Clustering-based alarm association rule generation method and device, equipment and medium
The alarm log is processed through a cluster-based method, a high-cohesion alarm cluster group is generated and transactions are divided in combination with the time window. The association rule learning algorithm is used to generate alarm association rules, which solves the problems of lag in fault discovery and inaccurate attribution in traditional technology, and realizes efficient fault analysis and positioning.
Patent Information
- Application Number
- CN202510400977.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-04
AI Technical Summary
Traditional alarm log processing technology cannot effectively process dynamic multi-dimensional alarm data, resulting in lagging fault discovery and inaccurate attribution, making it difficult to meet the needs of intelligent operation and maintenance in large-scale dynamic environments.
The clustering-based method is adopted, and the alarm log is clustered using the elbow rule, transactions are divided in combination with the time window, and alarm association rules are generated through the association rule learning algorithm, which is stored in the graph database, considering the alarm name and multi-dimensional characteristics of the monitoring object.
It significantly improves the confidence of rules and can capture complex patterns, such as the frequent triggering of different alarms or cascading faults across devices, providing a traceable causal relationship network to help quickly locate root cause alarms.
Smart Images

Figure CN120258120A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data operation and maintenance, and particularly relates to a method, device, equipment and medium for generating alarm association rules based on clustering. Background Art
[0002] With the evolution of enterprise IT systems towards cloud-native and microservices architectures, the scale of distributed systems has exploded, the volume of log data has increased exponentially, and the traditional manual inspection mode can no longer cope with a large number of alarms. Existing alarm log processing technologies mostly use fixed time windows and simple statistical models to group alarms, which have significant limitations.
[0003] First, only single-dimensional correlation analysis is performed based on timestamps, ignoring multi-dimensional features such as the semantics of alarm names and the topological relationships of monitored objects, resulting in the drowning of complex patterns such as cascading failures. Second, the generated association rules have poor generalization ability and are stored in a relational database, making it difficult to achieve intuitive reasoning of fault propagation paths and efficient conflict detection. These deficiencies lead to low attribution accuracy of complex faults in the operation and maintenance system, lagging rule updates, and difficulty in meeting the intelligent operation and maintenance requirements in a large-scale dynamic environment. Summary of the Invention
[0004] Based on this, the present invention provides a method, device, equipment and medium for generating alarm association rules based on clustering to solve the problems that traditional methods cannot effectively process dynamic multi-dimensional alarm data, resulting in lagging fault discovery and inaccurate attribution.
[0005] In a first aspect, an embodiment of the present invention provides a method for generating alarm association rules based on clustering, the method comprising:
[0006] In response to an alarm log information collection instruction, collect multiple alarm logs within a specified time period and sort the alarm logs in the order of the alarm timestamps of each alarm log;
[0007] Perform clustering processing on the sorted alarm logs based on the elbow method to obtain multiple alarm clustering groups, wherein each data item in the alarm clustering group includes an alarm name, a monitored object, and an alarm timestamp;
[0008] According to a preset time window, divide each alarm clustering group into at least one transaction and generate an item set corresponding to each transaction;
[0009] Wherein, each transaction includes at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitored object;
[0010] The association rule learning algorithm is used to mine frequent itemsets for each itemset, and based on the mining results, an alarm association rule for describing the attribution relationship between fault description information is generated and stored in the graph database.
[0011] In a second aspect, an embodiment of the present invention provides a clustering-based alarm association rule generation device, which includes:
[0012] An alarm log collection module, configured to collect multiple alarm logs within a specified time period in response to an alarm log information collection instruction, and sort each alarm log in the order of the alarm timestamps of each alarm log.
[0013] An alarm clustering group division module, configured to perform clustering processing on each sorted alarm log based on the elbow method to obtain multiple alarm clustering groups, where each data item in the alarm clustering group includes an alarm name, a monitoring object, and an alarm timestamp.
[0014] An itemset generation module, configured to divide each alarm clustering group into at least one transaction according to a preset time window, and generate an itemset corresponding to each transaction.
[0015] Wherein, each transaction includes at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitoring object.
[0016] An alarm association rule generation module, configured to use the association rule learning algorithm to mine frequent itemsets for each itemset, and based on the mining results, generate an alarm association rule for describing the attribution relationship between fault description information and store it in the graph database.
[0017] In a third aspect, an embodiment of the present invention further provides an electronic device, where the electronic device includes:
[0018] At least one processor; and
[0019] A memory communicatively connected to the at least one processor; wherein,
[0020] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor can execute a clustering-based alarm association rule generation method according to any embodiment of the present invention.
[0021] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, where the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement a clustering-based alarm association rule generation method according to any embodiment of the present invention when executed.
[0022] Fifth aspect, an embodiment of the present invention further provides a computer program product, which includes a computer program that, when executed by a processor, implements a method for generating an alarm association rule based on clustering according to any embodiment of the embodiments of the present invention.
[0023] The technical solution of the embodiment of the present invention creatively proposes to automatically determine the optimal number of clusters by using the elbow method, group the alarms within the time window according to features, and form a highly cohesive alarm clustering group, which can effectively filter out isolated noises, enabling subsequent association rule mining to focus on alarm combinations with strong spatio-temporal correlations and significantly improving the rule confidence. Different from the prior art that only relies on timestamp sorting, this solution synchronously considers multi-dimensional features such as alarm names and monitored objects during clustering, divides transactions by combining dynamic time windows, and this spatio-temporal coupling analysis can capture complex patterns such as "the same device frequently triggers different alarms" or "cascading failures across devices". By storing association rules in a graph database, discrete alarms are transformed into a traceable causal relationship network, and at the same time, by dynamically updating the rule library according to new logs, it helps operation and maintenance personnel quickly locate the root cause alarm based on the topology graph.
[0024] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0026] Figure 1 is a flowchart of a method for generating an alarm association rule based on clustering according to Embodiment 1 of the present invention;
[0027] Figure 2 is a reference diagram of multiple alarm clustering groups obtained by dividing alarm logs under a specified number of clusters applicable to the embodiment of the present invention;
[0028] Figure 3 is a flowchart of another method for generating an alarm association rule based on clustering according to Embodiment 2 of the present invention;
[0029] Figure 4 is a schematic structural diagram of an apparatus for generating an alarm association rule based on clustering according to Embodiment 3 of the present invention;
[0030] Figure 5It is a schematic structural diagram of an electronic device for the method for generating an alarm association rule based on clustering according to Embodiment 4 of the present invention. Detailed implementation manners
[0031] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] Embodiment 1
[0034] Figure 1 It is a flowchart of a method for generating an alarm association rule based on clustering according to Embodiment 1 of the present invention. This embodiment is applicable to the situation of alarm log management and fault analysis for various big data platforms. This method can be executed by a device for generating an alarm association rule based on clustering. This device can be implemented in the form of hardware and / or software, and this device can be configured in a big data distributed system.
[0035] As Figure 1 shown, the method includes:
[0036] S110. In response to an alarm log information collection instruction, collect multiple alarm logs within a specified time period, and sort each alarm log in the order of the alarm timestamps of each alarm log.
[0037] In a system environment, there may be various different alarm situations, such as hardware device failure alarms, software runtime exception alarms, etc. To effectively manage and analyze these alarms, it is first necessary to collect relevant alarm log information. When the system receives an instruction specifically for collecting alarm log information, this instruction is like a startup signal, telling the system to start the data collection work.
[0038] Alarm logs refer to the log files that record various alarm information occurring in the system, containing relevant data about the alarms, such as the time when the alarm occurred, the specific content of the alarm, etc.; the alarm timestamp is a time information that precisely identifies the moment when the alarm occurred, which can be accurate to seconds, milliseconds, or even finer time units. By rearranging all the alarm logs according to the chronological order of the timestamps, making the earliest-occurring alarm log ranked at the front and the latest-occurring one at the end, it is for subsequent analysis of the occurrence process and patterns of alarms in chronological order.
[0039] 120. Perform clustering processing on the sorted alarm logs based on the elbow method to obtain multiple alarm clustering groups. Among them, each data item in the alarm clustering group contains the alarm name, the monitored object, and the alarm timestamp.
[0040] The elbow method is a method used to determine the optimal number of clusters in clustering analysis. By calculating the sum of squared errors (SEE) under different numbers of clusters, when there is an obvious turning point (similar to the shape of an elbow) in the decline rate of the SSE as the number of clusters increases, finding this elbow point can determine a more appropriate number of clusters. Use the elbow method to process the alarm logs that have been sorted in chronological order, and divide them into different groups, that is, alarm clustering groups, and the alarm clustering groups are the groupings of the alarm logs obtained after clustering processing.
[0041] Optionally, performing clustering processing on the sorted alarm logs based on the elbow method to obtain multiple alarm clustering groups may include:
[0042] Convert the sorted alarm logs into a standardized format applicable to the elbow method to obtain a standardized log set containing multiple standardized alarm logs;
[0043] Use the elbow method to calculate the number of clusters based on the standardized log set, and divide the sorted alarm logs according to the number of clusters to obtain multiple alarm clustering groups.
[0044] Specifically, the elbow method is a specific clustering algorithm that has certain requirements for the input data format. The sorted alarm logs may not be directly applicable to the elbow method for calculation in terms of format. Therefore, it is necessary to convert these alarm logs into a standardized format that meets the requirements of the elbow method. In the scenario of alarm logs, the standardized format usually converts various information in the alarm logs (such as alarm name, monitored object, alarm timestamp, etc.) into numerical values or other forms that are convenient for mathematical calculation and comparison, so that they can be used in the clustering algorithm. The standardization process includes operations such as encoding and normalization of each piece of information in the alarm logs. For example, if the alarm levels include P0 - P4, correspondingly, the alarm levels are converted into numerical codes in the way of P0 = 0, P1 = 1... The monitored object can be one-hot encoded, and the alarm timestamp is converted into a Unix timestamp, etc. The standardized log set refers to a set composed of multiple alarm logs after standardization processing. The alarm logs in this set all adopt the standardized format and can be directly used as the input data for the elbow method to calculate the appropriate number of clusters. After conversion, all the sorted alarm logs become in a standardized form. These standardized alarm logs are combined together to form a standardized log set, preparing for subsequent calculation using the elbow method.
[0045] It should be noted that the core purpose of the elbow method is to determine an appropriate number of clusters. For the standardized log set, the elbow method will try different numbers of clusters and calculate the sum of squared errors (SSE) for each number of clusters. SSE measures the sum of the squares of the distances from each data point to its cluster center. The smaller the SSE, the better the clustering effect. As the number of clusters increases, the SSE will gradually decrease, but when the number of clusters increases to a certain extent, the decline rate of the SSE will become very small. The elbow method is to find this turning point where the decline rate becomes significantly smaller, and the number of clusters corresponding to this turning point is the more appropriate number of clusters. After determining the number of clusters, the sorted alarm logs can be divided according to this number. For example, when the number of clusters is 3, a cluster number can be assigned to each alarm log in each cluster group. The cluster numbers can start from 0, and the maximum cluster number in each cluster group is equal to the number of clusters - 1. At the same time, since the alarm logs have been sorted in ascending order of the timestamp, the cluster numbers assigned to the alarm logs in each cluster group are also sorted based on the timestamp. Among them, Figure 2 is a reference diagram of multiple alarm cluster groups obtained by dividing the alarm logs when the number of clusters is 3.
[0046] S130: According to a preset time window, each alarm cluster group is divided into at least one transaction, and an item set corresponding to each transaction is generated.
[0047] Among them, each transaction contains at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitoring object.
[0048] The preset time window is a time length dynamically set according to the scale of the collected alarm logs, and is used as the basis for dividing transactions for the alarm clustering group. In the context of alarm analysis, a transaction is a data set obtained by dividing the alarm clustering group according to the preset time window. Each transaction contains alarm-related information within a specific time range, mainly fault description information. At the same time, a transaction can be regarded as an independent analysis unit. By analyzing the transaction, the fault conditions that occurred in the system during a certain period and the relationships between these faults can be discovered. For example, a transaction may contain all the fault description information that occurred on server A within a certain 1 hour. By analyzing this transaction, we can understand the operating status and problems of server A within this 1 hour.
[0049] An itemset is a set corresponding to a transaction. It contains the relevant information in the transaction, especially the fault description information. Its role is to organize and sort out the information in the transaction to facilitate data mining and analysis operations. By analyzing the itemset, frequent itemsets can be mined, that is, combinations of fault description information that often appear together. The fault description information is a way of information description formed by combining an alarm name and a monitoring object, which can more accurately describe the fault conditions that occur in the system and clearly indicate which monitoring object has what kind of alarm. For example, "The number of database connections of database server E is high" is a fault description information, which clearly explains the monitored object (database server E) and the name of the fault (the number of database connections is high).
[0050] Furthermore, before dividing each alarm clustering group into at least one transaction according to the preset time window, it may further include:
[0051] Obtain the minimum timestamp and the maximum timestamp of the alarm logs in each alarm clustering group, and calculate the time span of each alarm clustering group;
[0052] Obtain the time span of each alarm clustering group, and calculate the average value of the time span by using the value of the clustering quantity, and use the average value of the time span as the size of the preset time window.
[0053] Since each alarm clustering group contains multiple alarm logs, and each alarm log has its corresponding timestamp which records the specific moment when the alarm occurred, first find the minimum timestamp and the maximum timestamp from all the alarm logs in each alarm clustering group. The minimum timestamp represents the earliest time when an alarm occurred in the clustering group, and the maximum timestamp represents the latest time. By subtracting the minimum timestamp from the maximum timestamp, the obtained difference is the time span of the alarm clustering group, and this time span reflects the duration during which alarms occurred within the clustering group.
[0054] First, collect the time spans of each alarm clustering group. These time spans can reflect the differences in the durations during which alarms occurred in different clustering groups. Using the number of clusters calculated by the elbow method before, add up the time spans of all alarm clustering groups and then divide by the number of clusters to obtain the average value of the time spans. Take the average value of the time spans as the preset time window size. Subsequently, when dividing each alarm clustering group according to the time window for transaction partitioning, this calculated time window size will be used, which can make the transaction partitioning more conform to the time pattern of alarm occurrences within the alarm clustering group.
[0055] S140. Use the association rule learning algorithm to mine frequent itemsets from each itemset, and based on the mining results, generate alarm association rules for describing the attribution relationships between fault description information, and store them in the graph database.
[0056] The association rule learning algorithm is an important type of algorithm in data mining, and its main goal is to discover the association relationships between different items in the dataset. Common association rule learning algorithms include the Apriori algorithm, the FP-Growth algorithm, etc. By selecting an algorithm to analyze the itemset in the dataset, find frequent itemsets, and generate association rules based on the frequent itemsets. Association rules are usually expressed in the form of "X→Y", where X and Y respectively represent a set of fault description information. A frequent itemset is a set of items that appear with a relatively high frequency in the dataset. In the embodiments of the present invention, for the itemset in alarm analysis, a frequent itemset is a combination of fault description information that often appears together, and to determine whether an itemset is a frequent itemset, it needs to be determined according to a preset minimum support threshold. If the frequency of an itemset appearing in the dataset is greater than or equal to the minimum support threshold, then it is a frequent itemset. For example, if we set the minimum support threshold to 20%, and the itemset "The CPU usage rate of server A is high" and "The network packet loss rate of server D is high" appears in all itemsets with a frequency of more than 20%, then it is a frequent itemset.
[0057] An alarm association rule is a rule obtained by mining item sets related to alarms through an association rule learning algorithm, which is used to describe the attribution relationship between different fault description information. For example, an alarm association rule may be "If the CPU usage rate of server A is high, then it may cause a high network packet loss rate of server D". Through these rules, other related faults that may occur can be predicted, so as to take preventive measures in advance.
[0058] A graph database is a database system that stores and manages data in a graph structure. It consists of nodes (fault description information) and edges (alarm association rules). In alarm analysis, using a graph database can conveniently store and query alarm association rules. Through a visualization tool, the relationship between different fault description information can be clearly seen, which helps technicians in fault diagnosis and analysis. For example, through the visualization interface of the graph database, we can see which other fault description information is associated with a certain fault description information, as well as information such as the strength and direction of these associations.
[0059] Optionally, the method may further include:
[0060] In response to an alarm association rule query request sent by the client, obtain the key query items included in the alarm association rule query request; where the key query items at least include: keyword matching item set name, confidence threshold range, and support threshold range;
[0061] Traverse all nodes and directed edges in the graph database according to the request, and filter out the target association rules that meet the conditions;
[0062] Dynamically render the filtered target association rules into a topology graph according to a preset or user-defined mapping rule;
[0063] During the real-time display of the topology graph, if an interactive trigger operation on a node or a directed edge in the topology graph is received by the user, then highlight all paths that have multi-hop associations with the current node or edge, and dynamically mark the confidence and support of the corresponding association relationships on the paths.
[0064] In the embodiments of the present invention, the client can be a specific software on the computer used by the operation and maintenance personnel, which is used to send an alarm association rule query request. The alarm association rule query request is a kind of request sent by the client to the system, aiming to query the alarm association rules stored in the system. The request contains the query conditions set by the user, so that the system can filter out the alarm association rules that meet the requirements. The key query items are the important query conditions set by the user in the alarm association rule query request, which are used to accurately filter the alarm association rules. It includes the keyword matching item set name, confidence threshold range, and support threshold range. Among them, the keyword matching item set name refers to the keywords input by the user, and according to these keywords, matching is performed in the name of the item set to filter out the alarm association rules corresponding to the relevant item sets. For example, if the user inputs the keyword "memory leak", the system will search for the alarm association rules related to the item set whose name contains "memory leak". Among them, the confidence threshold range is an interval preset by the user, which is used to filter out the alarm association rules whose confidence is within this interval. For example, if the user sets the confidence threshold range to 0.7 to 0.9 and the support threshold range to 0.2 to 0.4, only the alarm association rules whose confidence and support are both within the corresponding intervals will be filtered out.
[0065] The graph database is a database that stores and manages data in a graph structure (composed of nodes and directed edges). In the embodiments of the present invention, the nodes store entities such as fault description information, and the directed edges store alarm association rules, that is, the attribution relationship between fault description information, that is, from one fault description information to another fault description information, indicating that there is a certain association between them. Among them, the directed edges can also contain relevant attributes, such as the confidence and support of the association rules.
[0066] After obtaining the key query items, according to the query conditions, the graph database storing the alarm association rules is traversed. By checking the alarm association rules corresponding to each node and directed edge, it is judged whether they meet the conditions such as the keyword matching item set name, confidence threshold range, and support threshold range set by the user. The alarm association rules that meet the key query item conditions set by the user will be filtered out and become the target association rules.
[0067] After filtering out the target association rules that meet the conditions, the target association rules are dynamically rendered and displayed to the user in an intuitive way of a topology graph. Among them, the preset mapping rules mainly refer to mapping the confidence value of the association rules to the default color attribute of the connection line. Among them, the confidence value is linearly associated with the color depth, and the higher the confidence, the darker the color. And the user's mapping rules can include custom regulations on colors. At this time, according to the target color required by the user, the default color attribute is replaced, and the information in the target association rules is converted into elements such as nodes and edges in the topology graph, and the topology graph is generated and displayed in real time.
[0068] When the topology graph is being displayed to the user in real time, the user can perform some interaction operations on the nodes or directed edges in the topology graph. Interaction trigger operations refer to the operations that the user performs on the nodes or directed edges on the topology graph display interface, such as clicking, mouse hovering, double-clicking, etc. These operations will trigger the system to perform corresponding processing and feedback. After receiving these interaction trigger operations from the user, the system will analyze the currently operated node or directed edge and search for all paths that have multi-hop associations (i.e., are connected through multiple intermediate nodes or edges) with this node or edge. Multi-hop association means that in the topology graph, the association between two nodes or edges may not be direct, but is connected through multiple intermediate nodes or edges. This type of association relationship that can be established through multiple steps is called multi-hop association. For example, if node A and node C are connected through node B, then the association between A and C is a two-hop association. Multi-hop associations can help users discover more complex fault relationship networks. Highlight display means that in the topology graph, specific paths, nodes, or edges are displayed in a prominent color or style so that users can notice them more easily.
[0069] In the embodiment of the present invention, after the user performs an interaction trigger operation on a certain node or directed edge, the system will highlight all paths that have multi-hop associations with this node or edge, highlighting these associated paths. Dynamic annotation means that in the topology graph, information such as the confidence level and support level of the corresponding association relationship on the path is annotated and updated according to the real-time situation. Since after finding the paths that have multi-hop associations with the current node or edge, the confidence level and support level values of the corresponding association relationships will be annotated on these paths, but if these values change (for example, due to data updates resulting in changes in the confidence level and support level), the annotation will be dynamically updated accordingly.
[0070] The technical solution of the embodiment of the present invention creatively proposes to automatically determine the optimal number of clusters using the elbow method, group the alarms within the time window according to features, and form highly cohesive alarm cluster groups, which can effectively filter out isolated noises, enabling subsequent association rule mining to focus on alarm combinations with strong spatio-temporal correlations and significantly improving the rule confidence level; different from the existing technology that only relies on timestamp sorting, this solution synchronously considers multi-dimensional features such as alarm names and monitored objects during clustering, and divides transactions by combining dynamic time windows. This spatio-temporal coupling analysis can capture complex patterns such as "the same device frequently triggering different alarms" or "cascading failures across devices"; store the association rules through a graph database, convert discrete alarms into a traceable causal relationship network, and at the same time, by dynamically updating the rule base according to new logs, help the operation and maintenance personnel quickly locate the root cause alarm based on the topology graph.
[0071] Embodiment Two
[0072] Figure 3The following is a flowchart of another method for generating alarm association rules based on clustering provided in the second embodiment of the present invention. This embodiment is a refinement based on the above embodiment. As Figure 3 shown, the method includes:
[0073] S310. In response to an alarm log information collection instruction, collect multiple alarm logs within a specified time period, and sort each alarm log in the order of the alarm timestamps of the alarm logs.
[0074] S320. Perform clustering processing on the sorted alarm logs based on the elbow method to obtain multiple alarm clustering groups. Each data item in the alarm clustering group includes an alarm name, a monitored object, and an alarm timestamp.
[0075] S330. Obtain the target minimum timestamp in all the alarm logs, and obtain the first window time by adding a preset time window size to the target minimum timestamp, and use the time period from the target minimum timestamp to the first window time as the first time interval.
[0076] First, find the earliest alarm occurrence time in all the alarm logs, that is, the target minimum timestamp. The target minimum timestamp represents the starting point of the entire alarm event sequence. The first window time = target minimum timestamp + time window size, which is used for subsequent division of the alarm clustering groups; the first time interval = [target minimum timestamp, first window time). For example, if the target minimum timestamp is 2025-03-24-10:00:00 and the time window is 30 minutes, then the first time interval is [2025-03-24-10:00:00, 2025-03-24-10:30:00).
[0077] S340. Perform transaction division on the alarm clustering groups in sequence according to the first time interval. If the alarm timestamps of all the alarm logs in the current alarm clustering group fall within the first time interval, directly divide the current alarm aggregation group into the first transaction under the first time interval.
[0078] When dividing the transactions, there are two cases. The alarm timestamps of all the logs in the current alarm clustering group all fall within the first time interval. In the first case, the alarm clustering group that is completely within the first time interval is used as the basic unit for association rule analysis, that is, the first transaction.
[0079] S350. If there is at least one target alarm log in the current aggregation data group whose alarm timestamp does not fall within the first time interval, construct a second window time by adding a preset time window size to the first window time, and use the time period from the first window time to the second window time as the second time interval.
[0080] The second case is that there are cross-time interval logs, that is, the alarm timestamps of at least one alarm log in the current clustering group exceed the first time interval. At this time, first define the second window time = the first window time + the time window size; then define the second time interval = [the first window time, the second window time), for example, the second time interval is: [2025-03-24-10:30:00, 2025-03-24-11:00:00). At this time, an aggregated data group is split into two transactions, and the logs that exceed the first time interval are classified into the second transaction and belong to the second time interval.
[0081] S360. Divide all the target alarm logs in the current aggregated data group into the second transaction under the second time interval, complete the transaction division of the current alarm clustering group, and generate item sets corresponding to each transaction respectively.
[0082] As Figure 2 shown, the aggregated data group numbered 0 includes three alarm logs, namely: ① High CPU usage - Server A - 2025-03-24-10:00:00; ② High network packet loss rate - Server D - 2025-03-24-10:15:00; ③ Hardware failure - Server L - 2025-03-24-10:40:00. Then in this aggregated data group, alarm logs ① and ② are classified into the first transaction, and alarm log ③ is classified into the second transaction. The first transaction (corresponding to the first time interval) includes: High CPU usage - Server A and High network packet loss rate - Server D; the second transaction (corresponding to the second time interval) includes: Hardware failure - Server L.
[0083] Convert the alarm logs in each transaction into item sets. If there is only the first transaction in the current aggregated data group, it means that the current aggregated data group corresponds to one item set. If the current aggregated data group is split into the first transaction and the second transaction, it means that the current aggregated data group corresponds to two item sets. It should be clear that a transaction is a group of alarm logs divided by a time window and is the smallest unit of association rule analysis, and the set of alarm logs included in each transaction is called an item set, such as item set T1: {High CPU usage - Server A, High network packet loss rate - Server D} and item set T2: {Hardware failure - Server L}.
[0084] S370. Use the association rule learning algorithm to take each item set as a candidate first-order item set, and screen each sub-item set in the first-order item set according to a preset minimum support threshold, and merge the sub-item sets that meet the requirements to obtain frequent first-order item sets.
[0085] Support is the proportion of an itemset appearing in transactions and is used to measure its universality; the minimum support threshold is a manually set filtering threshold for filtering out occasional alarms; a sub-itemset is a subset of an itemset. For example, in itemset T1, the sub-itemsets are: {High CPU usage - Server A} and {High network packet loss rate - Server D}, while the sub-itemset of itemset T2 is only {Hardware failure_Server L}. Calculate the support (appearance frequency) of each sub-itemset in all transactions, and filter out the itemset with a support lower than the preset threshold, retaining the frequent first-order itemsets.
[0086] S380. Generate higher-order frequent itemsets iteratively layer by layer based on the frequent first-order itemsets. When no higher-order frequent itemsets can be generated, output the set of frequent itemsets of all orders to obtain the mining result. And based on the mining result, generate alarm association rules for describing the attribution relationship between fault description information and store them in the graph database.
[0087] Based on the frequent first-order itemsets, generate itemsets containing more items through combination. These itemsets are called higher-order frequent itemsets. For example, a second-order frequent itemset is composed of two frequent first-order itemsets, a third-order frequent itemset is composed of three frequent first-order itemsets or a second-order frequent itemset and a first-order frequent itemset, and so on. According to the order of the itemsets, starting from the first order, continuously generate higher-order frequent itemsets, and each iteration operates based on the frequent itemsets of the previous order. The mining result refers to the set of frequent itemsets of all orders finally obtained, and these frequent itemsets reflect the association relationship between different alarm logs in the dataset.
[0088] Generate rules for describing the causal relationship or association relationship between different alarms based on the mined frequent itemsets. For example, if an alarm X and an alarm Y are included in a frequent itemset, then an association rule may be generated indicating that the occurrence of alarm X may lead to the occurrence of alarm Y, which can be represented by X→Y.
[0089] Optionally, based on the mining result, generate alarm association rules for describing the attribution relationship between fault description information and store them in the graph database, which may include:
[0090] Obtain the sets of frequent itemsets of each order generated through iterative layer by layer, and traverse all non-empty subset combinations to generate candidate alarm association rules for describing the attribution relationship between fault description information.
[0091] Calculate the confidence of each candidate alarm association rule based on the set of frequent itemsets, and retain the candidate alarm association rules with a confidence not less than the preset minimum confidence threshold as the final alarm association rules.
[0092] Map each alarm association rule to a directed edge in the graph database and store it in the graph database.
[0093] For a given frequent itemset, its non-empty subset combinations refer to all possible subsets composed of some elements in the frequent itemset except the empty set. For example, for the frequent itemset {A, B, C}, its non-empty subset combinations include {A}, {B}, {C}, {A, B}, {A, C}, and {B, C}. Candidate alarm association rules are generated based on the non-empty subset combinations of frequent itemsets and are used to describe the possible attribution relationships between fault description information. For example, if the frequent itemset is {Fault A, Fault B, Fault C}, a candidate alarm association rule may be "If Fault A and Fault B occur, then Fault C may occur". In association rule mining, confidence is an indicator to measure the reliability of an association rule, which represents the probability of the occurrence of the rule consequent when the antecedent of the rule is satisfied. For example, for the association rule "If Fault A and Fault B occur, then Fault C may occur", the confidence is the probability of the occurrence of Fault C when Fault A and Fault B occur.
[0094] A graph database is a database system that stores and queries data in a graph structure. In the embodiments of the present invention, fault description information can be used as nodes, and the attribution relationships represented by alarm association rules can be used as directed edges (because the attribution relationships between faults may be directional. For example, Fault A may cause Fault B, but Fault B does not necessarily cause Fault A).
[0095] The technical solution of the embodiments of the present invention mainly describes, through the refinement of the overall solution, the method of dividing alarm clustering groups into transactions after clustering alarm logs, and the process of mining frequent itemsets using an association rule learning algorithm on this basis. By determining the minimum timestamp and the time window size to construct a time interval, the alarm data is organized into relatively independent transactions with time boundaries, standardizing the basic unit of data processing, being able to more accurately reflect the distribution of alarms in time, and helping to discover the characteristics and patterns of alarms in different time periods; using the graph database with efficient graph query and traversal capabilities, in scenarios such as finding associated faults of specific faults and analyzing fault propagation paths, the results can be obtained quickly, providing strong support for real-time monitoring and emergency handling of faults.
[0096] Embodiment 3
[0097] Figure 4 It is a schematic structural diagram of a clustering-based alarm association rule generation device provided in Embodiment 3 of the present invention. As Figure 4 shown, the device includes:
[0098] An alarm log collection module 410, configured to collect multiple alarm logs within a specified time period in response to an alarm log information collection instruction, and sort the alarm logs in the order of the alarm timestamps of the alarm logs.
[0099] An alarm clustering group division module 420 is used to perform clustering processing on each sorted alarm log based on the elbow method to obtain multiple alarm clustering groups. Each data item in the alarm clustering group contains an alarm name, a monitored object, and an alarm timestamp.
[0100] An item set generation module 430 is used to divide each alarm clustering group into at least one transaction according to a preset time window, and generate an item set corresponding to each transaction.
[0101] Wherein, each transaction contains at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitored object.
[0102] An alarm association rule generation module 440 is used to mine frequent item sets from each item set by using an association rule learning algorithm, and generate an alarm association rule for describing the attribution relationship between fault description information according to the mining result, and store it in the graph database.
[0103] The technical solution of the embodiment of the present invention creatively proposes to automatically determine the optimal number of clusters by using the elbow method, group the alarms within the time window according to features, and form highly cohesive alarm clustering groups, which can effectively filter out isolated noises, so that the subsequent association rule mining focuses on alarm combinations with strong spatio-temporal correlation, and significantly improves the rule confidence. Different from the prior art that only relies on timestamp sorting, this solution synchronously considers multi-dimensional features such as alarm name and monitored object during clustering, and divides transactions in combination with a dynamic time window. This spatio-temporal coupling analysis can capture complex patterns such as "the same device frequently triggers different alarms" or "cross-device cascading failures". By storing association rules in the graph database, discrete alarms are transformed into a traceable causal relationship network, and at the same time, by dynamically updating the rule base according to new logs, it helps the operation and maintenance personnel to quickly locate the root cause alarm based on the topology graph.
[0104] Optionally, based on the above embodiments, the alarm clustering group division module 420 may include:
[0105] A format conversion unit is used to convert each sorted alarm log into a standardized format applicable to the elbow method to obtain a standardized log set containing multiple standardized alarm logs.
[0106] A clustering analysis unit is used to calculate the number of clusters according to the standardized log set by using the elbow method, and divide each sorted alarm log according to the number of clusters to obtain multiple alarm clustering groups.
[0107] Optionally, based on the above embodiments, the item set generation module 430 may include:
[0108] The first time interval generation unit is used to obtain the target minimum timestamp in all alarm logs, obtain the first window time by superimposing a preset time window size on the basis of the target minimum timestamp, and use the time from the target minimum timestamp to the first window time as the first time interval;
[0109] The first transaction division unit is used to sequentially perform transaction division on the alarm clustering groups according to the first time interval. If the alarm timestamps of all alarm logs in the current alarm clustering group all fall within the first time interval, directly divide the current alarm aggregation group into the first transaction under the first time interval;
[0110] The second time interval generation unit is used to, if there is at least one target alarm log in the current aggregation data group whose alarm timestamp does not fall within the first time interval, construct a second window time by superimposing a preset time window size on the basis of the first window time, and use the time from the first window time to the second window time as the second time interval;
[0111] The second transaction division unit is used to divide all target alarm logs in the current aggregation data group into the second transaction under the second time interval, completing the transaction division of the current alarm clustering group.
[0112] Optionally, on the basis of the above embodiments, it may further include a time window dynamic calculation unit, which is used to obtain the minimum timestamp and the maximum timestamp of the alarm logs in each alarm clustering group before dividing each alarm clustering group into at least one transaction according to the preset time window, and calculate the time span of each alarm clustering group;
[0113] Obtain the time span of each alarm clustering group, calculate the average value of the time span using the value of the clustering quantity, and use the average value of the time span as the preset time window size.
[0114] Optionally, on the basis of the above embodiments, the alarm association rule generation module 440 may include:
[0115] The first-order item set construction unit is used to use the association rule learning algorithm to use each item set as a candidate first-order item set, and screen each sub-item set in the first-order item set according to a preset minimum support threshold, and merge the sub-item sets that meet the requirements to obtain a frequent first-order item set;
[0116] The item set iteration unit is used to iteratively generate higher-order frequent item sets layer by layer based on the frequent first-order item set until no higher-order frequent item sets can be generated, and output the set of frequent item sets of all orders to obtain the mining result.
[0117] Optionally, on the basis of the above embodiments, the alarm association rule generation module 440 may further include:
[0118] A candidate alarm association rule generation unit, configured to obtain sets of frequent itemsets at each level generated by iterative generation layer by layer, and traverse all non-empty subset combinations to generate candidate alarm association rules for describing the attribution relationship between fault description information;
[0119] An alarm association rule screening unit, configured to calculate the confidence of each candidate alarm association rule based on the set of frequent itemsets, and retain the candidate alarm association rules whose confidence is not less than a preset minimum confidence threshold as the final alarm association rules;
[0120] An alarm association rule storage unit, configured to map each alarm association rule to a directed edge in a graph database and store it in the graph database.
[0121] Optionally, based on the above embodiments, it may further include: a front-end service unit, configured to respond to an alarm association rule query request sent by a client and obtain key query items included in the alarm association rule query request; where the key query items at least include: a keyword matching itemset name, a confidence threshold range, and a support threshold range;
[0122] Traverse all nodes and directed edges in the graph database according to the request, and filter out target association rules that meet the conditions;
[0123] Dynamically render the filtered target association rules into a topology graph according to a preset or user-defined mapping rule;
[0124] During the real-time display of the topology graph, if an interaction trigger operation for a node or a directed edge in the topology graph is received, highlight all paths that have a multi-hop association with the current node or edge, and dynamically mark the confidence and support of the corresponding association relationship on the path.
[0125] An apparatus for generating alarm association rules based on clustering provided by an embodiment of the present invention can execute a method for generating alarm association rules based on clustering provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0126] Embodiment 4
[0127] Figure 5FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0128] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0129] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0130] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a method for generating an alarm association rule based on clustering.
[0131] That is: in response to an alarm log information collection instruction, collect multiple alarm logs within a specified time period, and sort the alarm logs in the order of their alarm timestamps;
[0132] Perform clustering processing on the sorted alarm logs based on the elbow method to obtain multiple alarm clustering groups, where each data item in the alarm clustering group contains an alarm name, a monitored object, and an alarm timestamp;
[0133] According to a preset time window, divide each alarm clustering group into at least one transaction, and generate an item set corresponding to each transaction;
[0134] Among them, each transaction contains at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitored object;
[0135] Use an association rule learning algorithm to mine frequent item sets from each item set, and generate an alarm association rule for describing the attribution relationship between fault description information according to the mining result, and store it in the graph database.
[0136] In some embodiments, a clustering-based alarm association rule generation method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by the processor 11, one or more steps of the above-described clustering-based alarm association rule generation method can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute a clustering-based alarm association rule generation method by any other suitable means (e.g., by means of firmware).
[0137] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0138] A computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0139] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0140] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0141] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend, middleware, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0142] The computing system can include a client and a server. The client and the server are generally remote from each other and typically interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0143] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0144] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for generating alarm association rules based on clustering, characterized in that including: In response to an alarm log information collection instruction, collect multiple alarm logs within a specified time period, and sort each alarm log in the order of the alarm timestamps of the alarm logs; Based on the elbow method, perform clustering processing on the sorted alarm logs to obtain multiple alarm clustering groups, where each data item in the alarm clustering group includes an alarm name, a monitored object, and an alarm timestamp; According to a preset time window, divide each alarm clustering group into at least one transaction respectively, and generate item sets corresponding to each transaction respectively; Wherein, each transaction includes at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitored object; Adopt an association rule learning algorithm to mine frequent item sets from each item set, and generate an alarm association rule for describing the attribution relationship between fault description information according to the mining result, and store it in the graph database.
2. The method according to claim 1, characterized in that, Based on the elbow method, perform clustering processing on the sorted alarm logs to obtain multiple alarm clustering groups, including: Convert each sorted alarm log into a standardized format applicable to the elbow method to obtain a standardized log set including multiple standardized alarm logs; Use the elbow method to calculate the number of clusters according to the standardized log set, and divide each sorted alarm log according to the number of clusters to obtain multiple alarm clustering groups.
3. The method according to claim 1, characterized in that, According to a preset time window, divide each alarm clustering group into at least one transaction respectively, including: Obtain the target minimum timestamp in all alarm logs, and obtain the first window time by adding a preset time window size to the target minimum timestamp, and use the target minimum timestamp to the first window time as the first time interval; Perform transaction division on the alarm clustering group in sequence according to the first time interval. If the alarm timestamps of all alarm logs in the current alarm clustering group all fall within the first time interval, directly divide the current alarm aggregation group into the first transaction under the first time interval; If there is at least one target alarm log in the current aggregation data group whose alarm timestamp does not fall within the first time interval, construct a second window time by adding a preset time window size to the first window time, and use the first window time to the second window time as the second time interval; Divide all target alarm logs in the current aggregation data group into the second transaction under the second time interval to complete the transaction division of the current alarm clustering group.
4. The method according to claim 3, characterized in that, Before dividing each alarm clustering group into at least one transaction according to a preset time window, it also includes: Obtain the minimum timestamp and the maximum timestamp of the alarm logs in each alarm clustering group, and calculate the time span of each alarm clustering group; Obtain the time span of each alarm clustering group, and calculate the average value of the time span by using the value of the number of clusters, and use the average value of the time span as the preset time window size.
5. The method according to any one of claims 1-4, characterized in that, Adopt an association rule learning algorithm to mine frequent item sets from each item set, including: Use the association rule learning algorithm to use each item set as a candidate first-order item set, and screen each sub-item set in the first-order item set according to a preset minimum support threshold, and merge the sub-item sets that meet the requirements to obtain a frequent first-order item set; Generate higher-order frequent item sets iteratively layer by layer based on frequent first-order item sets until no higher-order frequent item sets can be generated. Then output the set of frequent item sets of all orders to obtain the mining result.
6. The method according to claim 5, characterized in that, According to the mining result, generate alarm association rules for describing the attribution relationship between fault description information, and store them in the graph database, including: Obtain the sets of frequent item sets of each order generated by iterative layer by layer, and traverse all non-empty subset combinations to generate candidate alarm association rules for describing the attribution relationship between fault description information; Calculate the confidence of each candidate alarm association rule based on the set of frequent item sets, and retain the candidate alarm association rules with a confidence not less than the preset minimum confidence threshold as the final alarm association rules; Map each alarm association rule to a directed edge in the graph database and store it in the graph database.
7. The method according to claim 6, wherein The method further includes: In response to an alarm association rule query request sent by the client, obtain the key query items included in the alarm association rule query request; where the key query items at least include: keyword matching item set name, confidence threshold range, and support threshold range; Traverse all nodes and directed edges in the graph database according to the request, and filter out the target association rules that meet the conditions; Dynamically render the filtered target association rules into a topology graph according to a preset or user-defined mapping rule; During the real-time display of the topology graph, if an interaction trigger operation on a node or directed edge in the topology graph is received by the user, highlight all paths that have a multi-hop association with the current node or edge, and dynamically mark the confidence and support of the corresponding association relationships on the paths.
8. An alarm association rule generation device based on clustering, characterized in that Including: An alarm log collection module, which is used to respond to an alarm log information collection instruction, collect multiple alarm logs within a specified time period, and sort each alarm log according to the chronological order of the alarm timestamps; An alarm clustering group division module, which is used to perform clustering processing on each sorted alarm log based on the elbow method to obtain multiple alarm clustering groups. Each data item in the alarm clustering group includes an alarm name, a monitored object, and an alarm timestamp; An item set generation module, which is used to divide each alarm clustering group into at least one transaction according to a preset time window, and generate item sets corresponding to each transaction; Wherein, each transaction contains at least one fault description information, and each fault description information is obtained by combining an alarm name and a monitored object; An alarm association rule generation module, which is used to mine frequent item sets from each item set using an association rule learning algorithm, and generate alarm association rules for describing the attribution relationship between fault description information according to the mining result, and store them in the graph database.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a method for generating alarm association rules based on clustering according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement a method for generating an alarm association rule based on clustering according to any one of claims 1-7 when executed by a processor.
Citation Information
Cited By
Road advertisement putting method and system based on intelligent travel data
CN120782493A
Object monitoring method and device, electronic equipment and object monitoring system
CN121392754A