Alarm convergence method and system combined with knowledge graph

By combining the alarm convergence method of the knowledge graph, using text similarity, time interval and knowledge graph association relationship, the problem of flooding alarm information in the database performance monitoring system is solved, and more efficient and accurate alarm processing is achieved.

CN120104807AActive Publication Date: 2025-06-06BEIJING XINSHU TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510186350.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-06
Estimated Expiration
2045-02-20

AI Technical Summary

Technical Problem

When faced with a large number of alarms, the existing database performance monitoring system has a high false alarm rate and a flood of alarm information, making it difficult for operation and maintenance personnel to locate and solve problems.

Method used

The alarm convergence method combined with the knowledge graph is adopted, and the comprehensive calculation of text similarity, time interval and knowledge graph correlation relationship is combined to improve the accuracy and efficiency of alarm convergence.

Benefits of technology

It effectively reduces the number of alarms that operation and maintenance personnel need to deal with, improves work efficiency, and improves the accuracy of alarm processing by deeply understanding the internal connection between alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104807A_ABST
    Figure CN120104807A_ABST
Patent Text Reader

Abstract

The invention provides an alarm convergence method and system combined with a knowledge graph, introduces the knowledge graph to express the incidence relation between alarms, and provides an alarm similarity calculation method combined with text similarity, time intervals and the incidence relation of the knowledge graph. By means of the method, the similarity between alarms can be judged more accurately, and therefore the accuracy and efficiency of alarm convergence are improved. According to the method, the association relationship in the alarm content, the time and the knowledge graph is comprehensively considered, and the similar alarms are grouped, so that the number of alarms needing to be processed by operation and maintenance personnel is reduced, and the working efficiency is improved. Due to the fact that the complex incidence relation in the knowledge graph is used, the internal relation between the alarms is easy to understand deeply, the process of merging and converging the alarms is more accurate, and the accuracy of processing the alarms is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an alarm convergence method and system combined with a knowledge graph, and belongs to the field of database monitoring. Background Art

[0002] In the digital and information age, databases are the storage and management centers for data in various sectors of society, and the stability of database performance is crucial to the normal operation of the business. Therefore, real-time monitoring of database performance is an important task in the field of database operation and maintenance, and the database performance monitoring system developed based on this has also become a compulsory course for database managers.

[0003] However, as the number of controlled databases increases, the size of databases expands, and the complexity of data increases, the alarms triggered by traditional monitoring systems often have problems such as high false alarm rates and excessive alarm information. If the monitoring system triggers a small number of alarms, database administrators can easily locate and solve the problem; if the monitoring system triggers a large number of alarms, database administrators will be overwhelmed by the alarm information and unable to locate the problem, and there is no way to solve the problem.

[0004] When a large number of alarms appear, analysis can reveal that many of them have some correlations, including causal relationships, co-occurrence relationships, and similarity relationships. Therefore, for the database performance monitoring platform, it is necessary not only to issue timely alarms when performance problems occur in the database, but also to be able to analyze the alarms that appear, that is, to provide alarm convergence function.

[0005] The alarm convergence function is becoming increasingly important in current database performance monitoring platforms. This function aims to merge a large number of repeated and related alarm information into a small number of meaningful alarms through intelligent analysis and processing, thereby helping operation and maintenance personnel to quickly locate problems and improve operation and maintenance efficiency.

[0006] The key link in realizing the alarm convergence function is to calculate the similarity / correlation between different alarms. When the similarity / correlation exceeds the threshold, the different alarms are closely related and can be merged. The existing alarm convergence function often calculates the similarity / correlation between different alarms based on the text description of the alarm. Because the text description is relatively short and the description content may not be comprehensive and accurate, the calculation accuracy based on the text description of the alarm is generally low. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 This is a system structure diagram of the present invention.

[0008] Figure 2 The figure is a flow chart of the method of the present invention. Summary of the invention

[0009] To solve the above technical problems, the present invention proposes an alarm convergence method combined with a knowledge graph, which introduces a knowledge graph to express the association between alarms, and proposes an alarm similarity calculation method that combines text similarity, time interval and knowledge graph association. Through this method, the similarity between alarms can be judged more accurately, thereby improving the accuracy and efficiency of alarm convergence. The method includes the following steps:

[0010] (1) Alarm collection: Receive alarm information from various alarm data sources, format the alarm data, and store the processed alarm data in the system;

[0011] (2) Alarm analysis: including text similarity calculation, time interval calculation and knowledge graph analysis; the similarity between alarms is calculated based on the alarm text; the time interval calculation counts the time interval between alarms to determine whether the alarms occur continuously in a short period of time; the knowledge graph analysis uses the knowledge graph to calculate the correlation between alarms;

[0012] (3) Alarm convergence: Combine text similarity, time interval, and knowledge graph to calculate the comprehensive similarity between alarms. Based on the similarity calculation results, similar alarms are merged into one alarm. Finally, the converged alarm information is stored.

[0013] (4) Alarm display: The alarm information after convergence is displayed through a visual interface;

[0014] (5) Alarm configuration management: provides alarm threshold setting and alarm level management functions;

[0015] Further, step (3) comprises the following steps:

[0016] 3.1 Alarm grouping: Read all alarm data and group alarms according to different database instances. When calculating alarm similarity in the subsequent steps, the calculation is performed between alarms within the same database instance, and finally the grouped alarm set is output;

[0017] 3.2 Select alarm pairs: traverse each group and select two alarms in each group that have not been similarity calculated, and send them to step 3.3 for similarity calculation; select alarm a from the alarm set of a group i and a j Perform similarity calculation, where a i and a j Respectively represent the i-th and j-th alarms in the alarm set. In the first iteration, select any two alarms as the starting point; in subsequent iterations, select two alarms that have not been similarly calculated with each other; if all the alarms in each group have participated in the calculation, jump to step 3.6;

[0018] 3.3 Calculate alarm similarity:

[0019] Use the TF-IDF method to convert the text into a vector, and then calculate the two vectors a i and a j The cosine angle between them is the text similarity textsim(a i ,a j );

[0020] Calculate two alarms a i and a j The time interval between in,

[0021]

[0022] decay() is the decay function, a i .time and a j .time are respectively alarm a i and a j The occurrence time of decay(a i .time) and decay(a j .time) are respectively based on a i .time and a j .time is the decay function value calculated; λ is the decay rate, λ>0; time() is the current time; Δt is the preset time threshold;

[0023] Calculate two alarms a i and a j The degree of correlation between in, d(a i ,a j ) is an alarm a i and a j The shortest path length in the knowledge graph, w(a i ,a j ) is the sum of the weights of all edges on the shortest path, cn(a i ,a j ) is an alarm a i and a j The number of common neighbors of

[0024] Calculation alarm a i and a j The comprehensive alarm similarity sim(a i ,a j )=α×textsim(a i ,aj )+β×timesim(a i ,a j )+γ×graphsim(a i ,a j ), where α, β and γ are weight coefficients, 0<α<1, 0<β<1, 0<γ<1, and α+β+γ=1;

[0025] 3.4 Determining Similarity

[0026] sim(a i ,a j )≥threshold, go to step 3.5; otherwise, return to step 3.2 and continue to process the next pair of alarms, where threshold is the preset similarity threshold;

[0027] 3.5 Merge Alarms

[0028] If two alarms a i and a j similar, mark them and jump to step 3.2;

[0029] 3.6 Output merged alarms: Output the final merged alarm set according to the tags.

[0030] Based on the above method, the present invention further proposes an alarm convergence system combined with a knowledge graph, which includes an alarm collection module, an alarm analysis module, an alarm convergence module, an alarm display module and an alarm configuration management module:

[0031] (1) Alarm collection module: This module receives alarm information from various alarm data sources, formats the alarm data, and stores the processed alarm data in the system;

[0032] (2) Alarm analysis module: This module includes a text similarity calculation submodule, a time interval calculation submodule, and a knowledge graph analysis submodule; the text similarity calculation submodule calculates the similarity between alarms based on the alarm text; the time interval calculation submodule counts the time intervals between alarms to determine whether the alarms occur continuously in a short period of time; the knowledge graph analysis submodule uses the knowledge graph to calculate the correlation between alarms;

[0033] (3) Alarm convergence module: This module combines text similarity, time interval and knowledge graph to calculate the comprehensive similarity between alarms. Based on the similarity calculation results, similar alarms are merged into one alarm. Finally, the converged alarm information is stored.

[0034] (4) Alarm display module: This module displays the alarm information after convergence through a visual interface;

[0035] (5) Alarm configuration management module: This module provides alarm threshold setting and alarm level management functions;

[0036] Furthermore, the alarm convergence module includes the following steps:

[0037] 3.1 Alarm grouping: Read all alarm data and group alarms according to different database instances. When calculating alarm similarity in the subsequent steps, the alarms within the same database instance are calculated, and the grouped alarm set is finally output.

[0038] 3.2 Select alarm pairs: traverse each group and select two alarms in each group that have not been similarity calculated, and send them to step 3.3 for similarity calculation; select alarm a from the alarm set of a group i and a j Perform similarity calculation, where a i and a j Respectively represent the i-th and j-th alarms in the alarm set. In the first iteration, select any two alarms as the starting point; in subsequent iterations, select two alarms that have not been similarly calculated with each other; if all the alarms in each group have participated in the calculation, jump to step 3.6.

[0039] 3.3 Calculate alarm similarity:

[0040] Use the TF-IDF method to convert the text into a vector, and then calculate the two vectors a i and a j The cosine angle between them is the text similarity textsim(a i ,a j );

[0041] Calculate two alarms a i and a j The time interval between in,

[0042]

[0043] decay() is the decay function, a i .time and a j .time are respectively alarm a i and a j The occurrence time of decay(a i .time) and decay(a j .time) are respectively based on a i .time and a j.time is the decay function value calculated; λ is the decay rate, λ>0; time() is the current time; Δt is the preset time threshold.

[0044] Calculate two alarms a i and a j The degree of correlation between in, d(a i ,a j ) is an alarm a i and a j The shortest path length in the knowledge graph, w(a i ,a j ) is the sum of the weights of all edges on the shortest path, cn(a i ,a j ) is an alarm a i and a j The number of common neighbors of

[0045] Calculation alarm a i and a j The comprehensive alarm similarity sim(a i ,a j )=α×textsim(a i ,a j )+β×timesim(a i ,a j )+γ×graphsim(a i ,a j ), where α, β and γ are weight coefficients, 0<α<1, 0<β<1, 0<γ<1, and α+β+γ=1;

[0046] 3.4 Determining Similarity

[0047] sim(a i ,a j )≥threshold, go to step 3.5; otherwise, return to step 3.2 and continue to process the next pair of alarms, where threshold is the preset similarity threshold;

[0048] 3.5 Merge Alarms

[0049] If two alarms a i and a j similar, mark them and jump to 3.2;

[0050] 3.6 Output merged alarms: Output the final merged alarm set according to the tags.

[0051] The present invention comprehensively considers the alarm content, time and the association relationship in the knowledge graph, groups similar alarms, and helps reduce the number of alarms that operation and maintenance personnel need to handle and improve work efficiency. Since the complex association relationship in the knowledge graph is used, it is easy to deeply understand the internal connection between alarms, which makes the process of alarm merging and convergence more precise and improves the accuracy of alarm processing. DETAILED DESCRIPTION

[0052] Example 1

[0053] The present invention proposes an alarm convergence method combined with a knowledge graph, which introduces a knowledge graph to express the association between alarms, and proposes an alarm similarity calculation method that combines text similarity, time interval and knowledge graph association. Through this method, the similarity between alarms can be judged more accurately, thereby improving the accuracy and efficiency of alarm convergence.

[0054] Based on the alarm convergence method combined with knowledge graph, an alarm convergence system is designed and implemented. The structure diagram of the system is shown in the figure Figure 1 shown.

[0055] The alarm convergence combined with the knowledge graph mainly includes the alarm collection module, alarm analysis module, alarm convergence module, alarm display module and alarm configuration management module. The introduction of each module is as follows:

[0056] (1) Alarm collection module: This module receives alarm information from various alarm data sources, formats the alarm data, and stores the processed alarm data in the system.

[0057] (2) Alarm analysis module: This module mainly includes three parts: text similarity calculation, time interval calculation and knowledge graph analysis. Text similarity calculation calculates the similarity between alarms based on the alarm text; time interval calculation counts the time interval between alarms to determine whether the alarms occur continuously in a short period of time; knowledge graph analysis uses the knowledge graph to calculate the correlation between alarms.

[0058] (3) Alarm convergence module: First, the comprehensive similarity between alarms is calculated by combining text similarity, time interval and knowledge graph. Then, based on the similarity calculation results, similar alarms are merged into one alarm. Finally, the converged alarm information is stored.

[0059] (4) Alarm display module: displays the alarm information after convergence through a visual interface.

[0060] (5) Alarm configuration management: This module provides functions such as alarm threshold setting and alarm level management.

[0061] In the alarm analysis module of the above alarm convergence system, an alarm convergence method combined with knowledge graph is adopted. The flowchart of this method is as follows: Figure 2 shown.

[0062] The core steps of the alarm convergence method combined with knowledge graph include:

[0063] (1) Alarm grouping: In this step, all alarm data is read and the alarms are grouped according to different database instances. When calculating the alarm similarity in the subsequent step, it is only calculated between alarms within the same database instance. This step finally outputs the grouped alarm set.

[0064] (2) Select alarm pairs: traverse each group and select two alarms in each group that have not been similarity calculated, and send them to step (3) for similarity calculation. For example: select two alarms a from the alarm set of a group. i and a j Perform similarity calculation, where a i and a j Respectively represent the i-th and j-th alarms in the alarm set. In the first iteration, any two alarms can be selected as starting points; in subsequent iterations, two alarms that have not been similarly calculated are selected.

[0065] If all the alarms in each group have participated in the calculation, then jump to step (6) to complete the alarm convergence process.

[0066] (3) Calculate alarm similarity: This step calculates the similarity between two alarms (such as a i and a j ), in the calculation process, the text similarity, time interval and the association relationship based on the knowledge graph are calculated separately.

[0067] 1) Text similarity is used to measure the similarity between two alarm contents. This part uses cosine similarity to calculate, that is, the TF-IDF method is used to convert the text into a vector representation, and then the cosine angle between the two vectors is calculated. The smaller the angle, the higher the similarity. i and a j ) is expressed as textsim(a i ,a j ).

[0068] 2) The time interval is used to indicate the closeness between the occurrence times of two alarms. i .time and a j .time respectively indicates alarm a i and a jThe occurrence time of two alarms a i and a j The time interval timesim(a i ,a j ) The calculation method can be expressed as:

[0069]

[0070] in,

[0071]

[0072] Where decay() is the decay function, decay(a i .time) and decay(a j .time) respectively represent the i .time and a j .time is the decay function value calculated; λ is the decay rate, λ>0, which controls the decay speed; time() represents the current time; Δt is the preset time threshold, which is used to indicate the size of the time window.

[0073] 3) When calculating the association relationship based on the knowledge graph, the alarm knowledge graph in the system is relied on. The alarm knowledge graph is used to represent the association relationship between alarms and provide empirical support for alarm convergence. In the alarm knowledge graph, nodes represent alarms and edges represent the association relationship between alarms. The main attributes of edges include type and weight, where the type represents the type of association relationship between alarms, such as causal relationship, co-occurrence relationship, etc., and the weight represents the strength of the association relationship, which is set based on expert experience.

[0074] In the alarm knowledge graph, the shorter the shortest path length of the alarm nodes in the knowledge graph, the closer the association between them is; the weight on the path can indicate the strength of the association between alarms, such as causal relationships usually have higher weights than co-occurrence relationships; the more common neighbors the alarm nodes have in the knowledge graph, the closer the association between them is. Based on this, the strength of the association relationship based on the knowledge graph is quantified using the graphsim function. i ,a j ) indicates two alarms a i and a j The degree of correlation between them is calculated as follows:

[0075]

[0076] in,

[0077]

[0078] Among them, d(ai ,a j ) indicates an alarm a i and a j The shortest path length in the knowledge graph, w(a i ,a j ) represents the sum of the weights of all edges on the shortest path, cn(a i ,a j ) indicates an alarm a i and a j The number of common neighbors.

[0079] Based on the alarm a calculated above i and a j The text similarity between i ,a j ), time interval timesim(a i ,a j ) and the degree of association based on the knowledge graph graphsim (a i ,a j ), the alarm a can be calculated i and a j The comprehensive alarm similarity sim(a i ,a j ), which is calculated as:

[0080] sim(a i ,a j )=α*textsim(a i ,a j )+β*timesim(a i ,a j )+γ*graphsim(a i ,a j )

[0081] Among them, α, β and γ are weight coefficients used to adjust the contribution of different similarity components to the total similarity, 0<α<1, 0<β<1, 0<γ<1, and satisfy α+β+γ=1.

[0082] (4) Determine similarity

[0083] Check the comprehensive alarm similarity sim(a i ,a j ) is greater than or equal to the preset similarity threshold threshold. i ,a j )≥threshold, the process goes to the "Merge alarms" step; otherwise, the process returns to the "Select alarm pair" step and continues to process the next pair of alarms.

[0084] (5) Merge alarms

[0085] If two alarms a i and a j If they are similar, they are marked and then go to step (2).

[0086] (6) Output the merged alarm

[0087] Output the final merged alarm set according to the tags.

[0088] The above alarm convergence method combined with knowledge graph can group similar alarms by comprehensively considering the alarm content, time and the association relationship in the knowledge graph, which helps to reduce the number of alarms that operation and maintenance personnel need to handle and improve their work efficiency. More importantly, due to the use of complex associations in the knowledge graph, it is easy to deeply understand the internal connection between alarms, which makes the alarm merging and convergence process more precise and improves the accuracy of alarm processing.

[0089] Example 2

[0090] The alarm convergence method combined with the knowledge graph is the core of the present invention. Therefore, the embodiment part focuses on describing the calculation process of the method.

[0091] Assume there are two alarms a 1 and a 2 , they are from the monitoring of the same database instance.

[0092] (1) Alarm a 1 The information is as follows:

[0093] 1) Content: Database connection pool exhausted

[0094] 2) Timestamp: 2023-10-23 10:00:00

[0095] Alarma 1 Position in the knowledge graph: with alarm a 3 (Content is "Database query timeout") has a causal relationship (weight is 0.8) with alarm a 4 (The content is "Server load is too high") has a co-occurrence relationship (weight is 0.5).

[0096] (2) Alarm a 2 The information is as follows:

[0097] 1) Content: Database query performance degraded, suspected connection pool problem

[0098] 2) Timestamp: 2023-10-23 10:10:00

[0099] Alarma2 Position in the knowledge graph: with alarm a 1 There is a co-occurrence relationship (weight is 0.7) with alarm a 4 There is a co-occurrence relationship (weight is 0.5).

[0100] For the above alarm information, the detailed calculation steps of the alarm convergence method combined with the knowledge graph are as follows:

[0101] (1) Alarm grouping: Due to alarm a 1 and a 2 They come from the same database instance, so they are grouped into the same alarm set.

[0102] (2) Select an alarm pair: Assume alarm a 1 and a 2 The similarity has not been calculated before, so this time we choose to warn a 1 and a 2 Perform similarity calculation.

[0103] (3) Calculate alarm similarity: This step calculates the similarity of two alarms a 1 and a 2 The similarity between them is calculated by combining the text similarity, time interval and the association relationship based on the knowledge graph.

[0104] 1) Text similarity is used to measure the similarity between two alarm contents. Use TF-IDF to convert the alarm contents into vectors and calculate the cosine similarity. Assume that textsim(a 1 ,a 2 )The calculated result is 0.8.

[0105] 2) The time interval is used to indicate the closeness between the occurrence times of two alarms.

[0106] From two alarms a 1 and a 2 From the basic information, we can see that two alarms a 1 and a 2 The time difference is 10 minutes, that is, |a 1 .time–a 2 .time|=10 minutes. Assume Δt is 60 minutes, λ is 0.01, and the decay function decay(a 1 .time) and decay(a 2 .time) can be approximated to 1 in this case.

[0107] According to this, timesim(a 1 ,a 2 )=max(0,(1-0 / 60)*1)≈0.83.

[0108] 3) When calculating the association relationship based on the knowledge graph, it relies on the alarm knowledge graph in the system.

[0109] From two alarms a 1 and a 2 From the basic information of the alarm knowledge graph, we can see that because the alarm a 1 and a 2 There is a direct connection between them, so the shortest path length between them is 1, and the path weight w(a 1 ,a 2 ) is 0.7. Alarm a 1 and a 2 The common neighbor cn(a 1 ,a 2 ) contains the warning a 4 , so cn(a 1 ,a 2 )=1. Therefore,

[0110]

[0111] Based on the alarm a calculated above 1 and a 2 The text similarity between 1 ,a 2 ), time interval timesim(a 1 ,a 2 ) and the degree of association based on the knowledge graph graphsim (a 1 ,a 2 ), assuming weight coefficients α = 0.5, β = 0.3, γ = 0.2, we can calculate alarm a 1 and a 2 The comprehensive alarm similarity sim(a 1 ,a 2 )for:

[0112] sim(a 1 ,a 2 )=0.5*0.8+0.3*0.83+0.2*0.15=0.679

[0113] (4) Determine similarity

[0114] Assume that the preset similarity threshold is 0.6, because sim(a 1 ,a 2 )=0.679≥threshold, so alarm a is judged 1 and a 2 are similar.

[0115] (5) Merge alarms

[0116] Two alarms a 1 and a 2 Similarly, mark them and then jump to step (2).

[0117] (6) Output the merged alarm

[0118] Similar alarms are grouped and output according to tags for further processing by operation and maintenance personnel.

[0119] From this example, we can see that this method can comprehensively consider text similarity, time interval and association relationships based on the knowledge graph to more comprehensively and accurately evaluate the similarity between alarms. In particular, after the introduction of the alarm knowledge graph, based on the alarm association relationships in the knowledge graph, it is possible to identify alarms that actually describe the same or related problems although the text content is not exactly the same, thereby improving the accuracy of alarm convergence.

[0120] The units, devices or modules described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. For the convenience of description, the above devices are described separately by functions divided into various modules. Of course, when implementing this application, the functions of each module can be implemented in the same or more software and / or hardware, or the modules that implement the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0121] Those skilled in the art also know that, in addition to implementing the controller in a purely computer-readable program code, the controller can be made to implement the same function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered as a hardware component, and the devices for implementing various functions included therein can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules for implementing the method and structures within the hardware component.

[0122] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0123] It can be known from the description of the above implementation methods that those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application can be essentially or partly contributed to the prior art in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes several instructions for enabling a computer device (which can be a personal computer, a mobile terminal, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application or certain parts of the embodiments.

[0124] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc.

[0125] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.

Claims

1. An alarm convergence method combined with a knowledge graph, the method comprising the following steps: (1) Alarm collection: Receive alarm information from various alarm data sources, format the alarm data, and store the processed alarm data in the system; (2) Alarm analysis: including text similarity calculation, time interval calculation, and knowledge graph analysis; (3) Alarm convergence: Combine text similarity, time interval, and knowledge graph to calculate the comprehensive similarity between alarms. Based on the similarity calculation results, similar alarms are merged into one alarm. Finally, the converged alarm information is stored. (4) Alarm display: The alarm information after convergence is displayed through a visual interface; (5) Alarm configuration management: provides alarm threshold setting and alarm level management functions; Its characteristics are as follows: in alarm analysis, the similarity between alarms is calculated based on the alarm text; time interval calculation counts the time interval between alarm occurrences to determine whether the alarms occur continuously in a short period of time; knowledge graph analysis uses the knowledge graph to calculate the correlation between alarms.

2. The method for alarm convergence combined with knowledge graph according to claim 1, characterized in that: Step (3) The following steps are involved: 3.1 Alarm grouping: Read all alarm data and group alarms according to different database instances. When calculating alarm similarity in the subsequent steps, the calculation is performed between alarms within the same database instance, and finally the grouped alarm set is output; 3.2 Select alarm pairs: traverse each group and select two alarms in each group that have not been similarity calculated, and send them to step 3.3 for similarity calculation; select alarm a from the alarm set of a group i and a j Perform similarity calculation, where a i and a j Respectively represent the i-th and j-th alarms in the alarm set. In the first iteration, select any two alarms as the starting points; in subsequent iterations, select two alarms that have not been similarly calculated with each other; If all alarms in each group have participated in the calculation, jump to step 3.6; 3.3 Calculate alarm similarity: Use the TF-IDF method to convert the text into a vector, and then calculate the two vectors a i and a j The cosine angle between them is the text similarity textsim(a i ,a j ); Calculate two alarms a i and a j The time interval between in, decay() is the decay function, a i .time and a j .time are respectively alarm a i and a j The occurrence time of decay(a i .time) and decay(a j .time) are respectively based on a i .time and a j .time is the decay function value calculated; λ is the decay rate, λ>0; time() is the current time; Δt is the preset time threshold; Calculate two alarms a i and a j The degree of correlation between in, d(a i ,a j ) is an alarm a i and a j The shortest path length in the knowledge graph, w(a i ,a j ) is the sum of the weights of all edges on the shortest path, cn(a i ,a j ) is an alarm a i and a j The number of common neighbors of Calculation alarm a i and a j The comprehensive alarm similarity sim(a i ,a j )=α×textsim(a i ,a j )+β×timesim(a i ,a j )+γ×graphsim(a i ,a j ), where α, β and γ are weight coefficients, 0<α<1, 0<β<1, 0<γ<1, and α+β+γ=1; 3.4 Determining Similarity sim(a i ,a j )≥threshold, go to step 3.5; otherwise, return to step 3.2 and continue to process the next pair of alarms, where threshold is the preset similarity threshold; 3.5 Merge Alarms If two alarms a i and a j similar, mark them and jump to step 3.2; 3.6 Output merged alarms: Output the final merged alarm set according to the tags.

3. An alarm convergence system combined with a knowledge graph, the system includes an alarm collection module, an alarm analysis module, an alarm convergence module, an alarm display module and an alarm configuration management module: (1) Alarm collection module: This module receives alarm information from various alarm data sources, formats the alarm data, and stores the processed alarm data in the system; (2) Alarm analysis module: This module includes a text similarity calculation submodule, a time interval calculation submodule, and a knowledge graph analysis submodule; (3) Alarm convergence module: This module combines text similarity, time interval and knowledge graph to calculate the comprehensive similarity between alarms. Based on the similarity calculation results, similar alarms are merged into one alarm. Finally, the converged alarm information is stored. (4) Alarm display module: This module displays the alarm information after convergence through a visual interface; (5) Alarm configuration management module: This module provides alarm threshold setting and alarm level management functions; It is characterized in that: in the alarm analysis module, the text similarity calculation submodule calculates the similarity between alarms based on the alarm text; the time interval calculation submodule counts the time interval between alarms to determine whether the alarms occur continuously in a short period of time; the knowledge graph analysis submodule uses the knowledge graph to calculate the correlation between alarms.

4. The alarm convergence system combined with knowledge graph as claimed in claim 3, characterized in that: In the alarm convergence module, The following steps are involved: 3.1 Alarm grouping: Read all alarm data and group alarms according to different database instances. When calculating alarm similarity in the subsequent steps, the alarms within the same database instance are calculated, and the grouped alarm set is finally output. 3.2 Select alarm pairs: traverse each group and select two alarms in each group that have not been similarity calculated, and send them to step 3.3 for similarity calculation; select alarm a from the alarm set of a group i and a j Perform similarity calculation, where a i and a j Respectively represent the i-th and j-th alarms in the alarm set. In the first iteration, select any two alarms as the starting point; in subsequent iterations, select two alarms that have not been similarly calculated with each other; if all the alarms in each group have participated in the calculation, jump to step 3.

6. 3.3 Calculate alarm similarity: Use the TF-IDF method to convert the text into a vector, and then calculate the two vectors a i and a j The cosine angle between them is the text similarity textsim(a i ,a j ); Calculate two alarms a i and a j The time interval between in, decay() is the decay function, a i .time and a j .time are respectively alarm a i and a j The occurrence time of decay(a i .time) and decay(a j .time) are respectively based on a i .time and a j .time calculated decay function value; λ is the decay rate, λ>0; time() is the current time; Δt is the preset time threshold. Calculate two alarms a i and a j The degree of correlation between in, d(a i ,a j ) is an alarm a i and a j The shortest path length in the knowledge graph, w(a i ,a j ) is the sum of the weights of all edges on the shortest path, cn(a i ,a j ) is an alarm a i and a j The number of common neighbors of Calculation alarm a i and a j The comprehensive alarm similarity sim(a i ,a j )=α×textsim(a i ,a j )+β×timesim(a i ,a j )+γ×graphsim(a i ,a j ), where α, β and γ are weight coefficients, 0<α<1, 0<β<1, 0<γ<1, and α+β+γ=1; 3.4 Determining Similarity sim(a i ,a j )≥threshold, go to step 3.5; otherwise, return to step 3.2 and continue to process the next pair of alarms, where threshold is the preset similarity threshold; 3.5 Merge Alarms If two alarms a i and a j similar, mark them and jump to 3.2; 3.6 Output merged alarms: Output the final merged alarm set according to the tags.

Citation Information

Patent Citations

  • Calculation method of sub-synchronous oscillation mode attenuation coefficients based on Prony algorithm

    CN104852392A

  • Scientific knowledge discovery method and system based on knowledge graph

    CN117786122A

  • IT system alarm data processing method and device based on knowledge graph

    CN118057327A

  • Database knowledge dialogue method and system based on retrieval enhancement

    CN119415638A

  • Systems and methods for classifying malicious network events

    US9306962B1