Ticket order alarm system, method, device, medium and product

By designing an alarm system for ticket orders, using the configuration management module, log collection module, information processing module and reach service module, the problems of delay in alarm response and new difficulties in monitoring points in the existing technology are solved, and efficient alarm processing and reduced operation and maintenance costs are achieved.

CN120066895APending Publication Date: 2025-05-30CTRIP TRAVEL NETWORK TECH SHANGHAI0
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510147799.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The alarm method for existing ticket orders has the problem of delayed alarm response, and it is necessary to modify the application code and re-release the system before adding a monitoring point.

Method used

An alarm system for ticketing orders is designed, including order application, log service module, configuration management module, log collection module, information processing module, contact service module and alarm execution module. The configuration management module uniformly configures the alarm configuration information, uses the log collection module to collect the application operation log, the information processing module identifies abnormal orders and generates alarm information, and finally reaches the service module to configure the trigger alarm execution module.

Benefits of technology

It realizes that without modifying application code and system republishing, new monitoring points are added to promptly notify processors, reduce alarm response delays, improve processing efficiency, and reduce the operation and maintenance costs of the alarm system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066895A_ABST
    Figure CN120066895A_ABST
Patent Text Reader

Abstract

The invention provides a ticket order alarm system, method and device, a medium and a product, and the system is configured as follows: an order application sends alarm configuration information to a configuration management module; the configuration management module configures the log acquisition module, the information processing module and the touch service module based on the alarm configuration information; the log acquisition module acquires application basic information and application running logs corresponding to the order applications stored in the log service module, and sends the application basic information and the application running logs to the information processing module; the information processing module judges that an order corresponding to the application running log is an abnormal order based on at least one preset keyword included in the application running log, generates alarm information and sends the alarm information to the touch service module; and the touch service module receives the alarm information, forwards the alarm information to the alarm execution module, and configures and triggers the alarm execution module according to the alarm configuration information. The alarm response delay can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In the field of operation monitoring of ticket order processing systems, the existing technology mainly adopts an alarm mechanism based on business metric data points. For the alarm mechanism based on business metric data points, it is necessary to pre-implant monitoring code in the application program. If there are new monitoring points to be added, the application code and the system must be modified and republished, resulting in a delay in alarm response. Summary of the Invention

[0003] In view of this, the present disclosure provides an alarm system, method, device, medium and product for ticket orders, so as to at least solve the problem of large alarm response delay in the existing alarm method for ticket orders.

[0004] On the one hand, an embodiment of the present disclosure provides an alarm system for ticket orders, including: at least one order application, a log service module, a configuration management module, a log collection module, an information processing module, a reach service module, and an alarm execution module; the system is configured to:

[0005] The order application sends alarm configuration information to the configuration management module;

[0006] The configuration management module configures the log collection module, the information processing module, and the reach service module based on the alarm configuration information;

[0007] The log collection module collects the application basic information and application operation logs corresponding to the order application stored in the log service module, and sends them to the information processing module; wherein, the application operation logs include the log information of the order application processing orders;

[0008] The information processing module determines that the order corresponding to the application operation log is an abnormal order based on at least one preset keyword included in the application operation log, generates alarm information, and sends the alarm information to the reach service module; wherein, the alarm information includes: the order number of the abnormal order and the abnormal information;

[0009] The reach service module receives the alarm information, forwards the alarm information to the alarm execution module, and configures the trigger of the alarm execution module according to the alarm configuration information.

[0010] On the other hand, an embodiment of the present disclosure also provides an alarm method for ticket orders, which is applied to the alarm system for ticket orders. The system includes: at least one order application, a log service module, a configuration management module, a log collection module, an information processing module, a reach service module, and an alarm execution module; the method includes:

[0011] The order application sends alarm configuration information to the configuration management module;

[0012] The configuration management module configures the log collection module, the information processing module, and the reach service module based on the alarm configuration information;

[0013] The log collection module collects the application basic information and the application operation logs corresponding to the order application stored in the log service module, and sends them to the information processing module; among them, the application operation logs include the log information of the order application processing the order;

[0014] Based on at least one preset keyword included in the application operation logs, the information processing module determines that the order corresponding to the application operation logs is an abnormal order, generates an alarm message, and sends the alarm message to the reach service module; among them, the alarm message includes: the order number and the abnormal information of the abnormal order;

[0015] The reach service module receives the alarm message, forwards the alarm message to the alarm execution module, and configures and triggers the alarm execution module according to the alarm configuration information.

[0016] On the other hand, an embodiment of the present disclosure further provides an alarm device for ticket orders, including:

[0017] A processor;

[0018] A memory storing computer-readable instructions;

[0019] Wherein, the processor is configured to execute the above method by executing the computer-readable instructions.

[0020] On the other hand, an embodiment of the present disclosure further provides a computer-readable storage medium storing computer-readable instructions, which, when executed by a processor, implement the above method.

[0021] On the other hand, an embodiment of the present disclosure further provides a computer program product including computer-readable instructions, which, when executed by a processor, implement the above method.

[0022] For the alarm system, method, device, medium, and product of the ticket orders of the present disclosure, the alarm configuration information is uniformly configured through the configuration management module, the application operation logs such as those stored in the log service module are collected by the log collection module, the abnormal orders are identified by the information processing module and the alarm messages are generated, and finally the reach service module configures and triggers the alarm execution module, so that when new monitoring points need to be added, there is no need to modify the application code and republish the system, the processing party can be notified in time when the application is abnormal, the alarm response delay can be reduced, the order number and the abnormal information of the abnormal order can be sent to the processing party at the same time, the processing efficiency can be improved, and the operation and maintenance cost of the alarm system can also be reduced. Description of the Drawings

[0023] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0024] Figure 1 It is a schematic diagram of an alarm system for ticket orders provided by an embodiment of the present disclosure;

[0025] Figure 2 is Figure 1 a schematic diagram of a configuration process of the alarm system for ticket orders in

[0026] Figure 3 It is a schematic structural diagram of an alarm system for ticket orders provided by an embodiment of the present disclosure;

[0027] Figure 4 It is a schematic diagram of a computer storage medium provided by an embodiment of the present disclosure. Detailed implementation manners

[0028] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Identical reference numerals in the figures denote identical or similar structures, and thus their repeated description will be omitted.

[0029] The terms "first", "second", and similar terms used in the detailed description do not denote any order, quantity, or importance, but are only used to distinguish different components. In addition, in the description of the present disclosure, the orientation or positional relationship indicated by terms such as "upper", "lower", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for convenience of description and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present disclosure.

[0030] It should be noted that, without conflict, the features in the embodiments of the present disclosure and those in different embodiments can be combined with each other.

[0031] As Figure 1 and Figure 2 shown, on the one hand, an embodiment of the present disclosure provides an alarm system for ticket orders, including: at least one order application, a log service module, a configuration management module, a log collection module, an information processing module, a reach service module, and an alarm execution module.

[0032] The alarm system of this ticket order is configured as follows:

[0033] S110. The order application sends the alarm configuration information to the configuration management module;

[0034] S120. The configuration management module configures the log collection module, the information processing module, and the reach service module based on the alarm configuration information;

[0035] S130. The log collection module collects the application basic information and application operation logs corresponding to the order application stored in the log service module, and sends them to the information processing module; among them, the application operation logs include the log information of the order application processing the order;

[0036] S140. The information processing module determines that the order corresponding to the application operation log is an abnormal order based on at least one preset keyword included in the application operation log, generates alarm information, and sends the alarm information to the reach service module; among them, the alarm information includes: the order number and abnormal information of the abnormal order;

[0037] S150. The reach service module receives the alarm information, forwards the alarm information to the alarm execution module, and configures the trigger of the alarm execution module according to the alarm configuration information.

[0038] Among them, Figure 1 the dotted line in represents the configuration interaction, and the solid line represents the system process interaction.

[0039] For the above-mentioned order application, as a business system instance to be monitored, it can be deployed in a distributed architecture, and each order application is responsible for processing the core business processes of air ticket orders (such as order creation, payment, ticket issuance, etc.). Each order application actively pushes the alarm configuration information (including log collection rules, keyword templates, alarm trigger conditions, etc.) to the configuration management module through a preset configuration interface. The above settings avoid the problem of having to redeploy the application when modifying the monitoring points in the traditional solution by separating the alarm configuration from the business code.

[0040] For the above-mentioned configuration management module, it receives and stores the alarm configuration information from the order application, and dynamically generates the following configuration policies: log collection policy, information processing rules, reach policy, etc. Among them, the log collection policy can define the collection period and log type of the log collection module. The information processing rules can send the keyword matching rules (preset keyword library) and abnormal classification algorithm parameters to the information processing module. The reach policy can set the trigger conditions (such as alarm level thresholds) and notification channels (SMS / email / internal IM) of the alarm execution module. Adopting a templated configuration mechanism, it supports multiple applications to share the same configuration template, realizing batch updates of monitoring policies.

[0041] For the above-mentioned log service module, as an independent log storage center, it receives and stores the running log data of each order application in real time, including application basic information and application running logs. The application basic information includes metadata such as application ID, service node IP, version number, etc.; the application running logs include log records generated during the order processing process, containing structured fields such as order number, operation time, business status code, exception stack information, etc.

[0042] For the above-mentioned log collection module, according to the collection policy issued by the configuration management module, it periodically pulls the log data of the target order application from the log service module. Specifically, it can include: incremental collection and data preprocessing. Incremental collection is to obtain the latest logs based on timestamps to avoid resource waste caused by full-volume data transmission. Data preprocessing is to format the logs (such as JSON conversion) and extract key fields (order number, exception description). The preprocessed log data stream is pushed to the information processing module.

[0043] For the above-mentioned information processing module, the core processing logic is divided into two stages: anomaly detection and alarm information encapsulation. In the anomaly detection stage, keyword matching is performed on each received log: the log text is compared with a preset keyword library (such as "payment timeout", "insufficient inventory"). If at least one keyword is hit, the order is determined to be an abnormal order. Generate raw alarm data: including the order number of the abnormal order (such as order number, ticket issuing order number) and abnormal information (abnormal type code, occurrence time). The alarm information encapsulation stage includes associating additional information and generating a detailed link. The process of associating additional information can extract the summary of associated information (such as user level, order amount) from the business database according to the order number. The process of generating a detailed link can generate a link that can jump to the order details for the processing personnel to quickly access the context data. Through keyword matching and data association, the problem of fragmented alarm information in the traditional solution can be solved.

[0044] For the above-mentioned reach service module, as an alarm distribution center, it can perform the following operations: receive the alarm information from the information processing module; dynamically select an alarm channel according to the reach policy of the configuration management module (such as giving priority to sending "high-priority order anomaly" to the mobile phone of the on-duty manager); trigger the alarm execution module and monitor the alarm status (such as confirming whether it has been read).

[0045] For the above-mentioned alarm execution module, it interfaces with external notification systems (such as SMS gateways, enterprise internal communication tools). The specific functions can include: rendering the alarm content according to a preset template (example template: [Emergency] Order {order number} has {abnormal type}, details: {link}); implementing a retry mechanism: if the first notification fails, resend according to the exponential backoff strategy; record the alarm reach status and generate a reach success rate report.

[0046] With the above settings of the present disclosure, the alarm configuration information is uniformly configured through the configuration management module, the application operation logs such as the storage of the log collection module and the log service module are collected, the information processing module identifies abnormal orders and generates alarm information, and finally reaches the service module to configure and trigger the alarm execution module. Therefore, when new monitoring points are needed, there is no need to modify the application code and republish the system. When the application is abnormal, the processing party can be notified in time, the alarm response delay can be reduced, the order number and abnormal information of the abnormal order can be sent to the processing party at the same time, the processing efficiency can be improved, and the operation and maintenance cost of the alarm system can also be reduced.

[0047] In some embodiments, the orders include: flight ticket orders, train ticket orders, ship ticket orders, hotel orders, etc., but are not limited thereto.

[0048] In some embodiments, the order number includes at least one of: order number or ticket issuing order number, but is not limited thereto. The abnormal information includes: the summary of the associated information of the order corresponding to the order number and the detail link, but is not limited thereto.

[0049] In some embodiments, the alarm system for ticket orders is further configured that: the information processing module classifies the abnormal orders, and the alarm information further includes the abnormal category of the abnormal order; wherein, the abnormal category includes: high-priority order abnormality, new abnormality, month-on-month growth abnormality, and attention abnormality. The high-priority order abnormality may refer to the abnormality of an order that has a greater impact on the platform business, a higher user attention, or a stricter customer service requirement. The new abnormality may refer to the abnormal situation that appears for the first time in the system monitoring, that is, a certain preset abnormal index is triggered for the first time in the current monitoring period. The month-on-month growth abnormality may refer to the situation where the number of abnormal orders shows a significant increase compared with the previous statistical period within a specific statistical period (such as daily, weekly, etc.). The attention abnormality may refer to a specific abnormal situation that the system or the processing personnel pay attention to according to the actual business needs (the processing personnel can pay attention to or cancel the attention to this kind of abnormality). In this embodiment, the information processing module is not only responsible for detecting abnormalities in the collected application operation logs, but also further classifies the abnormal orders after detecting the abnormal orders. That is, when the information processing module determines that a certain order is abnormal through keyword matching or other methods, in addition to generating alarm information including the order number and abnormal description, it will also classify the abnormal order according to the preset abnormal category. By adopting the above abnormal classification method, in addition to including the order number and basic abnormal description, the alarm information also clearly marks the abnormal category, enabling the processing personnel to quickly adopt different processing strategies according to the nature and priority of the abnormality. This embodiment effectively solves the problems of fragmented information and unclear priority in traditional alarms, thereby greatly improving the fault location efficiency, reducing the platform risks and economic losses caused by the delay in processing abnormal orders, and improving the user experience to a certain extent.

[0050] In some embodiments, the information processing module classifies abnormal orders into categories, including: the information processing module uses at least one string similarity calculation algorithm to calculate the similarity between the application operation log and the preset abnormal category string, and determines the abnormal category of the abnormal order by weighted calculation of different string similarity calculation algorithms. In this embodiment, the following steps may be specifically included:

[0051] First, preset anomaly category string library. The system predefines description strings or keyword templates corresponding to various anomalies (such as "payment timeout", "inadequate inventory", etc.), which serve as reference standards for determining anomaly categories.

[0052] Second, string similarity calculation. After detecting an abnormal log, the information processing module uses at least one string similarity calculation algorithm (such as Levenshtein Distance, Longest Common SubString, Cosine, etc.) to match the abnormal log text with the preset template. Each algorithm has its own advantages, which can avoid the limitations of a single algorithm in processing noise or text diversity.

[0053] Third, weighted calculation and judgment. To improve the accuracy of matching, the system performs weighted fusion on the results of multiple string similarity calculation algorithms. After comprehensively analyzing the matching scores of each algorithm, the system determines the similarity between the abnormal log and each preset abnormal category, and finally determines the abnormal category to which the abnormal order should belong.

[0054] This embodiment can more accurately identify and classify abnormal log information by introducing a weighted judgment method based on multiple string similarity calculation algorithms. Compared with a single matching rule, this method can effectively reduce the risk of misjudgment and missed judgment, and improve the intelligence and robustness of abnormal classification. When the system detects an abnormal log, it can automatically and accurately determine the abnormal category to which it belongs, so that subsequent alarm triggering and fault handling are more targeted and timely, effectively shortening the troubleshooting time, reducing the platform operation and maintenance costs, and to a certain extent preventing economic losses and customer complaints caused by delayed responses.

[0055] In some embodiments, the warning system for ticket orders is further configured to: horizontally aggregate the application running logs applied to at least two orders based on the order number and order characteristic attributes to generate a warning message; wherein, the order characteristic attributes include: order usage time, user level, latest ticket issuing time of the order, supplier contracted service package information, order amount, and order profit. In this embodiment, the dimension for generating warning messages is further expanded, no longer limited to the log data processing within a single order application, but by horizontally aggregating, the application running logs from at least two order applications are integrated according to the "order number" and "order characteristic attributes" to generate a unified warning message. Among them, each order has a unique identifier (such as an order number or a ticket issuing order number) in each order application, and this identifier serves as the basis for horizontal aggregation. By horizontally aggregating the log data from different order applications, this embodiment can form a comprehensive order view, making the information of abnormal orders more complete and facilitating the quick confirmation of the problem cause. The aggregated warning message integrates the key characteristic attributes together, and the processing personnel can quickly judge the severity of the abnormal order based on these detailed information, so as to take targeted handling measures and shorten the troubleshooting and response time.

[0056] In some embodiments, the warning system for ticket orders is further configured to: the configuration management module saves the templatized configuration of the order application, and multiple order applications perform warning configuration based on the same templatized configuration to form warning configuration information; the configuration management module manages the warning configuration information of the log collection module, the information processing module, and the reach service module. Among them, the templatized configuration contains various configuration information required by the warning system, such as log collection rules, key information extraction strategies, warning trigger conditions, and notification methods, etc. Multiple order applications do not need to configure warning rules independently, but perform warning settings based on the same templatized configuration, so as to form unified warning configuration information. The configuration management module distributes the strategies in the templatized configuration to the log collection module, the information processing module, and the reach service module to ensure that they adopt the same rules when performing log collection, anomaly detection, and warning notification. In this way, when the warning monitoring requirements change or new monitoring points are added, only the templatized configuration needs to be modified to synchronously update all relevant modules, without the need to modify the code and republish the system for each order application separately. This embodiment can achieve unified management of the warning system for ticket orders, reduce the complexity and operation and maintenance costs of the system, improve the consistency and stability of the system, and enable the system to respond quickly and expand flexibly.

[0057] Continue to refer to Figure 1 and Figure 2, on the other hand, embodiments of the present disclosure further provide an alarm method for ticket orders, which is applied to an alarm system for ticket orders. The alarm system for ticket orders includes: at least one order application, a log service module, a configuration management module, a log collection module, an information processing module, a reach service module, and an alarm execution module.

[0058] The alarm method for ticket orders includes the following steps:

[0059] S110. The order application sends alarm configuration information to the configuration management module;

[0060] S120. The configuration management module configures the log collection module, the information processing module, and the reach service module based on the alarm configuration information;

[0061] S130. The log collection module collects the application basic information and application operation logs corresponding to the order application stored in the log service module, and sends them to the information processing module; wherein, the application operation logs include log information of the order application processing orders;

[0062] S140. The information processing module determines that the order corresponding to the application operation log is an abnormal order based on at least one preset keyword included in the application operation log, generates alarm information, and sends the alarm information to the reach service module; wherein, the alarm information includes: the order number of the abnormal order and the abnormal information;

[0063] S150. The reach service module receives the alarm information, forwards the alarm information to the alarm execution module, and configures to trigger the alarm execution module according to the alarm configuration information.

[0064] For the specific technical solutions and technical effects of the alarm method for ticket orders of the present disclosure, reference can be made to the embodiments of the alarm method for ticket orders described above, and details are not elaborated here.

[0065] As Figure 3 shown, on another aspect, embodiments of the present disclosure further provide an alarm device for ticket orders, including: a processor; a memory storing computer-readable instructions. Wherein, the processor is configured to execute the alarm method for ticket orders by executing the computer-readable instructions.

[0066] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation manner, a complete software implementation manner (including firmware, microcode, etc.), or an implementation manner combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "platform" here.

[0067] Next, with reference to Figure 3Describe the electronic device 600 according to this embodiment of the present disclosure. Figure 3 The displayed electronic device 600 is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0068] As Figure 3 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different platform components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.

[0069] Among them, the storage unit 620 stores computer-readable instructions, which can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present disclosure described in the method part of this specification. For example, the processing unit 610 can execute the steps as Figure 2 shown.

[0070] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.

[0071] The storage unit 620 may also include a program / utilities 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.

[0072] The bus 630 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0073] The electronic device 600 can also communicate with one or more external devices 700 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 600, and / or communicate with any device (such as a router, a modem, etc.) that enables the electronic device 600 to communicate with one or more other computing devices. Such communication can be carried out through the input / output (I / O) interface 650. Moreover, the electronic device 600 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 can communicate with other modules of the electronic device 600 through the bus 630. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms, etc.

[0074] For the warning device of the ticket order of the present disclosure, its specific technical solution and technical effect can refer to the embodiments of the warning method of the ticket order described above, and will not be elaborated here.

[0075] As Figure 4 shown, on the other hand, an embodiment of the present disclosure also provides a computer-readable storage medium, which stores computer-readable instructions. The processor of the computing device can read the computer-readable instructions from the computer-readable storage medium, and the processor executes the computer-readable instructions, so that the computing device executes the warning method of the ticket order described in each of the above embodiments.

[0076] The computer-readable storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0077] A computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable instructions. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer-readable instructions contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0078] The computer-readable instructions included in the computer-readable storage medium of the embodiments of the present disclosure may be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages - such as Java, C++, etc., and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0079] For the specific technical solutions and technical effects of the computer-readable storage medium of the present disclosure, reference may be made to the embodiments of the foregoing warning method for ticket orders, which will not be elaborated herein.

[0080] In another aspect, the embodiments of the present disclosure also provide a computer program product, which includes computer-readable instructions stored in a computer-readable storage medium. The processor of the computing device may read the computer-readable instructions from the computer-readable storage medium, and the processor executes the computer-readable instructions, causing the computing device to execute the warning method for ticket orders described in the foregoing various embodiments.

[0081] For the specific form of writing of the computer-readable instructions included in the computer program product of the embodiments of the present disclosure in a programming language, reference may be made to the computer-readable instructions included in the foregoing embodiments of the computer-readable storage medium, which will not be elaborated herein.

[0082] For the specific technical solutions and technical effects of the computer program product of the present disclosure, reference may be made to the embodiments of the foregoing warning method for ticket orders, which will not be elaborated herein.

[0083] The above content is a further detailed description of the present disclosure in combination with specific optional embodiments. It cannot be determined that the specific implementation of the present disclosure is only limited to these descriptions. For those of ordinary skill in the technical field to which the present disclosure pertains, without departing from the concept of the present disclosure, several simple deductions or substitutions can also be made, and all should be regarded as belonging to the protection scope of the present disclosure.

Claims

1. A ticket order alarm system, characterized in that: include: At least one order application, log service module, configuration management module, log collection module, information processing module, contact service module and alarm execution module; The system is configured to: The order application sends the alarm configuration information to the configuration management module; The configuration management module configures the log collection module, the information processing module and the contact service module based on the alarm configuration information; The log collection module collects the basic application information and application operation log corresponding to the order application stored in the log service module, and sends them to the information processing module; wherein the application operation log includes the log information of the order application processing the order; The information processing module determines that the order corresponding to the application operation log is an abnormal order based on at least one preset keyword in the application operation log, generates an alarm message, and sends the alarm message to the contact service module; wherein the alarm message includes: the order number and abnormal information of the abnormal order; The contact service module receives the alarm information, forwards the alarm information to the alarm execution module, and triggers the alarm execution module according to the alarm configuration information configuration.

2. The ticket order warning system according to claim 1, characterized in that: The order number includes: at least one of an order number or a ticket number; The abnormal information includes: a summary of associated information and a detail link of the order corresponding to the order number.

3. The ticket order warning system according to claim 1, characterized in that: The system is also configured to: The information processing module categorizes the abnormal orders, and the alarm information also includes the abnormal categories of the abnormal orders; wherein the abnormal categories include: high-priority order abnormalities, new abnormalities, month-on-month growth abnormalities, and attention abnormalities.

4. The ticket order warning system according to claim 3, characterized in that: The information processing module classifies the abnormal orders into categories, including: The information processing module uses at least one string similarity calculation algorithm to calculate the similarity between the application operation log and a preset abnormal category string, and determines the abnormal category of the abnormal order by weighted calculation of different string similarity calculation algorithms.

5. The ticket order warning system according to claim 1, characterized in that: The system is also configured to: Based on the order number and order characteristic attributes, the application operation logs from at least two of the order applications are horizontally aggregated to generate one alarm message; wherein the order characteristic attributes include: order usage time, user level, latest ticket issuance time of the order, supplier contract service package information, order amount and order profit.

6. The ticket order warning system according to claim 1, characterized in that: The system is also configured to: The configuration management module saves the templated configuration of the order application, and multiple order applications perform alarm configuration based on the same templated configuration to form the alarm configuration information; The configuration management module manages the alarm configuration information of the log collection module, the information processing module and the contact service module.

7. A ticket order alarm method, characterized in that: An alarm system applied to ticket orders, the system comprising: at least one order application, a log service module, a configuration management module, a log collection module, an information processing module, a contact service module and an alarm execution module; the method comprising: The order application sends the alarm configuration information to the configuration management module; The configuration management module configures the log collection module, the information processing module and the contact service module based on the alarm configuration information; The log collection module collects the basic application information and application operation log corresponding to the order application stored in the log service module, and sends them to the information processing module; wherein the application operation log includes the log information of the order application processing the order; The information processing module determines that the order corresponding to the application operation log is an abnormal order based on at least one preset keyword in the application operation log, generates an alarm message, and sends the alarm message to the contact service module; wherein the alarm message includes: the order number and abnormal information of the abnormal order; The contact service module receives the alarm information, forwards the alarm information to the alarm execution module, and triggers the alarm execution module according to the alarm configuration information configuration.

8. A ticket order alarm device, characterized in that: include: processor; a memory storing computer-readable instructions; Wherein the processor is configured to perform the method according to claim 7 via executing the computer readable instructions.

9. A computer-readable storage medium storing computer-readable instructions, characterized in that: When the computer readable instructions are executed by a processor, the method according to claim 7 is implemented.

10. A computer program product comprising computer readable instructions, characterized in that: When the computer readable instructions are executed by a processor, the method according to claim 7 is implemented.