Network equipment alarm analysis method based on user-defined multi-layer analysis rule

By adopting custom multi-layer analysis rules and general matching logic in network device alarm analysis, the problems of high difficulty in writing rules and poor reusability in the existing technology are solved, and more flexible and efficient alarm analysis processing is achieved.

CN120200894APending Publication Date: 2025-06-24BEIJING ZZNODE TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510378184.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the process of alarm analysis of network equipment, the rules are difficult to write, poor flexibility, and lack the ability to configure common rules, so the reuse of alarm analysis rules cannot be achieved.

Method used

Using a method based on custom multi-layer resolution rules, multi-level alarm resolution rules are constructed by defining alarm resolution scope tuples, and a general matching logic is introduced to support fuzzy queries and rule reuse.

Benefits of technology

It improves the flexibility and reusability of alarm analysis processing, reduces the difficulty of rules writing and maintenance, improves development efficiency and reduces labor costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200894A_ABST
    Figure CN120200894A_ABST
Patent Text Reader

Abstract

The invention relates to a network equipment alarm analysis method based on a user-defined multi-layer analysis rule, which is characterized by comprising the following steps of: 1, carrying out segmentation and slicing on a processing rule by customizing the multi-layer analysis rule according to requirements, namely, carrying out segmentation processing on a complex analysis processing requirement, and solving the problems of high complexity and poor flexibility of analysis rule configuration in the existing scheme. Defining an alarm analysis range tuple, and constructing a multi-level alarm analysis rule according to service requirements and the analysis range tuple; 2, receiving an alarm message according to an alarm message object structure defined by a system, performing fuzzy query on an alarm analysis rule according to analysis range tuple information and an alarm category identifier in an alarm message object, and analyzing an alarm object attribute according to the analysis rule; and step 3, outputting analyzed alarm object information after completing alarm analysis processes of all levels in multiple cycles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network device monitoring in IT network operation and maintenance management, and particularly to a network device alarm parsing method based on a custom multi-layer parsing rule. Background Art

[0002] Reference Figure 6 As shown, the existing technical solutions mainly use a configurable rule method to implement the parsing and processing of network device alarms. First, analyze the alarm characteristics of network devices according to the manufacturer's information, and construct the parsing rules for such alarms according to each network device alarm characteristic and save them. When the parsing module receives an alarm message, extract the alarm characteristics, and find the corresponding alarm parsing rules according to the alarm characteristics, alarm manufacturer, device type, and device model, and then parse the alarm object through the parsing rules, generate a standardized alarm message object and output it.

[0003] The problems and defects existing in the prior art are mainly as follows:

[0004] (1) The alarm parsing process is divided into one or several fixed stages. Each stage requires configuring different parsing rule modules, with poor flexibility and high rule writing difficulty. The alarm parsing process in the existing solution is divided into processes such as basic parsing, general parsing, and special processing. Each process requires an independent template and configures a set of processing rules. The rules at each level complete specific processing tasks, and the rules only act once. It is impossible to divide the processing rules into multiple segments and execute them one by one. Therefore, the parsing rules corresponding to complex parsing processing requirements are also relatively complex, and the writing and modification difficulties are both very high.

[0005] (2) Each type of alarm corresponds to a type of parsing rule, lacking the ability to configure general rules and unable to achieve the reuse of alarm parsing rules. The existing solution configures parsing rules based on device identifiers and alarm category identifiers. That is, when matching parsing rules, the clear device identifier and alarm category identifier are used as the primary key for rule selection, lacking the ability of fuzzy rule matching and unable to achieve the reuse of alarm parsing rules. Summary of the Invention

[0006] In view of the defects or deficiencies existing in the prior art, the present invention provides a network device alarm parsing method based on a custom multi-layer parsing rule. By customizing the multi-layer parsing rule as needed, the processing rule is segmented and sliced, that is, a complex parsing processing requirement is processed in segments, solving the problems of high complexity and poor flexibility in parsing rule configuration in the existing solution. In addition, by customizing the parsing rule tuple as needed and introducing a general matching logic to achieve the configuration of general alarm parsing rules, the problem that the parsing rules in the existing solution cannot be reused is solved.

[0007] The technical solution of the present invention is as follows:

[0008] A method for parsing network device alarms based on custom multi - layer parsing rules, characterized by including the following steps:

[0009] Step 1, define an alarm parsing scope tuple, and construct multi - level alarm parsing rules according to business requirements and the parsing scope tuple;

[0010] Step 2, receive alarm messages according to the alarm message object structure defined by the system, perform a fuzzy query for alarm parsing rules based on the parsing scope tuple information and the alarm category identifier in the alarm message object, and parse the alarm object attributes according to the parsing rules;

[0011] Step 3, after completing the alarm parsing process for all levels through multiple loops, output the information of the parsed alarm object.

[0012] It includes an alarm message object input module, an alarm attribute parsing module, an alarm parsing rule loading and caching module that supports the parsing of alarm attributes, an alarm parsing rule management and maintenance module, and an alarm message object output module. The alarm attribute parsing module includes an alarm message object information extraction module, an alarm parsing rule matching module, and an alarm attribute parsing and saving module. The alarm parsing rule loading and caching module includes an alarm parsing rule reading module, an alarm parsing rule caching module, and an alarm parsing rule tree construction module. The alarm parsing rule management and maintenance module includes an alarm parsing rule maintenance module and an alarm parsing rule storage module.

[0013] The construction process of the multi - level alarm parsing rules in Step 1 includes the following steps:

[0014] Step a1, determine and configure the alarm rule layer number;

[0015] Step a2, determine and configure the alarm category identifier;

[0016] Step a3, determine and configure the alarm attributes to be parsed, and configure the alarm parsing rules for the attributes to be parsed;

[0017] Step a4, determine and configure the parsing tuple instance;

[0018] Step a5, judge whether to continue processing. If yes, return to Step a1. If no, end.

[0019] The matching process of the multi - level alarm parsing rules in Step 1 includes the following steps:

[0020] Step b1, read the alarm object level counter to determine the alarm rule tree, and judge whether the rule tree can be matched. If not, end. If so, enter Step b2;

[0021] Step b2, traverse the rule tree once through the alarm category identifier and parsing tuple instance attributes;

[0022] Step b3, determine whether a corresponding node can be matched. If so, go to step b6; if not, go to step b4;

[0023] Step b4, match the general rule identifier information "*";

[0024] Step b5, determine whether a corresponding node can be matched. If not, end; if so, go to step b6;

[0025] Step b6, determine whether the traversal is completed. If not, return to step b2; if so, go to step b7;

[0026] Step b7, output the list of matched nodes in order;

[0027] Step b8, generate the key value of the parsing rule list according to the list of matched nodes;

[0028] Step b9, traverse the parsing rule list, and end after outputting the alarm attribute parsing rule list.

[0029] The multiple loops in step 3 to complete the alarm parsing process for all levels include the following steps:

[0030] Step 3.1, start the alarm parsing service and load the alarm parsing rules;

[0031] Step 3.2, construct a parsing rule tree and a hash map HashMap based on the parsing rules;

[0032] Step 3.3, read the alarm message object information and extract the relevant identification information;

[0033] Step 3.4, query the alarm parsing rules based on the hierarchical encoding, alarm category ID, and parsing tuple instance, and determine whether the parsing rules exist. If not, go to step 3.7; if so, go to step 3.5;

[0034] Step 3.5, perform alarm attribute parsing and processing based on the parsing rules;

[0035] Step 3.6, determine whether the parsing rules for the next level exist. If so, return to step 3.3; if not, go to step 3.7;

[0036] Step 3.7, output the parsed alarm message object and end.

[0037] The technical effects of the present invention are as follows: the present invention is a network device alarm parsing method based on customized multi-layer parsing rules, which has a more open configuration capability than the prior art, supports parsing rule reuse and fuzzy matching of parsing rules, and supports multi-level dynamic parsing of alarms in a pipeline manner. In different application scenarios, alarm configuration parsing can be completed on demand without additional development, thereby improving the efficiency of alarm parsing and processing development and reducing labor costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 It is a schematic diagram of the module combination structure involved in implementing the network device alarm analysis method based on user-defined multi-layer analysis rules of the present invention. Figure 1 It includes an alarm message object input module, an alarm attribute parsing module, an alarm parsing rule loading and caching module supporting the alarm attribute parsing, and an alarm parsing rule management and maintenance module, an alarm message object output module, the alarm attribute parsing module includes an alarm message object information extraction module, an alarm parsing rule matching module, and an alarm attribute parsing and saving module, the alarm parsing rule loading and caching module includes an alarm parsing rule reading module, an alarm parsing rule caching module, and an alarm parsing rule tree construction module, the alarm parsing rule management and maintenance module includes an alarm parsing rule maintenance module, and an alarm parsing rule storage module.

[0039] Figure 2 It is a flowchart of alarm analysis rule construction. Figure 2 It includes step 1, determining and configuring the alarm rule layer number; step 2, determining and configuring the alarm category identifier; step 3, determining and configuring the alarm attribute to be parsed, and configuring the alarm parsing rules for the attribute to be parsed; step 4, determining and configuring the parsing tuple instance; step 5, judging whether it is necessary to continue processing, if yes, return to step 1, if not, end. Step 1 includes: the rule configuration is generally from general to special order, the general rules are configured in the front layer to process the general attribute information, and the special rules are configured in the back layer to process the special attribute information, so as to improve the rule reuse and flexibility. Step 3 includes: the alarm attributes are defined on demand, multiple attributes can be configured, and the attributes can be expanded on demand, and support subsequent modification through rules. All defined alarm attributes are included in the alarm object output and can be referenced arbitrarily at different levels. Step 4 includes: determining the scope of the rule based on business knowledge, that is, parsing the tuple instance. To improve reusability, try to expand the scope. For example, if the alarms of the same device type are consistent, do not configure the specific model, otherwise the alarm scope will be narrowed. The front layer should use rules with strong universality.

[0040] Figure 3 It is a schematic diagram of a parsing rule index tree constructed based on parsing rule identifiers. Figure 3Among them, L is the rule hierarchy, L-1 is the first root node of the rule hierarchy, L-2 is the second root node of the rule hierarchy, and so on. L-n is the nth root node of the rule hierarchy, where n is a positive integer. A is the alarm category identification layer, A-1 is the first node of the alarm category identification layer, A-2 is the second node of the alarm category identification layer, and so on. A-n is the nth node of the alarm category identification layer. RC1 is the first layer of the parsing tuple attributes, RC2 is the second layer of the parsing tuple attributes, and so on. RCn is the nth layer of the parsing tuple attributes, and RCn-n is the nth node of the nth layer of the parsing tuple attributes.

[0041] Figure 4 It is a schematic diagram of the alarm parsing rule matching process. Figure 4 Among them, it includes Step 1: Read the alarm object hierarchy counter to determine the alarm rule tree, and determine whether the rule tree can be matched. If not, end. If so, enter Step 2. Step 2 includes Step 2.1: Traverse the rule tree once through the alarm category identification and the parsing tuple instance attributes. Step 2.2: Determine whether the corresponding node can be matched. If so, enter Step 2.5. If not, enter Step 2.3. Step 2.3: Match the general rule identification information "*". Step 2.4: Determine whether the corresponding node can be matched. If not, end. If so, enter Step 2.5. Step 2.5: Determine whether the traversal is completed. If not, return to Step 2.1. If so, enter Step 3. Step 3: Output the matching node list in order. Step 4: Generate the key value of the parsing rule list according to the matching node list. Step 5: Traverse the parsing rule list and end after outputting the alarm attribute parsing rule list.

[0042] Figure 5 It is a schematic diagram of the alarm parsing processing process. Figure 5 Among them, it includes Step 1: Start the alarm parsing service and load the alarm parsing rules. Step 2: Build the parsing rule tree and the hash map HashMap based on the parsing rules. Step 3: Read the alarm message object information and extract the relevant identification information. Step 4: Query the alarm parsing rules based on the hierarchy code, alarm category ID, and parsing tuple instance, and determine whether the parsing rules exist. If not, enter Step 7. If so, enter Step 5. Step 5: Parse and process the alarm attributes based on the parsing rules. Step 6: Determine whether the parsing rules of the next level exist. If so, return to Step 3. If not, enter Step 7. Step 7: End after outputting the parsed alarm message object.

[0043] Figure 6 It is a schematic diagram of the parsing and processing process of network device alarms implemented by the configurable rule method in the prior art. Step 6 includes receiving the alarm object, basic alarm parsing, alarm attribute parsing according to the alarm attribute parsing rules, and alarm object output. Specific implementation mode

[0044] The present invention will be described below in conjunction with the accompanying drawings ( Figures 1 - 5 ) and embodiments.

[0045] Figure 1 is a schematic diagram of the module combination structure involved in implementing the network device alarm parsing method based on custom multi - layer parsing rules of the present invention. Figure 2 is a schematic diagram of the alarm parsing rule construction process. Figure 3 is a schematic diagram of the parsing rule index tree constructed based on the parsing rule identifier. Figure 4 is a schematic diagram of the alarm parsing rule matching process. Figure 5 is a schematic diagram of the alarm parsing processing process.

[0046] Figure 6 is a schematic diagram of the parsing and processing process of network device alarms implemented by the configurable rule method in the prior art. Refer to Figures 1 to 6 As shown, a network device alarm parsing method based on custom multi - layer parsing rules includes the following steps: Step 1, define the alarm parsing range tuple, and construct multi - level alarm parsing rules according to service requirements and the parsing range tuple; Step 2, receive alarm messages according to the alarm message object structure defined by the system, and perform fuzzy query of alarm parsing rules based on the parsing range tuple information and the alarm category identifier in the alarm message object, and parse the alarm object attributes according to the parsing rules; Step 3, after completing the alarm parsing process of all levels through multiple loops, output the information of the parsed alarm object.

[0047] It includes an alarm message object input module, an alarm attribute parsing module, an alarm parsing rule loading and caching module and an alarm parsing rule management and maintenance module to support the alarm attribute parsing, and an alarm message object output module. The alarm attribute parsing module includes an alarm message object information extraction module, an alarm parsing rule matching module, and an alarm attribute parsing and saving module. The alarm parsing rule loading and caching module includes an alarm parsing rule reading module, an alarm parsing rule caching module, and an alarm parsing rule tree construction module. The alarm parsing rule management and maintenance module includes an alarm parsing rule maintenance module and an alarm parsing rule storage module.

[0048] The construction process of the multi - level alarm parsing rules in Step 1 includes the following steps: Step a1, determine and configure the alarm rule layer number; Step a2, determine and configure the alarm category identifier; Step a3, determine and configure the alarm attributes to be parsed, and configure the alarm parsing rules for the attributes to be parsed; Step a4, determine and configure the parsing tuple instance; Step a5, judge whether to continue processing. If yes, return to Step a1. If no, end.

[0049] The matching process of the multi-level alarm parsing rule in Step 1 includes the following steps: Step b1, read the alarm object level counter to determine the alarm rule tree, and determine whether the rule tree can be matched. If not, end the process. If so, proceed to Step b2; Step b2, traverse the rule tree once through the alarm category identifier and the parsing tuple instance attributes; Step b3, determine whether the corresponding node can be matched. If so, proceed to Step b6. If not, proceed to Step b4; Step b4, match the general rule identifier information "*"; Step b5, determine whether the corresponding node can be matched. If not, end the process. If so, proceed to Step b6; Step b6, determine whether the traversal is completed. If not, return to Step b2. If so, proceed to Step b7; Step b7, output the list of matched nodes in order; Step b8, generate the key value of the parsing rule list based on the list of matched nodes; Step b9, traverse the parsing rule list, output the alarm attribute parsing rule list, and then end the process.

[0050] The process of completing the alarm parsing for all levels through multiple loops in Step 3 includes the following steps: Step 3.1, start the alarm parsing service and load the alarm parsing rules; Step 3.2, construct the alarm parsing rule tree and the hash map HashMap based on the parsing rules; Step 3.3, read the alarm message object information and extract the relevant identifier information; Step 3.4, query the alarm parsing rule based on the level code, alarm category ID, and parsing tuple instance, and determine whether the parsing rule exists. If not, proceed to Step 3.7. If so, proceed to Step 3.5; Step 3.5, perform alarm attribute parsing and processing based on the parsing rule; Step 3.6, determine whether the parsing rule for the next level exists. If so, return to Step 3.3. If not, proceed to Step 3.7; Step 3.7, output the parsed alarm message object and then end the process.

[0051] The present invention relates to a network device alarm parsing method and device based on a custom multi-level parsing rule, which has a more open configuration ability compared with the prior art, supports the reuse of parsing rules and fuzzy matching of parsing rules, and supports multi-level dynamic parsing and processing of alarms in a pipeline manner. In different application scenarios, alarm configuration parsing can be completed as needed without additional development, improving the development efficiency of alarm parsing processing and reducing labor costs.

[0052] Alarm access adaptation of the present invention: Develop an alarm interface protocol adaptation module to receive alarms and send the original alarms appended with device information as a standard message object to the device of the present invention according to the requirements of the parsing module. There is no need to pay attention to the service information in the alarm content, and the alarm can be parsed and processed through subsequent rule configuration methods, and the alarm message object that meets the requirements can be output, thus simplifying the processing process of the interface module.

[0053] Alarm parsing and processing of the present invention: Alarm parsing is implemented based on configurable parsing rules.

[0054] The present invention supports multi-level alarm processing in a pipeline manner. That is, complex alarm parsing rules can be split, and more general rule slices can be abstracted to improve the generality of alarm rules and reduce the scale of alarm rule configuration and maintenance. When the requirements change, only subsequent levels need to be added directly, and there is no need to modify the original rules, reducing the complexity of modifying alarm rules.

[0055] The present invention supports the configuration of general parsing rules. That is, the reuse of alarm rules is achieved by introducing the general matching identifier "*". When an alarm parsing rule contains "*", it indicates that it is applicable to all types represented by "*". There is no need to perform precise configuration for each specific type.

[0056] The present invention supports fuzzy matching of parsing rules. That is, during the parsing process, it supports the fuzzy matching ability from precise rules to general rules. The present invention automatically loads alarm parsing rules into memory and generates an alarm rule tree, and traverses the parsing rules according to the instance attributes of alarm parsing tuples in the order of first precise and then general. When no precise parsing rule is found, the general parsing rule is automatically used for alarm processing to achieve maximum alarm parsing processing.

[0057] The network device alarm parsing method and device based on custom multi-level parsing rules of the present invention include the definition of parsing tuples and parsing template definition methods for custom multi-level parsing rules; the construction method and rule matching method of custom multi-level parsing rule trees; and the alarm parsing process based on custom multi-level rules.

[0058] The purpose of the present invention is to provide a simple, general and flexibly configurable alarm parsing solution during the alarm parsing process, realizing configurable alarm parsing by customizing rule tuples, extracting general rules and performing fuzzy matching of rules.

[0059] Reference Figure 1 , first define the alarm parsing scope tuple, and construct multi-level alarm parsing rules according to business requirements and the parsing scope tuple. Then receive the alarm message according to the alarm message object structure defined by the system, and perform fuzzy query of the alarm parsing rule based on the alarm category identifier and parsing scope tuple information in the alarm message object, and parse the alarm object attributes according to the parsing rule. After multiple loops to complete the alarm parsing of all levels, output the information of the parsed alarm object.

[0060] (1) Definition of alarm parsing scope tuple

[0061] The alarm parsing scope tuple (hereinafter referred to as the parsing tuple) is the alarm parsing rule identifier, and the alarm parsing module matches the alarm parsing rule according to the parsing tuple information.

[0062] The parsing tuple can be defined as needed according to business requirements and characteristics. Both the alarm parsing rule and the alarm object need to construct corresponding identification information according to the defined parsing range tuple to meet the matching between the alarm and the parsing rule.

[0063] Definition of Alarm Parse Meta Data:

[0064] APMD = Rc1:Rc2..Rcn

[0065] The definition of the parsing range tuple includes two parts: the definition of attributes (Rc) and the definition of format:

[0066] The definition of attributes is the attribute information that makes up the parsing tuple, such as device manufacturer, type, model, identifier, and alarm interface protocol, etc., which can be defined as needed according to business characteristics.

[0067] The definition of format is the information combination of multiple tuple attributes. This solution uses ":" as the separator between attributes. That is, different attribute values are connected into a string through ":" and saved. After the order of the parsing tuple attributes is defined, it cannot be adjusted. If an individual attribute in the parsing tuple instance is empty, it needs to be occupied by "*", which means that any value can be matched during the matching process. For example: the parsing tuple definition sample "device manufacturer:device type:device model:interface protocol:device identifier", and the parsing tuple instance sample based on the parsing tuple "Huawei:switch:*:trap:*" (the instance is not case-sensitive).

[0068] (2) Definition of Alarm Message Object

[0069] The alarm message object is the general format of the alarm object received, processed, and output by the alarm parsing module. It contains the necessary alarm attributes and supports the parsing module to add attributes and modify attribute values according to the parsing rules.

[0070] Structure definition of Alarm Message Object:

[0071] AMO = {

[0072] alarmTypeId String;

[0073] alarmRawInfo String;

[0074] alarmApmdId String;

[0075] alarmParseRuleLevel int;

[0076] alarmBaseInfo1…n String;

[0077] alarmCollectinfo1…n String;

[0078] alarmOtherInfo1…n String;

[0079] }

[0080] Alarm category identifier (alarmTypeId): The alarm category identifier that matches the rule.

[0081] Alarm original message (alarmRawInfo): The alarm object information obtained by collecting the original alarm from the device and converting it into text.

[0082] Parsed tuple instance (alarmApmdId): The parsed tuple value generated according to the parsed tuple definition through alarm information (basic information, collection information, other information, etc.). For specific examples, refer to the examples in the "Alarm Parsing Range Tuple Definition".

[0083] Alarm rule level (alarmParseRuleLevel): The default value is 1, which is maintained by the parsing module during the subsequent parsing process and is incremented by 1 after each layer of rule processing.

[0084] Alarm basic information (alarmBaseInfo1…n): A list of basic attributes such as the alarm interface protocol, device manufacturer, device type, device model, and device identifier, which can be defined as needed.

[0085] Alarm collection information (alarmCollectinfo1…n): A list of attribute information during the alarm collection process. This part of the information is generally not modified during the parsing process and can be defined as needed.

[0086] Alarm other attributes (alarmOtherInfo1…n): Can be added arbitrarily through parsing rules during the processing process, or added in the previous module, such as the protocol adaptation module. Subsequently, they can all be modified through parsing rules, such as the alarm sequence number, alarm unique identifier, alarm level, etc.

[0087] (3) Definition of Alarm Parsing Rule Template

[0088] The alarm parsing rule template (hereinafter referred to as the parsing template) provides a storage structure for alarm parsing rules.

[0089] Structure definition of the alarm parsing rule template (AlarmParseRuleTemplete):

[0090] APRT = {

[0091] alarmParseRuleLevel int;

[0092] alarmTypeId String;

[0093] alarmApmdId String;

[0094] alarmColumnName String;

[0095] alarmParseRuleInfo String;

[0096] }

[0097] Rule level (alarmParseRuleLevel): The level where the configuration rule is located, and the levels need to be configured in sequence.

[0098] Alarm category identifier (alarmTypeId): The rule matches the alarm category identifier, and it supports configuring the general identifier "*" to match all alarm message types.

[0099] Parsed tuple instance (alarmApmdId): The parsed tuple instance of different alarms constructed based on the parsed tuple definition.

[0100] Alarm attribute name (alarmColumnName): The name of the alarm attribute that needs to be parsed, and it supports custom extensions. All defined attributes will be output after parsing.

[0101] Alarm attribute parsing rule (alarmParseRuleInfo): The module extracts the target information from the input information according to the configured parsing rule and saves it to the current attribute. If there is data in the current attribute, it will be automatically overwritten. The rule supports using the built-in functions of the module.

[0102] (IV) References Figure 2 , Alarm parsing rule construction:

[0103] Step 1: Determine the rule level. The rule level starts from 1 and increases continuously thereafter;

[0104] Step 2: Analyze according to the received alarm message object information to determine and configure the alarm category identifier; if the clear category identifier cannot be determined, configure it as the general identifier "*";

[0105] Step 3: Determine the set of alarm attributes to be parsed and the alarm attribute parsing rules for extracting attribute values from the alarm message. The alarm attribute parsing rules are a set of parsing rules for attributes (the parsing module has built-in parsing tool plugins, such as string processing function plugins, which can be called through the parsing rules), and can be added as needed. The newly added attributes are automatically added to the alarm message object, and all existing attributes of the alarm message object can be accessed in the parsing rules. When the alarm category identifier and the parsed tuple instance value information are modified, flexible matching of the next-level parsing rules can be achieved, which is equivalent to continuously changing the unique identifier information of the alarm matching rules for an alarm;

[0106] Step 4: Determine the parsed tuple instance, that is, determine the scope of the configuration rule. The parsed tuple can be filled in according to the generality of the rule. If the rule is general (applicable to all manufacturers), then the manufacturer attribute of the parsed tuple is filled with the general identifier "*", and other attributes are filled in the same way;

[0107] Step 5: If further processing of the alarm message after the processing of the rules at this level is required, then re-configure the rules for the second, third, and subsequent levels according to the methods in Steps 1 to 4. And so on, until the alarms parsed according to all levels of parsing rules meet the parsing requirements. During the configuration of subsequent levels, the alarm category identifier and the alarm parsing tuple instance can be modified.

[0108] (5) Construction of the alarm parsing rule tree

[0109] The alarm parsing rule tree is the data structure in which the alarm parsing rules, rule identifiers, and parsed tuples are loaded into memory during the operation of the module.

[0110] For different parsing rules, they are saved in a Key-Value list structure in memory, where the Key (index) is jointly composed of the level, alarm category identifier, and parsed tuple. The Value (value) saves the alarm attribute and the parsing rule object information of the attribute.

[0111] Definition of the alarm parsing rule list (AlarmParseRuleList):

[0112] APRL = {(alarmParseRuleId[i],(alarmParseCol[ij],alarmParseColRule[ij]))…}

[0113] alarmParseRuleId: Alarm parsing rule ID, that is, a concatenated string according to "rule level: alarm category identifier: parsed tuple instance".

[0114] (alarmParseCol[ij], alarmParseColRule[ij]): List of alarm attribute names (alarmParseCol[ij]) and alarm attribute parsing rules (alarmParseColRule[ij]).

[0115] At the same time, build a rule index tree in memory to save all alarm parsing rule identifiers, and search for the parsing rule identifiers by traversing the tree.

[0116] Reference Figure 3 , Definition of the alarm parsing rule index tree (AlarmParseRuleIndexTree):

[0117] 1. Build a parsing rule tree with the level (alarmParseRuleLevel) as the root node, that is, generate a parsing rule tree for each level;

[0118] 2. Use the alarm category identifier (alarmTypeId) as the second-level node of the parsing rule tree;

[0119] 3. Build the third to nth-level nodes in sequence according to each attribute (Rcn) of the parsing tuple (alarmApmdId).

[0120] (VI) Reference Figure 4 , Alarm parsing rule matching method

[0121] Alarm parsing rule matching is the process of traversing the alarm parsing rule tree based on the alarm category information and parsing tuple information carried by the alarm message object, and obtaining the target parsing and processing rules.

[0122] Step 1: Select the algorithm rule tree (AlarmParseRuleIndexTree) according to the rule level information. The level defaults to 1, and the level is incremented by 1 after each layer is matched;

[0123] Step 2: Traverse the rule tree in sequence according to the alarm category identifier and parsing tuple instance attribute information in the rule tree returned in Step 1. If it exists, continue to search under this node; if it does not exist, judge whether there is a "*", that is, the general identifier information. If the general identifier information exists, continue to search under this node. If it does not exist, return "rule does not exist" and end the search process;

[0124] Step 3: When the search is completed, return all the node information matched by the rule tree in sequence;

[0125] Step 4: Based on the information returned in Step 3, splice all node values according to the rule formed by the alarm parsing rule IDs in the parsing rule list (APRL) to generate the alarm parsing rule ID value to be queried;

[0126] Step 5: Traverse the parsing rule list (APRL) based on the alarm parsing rule ID value returned in Step 4 to obtain the corresponding alarm parsing rule information, that is, obtain the alarm attributes and attribute parsing rules.

[0127] (7) Alarm Attribute Parsing Process

[0128] The alarm attribute parsing process is to parse the alarm message object based on the specific alarm parsing rule read and write the parsing result back to the alarm message object. The alarm attribute parsing rule consists of two parts: the alarm attribute name and the alarm parsing rule:

[0129] Alarm Attribute Name (alarmParseCol): That is, the target alarm attribute name. The processing result after the execution of the alarm parsing rule is saved to this attribute. If this attribute name already exists in the alarm message object, the parsing result will update its value; otherwise, this attribute will be automatically added to the alarm message object and assigned a value.

[0130] Alarm Parsing Rule (alarmParseColRule): Rule information for processing and converting based on the attribute information in the alarm message object. The parsing module builds in common processing functions and regular expression tools to implement parsing and conversion processing for it. The corresponding processing tools can be continuously expanded as needed.

[0131] Step 1: Read the target attribute and the parsing rule corresponding to the target attribute;

[0132] Step 2: Extract the input attribute values involved in the rule from the alarm object;

[0133] Step 3: Perform parsing processing on the attribute values according to the rule;

[0134] Step 4: If the target attribute exists in the alarm parsing object, directly save the parsing result to the corresponding attribute; otherwise, create the corresponding target attribute in the alarm object and save the parsing result to the alarm message object;

[0135] Step 5: Loop through Steps 1 to 4 until all alarm attributes are parsed and this parsing process ends.

[0136] (8) References Figure 5 , the overall process of alarm parsing and processing

[0137] Step 1: Start the alarm parsing service, and the module automatically loads the alarm parsing rules according to the alarm parsing rule module;

[0138] Step 2: Construct a parsing rule tree in memory according to the parsing rule scope information;

[0139] Step 3: Receive the alarm message object, and extract the alarm category ID and parsing tuple instance information;

[0140] Step 4: Traverse the parsing rule tree based on the alarm category identifier and parsing tuple instance attribute information to obtain the parsing rule information. If the parsing rule does not exist, directly jump to Step 7;

[0141] Step 5: Perform alarm parsing processing according to the read parsing rule. And write back the parsing result to the alarm object;

[0142] Step 6: Continue to read the next-level parsing rule according to Step 4. If it exists, continue to perform alarm parsing processing according to Steps 4 and 5 until there are no more post-processing rules;

[0143] Step 7: Output the alarm message object to complete the alarm parsing.

[0144] The content not described in detail in the specification of the present invention belongs to the prior art well-known to those skilled in the art. It is hereby pointed out that the above description helps those skilled in the art to understand the present invention, but does not limit the protection scope of the present invention. Any implementation that makes equivalent replacements, modifications and improvements, and / or simplifies the above description without departing from the essential content of the present invention falls within the protection scope of the present invention.

Claims

1. A network device alarm analysis method based on custom multi-layer analysis rules, characterized in that: The following steps are involved: Step 1: Define the alarm analysis scope tuple, and build multi-level alarm analysis rules according to business requirements and analysis scope tuple; Step 2: receiving the alarm message according to the alarm message object structure defined by the system, and fuzzy querying the alarm parsing rules according to the parsing range tuple information and the alarm category identifier in the alarm message object, and parsing the alarm object attributes according to the parsing rules; Step 3: After completing the alarm analysis process at all levels in multiple cycles, output the alarm object information after analysis.

2. The network device alarm analysis method based on customized multi-layer analysis rules according to claim 1 is characterized in that: It includes an alarm message object input module, an alarm attribute parsing module, an alarm parsing rule loading and caching module supporting the alarm attribute parsing, and an alarm parsing rule management and maintenance module, and an alarm message object output module. The alarm attribute parsing module includes an alarm message object information extraction module, an alarm parsing rule matching module, and an alarm attribute parsing and saving module. The alarm parsing rule loading and caching module includes an alarm parsing rule reading module, an alarm parsing rule caching module, and an alarm parsing rule tree construction module. The alarm parsing rule management and maintenance module includes an alarm parsing rule maintenance module, and an alarm parsing rule storage module.

3. The network device alarm analysis method based on customized multi-layer analysis rules according to claim 1 is characterized in that: The construction process of multi-level alarm analysis rules in step 1 includes the following steps: Step a1, determine and configure the alarm rule layer number; Step a2, determine and configure the alarm category identifier; Step a3, determining and configuring the alarm attributes to be analyzed, and configuring the alarm analysis rules for the attributes to be analyzed; Step a4, determining and configuring the parsed tuple instance; Step a5, determine whether to continue processing, if yes, return to step a1, if no, end.

4. The network device alarm analysis method based on customized multi-layer analysis rules according to claim 1 is characterized in that: The matching process of the multi-level alarm parsing rules in step 1 includes the following steps: Step b1, read the alarm object level counter to determine the alarm rule tree, and determine whether the rule tree can be matched. If not, end; if yes, proceed to step b2; Step b2, traversing the rule tree once through the alarm category identification and parsing tuple instance attributes; Step b3, determine whether the corresponding node can be matched, if yes, proceed to step b6, if not, proceed to step b4; Step b4, matching the general rule identification information "*"; Step b5, determine whether the corresponding node can be matched, if not, end, if yes, go to step b6; Step b6, determine whether the traversal is completed, if not, return to step b2, if yes, go to step b7; Step b7, output the matching node list in order; Step b8, generating a key value of a parsing rule list according to the matching node list; Step b9, traverse the parsing rule list, output the alarm attribute parsing rule list and then end.

5. The network device alarm analysis method based on customized multi-layer analysis rules according to claim 1 is characterized in that: The alarm analysis process of completing all levels of the alarm analysis in multiple cycles in step 3 includes the following steps: Step 3.1, start the alarm analysis service and load the alarm analysis rules; Step 3.2, construct a parsing rule tree and a hash map HashMap based on the parsing rules; Step 3.3, read the alarm message object information and extract relevant identification information; Step 3.4, based on the level code and alarm category ID, parse the tuple instance to query the alarm parsing rule, and determine whether the parsing rule exists. If not, proceed to step 3.7; if yes, proceed to step 3.5; Step 3.5, analyzing and processing the alarm attributes based on the analysis rules; Step 3.6, determine whether the next level of parsing rules exists, if yes, return to step 3.3, if no, go to step 3.7; Step 3.7, output the parsed alarm message object and end.

Citation Information

Cited By

  • A method and electronic device for processing alarm information in a storage system

    CN122570273A

  • A storage system alarm information processing method and an electronic device

    CN122570273B