A business system monitoring method and system based on business dimensions and a medium

By constructing the monitoring topology results of the business system and combining the operational status data of hardware and software, comprehensive monitoring of the business system is achieved, solving the single-dimensional problem of traditional monitoring methods and improving the accuracy of monitoring and the efficiency of fault diagnosis.

CN120151228BActive Publication Date: 2025-12-19BAI ZEYAO TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510111177.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-12-19
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

Traditional business system monitoring methods are limited to a single dimension, failing to comprehensively and accurately reflect the actual operating status of the business system and lacking holistic monitoring of software and hardware.

Method used

By acquiring hardware and software information from the business system, a monitoring topology based on the business dimension is constructed. The operating status data of the hardware and software is mapped to the topology results, analyzed, and the monitoring results are output, thereby achieving comprehensive monitoring of the business system.

Benefits of technology

It enables comprehensive monitoring of business systems, timely detection of anomalies, ensures stable system operation, and provides intuitive monitoring results and troubleshooting support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151228B_ABST
    Figure CN120151228B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on service dimension's service system monitoring method, system and medium, by obtaining hardware and software information in service system, and the running state data of hardware and software;According to the association between each hardware and software, constructs service monitoring topological structure;The running state data of hardware and software is mapped into the service monitoring topological structure, forms the monitoring data of service dimension;The monitoring data is analyzed based on service dimension, and the monitoring result of service system is obtained, and monitoring result output display is shown.This application discloses the method and system, based on service dimension to service system is monitored, to realize and promptly discover business exception, to guarantee the stable operation of service system, and the application method constructs service system topological structure and visualizes display to monitoring result, while monitoring the service system in integrity, provide more intuitive service system running state.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of business information monitoring, and in particular to a business system monitoring method and system based on business dimensions and a medium. BACKGROUND

[0002] With the development of information technology, business systems are becoming increasingly complex, and the businesses supported by the business systems are also increasing. Therefore, in order to realize the normal development of various businesses, the stability and security of the business systems are becoming more and more important.

[0003] Traditional business system monitoring methods are often limited to a single dimension of hardware or software, and it is difficult to comprehensively and truly reflect the actual running state of the business system. For example: most monitoring systems are still limited to monitoring hardware resources such as CPU usage, memory occupation, hard disk space, and network traffic; at the same time, the monitoring of software is limited to the number of client connections, data request frequency, and processing speed. Such a single-dimensional monitoring mode cannot effectively integrate hardware and software resources to form a comprehensive monitoring of the business system.

[0004] Therefore, the prediction method in the prior art needs to be further improved. SUMMARY

[0005] In view of the deficiencies in the above related art, the purpose of the present application is to provide a business system monitoring method and system based on business dimensions and a medium, which overcomes the defects of the prior art that the monitoring system is limited to a single dimension and cannot comprehensively and accurately monitor the business system.

[0006] The technical solution adopted by the present application to solve the technical problems is as follows:

[0007] In a first aspect, the present application discloses a business system monitoring method based on business dimensions, which comprises:

[0008] Obtaining hardware and software information in the business system, and running state data of the hardware and software;

[0009] According to the correlation between each hardware and software, a business monitoring topology result is constructed;

[0010] The running state data of the hardware and software is mapped into the business monitoring topology result to form monitoring data of the business dimensions;

[0011] The monitoring data is analyzed based on the business dimensions to obtain a monitoring result of the business system, and the monitoring result is output and displayed.

[0012] Optionally, the step of obtaining hardware and software information in the business system, and running state data of the hardware and software comprises:

[0013] Obtaining device information of each hardware in the service system and software information installed in each hardware device, wherein the device information comprises device name information, IP address information, and slave relationship information between devices;

[0014] Obtaining running state information of the hardware according to physical performance and state of the hardware, and obtaining running state information of the software according to performance of each application program and device resource usage information.

[0015] Optionally, the step of constructing the service monitoring topology result according to the association relationship between each hardware and software comprises:

[0016] Determining the relationship between the software and the physical machine or the virtual machine according to whether the IP address of the monitored software and the IP address of the physical machine or the virtual machine are the same;

[0017] Determining the physical machine to which each virtual machine belongs according to detailed information of the physical machine and the virtual machine scanned by the hyper-converged protocol;

[0018] Obtaining the connection relationship between the network device and the physical machine or the virtual machine according to the network device SNMP protocol;

[0019] Constructing the service monitoring topology structure according to the relationship between the software and the physical machine or the virtual machine, the physical machine to which each virtual machine belongs, and the connection relationship between the network device and the physical machine or the virtual machine.

[0020] Optionally, the step of obtaining the connection relationship between the network device and the physical machine or the virtual machine according to the network device SNMP protocol comprises:

[0021] Obtaining the network MAC address and the IP address of each physical machine and each virtual machine through the SNMP protocol respectively;

[0022] Obtaining MIB table information of all network devices respectively, and determining a first end network device according to the MIB table information corresponding to each network device;

[0023] Determining device information connected with the first end network device according to port information corresponding to the first end network device;

[0024] Shielding the first end network device, taking the device connected with the first end network device as a second end device, and searching for device information connected with the second end device according to port information corresponding to the second end network device;

[0025] Shielding the second end network device, taking the device connected with the second end network device as a third end network device, and searching for device information connected with the third end network device according to port information corresponding to the third end device;

[0026] Shielding the third end network device, repeating the above steps of taking the searched Nth end device connected device as an N+1th end device, and searching for device information connected with the N+1th end device according to port information corresponding to the N+1th end device, until the network device is searched, and obtaining a connection relationship between all network devices and physical machines or virtual machines.

[0027] Optionally, the step of constructing a service monitoring topology structure according to the relationship between the software and the physical machines or the virtual machines, the physical machines to which the virtual machines belong, and the connection relationship between the network devices and the physical machines or the virtual machines comprises:

[0028] Fusing the connection relationship between the network devices and the physical machines or the virtual machines, the physical machines to which the virtual machines belong, and the relationship between the software and the physical machines or the virtual machines, and constructing a service monitoring topology structure.

[0029] Optionally, the step of determining the first end network device according to the MIB table information corresponding to each network device comprises:

[0030] Obtaining iproute table information of each device, and searching for a MAC address of a next device connected according to the iproute table information of the device;

[0031] Judging whether the MAC address of the next device connected is same as a MAC address of another device, and if the MAC address of the next device connected is different from the MAC address of the another device, the next device connected is an end network device.

[0032] Optionally, the step of analyzing the monitoring data based on a service dimension and obtaining a monitoring result of a service system comprises:

[0033] Inputting the monitoring data into a trained prediction model to obtain a prediction value of running state data corresponding to different business subject types in different service dimensions;

[0034] Inputting the prediction value of the running state data corresponding to the different business subject types in the different service dimensions and a real value of the currently obtained running state data into a trained anomaly detection model to obtain a monitoring result output by the anomaly detection model, wherein the anomaly detection model is trained based on service monitoring indexes and monitoring rules respectively configured for the different business subject types in the different service dimensions.

[0035] Optionally, before the step of analyzing the monitoring data based on the business dimension to obtain the monitoring result of the business system, the method further comprises:

[0036] According to the corresponding business subject type in the monitoring data, a matching business monitoring index and monitoring rule are obtained;

[0037] Based on the business monitoring index and monitoring rule respectively configured in different business subject types in different business dimensions, and the prediction model and the abnormal detection model trained by the historical monitoring data corresponding to each business subject type.

[0038] In a second aspect, the application provides a business system monitoring system based on a business dimension, comprising:

[0039] An information acquisition module is configured to acquire hardware and software information in the business system, and running state data of the hardware and software;

[0040] A topology construction module is configured to construct a business monitoring topology result according to the association relationship between each hardware and software;

[0041] A monitoring data generation module is configured to map the running state data of the hardware and software into the business monitoring topology result to form monitoring data of the business dimension;

[0042] A monitoring data analysis module is configured to analyze the monitoring data based on the business dimension to obtain the monitoring result of the business system, and to output and display the monitoring result.

[0043] In a third aspect, the application provides a computer readable storage medium, wherein the computer readable storage medium stores one or more computer readable programs, the one or more computer readable programs can be executed by one or more processors, and when the computer readable programs are executed by the processor, the business system monitoring method based on the business dimension is implemented.

[0044] Advantages:

[0045] This embodiment discloses a business system monitoring method, system, and medium based on business dimensions. It acquires hardware and software information and operational status data of the business system; constructs a business monitoring topology based on the relationships between various hardware and software components; maps the operational status data of the hardware and software to the business monitoring topology to form business-dimensional monitoring data; analyzes the monitoring data based on the business dimension to obtain the monitoring results of the business system, and outputs and displays the monitoring results. The method and system disclosed in this application monitor the business system based on the business dimension to promptly detect business anomalies and ensure the stable operation of the business system. Furthermore, this method combines hardware and software information to construct a business system topology and visualizes the monitoring results. While providing comprehensive and accurate monitoring results, it also offers a more intuitive understanding of the business system's operational status, providing technical support for users to quickly locate anomalies and more efficiently troubleshoot problems. Attached Figure Description

[0046] Figure 1 This is a flowchart illustrating the steps of a business system monitoring method based on business dimensions according to an embodiment of the present invention.

[0047] Figure 2 This is an example diagram of newly added business monitoring information in the business system according to an embodiment of the present invention;

[0048] Figure 3 This is a diagram illustrating the ownership information of physical machines and virtual machines in the business system according to an embodiment of the present invention;

[0049] Figure 4 This is a flowchart illustrating the steps for finding the association between network devices and physical machines / virtual machines in an embodiment of the present invention.

[0050] Figure 5 This is a topology table of devices in the business system in this embodiment of the invention;

[0051] Figure 6 This is a schematic diagram of the topology between devices in the business system according to an embodiment of the present invention;

[0052] Figure 7 This is a diagram showing the alarm information in the business system topology results of this embodiment of the invention;

[0053] Figure 8 This is a diagram illustrating the classification of monitoring information in the business system according to an embodiment of the present invention;

[0054] Figure 9 This is a diagram showing the list of alarm content in an embodiment of the present invention;

[0055] Figure 10Information display diagram of the corresponding IA help inquired by the alarm content in the embodiment of the present application;

[0056] Figure 11 Instance step flow chart of the adaptive monitoring rule in the embodiment of the present application;

[0057] Figure 12 Analysis principle schematic diagram of the business dimension data in the embodiment of the present application;

[0058] Figure 13 Principle block diagram of the business system monitoring system based on the business dimension in the embodiment of the present application. DETAILED DESCRIPTION

[0059] In order to make the purpose, technical scheme and advantages of the present application more clear, the present application is further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0060] The business system is a system used for processing daily business operation, management and information flow integration in an enterprise or organization. It is usually composed of multiple modules or components, each of which is designed with specific business function or process. The business system can cover multiple functionally different modules, so it is a comprehensive system. With the improvement of the automation level of the business system, the system result also becomes more and more complex, so the operation safety of the business system is more and more important.

[0061] The traditional monitoring method is often limited to a single hardware or software level, and cannot comprehensively reflect the actual operation status of the business system. When the business system has a problem, it is unable to determine whether the problem is caused by the business system software itself or the dependent hardware, so it is unable to make accurate monitoring judgment, and further lacks the overall alarm analysis of all software / hardware involved in the business, and is unable to give overall monitoring index analysis and statistics.

[0062] In order to solve the above problems in the prior art, the embodiment provides a business system monitoring method, system and medium based on a business dimension, which obtains hardware and software information in a business system and running state data of the hardware and software; constructs a business monitoring topology result according to an association relationship between each hardware and software; maps the running state data of the hardware and software into the business monitoring topology result to form monitoring data of the business dimension; analyzes the monitoring data based on the business dimension to obtain a monitoring result of the business system, and outputs and displays the monitoring result. The method and system disclosed in the embodiment comprehensively analyze the software and hardware to quickly determine problems in the business system, and visually display the monitoring information based on the topology result, which provides convenience for a user to comprehensively understand the business system monitoring information.

[0063] The business system monitoring method, system and medium based on a business dimension disclosed in the embodiment will be further described below with reference to the accompanying drawings.

[0064] The application discloses a business system monitoring method based on a business dimension, as shown in the accompanying drawings, which comprises the following steps. Figure 1

[0065] Step S1, obtaining hardware and software information in a business system and running state data of the hardware and software.

[0066] When it is necessary to monitor the business system to determine whether an abnormality occurs in the business system, first, each item of data in the business system needs to be obtained, and based on the obtained each item of data, analysis is performed to determine whether an abnormality occurs. In order to comprehensively monitor the business system, in this step, not only the data of the hardware in the business system is collected, but also the data of the software in the business system is collected, and these data not only come from the business system itself, but also include various data generated when the business system runs.

[0067] Further, the hardware in the business system includes a server, a storage device, a network device, a terminal device or other auxiliary devices (such as a printer, a scanner, etc.), and the software in the business system is various management systems or office automation systems, or other software supporting daily operation and management activities of an enterprise.

[0068] Specifically, the step of obtaining hardware and software information in a business system and running state data of the hardware and software comprises the following steps.

[0069] ​The device information of each hardware in the service system and the software information installed in each hardware device are acquired, wherein the device information comprises device name information, IP address information, and the slave relationship information between devices; the running state information of the hardware is acquired according to the physical performance and state of the hardware, and the running state information of the software is acquired according to the performance of each application program and the device resource usage information. The collected running state data comprises CPU, memory, disk, network, request times, response times, online time, operation times, and response time and other key performance indicators.

[0070] The service system contains different types of services, in order to realize comprehensive monitoring of the service system, different service monitoring modules can be established according to different service requirements, so as to realize the division of service monitoring based on service type, thereby improving the accuracy of monitoring. As shown in Figure 2 As shown in the OA system, the OA system can be selected to contain how many hardware and software resources, and the added service monitoring is grouped, so as to realize systematic monitoring of the service system.

[0071] Step S2, according to the association relationship between each hardware and software, a business monitoring topology result is constructed.

[0072] When the above step S2 acquires various different data in the service system, the business monitoring topology result can be constructed according to the association relationship between the hardware and the software in the service system.

[0073] The association relationship between hardware and software includes the association relationship between physical machines and software, the slave relationship between physical machines and virtual machines, and the association relationship between each network device and physical machine / virtual machine. The monitoring topology result of the service system is constructed through the above association relationship between hardware and software.

[0074] Specifically, the step of constructing the business monitoring topology result according to the association relationship between each hardware and software comprises:

[0075] Step S221, according to whether the IP addresses of the monitored software and the physical machine or the virtual machine are the same, the relationship between the software and the physical machine or the virtual machine is determined.

[0076] In the judgment of the association between software and physical machine / virtual machine, the relationship between the software and the physical machine or virtual machine is determined by judging whether the IP address of the monitored software is the same as the IP address of the physical machine or virtual machine. If the IP address corresponding to the software is the same as the IP address of the physical machine or virtual machine, the software belongs to the physical machine or virtual machine. For example: the IP address of the monitored software nginx is 192.168.31.23, and the IP address of the virtual machine rocky8.9-QA is also 192.168.31.23, so nginx belongs to the virtual machine rocky8.9-QA.

[0077] Step S222, according to the detailed information of the physical machine and the virtual machine scanned by the hyper-converged protocol, determine the physical machine to which each virtual machine belongs.

[0078] Hyper-converged protocol construction refers to the highly integrated and unified management of computing resources, storage resources and network resources on a physical machine through software-defined methods. Under this architecture, the physical machine carries the operation of all virtualization components, including virtual machines. Virtual machines are logical computers created on physical machines through virtualization technology, and they share the hardware resources of the physical machine but are logically isolated from each other.

[0079] In the hyper-converged or virtualized environment, the physical machine information of the virtual machine can be obtained by viewing the detailed information of the virtual machine, and the physical machine information of the virtual machine can be obtained by viewing the detailed information of the virtual machine. The virtual machine associated with the physical machine can be determined. It can also be selected by viewing the summary or configuration information of the virtual machine to find the physical machine name associated with the virtual machine, thereby determining the physical machine to which the virtual machine belongs. In combination Figure 3 As shown, the virtual machines Docker-31.47, Dev-02-31.24, etc. under the physical machine ESXi-A are scanned by the Nutanix protocol, and it is determined that the virtual machines Docker-31.47, Dev-02-31.24, etc. belong to the physical machine ESXi-A.

[0080] Step S223, according to the network device SNMP protocol, obtain the connection relationship between the network device and the physical machine or virtual machine.

[0081] In addition to the physical machines or virtual machines, there are also many network devices in the business system. In this step, the topology relationship between each network device and the physical machine or between each network device and the virtual machine in the business system can be discovered according to the network device SNMP protocol. Specifically, the topology relationship between each network device and the physical machine or between each network device and the virtual machine includes: physical machine / virtual machine network MAC address / IP address discovery, network layer topology discovery, link layer topology discovery, and host layer topology discovery. The network layer topology discovery is mainly for the routers, subnets in the network, and the connection relationship between them. The link layer topology discovery is mainly for the physical connection relationship between the switches, routers and other devices in the network, and the connection between them and the host. The host layer topology discovery is mainly for the host devices in the network and the connection relationship between the host devices. Through the above steps, the network topology of the business system can be discovered, and the network topology of the business system can be discovered.

[0082] In an embodiment, in combination with Figure 4 As shown, the step of obtaining the connection relationship between the network device and the physical machine or the virtual machine according to the network device SNMP protocol includes:

[0083] Step S231, the network MAC address and IP address of each physical machine and each virtual machine are obtained respectively through the SNMP protocol. In specific implementation, the network MAC address and IP address corresponding to each physical machine / virtual machine are obtained through the SNMP protocol, Agent protocol, Nutanix protocol, etc.

[0084] Step S232, the MIB table information of all network devices is obtained respectively, and the first end network device is determined according to the MIB table information corresponding to each network device.

[0085] The MIB table information includes: dot1dTpFdbTable table information, dot1dBasePortTable table information, ifTable table information, ipRouteTable table information, and ipNetToMediaTable table information. When the above MIB table information is obtained, the connection relationship between each network device and the physical machine or the virtual machine can be judged according to the corresponding field value in the table information.

[0086] In this step, first, the first end network device in the current connection relationship is determined according to the MIB table information corresponding to each network device, then the determined first end network device is removed from the current connection result, the end network device in the connection result after the first end network device is removed is searched, and the searched end network device is defined as a second end network device, the searched end network device is removed in turn, the end network device in the connection network after the searched end network device is removed is repeatedly searched, and the connection relationship between each step and the searched end network device is established, so as to obtain the connection relationship between each device in the entire network result, that is, the connection relationship between the network device and the physical machine or the virtual machine.

[0087] The step of determining the first end network device according to the MIB table information corresponding to each network device in this step specifically comprises:

[0088] The iproute table information of each device is obtained, the MAC address of the next connected device is searched according to the iproute table information of the device, it is judged whether the MAC address of the next connected device is same as the MAC address of other devices, if the MAC address of the next connected device is different from the MAC address of other devices, the next connected device searched at present is an end network device.

[0089] When the iproute table information of each device is obtained, the MAC address of the next device can be searched in the ARPS table of the current device according to the next device ip address (nexthop) in the iproute table information, if the MAC address of the next device searched is matched with the MAC address of the port of other devices, it is explained that the device connected with the port of the device matched with the next device, therefore, the next device searched in this step is not an end network device, otherwise, the MAC address of the next device is not matched with the MAC address of the port of other devices, then the next device searched in this step is an end network device.

[0090] When the end network device is searched, whether other devices are the next connected device is judged by checking the MAC address contained in the ARPS table of the current device, if the MAC address contained in the ARPS table is matched with the MAC address of other devices, the port number and infindex of the baseport are found according to the MAC address of the client, the port information of the network device is found according to the infindex of the baseport, and the association relationship between the end network device and other physical machines or virtual machines is obtained according to the obtained port information.

[0091] Step S233: Determine the device information connected to the first terminal network device based on the port information corresponding to the first terminal network device;

[0092] Step S233: Shield the first terminal network device, and designate the device connected to the first terminal network device as the second terminal device. Find the device information connected to the second terminal device based on the port information corresponding to the second terminal network device.

[0093] Step S234: Shield the second-end network device, and designate the device connected to the second-end network device as the third-end network device. Find the device information connected to the third-end device based on the port information corresponding to the third-end device.

[0094] Step S234: Block the third-end network device. Repeat the above steps to treat the device connected to the Nth end device as the N+1th end device. Search for the device information connected to the N+1th end device based on the port information corresponding to the N+1th end device until the network device is found, and obtain the connection relationship between all network devices and physical machines or virtual machines.

[0095] Specifically, after each end network device is found in steps S233-S234, the MAC addresses contained in the ARPS table of the found end network devices are checked to determine whether other devices are the next connected devices. If the MAC addresses contained in the ARPS table match the MAC addresses of other devices, the port number and infindex of the local baseport are found based on the client MAC address. The port information of the network device is found based on the infindex of the baseport. The association between the end network device and other physical machines or virtual machines is obtained based on the obtained port information.

[0096] Step S24: Construct a service monitoring topology based on the relationship between the software and the physical machine or virtual machine, the physical machine to which each virtual machine belongs, and the connection relationship between the network device and the physical machine or virtual machine.

[0097] Once the relationships between software and physical machines or virtual machines, the attribution relationships between each virtual machine and a physical machine, and the connection relationships between all network devices and physical machines or virtual machines are obtained, the connection relationships between network devices and physical machines or virtual machines, the physical machines to which each virtual machine belongs, and the relationships between each software and physical machines or virtual machines can be integrated to construct a business monitoring topology.

[0098] like Figure 5 As shown, based on the relationships between various devices, a topology table of the business system is first obtained, and then the final business relationship topology diagram is generated based on the topology table.Figure 6 Fig. 1 shows a business topology diagram of an OA system, which includes a plurality of physical machines, various software installed on the physical machines, and switches connected to the physical machines.

[0099] Step S3: mapping the running state data of the hardware and the software to the business monitoring topology result to form monitoring data of the business dimension.

[0100] After the business monitoring topology result is constructed, the detailed information of the hardware, the detailed information of the software, and the running state data of the hardware and the software obtained in step S1 are mapped to the business monitoring topology result to realize visualized display of the entire business system.

[0101] Step S4: analyzing the monitoring data based on the business dimension to obtain a monitoring result of the business system and outputting and displaying the monitoring result.

[0102] The visualized display of the business monitoring topology result in step S3 above not only includes the topology structure among various devices in the business system, but also can include monitoring data information (monitoring overview), an alarm list, and a statistical report, etc., to facilitate a user to understand the overall running state of the business system from the business monitoring topology result.

[0103] In an implementation manner, the visualized display of the business system can include a business topology monitoring display module, a monitoring overview module, an alarm list display module, and a statistical report display module. As shown in Fig. 2, Figure 7 As shown in Fig. 2, the business topology monitoring display module not only includes the association relationship among the hardware / software involved in the business system, but also displays the real-time network traffic among the monitoring devices in the business system, real-time abnormal conditions in the business system, and basic information of the devices involved in the business system. As shown in Fig. 3, Figure 8 As shown in Fig. 4, the monitoring overview module displays the hardware switch-on / off situation, the software start / stop situation, the operating system proportion, the network ranking proportion, the CPU utilization distribution, and the memory utilization distribution, etc. in the business system. As shown in Fig. 5, Figure 9 As shown in Fig. 6 and Fig. 7, the alarm list display module is used to display the alarm information of the hardware or the software associated with the device, and through the alarm information, the corresponding AI help can be queried to help the user to repair the business abnormality as soon as possible and ensure the normal and smooth running of the business. In the statistical report display module, the alarm statistics, the device / software type distribution statistics, the utilization ranking statistics, the abnormality statistics, and the early warning statistics can be displayed. Figure 10

[0104] ​In order to obtain the above-mentioned abnormal statistics and alarm information, and map the above-mentioned information to the business monitoring topology result for display, in this step, the monitoring data is analyzed based on the business dimension to obtain the monitoring result of the system, and the abnormal statistics and alarm information are obtained according to the monitoring result.

[0105] In order to realize the accuracy of the business system monitoring, in this step, the business-related monitoring abnormal rules are customized according to different business subject types. According to the business historical monitoring data and business changes, the business abnormal rules and abnormal strategies are automatically adjusted to improve the accuracy and adaptability of the monitoring system. Specifically, in this step, the business subject types are first configured. Generally, different business subject types are defined according to specific business needs, such as OA business, ERP business, e-commerce business, etc., and each business subject type corresponds to a specific set of monitoring indicators and rules. Secondly, the business monitoring indicators are generated according to the configured business subject types. Since the business monitoring indicators are closely related to the business subject types, the business monitoring indicators can be directly determined according to the business subject types, for example: for e-commerce business, the indicators such as the number of requests per second, service response speed, and the number of current connected users are focused on. Thirdly, the business monitoring rules are generated according to the business monitoring indicators and the business subject types. Since these rules will define how the system should respond under certain conditions, such as when the indicators exceed the preset threshold. For example, if the number of connected users and the number of requests per second of the e-commerce system surge, when the number of connected users exceeds the limit value of the business monitoring indicator, the system will trigger a warning to notify the relevant personnel for further analysis and processing to ensure the smooth and safe operation of the business system.

[0106] After the different business subject types and the business monitoring indicators and business monitoring rules corresponding to each business subject type have been generated, the received hardware and software information is analyzed according to the business subject types and the business monitoring indicators and business monitoring rules corresponding to each business subject type, thereby obtaining the monitoring result.

[0107] In this step, the business monitoring rules can be used to predict the key abnormal indicators in the future period of time according to the business characteristics by selecting appropriate machine learning algorithms, and to dynamically adjust the current business system according to the prediction results.

[0108] Specifically, the step of analyzing the monitoring data based on the business dimension to obtain the monitoring result of the business system comprises:

[0109] Step S41, input the monitoring data into the trained prediction model to obtain the prediction value of the running state data corresponding to different business subject types in different business dimensions.

[0110] Step S42, input the predicted value of the running state data corresponding to different business subject types in different business dimensions and the real value of the currently obtained running state data into the trained anomaly detection model, to obtain the monitoring result output by the anomaly detection model, wherein the anomaly detection model is trained based on the business monitoring indicators and monitoring rules respectively configured for different business subject types in different business dimensions.

[0111] For example, using a prediction algorithm to predict the number of users in the same time period next month based on the historical data trend of the number of users of an e-commerce website, when the real user data of next month is obtained, the real user data is compared with the predicted data, and the parameters of the prediction algorithm are dynamically adjusted according to the comparison result.

[0112] Specifically, before the step of analyzing the monitoring data based on the business dimension to obtain the monitoring result of the business system, the method further comprises:

[0113] According to the corresponding business subject type in the monitoring data, the matching business monitoring indicators and monitoring rules are obtained;

[0114] Based on the business monitoring indicators and monitoring rules respectively configured for different business subject types in different business dimensions, and the historical monitoring data corresponding to each business subject type obtained, a prediction model and an anomaly detection model are trained.

[0115] Next, taking the OA system as the business subject type: setting the company employee size to 100 (corresponding to the parameter employees), setting the working day to be: 8 am-6 pm on non-holidays, and the number of OA system businesses to be 30, as an example, the steps of the adaptive monitoring rules provided in this step in specific application are described.

[0116] 1) According to the OA business, the monitoring indicators and monitoring rules of the system are generated.

[0117] Ngn ix (Web server) monitoring indicators: client connection number (Connect ions active, i.e. the number of employees logging into the client).

[0118] Specific parameter limits: within working hours: the connection number cannot be lower than 30% of employees, i.e. 30 connections, and cannot be higher than 110% of employees, i.e. 110 connections. If the connection number is lower or higher, an abnormal alarm is issued. Outside working hours: the connection number cannot be higher than 20% of employees. If it is higher than 20, it means that the system may be attacked or other abnormalities, and an alarm is also issued.

[0119] Mysq l(database) monitoring index: Command Select per second.

[0120] Specific parameter limit: During working hours: Command Select per second cannot be lower than (emp loyees x 0.3) x 30, 30 is the number of services, i.e. 900 Command Selects, and cannot be higher than 110% of emp loyees multiplied by 30, i.e. 3300 Command Selects. If the number of Command Selects is lower or higher than the above, an abnormal alarm is sent. During non-working hours: the number of Command Selects cannot be higher than 20% of emp loyees multiplied by 30. If it is higher than 600, it means that the system may be attacked or abnormal, and an alarm is also sent.

[0121] Network port monitoring index of application server (corresponding to Ngn ix): sending rate and receiving rate.

[0122] During working hours: the sending / receiving rate cannot be lower than 3M / s and cannot be higher than 11M / s. If the sending / receiving rate is lower or higher than the above, an abnormal alarm is sent. During non-working hours: the sending / receiving rate cannot be higher than 2M / s. If it is higher than the above, it means that the system may be attacked or abnormal, and an alarm is also sent.

[0123] Adaptive monitoring rule: after running for a period of time, the monitoring index and monitoring rule of the OA system are dynamically adjusted according to historical data values. The specific algorithm is: the average value of the highest value of the monitoring item value in the past month is multiplied by 110% as the highest value, and the average value of the lowest value of the monitoring item value in the past month is multiplied by 90% as the lowest value, and then the monitoring index is dynamically adjusted.

[0124] 2) Monitor the OA system according to the adaptive monitoring rule and send an alarm.

[0125] In combination with Figure 11 As shown in the figure, the highest client connection number of Ngn ix in the OA system in the past month during working hours is obtained, and it is judged whether the highest client connection number of Ngn ix in the current month during working hours reaches the alarm upper limit. If it reaches, an alarm is sent, and the upper limit value of the Ngn ix client connection number during working hours is dynamically adjusted.

[0126] Then the highest client connection number of Ngn ix in the OA system in the past month during non-working hours is obtained, and it is judged whether the Ngn ix client connection number during non-working hours reaches the alarm upper limit. If it reaches, an alarm is sent, and the upper limit value of the Ngn ix client connection number during non-working hours is dynamically adjusted.

[0127] Similarly, the minimum client connection number of the Ngn ix in the OA system in the last month is obtained, and it is determined whether the minimum client connection number in the working hours of the current month reaches the upper limit of the alarm, if so, an alarm is sent, and the lower limit value of the Ngn ix client connection number in the working hours is dynamically adjusted. In addition, the minimum client connection number of the Ngn ix in the OA system in the last month is obtained, and it is determined whether the Ngn ix client connection number in the non-working hours of the current month reaches the lower limit of the alarm, if so, an alarm is sent, and the lower limit value of the Ngn ix client connection number in the non-working hours is dynamically adjusted.

[0128] In combination Figure 12 As shown in the monitoring method provided by the embodiment, when the monitoring data is analyzed based on the business monitoring indicators and the business exception rules, if it is detected that the business is abnormal, the abnormal indicators are displayed on the monitoring overview, and the alarm mechanism is triggered at the same time, and the abnormal information is sent through the email or the short message, so that the related personnel can analyze the abnormality and restore the normal operation of the business as soon as possible.

[0129] The business system monitoring method based on the business dimension provided by the embodiment can obtain the association relationship between the hardware and the software in the business system, construct the monitoring topology graph of the business system, analyze the monitoring data through the adaptive monitoring rules, detect the business exception, trigger the alarm and start the response process at the same time, realize the overall monitoring and analysis of all the hardware and the software in the business system, improve the accuracy of the monitoring, and realize the quick and accurate positioning of the abnormal business or the alarm time through the visual display of the business monitoring result, so as to provide technical support for the user to solve the abnormal information and quickly restore the business.

[0130] On the basis of the above-mentioned monitoring method, the application further discloses a business system monitoring system based on the business dimension, as shown in the accompanying drawings, which comprises: Figure 13 As shown in the accompanying drawings, the business system monitoring system based on the business dimension comprises:

[0131] The information acquisition module 100 is used for acquiring the hardware and software information in the business system and the running state data of the hardware and the software, and the function thereof is as described in step S1.

[0132] The topology construction module 200 is used for constructing the business monitoring topology result according to the association relationship between the hardware and the software, and the function thereof is as described in step S2.

[0133] The monitoring data generation module 300 is used for mapping the running state data of the hardware and the software to the business monitoring topology result to form the monitoring data of the business dimension, and the function thereof is as described in step S3.

[0134] The monitoring data analysis module 400 is configured to analyze the monitoring data based on the business dimension, obtain a monitoring result of the business system, and output and display the monitoring result, functions of which are described in step S4.

[0135] The application discloses the above-mentioned monitoring method and monitoring system, and further discloses a computer readable storage medium, wherein the computer readable storage medium stores one or more computer readable programs, the one or more computer readable programs can be executed by one or more processors, and the computer readable programs are executed by the processor to realize the business system monitoring method based on the business dimension.

[0136] The memory can include a high-speed RAM memory, and can further include a non-volatile memory, such as at least one disk memory.

[0137] The processor can be a central processing unit (CPU) or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present application.

[0138] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" means that the specific features, results, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, results, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.

[0139] The above-described embodiments only express several implementation manners of the present application, the description is more specific and detailed, but it cannot be understood as a limitation on the scope of the patent. It should be noted that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A business system monitoring method based on business dimensions, characterized in that, The method comprises the following steps: acquiring hardware and software information in a business system, and running state data of the hardware and software; constructing a business monitoring topology structure according to the association relationship between each hardware and software; mapping the running state data of the hardware and software into the business monitoring topology structure to form monitoring data of a business dimension; analyzing the monitoring data based on the business dimension to obtain a monitoring result of the business system, and outputting and displaying the monitoring result; the step of constructing the business monitoring topology structure according to the association relationship between each hardware and software comprises the following steps: determining the relationship between the software and the physical machine or the virtual machine according to whether the IP addresses of the monitored software and the physical machine or the virtual machine are the same; determining the physical machine to which each virtual machine belongs according to the detailed information of the physical machine and the virtual machine scanned by the hyper-converged protocol; acquiring the connection relationship between the network device and the physical machine or the virtual machine according to the SNMP protocol of the network device; wherein, the MIB table information of all network devices is acquired, and the first end network device is determined according to the MIB table information corresponding to each network device; then, the first end network device determined is removed from the current connection result, the end network device in the connection result after the first end network device is removed is searched, and the searched end network device is defined as the second end network device; the searched end network device is removed in turn, and the end network device in the connection network after the searched end network device is removed is repeatedly searched; then, the connection relationship of each searched end network device in each step is established, so that the connection relationship between the network device and the physical machine or the virtual machine is obtained; the business monitoring topology structure is constructed according to the relationship between the software and the physical machine or the virtual machine, the physical machine to which each virtual machine belongs, and the connection relationship between the network device and the physical machine or the virtual machine.

2. The business system monitoring method based on business dimension according to claim 1, characterized in that, the step of acquiring the hardware and software information in the business system, and the running state data of the hardware and software comprises the following steps: acquiring the device information of each hardware in the business system, and the software information installed in each hardware device; wherein, the device information comprises device name information, IP address information, and the slave relationship information between devices; the running state information of the hardware is acquired according to the physical performance and state of the hardware, and the running state information of the software is acquired according to the performance of each application program and the device resource usage information.

3. The business system monitoring method based on business dimension according to claim 2, characterized in that, the step of acquiring the connection relationship between the network device and the physical machine or the virtual machine according to the SNMP protocol of the network device comprises the following steps: the network MAC address and the IP address of each physical machine and each virtual machine are acquired respectively through the SNMP protocol; the MIB table information of all network devices is acquired respectively, and the first end network device is determined according to the MIB table information corresponding to each network device; the device information connected with the first end network device is determined according to the port information corresponding to the first end network device; the first end network device is shielded, the device connected with the first end network device is taken as the second end device, and the device information connected with the second end device is searched according to the port information corresponding to the second end network device; Shielding the second end network device, taking the device connected with the second end network device as a third end network device, and searching for device information connected with the third end device according to port information corresponding to the third end device; Repeating the above steps of shielding the Nth end network device, taking the device connected with the Nth end network device as an N+1 network end device, and searching for device information connected with the N+1 network end device according to port information corresponding to the N+1 network end device until the network device is queried, and obtaining the connection relationship between all network devices and physical machines or virtual machines, wherein N is a positive integer.

4. The business system monitoring method based on business dimension according to claim 2 or 3, characterized in that, The step of constructing the business monitoring topology structure according to the relationship between the software and the physical machine or the virtual machine, the physical machine to which each virtual machine belongs, and the connection relationship between the network device and the physical machine or the virtual machine comprises: Fusing the connection relationship between the network device and the physical machine or the virtual machine, the physical machine to which each virtual machine belongs, and the relationship between each software and the physical machine or the virtual machine, and constructing the business monitoring topology structure.

5. The business system monitoring method based on business dimension according to claim 4, characterized in that, The step of determining the first end network device according to MIB table information corresponding to each network device comprises: Obtaining iproute table information of each device, and searching for a MAC address of a next device connected according to the iproute table information of the device; Judging whether the MAC address of the next device connected is same as a MAC address of another device, and if the MAC address of the next device connected is different from the MAC address of the other device, the next device connected is an end network device.

6. The business system monitoring method based on business dimension according to claim 1, wherein, The step of analyzing the monitoring data based on the business dimension and obtaining the monitoring result of the business system comprises: Inputting the monitoring data into a trained prediction model to obtain a prediction value of running state data corresponding to different business subject types in different business dimensions; Inputting the prediction value of the running state data corresponding to different business subject types in different business dimensions and a real value of the running state data currently obtained into a trained anomaly detection model to obtain a monitoring result output by the anomaly detection model, wherein the anomaly detection model is trained based on business monitoring indicators and monitoring rules respectively configured for different business subject types in different business dimensions.

7. The business system monitoring method based on business dimension according to claim 6, characterized in that, The step of analyzing the monitoring data based on the business dimension and obtaining the monitoring result of the business system further comprises: According to the corresponding business subject type in the monitoring data, obtaining matched business monitoring indicators and monitoring rules; Training the prediction model and the anomaly detection model based on the business monitoring indicators and the monitoring rules respectively configured for different business subject types in different business dimensions and the historical monitoring data corresponding to each business subject type obtained.

8. A business system monitoring system based on business dimensions, characterized by, Comprise: An information acquisition module configured to acquire hardware and software information in a business system, and running state data of the hardware and the software; A topology construction module configured to construct a business monitoring topology result according to an association relationship between each hardware and software; The monitoring data generation module is configured to map the running state data of the hardware and the software to the business monitoring topology result, and form the monitoring data of the business dimension. The monitoring data analysis module is configured to analyze the monitoring data based on the business dimension, obtain the monitoring result of the business system, and output and display the monitoring result. The step of constructing the business monitoring topology structure according to the association relationship between the hardware and the software comprises: determining the relationship between the software and the physical machine or the virtual machine according to whether the IP addresses of the monitored software and the physical machine or the virtual machine are the same; determining the physical machine to which each virtual machine belongs according to the detailed information of the physical machine and the virtual machine scanned by the hyper-converged protocol; obtaining the connection relationship between the network device and the physical machine or the virtual machine according to the network device SNMP protocol; wherein, the MIB table information of all network devices is obtained, and the first end network device is determined according to the MIB table information corresponding to each network device; then, the determined first end network device is removed from the current connection result, the end network device in the connection result after the first end network device is removed is searched, and the searched end network device is defined as the second end network device; the searched end network device is removed in turn, and the end network device in the connection network after the searched end network device is removed is repeatedly searched; then, the end network device searched in each step is connected to establish a connection relationship, so as to obtain the connection relationship between the network device and the physical machine or the virtual machine; the business monitoring topology structure is constructed according to the relationship between the software and the physical machine or the virtual machine, the physical machine to which each virtual machine belongs, and the connection relationship between the network device and the physical machine or the virtual machine.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores one or more computer readable programs, which can be executed by one or more processors; when the computer readable programs are executed by the processor, the business system monitoring method based on the business dimension is realized.

Citation Information

Patent Citations

  • Operation and maintenance monitoring integral system and integral monitoring method used in IT (information technology) field

    CN103532780A

  • Topology discovery and network asset association method and device for network operation and maintenance system

    CN117579492A