, the target alarm cause, and the target repair suggestion as the original alarm data, and construct the alarm knowledge graph based on the original alarm data.
[0014] In a possible design, the determining the alarm causality pairs based on historical alarm data and the network topology structure includes:
[0015] Group all historical alarm data according to the network topology structure to obtain multiple historical alarm data groups;
[0016] Aggregate the historical alarm data in each historical alarm data group to generate a historical cluster set corresponding to each historical alarm data group;
[0017] Perform the following operations on each historical cluster set:
[0018] Screen out candidate associated clusters in the historical cluster set, where the size of the clusters in the candidate associated clusters is greater than or equal to 2;
[0019] Perform frequent item mining processing on the candidate associated clusters to generate alarm causality pairs.
[0020] In a possible design, the grouping all historical alarm data according to the network topology structure to obtain multiple historical alarm data groups includes:
[0021] Delete the invalid data in all historical alarm data to obtain all first historical alarm data;
[0022] Deduplicate all the first historical alarm data to obtain all the second historical alarm data;
[0023] Determine the baseband unit to which each second historical alarm data belongs according to the network topology structure;
[0024] Group all the second historical alarm data according to the baseband unit to which each second historical alarm data belongs to obtain multiple historical alarm data groups.
[0025] In a possible design, the aggregating the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group includes:
[0026] Aggregate the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group;
[0027] Perform secondary clustering on the cluster set based on the alarm number and alarm generation time of the alarm data in the target alarm data group to generate a target cluster set corresponding to the target alarm data group.
[0028] In a possible design, the aggregating the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group includes:
[0029] Sort the alarm data in the target alarm data group according to the alarm generation time to obtain a sorted target alarm data group;
[0030] Use the first target alarm data with the earliest order in the sorted target alarm data group as the first initial cluster;
[0031] Determine whether the aggregation condition is satisfied between the second target alarm data and the first target alarm data in the sorted target alarm data group, where the second target alarm data is any target alarm data in the sorted target alarm data group other than the first target alarm data;
[0032] If so, add the second target alarm data to the first initial cluster to obtain a first cluster;
[0033] If not, use the second target alarm data as the second initial cluster.
[0034] In a possible design, the aggregation condition includes:
[0035] The difference between the alarm generation time of the second target alarm data and the alarm generation time of the first target alarm data is less than a preset threshold; or
[0036] Based on the alarm knowledge graph, determine any target alarm data in the first initial cluster that has the same alarm cause as the second target alarm data; or
[0037] Based on the alarm knowledge graph, determine any target alarm data in the first initial cluster that has a causal relationship with the second target alarm data.
[0038] In a second aspect, the present application provides an alarm root cause information determination device, and the device includes:
[0039] A generation module, configured to perform aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group;
[0040] A first construction module, configured to construct an alarm propagation subgraph set corresponding to the target cluster set based on the alarm knowledge graph, where the alarm knowledge graph is constructed according to the original alarm data, and the alarm propagation subgraph characterizes the relevance between alarm data;
[0041] A first determination module, configured to determine the alarm root cause information of the target alarm data group based on the alarm propagation subgraph set.
[0042] In a possible design, the device further includes:
[0043] A second determination module, configured to determine alarm causal relationship pairs based on historical alarm data and a network topology, where the alarm causal relationship pair refers to two alarm data with a causal sequence;
[0044] A third determination module, configured to determine a target alarm cause and a target repair suggestion corresponding to the alarm data in the alarm causal relationship pair based on the correspondence between the alarm data and the alarm cause and the repair suggestion;
[0045] A second construction module, configured to use the alarm causal relationship pair, the target alarm cause, and the target repair suggestion as the original alarm data, and construct the alarm knowledge graph based on the original alarm data.
[0046] In a possible design, the second determination module is specifically configured to:
[0047] Group all the historical alarm data according to the network topology to obtain multiple historical alarm data groups;
[0048] Perform aggregation processing on the historical alarm data in each historical alarm data group to generate a historical cluster set corresponding to each historical alarm data group;
[0049] Perform the following operations on each historical cluster set:
[0050] Filter out candidate associated clusters in the historical cluster set, where the size of the clusters in the candidate associated clusters is greater than or equal to 2; perform frequent item mining processing on the candidate associated clusters to generate alarm causal relationship pairs.
[0051] In a possible design, the second determination module is specifically configured to:
[0052] Delete invalid data in all historical alarm data to obtain all first historical alarm data;
[0053] Deduplicate all the first historical alarm data to obtain all second historical alarm data;
[0054] Determine the baseband unit to which each second historical alarm data belongs according to the network topology structure;
[0055] Group all the second historical alarm data according to the baseband unit to which each second historical alarm data belongs to obtain multiple historical alarm data groups.
[0056] In a possible design, the generation module is specifically configured to:
[0057] Aggregate the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group;
[0058] Perform secondary clustering processing on the cluster set based on the alarm numbers and alarm generation times of the alarm data in the target alarm data group to generate a target cluster set corresponding to the target alarm data group.
[0059] In a possible design, the generation module is specifically configured to:
[0060] Sort the alarm data in the target alarm data group according to the alarm generation time to obtain a sorted target alarm data group;
[0061] Use the first target alarm data with the earliest order in the sorted target alarm data group as the first initial cluster;
[0062] Determine whether the second target alarm data in the sorted target alarm data group satisfies the aggregation condition with the first target alarm data, where the second target alarm data is any target alarm data in the sorted target alarm data group other than the first target alarm data;
[0063] If so, add the second target alarm data to the first initial cluster to obtain a first cluster;
[0064] If not, use the second target alarm data as the second initial cluster.
[0065] In a possible design, the aggregation condition includes:
[0066] The difference between the alarm generation time of the second target alarm data and the alarm generation time of the first target alarm data is less than a preset threshold; or
[0067] Based on the alarm knowledge graph, it is determined that there is any target alarm data in the first initial cluster with the same alarm cause as the second target alarm data; or
[0068] Based on the alarm knowledge graph, it is determined that there is any target alarm data in the first initial cluster that has a causal relationship with the second target alarm data.
[0069] In a third aspect, the present application provides an electronic device, including:
[0070] A memory for storing a computer program;
[0071] A processor, when executing the computer program stored on the memory, implements the steps of the alarm root cause information determination method in the first aspect above.
[0072] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the alarm root cause information determination method in the first aspect above are implemented.
[0073] Based on the above alarm root cause information determination method, aggregating the alarm data in the obtained target alarm data group to compress the alarm data can avoid the increase in maintenance costs caused by alarm out-of-control. At the same time, automatically tracing the alarm root cause based on the alarm knowledge graph can not only find the direct root cause but also infer the indirect root cause, improving the determination efficiency and accuracy of the alarm root cause information, and thus improving the efficiency and accuracy of fault location.
[0074] For the technical effects that can be achieved in each of the second to fourth aspects above and the various possible solutions in the first aspect, refer to the technical effects that can be achieved in the first aspect or the various possible solutions in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Figure 1 It is a schematic diagram of the scenario applicable to the embodiments of the present application;
[0076] Figure 2Flowchart of a method for determining alarm root cause information provided by an embodiment of the present application;
[0077] Figure 3 Schematic diagram of the construction of an alarm knowledge graph provided by an embodiment of the present application;
[0078] Figure 4 Partial schematic diagram of an alarm knowledge graph provided by an embodiment of the present application;
[0079] Figure 5 Schematic diagram of the structure of an alarm propagation sub-graph provided by an embodiment of the present application;
[0080] Figure 6 Schematic diagram of the structure of a target alarm propagation sub-graph provided by an embodiment of the present application;
[0081] Figure 7 Schematic diagram of the structure of an alarm root cause information determination device provided by an embodiment of the present application;
[0082] Figure 8 Schematic diagram of the structure of another alarm root cause information determination device provided by an embodiment of the present application;
[0083] Figure 9 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0084] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of the present application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist, and B exists alone. The connection between A and B may represent: A is directly connected to B and A is connected to B through C. In addition, in the description of the present application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0085] For the convenience of those skilled in the art to understand, the technical terms involved in the embodiments of the present application are first explained.
[0086] (1) The K-means clustering algorithm is an iterative clustering analysis algorithm. Its steps are as follows: initially divide the data into K groups, then randomly select K objects as the initial clustering centers, and then calculate the distances between each object and each seed clustering center, and assign each object to the clustering center closest to it. The clustering centers and the objects assigned to them represent a cluster. For each assigned sample, the clustering centers of the cluster will be recalculated based on the existing objects in the cluster. This process will be repeated continuously until a certain termination condition is met. The termination condition can be that no (or the minimum number of) objects are reassigned to different clusters, no (or the minimum number of) clustering centers change anymore, or the sum of squared errors is locally minimized.
[0087] (2) The Apriori algorithm for association rules is an association rule algorithm that uses an iterative method of layer-by-layer search to find the relationships between item sets in a database to form rules. Its process consists of joining (a kind of matrix operation for classes) and pruning (removing those unnecessary intermediate results). In this algorithm, the concept of an item set is the set of items. A set containing K items is a k-item set. The frequency of an item set is the number of transactions containing the item set, which is called the frequency of the item set. If an item set meets the minimum support, it is called a frequent item set.
[0088] (3) The FP-growth algorithm is an association analysis algorithm that adopts the following divide-and-conquer strategy: compress the database providing frequent item sets into a frequent pattern tree (FP-tree), but still retain the item set association information. The FP-tree is a special prefix tree composed of a frequent item header table and an item prefix tree.
[0089] The following briefly introduces the application scenarios applicable to the technical solutions of the embodiments of the present application. It should be noted that the application scenarios introduced below are only used to illustrate the embodiments of the present application rather than to limit them. In specific implementation, the technical solutions provided by the embodiments of the present application can be flexibly applied according to actual needs.
[0090] Figure 1 This is a schematic diagram of the application scenario applicable to the embodiments of the present application. This scenario mainly includes an operation and maintenance management unit 101, baseband units (1,..., N), peripheral hubs (1, 2,..., m - 1, m), and pico base station devices (1, 2, 3,..., n - 2, n - 1, n).
[0091] Exemplarily, the operation and maintenance management unit 101 can obtain the alarm data streams (including historical alarm data and current alarm data streams) generated by the pico base station devices (1, 2, 3,..., n - 2, n - 1, n) through the baseband units (1,..., N) and the peripheral hubs (1, 2,..., m - 1, m), and then determine the alarm root cause information based on the obtained alarm data streams.
[0092] Based on the above application scenarios, an alarm root cause information determination method provided by an embodiment of the present application performs aggregation processing on the alarm data in the obtained target alarm data group, realizes compression of the alarm data, and can avoid the increase in maintenance costs caused by alarm out-of-control. At the same time, based on the alarm knowledge graph, automatic tracing of the alarm root cause is performed. Not only can the direct root cause be found, but also the indirect root cause can be inferred, improving the determination efficiency and accuracy of the alarm root cause information, and further improving the efficiency and accuracy of fault location. Among them, the method and device in the embodiment of the present application are based on the same technical concept. Since the principles of the problems solved by the method and the device are similar, the embodiments of the device and the method can be referred to each other, and the repeated parts will not be described again.
[0093] To further illustrate the technical solutions provided by the embodiments of the present application, the following will be described in detail in combination with the accompanying drawings and specific implementation manners. Although the embodiments of the present application provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on routine or non-creative labor. In steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiments of the present application. When the method is actually processed or the device executes, it can be executed in the order shown in the embodiments or drawings or executed concurrently.
[0094] Figure 2 The following is a flowchart of an alarm root cause information determination method provided by an embodiment of the present application. This process can be executed by an alarm root cause information determination device, which can be implemented in software, hardware, or a combination of software and hardware, to improve the determination efficiency and accuracy of alarm root cause information. As Figure 2 shown, this process includes the following steps:
[0095] S201, perform aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group;
[0096] In the embodiment of the present application, in order to ensure the aggregation accuracy of the alarm data in the target alarm data group, as Figure 1 shown, the operation and maintenance management unit 101 can combine the alarm knowledge graph to perform aggregation processing on the alarm data in the target alarm data group. Among them, the alarm knowledge graph is constructed based on the original alarm data. Specifically:
[0097] As Figure 3As shown in the figure, it is a schematic diagram of the construction of an alarm knowledge graph provided by an embodiment of the present application. On the one hand, alarm causal pairs can be extracted from expert experience data and / or an automatic mining method of alarm causal relationships based on historical alarm data and network topology structure can be used to determine alarm causal pairs. Among them, an alarm causal pair refers to two alarm data with a causal sequence. The automatic mining method of alarm causal relationships can be:
[0098] Group all historical alarm data according to the network topology structure to obtain multiple groups of historical alarm data. Specifically, delete the invalid data in all historical alarm data according to the network topology structure to obtain the first alarm data stream. Among them, the invalid data includes dirty data and irrelevant data.
[0099] Furthermore, perform deduplication processing on all the first historical alarm data to obtain all the second historical alarm data. For example, extract the alarm information of each first historical alarm data. Among them, the alarm information includes the location area (through which it can be known which device in which area generates the alarm), alarm name, alarm type number, alarm classification (such as communication alarm, service quality alarm, processing error alarm, device alarm, environmental alarm), alarm level (such as emergency, important, minor, prompt), alarm content, alarm generation time, and alarm device number. And when it is determined that the alarm information of any first historical alarm data is the same as the alarm information of the remaining first historical alarm data, delete the any first historical alarm data.
[0100] Next, determine the baseband unit to which each second historical alarm data belongs according to the network topology structure, and group all the second historical alarm data according to the baseband unit to which each second historical alarm data belongs. For example, determine which second historical alarm data belongs to the same baseband unit according to the network topology structure, and divide the second historical alarm data belonging to the same baseband unit into a group to obtain multiple groups of historical alarm data.
[0101] After obtaining multiple groups of historical alarm data through the above method, perform the following operations on each group of historical alarm data:
[0102] Perform aggregation processing on the historical alarm data in the group of historical alarm data to generate a historical cluster set corresponding to the group of historical alarm data. Among them, the aggregation processing method can be an aggregation processing method based on the K-means clustering algorithm: (clustering based on time characteristics)
[0103] First, sort the historical alarm data in the historical alarm data group in ascending order according to the alarm generation time, and take the historical alarm data with the earliest order as an initial historical cluster. Select the alarm generation time of this historical alarm data as the center of this initial historical cluster. Then, compare the remaining historical alarm data in the historical alarm data group with the center of this initial historical cluster in turn according to the sorting order, and judge whether the distance between the alarm generation time of any historical alarm data in the historical alarm data group and the center of this initial historical cluster is less than the threshold. If so, add this any historical alarm data to this initial historical cluster; if not, take this any historical alarm data as a new initial historical cluster and perform cyclic processing according to the above method. Finally, generate a set of historical clusters corresponding to the historical alarm data group.
[0104] It should be noted that the size of the above threshold can be 5 or 10. The specific size depends on the situation and is not specifically limited here.
[0105] After generating the set of historical clusters corresponding to each historical alarm data group through the above method, perform the following operations on each set of historical clusters:
[0106] Screen out candidate associated clusters in the set of historical clusters, where the size of the clusters in the candidate associated clusters is greater than or equal to 2, and perform frequent item mining processing on the candidate associated clusters to generate alarm causal relationship pairs. For example, the Apriori algorithm or the FP-growth algorithm can be used to perform frequent item mining processing on the candidate associated clusters, set the maximum K-item set to 2, and finally generate a one-to-one relationship of strong key alarms. After manual verification by experts, alarm causal relationship pairs can be obtained.
[0107] On the other hand, extract the alarm causes and repair suggestions from the alarm manual, which can be stored in the alarm cause library, and based on the corresponding relationship between the alarm data and the alarm causes and repair suggestions (for example, the alarm data is a monitoring device temperature anomaly alarm, the corresponding alarm cause is that the board temperature is too high, and the repair suggestion is to lower the board temperature), determine the target alarm cause and target repair suggestion corresponding to the alarm data in the alarm causal relationship pair from the alarm cause library.
[0108] Therefore, the above warning causality pairs, the above target warning reasons, and the above target repair suggestions are used as the original warning data, and a warning knowledge graph is constructed based on the original warning data. For example, the warning data in the warning causality pairs is used as an entity, the relationship is a causal relationship, and the target warning reasons and target repair suggestions corresponding to the warning data in the warning causality pairs are used as the attributes of the entity to construct a warning knowledge graph. Or determine the types of the warning data in the warning causality pairs, use the types as entities, the relationship is a causal relationship, and use the target warning reasons and target repair suggestions corresponding to the warning data in the warning causality pairs as the attributes of the entity to construct a warning knowledge graph.
[0109] As Figure 4 shown, it is a partial schematic diagram of a warning knowledge graph provided by an embodiment of the present application. In Figure 4 it, warning data A1, warning data A2, warning data A3, warning data A4, warning data A5, and warning data A6 are entities.
[0110] Warning reason A1 and repair suggestion A1 are the attributes of warning data A1, warning reason A2 and repair suggestion A2 are the attributes of warning data A2, warning reason A3 and repair suggestion A3 are the attributes of warning data A3, warning reason A4 and repair suggestion A4 are the attributes of warning data A4, warning reason A5 and repair suggestion A5 are the attributes of warning data A5, and warning reason A6 and repair suggestion A6 are the attributes of warning data A6.
[0111] The relationship between warning reason A1 and warning reason A2 is a causal relationship, the relationship between warning reason A1 and warning reason A3 is a causal relationship, the relationship between warning reason A2 and warning reason A3 is a causal relationship, the relationship between warning reason A4 and warning reason A3 is a causal relationship, the relationship between warning reason A4 and warning reason A5 is a causal relationship, the relationship between warning reason A4 and warning reason A6 is a causal relationship, the relationship between warning reason A5 and warning reason A3 is a causal relationship, and the relationship between warning reason A6 and warning reason A5 is a causal relationship.
[0112] It should be noted that the construction method of the warning knowledge graph is not limited in the embodiments of the present application, and those skilled in the art can construct a warning knowledge graph based on the above original warning data according to specific situations.
[0113] Through the above method, a warning knowledge graph is constructed, and then the warning data in the target warning data group can be aggregated in combination with the warning knowledge graph to improve the accuracy of aggregation.
[0114] Optionally, the method for obtaining the target warning data group may be:
[0115] Delete invalid data in the current alarm data stream according to the network topology structure to obtain a first alarm data stream, where the invalid data includes dirty data and irrelevant data.
[0116] Furthermore, perform deduplication processing on the first alarm data stream to obtain a second alarm data stream. Specifically, extract the alarm information of each alarm data in the first alarm data stream, where the alarm information includes the location area (from which the area and device that generated the alarm can be known), alarm name, alarm type number, alarm classification (such as communication alarm, service quality alarm, processing error alarm, device alarm, environmental alarm), alarm level (such as emergency, important, minor, prompt), alarm content, alarm generation time, and alarm device number. And when it is determined that the alarm information of any alarm data in the first alarm data stream is the same as the alarm information of the remaining alarm data, delete the any alarm data.
[0117] Next, group the second alarm data stream according to the network topology structure to obtain multiple target alarm data groups. Specifically, determine the baseband unit to which each alarm data in the second alarm data stream belongs, and group the second alarm data stream according to the baseband unit to which each alarm data in the second alarm data stream belongs. For example, determine which alarm data in the second alarm data stream belongs to the same baseband unit according to the network topology structure, and divide the alarm data in the second alarm data stream that belongs to the same baseband unit into one group to obtain multiple target alarm data groups.
[0118] Perform the following operations on each obtained target alarm data group:
[0119] Perform aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group, where the specific aggregation method can be:
[0120] First, sort the alarm data in the target alarm data group according to the alarm generation time to obtain a sorted target alarm data group. And use the first target alarm data with the earliest order in the sorted target alarm data group as the first initial cluster.
[0121] Then, the remaining alarm data in the sorted target alarm data group are sequentially compared with the first target alarm data in the arranged order, and it is determined whether the second target alarm data in the sorted target alarm data group and the first target alarm data satisfy the aggregation condition, where the second target alarm data is any target alarm data in the sorted target alarm data group other than the first target alarm data. If so, the second target alarm data is added to the first initial cluster; if not, the second target alarm data is used as the second initial cluster, and the loop processing is performed according to the above method. Finally, a cluster set corresponding to the target alarm data group is generated.
[0122] In some possible designs, the aggregation condition may be: the difference between the alarm generation time of the second target alarm data and the alarm generation time of the first target alarm data is less than a preset threshold, where the size of the preset threshold may be 6 or 8, and the specific size depends on the situation and is not specifically limited here; or based on the above alarm knowledge graph, it is determined that there is any target alarm data in the first initial cluster with the same alarm cause as the second target alarm data; or based on the alarm knowledge graph, it is determined that there is any target alarm data in the first initial cluster that has a causal relationship with the second target alarm data.
[0123] At the same time, since alarms may not have been processed in time and some alarm data belong to the same type of fault, the generated cluster set can also be subjected to secondary clustering processing based on the alarm numbers and alarm generation times of the alarm data in the target alarm data group to generate a target cluster set corresponding to the target alarm data group.
[0124] S202, constructing an alarm propagation subgraph set corresponding to the target cluster set based on the alarm knowledge graph;
[0125] In the embodiment of the present application, an alarm propagation subgraph set corresponding to the target cluster set can be constructed based on the above alarm knowledge graph. Specifically, based on the alarm knowledge graph, it is determined whether there is a common cause between the alarm data in the target cluster set, and an alarm propagation subgraph set is generated based on the alarm data in the target cluster set that has a common cause, where the alarm propagation subgraph characterizes the correlation between alarm data.
[0126] As Figure 5 shown, it is a schematic structural diagram of an alarm propagation subgraph provided by an embodiment of the present application. In Figure 5 it, the common cause between alarm data A and alarm data B is alarm cause c, the common cause between alarm data A and alarm data D is alarm cause c, the common cause between alarm data B and alarm data D is alarm cause f, and the common cause between alarm data C and alarm data D is alarm cause k.
[0127] S203, determine the alarm root cause information of the target alarm data group based on the set of alarm propagation subgraphs.
[0128] In the application embodiment, the following operations need to be performed on each alarm propagation subgraph in the set of fault propagation subgraphs:
[0129] Find the minimum path of the alarm propagation subgraph to obtain the target alarm propagation subgraph, and in the target alarm propagation subgraph, determine the alarm root cause information through graph search.
[0130] For example, in Figure 5 the alarm propagation subgraph, find the minimum path to obtain the target alarm propagation subgraph as Figure 6 shown, which is a schematic structural diagram of a target alarm propagation subgraph provided by the application embodiment. By performing graph search on Figure 6 , it can be determined that alarm data A is the root cause alarm, and by locating alarm data A, alarm cause a, alarm cause b, and alarm cause c are possible causes. Further, through the cause intersection of relevant alarm data (alarm data A and alarm data D), it is determined that alarm cause c is the final possible cause. Thus, the output alarm root cause information is shown in Table 1:
[0131]
[0132]
[0133] Table 1 An alarm root cause information table
[0134] In Table 1, the root cause device belongs to an item that can be directly viewed.
[0135] In some possible embodiments, the present application can also evaluate the above-mentioned alarm root cause information determination method through some metrics. For example, the alarm compression rate = (the number of alarm data before aggregation - the number of alarm data after aggregation) / the number of alarm data before aggregation, the aggregation accuracy = the number of alarm data belonging to the same fault / the total number of faults, the root cause alarm hit rate = the number of faults with correct root cause alarms / the total number of faults, and the association hit rate = the number of alarm data with correct associations in the alarm causality pairs / the number of alarm data associated in the alarm causality pairs. When it is determined that the alarm compression rate is less than the preset compression rate, or the aggregation accuracy is less than the preset accuracy, or the root cause alarm hit rate is less than the preset hit rate, or the association hit rate is less than the preset association hit rate, relevant operation and maintenance supervision personnel are notified in a timely manner.
[0136] It should be noted that the above does not limit the values of the preset compression rate, preset accuracy, preset hit rate, and preset association hit rate. The specific values depend on the situation and are not specifically limited here.
[0137] Through the above method for determining the root cause information of alarms, the alarm data in the obtained target alarm data group is aggregated to compress the alarm data, which can avoid the increase in maintenance costs caused by out-of-control alarms. At the same time, based on the alarm knowledge graph, the automatic tracing of the root cause of alarms can not only find the direct root cause, but also infer the indirect root cause, improving the efficiency and accuracy of determining the root cause information of alarms, and further improving the efficiency and accuracy of fault location.
[0138] Based on the same inventive concept, an apparatus for determining the root cause information of alarms is further provided in an embodiment of the present application, as Figure 7 shown in the structural schematic diagram of an apparatus for determining the root cause information of alarms provided in an embodiment of the present application. The apparatus includes:
[0139] A generating module 701, configured to perform aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group;
[0140] A first constructing module 702, configured to construct a set of alarm propagation subgraphs corresponding to the target cluster set based on the alarm knowledge graph, where the alarm knowledge graph is constructed according to the original alarm data, and the alarm propagation subgraph represents the correlation between alarm data;
[0141] A first determining module 703, configured to determine the root cause information of the target alarm data group based on the set of alarm propagation subgraphs.
[0142] In a possible design, the generating module 701 is specifically configured to:
[0143] Perform aggregation processing on the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group;
[0144] Perform secondary clustering processing on the cluster set based on the alarm numbers and alarm generation times of the alarm data in the target alarm data group to generate a target cluster set corresponding to the target alarm data group.
[0145] In a possible design, the generating module 701 is specifically configured to:
[0146] Sort the alarm data in the target alarm data group according to the alarm generation time to obtain a sorted target alarm data group;
[0147] Use the first target alarm data with the earliest order in the sorted target alarm data group as the first initial cluster;
[0148] Determine whether the second target alarm data in the sorted target alarm data group satisfies the aggregation condition with the first target alarm data, where the second target alarm data is any target alarm data in the sorted target alarm data group other than the first target alarm data;
[0149] If so, add the second target alarm data to the first initial cluster to obtain the first cluster;
[0150] If not, use the second target alarm data as the second initial cluster.
[0151] In a possible design, the aggregation condition includes:
[0152] The difference between the alarm generation time of the second target alarm data and the alarm generation time of the first target alarm data is less than a preset threshold; or
[0153] Based on the alarm knowledge graph, determine that there is any target alarm data in the first initial cluster with the same alarm cause as the second target alarm data; or
[0154] Based on the alarm knowledge graph, determine that there is any target alarm data in the first initial cluster that has a causal relationship with the second target alarm data.
[0155] In other embodiments, in addition to the above Figure 7 shown modules, it may further include a second determination module, a third determination module, and a second construction module, as Figure 8 shown, which exemplarily shows the structural schematic diagram of another alarm root cause information determination device provided by the embodiments of the present application. The device includes: a generation module 701, a first construction module 702, a first determination module 703, a second determination module 801, a third determination module 802, and a second construction module 803.
[0156] The second determination module 801 is configured to determine alarm causal relationship pairs based on historical alarm data and network topology, where the alarm causal relationship pair refers to two alarm data with a causal sequence;
[0157] The third determination module 802 is configured to determine the target alarm cause and target repair suggestion corresponding to the alarm data in the alarm causal relationship pair based on the correspondence between alarm data and alarm causes and repair suggestions;
[0158] The second construction module 803 is configured to use the alarm causal relationship pair, the target alarm cause, and the target repair suggestion as the original alarm data, and construct the alarm knowledge graph based on the original alarm data.
[0159] In a possible design, the second determination module 801 is specifically configured to:
[0160] Group all historical alarm data according to the network topology structure to obtain multiple historical alarm data groups;
[0161] Perform aggregation processing on the historical alarm data in each historical alarm data group to generate a historical cluster set corresponding to each historical alarm data group;
[0162] Perform the following operations on each historical cluster set:
[0163] Screen out candidate associated clusters in the historical cluster set, where the size of the clusters in the candidate associated clusters is greater than or equal to 2; perform frequent item mining processing on the candidate associated clusters to generate alarm causal relationship pairs.
[0164] In a possible design, the second determination module 801 is specifically configured to:
[0165] Delete invalid data in all historical alarm data to obtain all first historical alarm data;
[0166] Perform deduplication processing on all the first historical alarm data to obtain all second historical alarm data;
[0167] Determine the baseband unit to which each second historical alarm data belongs according to the network topology structure;
[0168] Group all the second historical alarm data according to the baseband unit to which each second historical alarm data belongs to obtain multiple historical alarm data groups.
[0169] It should be noted here that the above device provided in the embodiment of the present application can implement all the method steps in the above method embodiment and can achieve the same technical effect. The same parts and beneficial effects as those in the method embodiment will not be specifically described in this embodiment.
[0170] Based on the same inventive concept, an electronic device is further provided in the embodiment of the present application. The electronic device can implement the functions of the foregoing alarm root cause information determination device. Refer to Figure 9 , the electronic device includes:
[0171] At least one processor 901, and a memory 902 connected to at least one processor 901. In the embodiment of the present application, the specific connection medium between the processor 901 and the memory 902 is not limited. Figure 9 It is taken as an example that the processor 901 and the memory 902 are connected through a bus 900. The bus 900 is in Figure 9is represented by a thick line. The connection manners between other components are only for illustrative purposes and are not limiting. The bus 900 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 9 it is only represented by a thick line in the figure, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 901 can also be referred to as a controller, and there is no limitation on the name.
[0172] In the embodiments of the present application, the memory 902 stores instructions executable by at least one processor 901. By executing the instructions stored in the memory 902, the at least one processor 901 can execute the method for determining the alarm root cause information described above. The processor 901 can implement Figure 7 the functions of each module in the device shown in FIG. 7 or 8.
[0173] Among them, the processor 901 is the control center of the device, and can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 902 and calling the data stored in the memory 902, various functions of the device and process data, so as to monitor the device as a whole.
[0174] In a possible design, the processor 901 may include one or more processing units. The processor 901 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 901. In some embodiments, the processor 901 and the memory 902 can be implemented on the same chip. In some embodiments, they can also be implemented separately on independent chips.
[0175] The processor 901 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method for determining the alarm root cause information disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0176] The memory 902 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 902 can include at least one type of storage medium. For example, it can include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical discs, etc. The memory 902 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 902 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0177] By designing and programming the processor 901, the code corresponding to the alarm root cause information determination method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 2 the steps of the alarm root cause information determination method of the illustrated embodiments when running. How to design and program the processor 901 is a well-known technology to those skilled in the art and will not be elaborated here.
[0178] Based on the same inventive concept, the embodiments of the present disclosure provide a computer storage medium, which includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute an alarm root cause information determination method as described in any of the foregoing discussions. Since the principle of the above computer storage medium for solving problems is similar to that of an alarm root cause information determination method, the implementation of the above computer storage medium can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0179] In the specific implementation process, the computer storage medium can include various storage media that can store program code, such as universal serial bus flash drives (USB, Universal Serial Bus Flash Drive), mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0180] Based on the same inventive concept, embodiments of the present disclosure further provide a computer program product, which includes computer program code. When the computer program code runs on a computer, it causes the computer to execute an alarm root cause information determination method as described in any of the foregoing discussions. Since the principle of the above computer program product for solving problems is similar to that of an alarm root cause information determination method, the implementation of the above computer program product can refer to the implementation of the method, and the repeated parts will not be described again.
[0181] The computer program product may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0182] The method in this application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in this application are executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM, or other programmable devices.
[0183] The computer program or instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium may be any available medium that the computer can access, or a data storage device such as a server or data center integrating one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disc; or it may be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0184] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories and optical memories, etc.) that contain computer-usable program code.
[0185] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0186] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0187] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0188] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A method for determining the root cause information of an alarm, characterized in that, the method includes: Performing aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group; Constructing an alarm propagation subgraph set corresponding to the target cluster set based on the alarm knowledge graph, where the alarm knowledge graph is constructed according to the original alarm data, and the alarm propagation subgraph characterizes the correlation between alarm data; Determining the root cause information of the target alarm data group based on the alarm propagation subgraph set.
2. The method according to claim 1, characterized in that, before performing aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group, it further includes: Determining alarm causal relationship pairs based on historical alarm data and network topology, where the alarm causal relationship pairs refer to two alarm data with a causal sequence; Determining the target alarm cause and target repair suggestion corresponding to the alarm data in the alarm causal relationship pair based on the corresponding relationship between alarm data, alarm cause, and repair suggestion; Taking the alarm causal relationship pair, the target alarm cause, and the target repair suggestion as the original alarm data, and constructing the alarm knowledge graph based on the original alarm data.
3. The method according to claim 2, characterized in that, the determining alarm causal relationship pairs based on historical alarm data and network topology includes: Grouping all historical alarm data according to the network topology to obtain multiple historical alarm data groups; Performing aggregation processing on the historical alarm data in each historical alarm data group to generate a historical cluster set corresponding to each historical alarm data group; Performing the following operations on each historical cluster set: Screening candidate associated clusters in the historical cluster set, where the size of the clusters in the candidate associated clusters is greater than or equal to 2; Performing frequent item mining processing on the candidate associated clusters to generate alarm causal relationship pairs.
4. The method according to claim 3, characterized in that, the grouping all historical alarm data according to the network topology to obtain multiple historical alarm data groups includes: Deleting invalid data in all historical alarm data to obtain all first historical alarm data; Performing deduplication processing on all the first historical alarm data to obtain all second historical alarm data; Determining the baseband unit to which each second historical alarm data belongs according to the network topology; Grouping all the second historical alarm data according to the baseband unit to which each second historical alarm data belongs to obtain multiple historical alarm data groups.
5. The method according to claim 1, characterized in that, the performing aggregation processing on the alarm data in the obtained target alarm data group to generate a target cluster set corresponding to the target alarm data group includes: Performing aggregation processing on the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group; Perform secondary clustering processing on the cluster set based on the alarm numbers and alarm generation times of the alarm data in the target alarm data group to generate a target cluster set corresponding to the target alarm data group.
6. The method according to claim 5, wherein, the aggregating the alarm data in the target alarm data group to generate a cluster set corresponding to the target alarm data group includes: Sort the alarm data in the target alarm data group according to the alarm generation time to obtain a sorted target alarm data group; Use the first target alarm data with the earliest order in the sorted target alarm data group as the first initial cluster; Determine whether the second target alarm data in the sorted target alarm data group satisfies the aggregation condition with the first target alarm data, where the second target alarm data is any target alarm data in the sorted target alarm data group other than the first target alarm data; If so, add the second target alarm data to the first initial cluster to obtain a first cluster; If not, use the second target alarm data as the second initial cluster.
7. The method according to claim 6, wherein, the aggregation condition includes: The difference between the alarm generation time of the second target alarm data and the alarm generation time of the first target alarm data is less than a preset threshold; or Based on the alarm knowledge graph, determine that there is any target alarm data in the first initial cluster with the same alarm cause as the second target alarm data; or Based on the alarm knowledge graph, determine that there is any target alarm data in the first initial cluster that has a causal relationship with the second target alarm data.
8. An alarm root cause information determination device, wherein, the device includes: A generation module, configured to perform aggregation processing on the alarm data in the acquired target alarm data group to generate a target cluster set corresponding to the target alarm data group; A construction module, configured to construct an alarm propagation sub-graph set corresponding to the target cluster set based on the alarm knowledge graph, where the alarm knowledge graph is constructed according to the original alarm data, and the alarm propagation sub-graph characterizes the relevance between alarm data; A first determination module, configured to determine the alarm root cause information of the target alarm data group based on the alarm propagation sub-graph set.
9. An electronic device, wherein, includes: A memory for storing a computer program; A processor, configured to implement the method steps according to any one of claims 1-7 when executing the computer program stored on the memory.
10. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1-7 are implemented.