Intelligent alarm analysis method for operation and maintenance scene, computer device and medium

Through the analysis of alarm information and calculation of correlation scores, automatic selection or push processing strategies are solved, and the problems of diversification and complexity of alarm information in operation and maintenance scenarios are achieved, rapid and accurate alarm processing and knowledge base updates are achieved, and operation and maintenance costs are reduced.

CN120276897APending Publication Date: 2025-07-08BEIJING QINGSONG YIKANG INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510350329.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the prior art, the diversification and high complexity of alarm information in operation and maintenance scenarios make it difficult for new employees to handle quickly and accurately, resulting in processing delays and system failures spread.

Method used

By analyzing the received alarm information, obtaining target information, and determining relevant processing strategies from the preset knowledge base, calculating correlation scores using multiple correlation indicators, automatically selecting or pushing processing strategies, and updating the knowledge base.

Benefits of technology

It improves the timeliness and accuracy of alarm processing, reduces manual processing time, reduces operation and maintenance costs, and enhances the intelligence level and processing capabilities of the operation and maintenance system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120276897A_ABST
    Figure CN120276897A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent alarm analysis method for an operation and maintenance scene, a computer device and a medium. The intelligent alarm analysis method for the operation and maintenance scene comprises the following steps: analyzing alarm information to obtain target information; determining a plurality of processing strategies associated with the target information from a preset knowledge base, and obtaining a plurality of association indexes of the target information and each processing strategy; based on a plurality of relevance indexes and a preset weight of each relevance index, calculating a relevance score of the target information and each processing strategy; the relevance scores are ranked from high to low, if the highest relevance score is larger than a preset threshold value, the processing strategy corresponding to the highest relevance score serves as a target strategy, and alarm information is automatically processed based on the target strategy; and if the highest relevance score is not greater than a preset threshold value, pushing the alarm information to the operation and maintenance personnel, receiving a processing strategy of the operation and maintenance personnel, and updating the processing strategy to a preset knowledge base. According to the method, the alarm information can be quickly and effectively processed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of alarm processing, and particularly to an intelligent alarm analysis method, a computer device, and a medium for an operation and maintenance scenario. Background Art

[0002] In the current era of rapid technological development, modern system architectures are undergoing unprecedented changes. With the wide application of information technology and the continuous growth of business requirements, the scale of various systems such as enterprise information systems, cloud computing platforms, and Internet of Things architectures continues to expand, and the structure is becoming increasingly complex.

[0003] However, while this increasingly complex and large-scale system architecture brings efficient and convenient services to society and enterprises, it also poses huge challenges to operation and maintenance work. During the daily operation of the system, a large number of alarm messages are generated, and these alarm messages are characterized by diversity and high complexity. The diversity is reflected in the numerous types of alarms, including hardware failure alarms, software exception alarms, network connection alarms, etc. Different types of alarms may originate from different system components and operation links. The high complexity is manifested in the fact that there may be complex correlation relationships between alarms. An alarm may be triggered by the combined action of multiple potential factors, or a single fault may simultaneously trigger multiple related alarms, making it very difficult to accurately determine the root cause and severity of the alarm.

[0004] For the operation and maintenance team, dealing with these complex alarm messages is a crucial task. However, the replacement of team members is inevitable, and the addition of new employees is also an inevitable part of the team's development. When new employees start working, due to their lack of sufficient operation and maintenance experience, they often have difficulty making quick and accurate judgments and handling when faced with a large amount of complex alarm information. They may not be familiar with the system architecture and operation mechanism, unable to understand the problems hidden behind the alarm information, and also difficult to find effective solutions in a short time. This will not only lead to delays in alarm handling, increase the duration and scope of system failures, but also pose a serious threat to the stable operation of the system and the normal development of business. Summary of the Invention

[0005] In view of this, the embodiments of the present disclosure provide an intelligent alarm analysis method, a computer device, and a medium for an operation and maintenance scenario, which can solve the problems such as slow alarm handling response, long processing cycle, and poor processing effect existing in the prior art.

[0006] In a first aspect, the embodiments of the present disclosure provide an intelligent alarm analysis method for an operation and maintenance scenario, including:

[0007] Parsing the received alarm information to obtain target information;

[0008] Determine a number of processing strategies associated with the target information from a preset knowledge base, and obtain multiple relevance indicators of the target information and each of the processing strategies, where the processing strategies include historical problems and solutions;

[0009] Based on the multiple relevance indicators and the preset weights of each relevance indicator, calculate the relevance score of the target information and each of the processing strategies;

[0010] Sort according to the level of the relevance scores. If the highest relevance score is greater than a preset threshold, use the processing strategy corresponding to the highest relevance score as the target strategy, and automatically process the alarm information based on the target strategy;

[0011] If the highest relevance score is not greater than the preset threshold, push the alarm information to the operation and maintenance personnel, receive the processing strategy of the operation and maintenance personnel, and update it to the preset knowledge base.

[0012] Optionally, the multiple relevance indicators include text similarity scores, historical relevance scores, and time relevance scores;

[0013] The calculating the relevance score of the target information and each of the processing strategies based on the multiple relevance indicators and the preset weights of each relevance indicator includes:

[0014] If the text similarity score is greater than the first upper threshold, the historical relevance score is greater than the second upper threshold, and the time relevance score is greater than the third upper threshold, perform weighted summation on the text similarity score, the historical relevance score, and the time relevance score according to the preset text similarity weight, historical relevance weight, and time relevance weight to obtain the relevance score;

[0015] If the text relevance score is not greater than the first lower threshold, the historical relevance score is not greater than the second lower threshold, and the time relevance score is not greater than the third lower threshold, determine that the relevance score is zero; the first lower threshold is less than the first upper threshold, the second lower threshold is less than the second upper threshold, and the third lower threshold is less than the third upper threshold;

[0016] If the text relevance score is not greater than the first lower threshold, the historical relevance score is not greater than the second upper threshold and greater than the second lower threshold, and the time relevance score is not greater than the third upper threshold and not greater than the third lower threshold, dynamically update the text similarity score to zero;

[0017] Obtain the sum of the original weights of the historical relevance weight and the temporal relevance weight, and update the ratio of the original weight of the historical relevance weight to the sum of the original weights to the current historical relevance weight, and update the ratio of the original weight of the temporal relevance weight to the sum of the original weights to the current temporal relevance weight;

[0018] Based on the current historical relevance weight and the current temporal relevance weight, perform a weighted sum on the historical relevance score and the temporal relevance score to obtain an association score.

[0019] Optionally, the method for obtaining the text similarity score between the target information and the processing strategy includes:

[0020] Split the target information into several first words;

[0021] Split the historical problem description in the processing strategy into several second words;

[0022] Use a word vector model to convert several of the first words into a first text vector, and convert several of the second words into a second text vector;

[0023] Calculate the norm of the first text vector, the norm of the second text vector, and the dot product of the first text vector and the second text vector;

[0024] Obtain a text similarity score based on the norm of the first text vector, the norm of the second text vector, and the dot product.

[0025] Optionally, the method for obtaining the historical relevance score between the target information and the processing strategy includes:

[0026] Convert the target information into a first vector, and convert the historical problem description in the processing strategy into a second vector;

[0027] Obtain the text similarity score between the first vector and the second vector;

[0028] Extract the first key features in the target information and the second key features in the processing strategy; both the first key features and the second key features include the alarm source and the alarm type;

[0029] Obtain the feature matching degree score between the first key features and the second key features;

[0030] Perform a weighted sum on the text similarity score and the feature matching degree score according to the preset weight of the text similarity and the preset weight of the feature matching degree to obtain the historical relevance score.

[0031] Optionally, the method for obtaining the time correlation score between the target information and the processing strategy includes:

[0032] Extract the first time information from the target information;

[0033] Extract the second time information from the processing strategy;

[0034] Convert the first time information and the second time information into a unified format to obtain a first standardized time and a second standardized time;

[0035] Obtain the time difference information between the first standardized time and the second standardized time;

[0036] Based on a preset time score rule and the time difference information, obtain the time correlation score.

[0037] Optionally, the method for constructing the preset knowledge base includes:

[0038] Based on a large language model, screen the official recommended solutions, expert recommended solutions, and forum recommended solutions corresponding to each alarm information from official documents, expert suggestions, and technical forums respectively;

[0039] According to the official recommended solution, determine the official document authority score, official document update time score, and official document integrity score;

[0040] Based on the preset official document authority weight, official document update time weight, and official document integrity weight, perform weighted summation on the official document authority score, the official document update time score, and the official document integrity score to obtain a first score;

[0041] According to the expert recommended solution, determine the expert popularity score, expert experience score, and expert historical evaluation accuracy score;

[0042] Based on the preset expert popularity weight, expert experience weight, and expert historical evaluation accuracy weight, perform weighted summation on the expert popularity score, the expert experience score, and the expert historical evaluation accuracy score to obtain a second score;

[0043] According to the forum recommended solution, determine the post like count score, post comment count score, and post reply time score;

[0044] Based on the preset post like count weight, post comment count weight, and post reply time weight, perform weighted summation on the post like count score, the post comment count score, and the post reply time score to obtain a third score;

[0045] Obtain several recommended solution corresponding to the scores greater than the preset reliability threshold among the first score, the second score, and the third score, and record them as reliable strategies;

[0046] Based on the large prediction model, fuse several of the reliable strategies, and generate a processing strategy for the corresponding alarm information according to the strategy content and logical relationship;

[0047] All types of alarm information and the corresponding processing strategies constitute a preset knowledge base.

[0048] Optionally, parse the received alarm information to obtain target information, including:

[0049] According to the type, source, and subsequent processing requirements of the alarm information, pre-define the fields for parsing the alarm information, and the fields include but are not limited to alarm time, alarm level, alarm device identifier, and alarm description;

[0050] Receive alarm information sent from different systems or devices;

[0051] Based on the pre-defined fields, parse the received alarm information, and use regular expression matching, data extraction tools, or parsing libraries to extract the content corresponding to the pre-defined fields from the alarm information;

[0052] Combine the content of each parsed field to generate target information.

[0053] In a second aspect, an embodiment of the present disclosure further provides a computer device, which adopts the following technical solution:

[0054] The computer device includes:

[0055] At least one processor; and,

[0056] A memory communicatively connected to the at least one processor; wherein,

[0057] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above-mentioned intelligent alarm analysis methods for the operation and maintenance scenario.

[0058] In a third aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute any one of the above-mentioned intelligent alarm analysis methods for the operation and maintenance scenario.

[0059] In a fourth aspect, an embodiment of the present disclosure further provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of any one of the above-mentioned methods are implemented.

[0060] The intelligent alarm analysis method for the operation and maintenance scenario disclosed in this application can quickly respond to alarm information through an automated parsing, matching, and processing process, reducing the time for manual alarm handling. Especially when facing a large number of alarm information, the advantage is more obvious; by comprehensively considering multiple correlation indicators to select processing strategies, combining historical experience and real-time situations, it improves the accuracy and applicability of the processing strategies and reduces the risk of misprocessing; updating the processing strategies of operation and maintenance personnel into the preset knowledge base continuously enriches and improves the knowledge base, forming a virtuous cycle of knowledge accumulation, and improving the intelligent level and processing ability of the entire operation and maintenance system; at the same time, it can effectively reduce the workload of manual alarm handling, reduce the dependence on the number and experience of operation and maintenance personnel, thereby reducing the operation and maintenance costs.

[0061] The above description is only an overview of the technical solution of this disclosure. In order to understand the technical means of this disclosure more clearly, it can be implemented according to the content of the specification. And to make the above and other purposes, features, and advantages of this disclosure more obvious and understandable, the following specific preferred embodiments are given and described in detail in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0063] Figure 1 It is a schematic flowchart of the intelligent alarm analysis method for the operation and maintenance scenario provided by the embodiment of this disclosure.

[0064] Figure 2 It is a schematic flowchart of the calculation method for the correlation score between the target information and each processing strategy provided by the embodiment of this disclosure.

[0065] Figure 3 It is a schematic flowchart of the method for obtaining the text similarity score between the target information and the processing strategy provided by the embodiment of this disclosure.

[0066] Figure 4 It is a schematic flowchart of the method for obtaining the historical correlation score between the target information and the processing strategy provided by the embodiment of this disclosure.

[0067] Figure 5 It is a schematic flowchart of the method for obtaining the time correlation score between the target information and the processing strategy provided by the embodiment of this disclosure.

[0068] Figure 6Schematic flowchart of the method for constructing a preset knowledge base provided by an embodiment of the present disclosure.

[0069] Figure 7 Schematic flowchart of the method for obtaining target information provided by an embodiment of the present disclosure.

[0070] Figure 8 Schematic diagram of the structure of a computer device provided by an embodiment of the present disclosure. Detailed implementation manners

[0071] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0072] It should be clear that the embodiments of the present disclosure are described by specific specific examples below. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.

[0073] It should also be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. In addition, this device can be implemented and this method can be practiced using other structures and / or functions in addition to one or more of the aspects described herein.

[0074] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure in a schematic manner. The diagrams only show the components related to the present disclosure, rather than being drawn according to the number, shape and size of the components in actual implementation. The type, quantity and ratio of each component in its actual implementation can be an arbitrary change, and the component layout type may also be more complex.

[0075] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0076] Referring Figure 1 , this application discloses an intelligent alarm analysis method for operation and maintenance scenarios, including:

[0077] S100, parsing the received alarm information to obtain target information.

[0078] Specifically, a business docking layer can be set as the entry of the entire system, and the alarm information generated by the business system is received through the business docking layer. It supports various flexible access methods such as standard

[0079] original alarm letterized RESTful API, plug-in docking, and Webhooks, etc., reducing the access cost of the business system. The original alarm information may contain a large amount of redundant content, and the obtained target information is more concise and critical, facilitating the subsequent steps to accurately find relevant processing strategies from the preset knowledge base, improving the efficiency and accuracy of information processing.

[0080] S200, determining several processing strategies associated with the target information from the preset knowledge base, and obtaining multiple relevance indicators between the target information and each processing strategy. The processing strategies include historical problems and solutions.

[0081] Screening relevant processing strategies from the preset knowledge base makes full use of historical experience and avoids searching for solutions again every time an alarm occurs; obtaining multiple relevance indicators provides a basis for accurately calculating the relevance score subsequently, helping to more precisely select appropriate processing strategies.

[0082] S300, calculating the relevance score between the target information and each processing strategy based on multiple relevance indicators and the preset weights of each relevance indicator.

[0083] By calculating the relevance score with weights, the importance of multiple relevance indicators is comprehensively considered, and the degree of association between the target information and the processing strategy can be evaluated more comprehensively and objectively, providing a quantitative basis for selecting the optimal processing strategy subsequently.

[0084] S400, sorting according to the level of the relevance score. If the highest relevance score is greater than the preset threshold, the processing strategy corresponding to the highest relevance score is used as the target strategy, and the alarm information is automatically processed based on the target strategy.

[0085] Automatically select the target strategy according to the relevance score and perform alarm processing, reducing manual intervention, improving the timeliness and efficiency of alarm processing, being able to respond to alarms in a short time, and reducing the losses caused by system failures.

[0086] S500, if the highest relevance score is not greater than the preset threshold, push the alarm information to the operation and maintenance personnel, receive the processing strategy of the operation and maintenance personnel, and update it to the preset knowledge base.

[0087] Specifically, the analyzed alarm information, reasons, and solutions can be notified to relevant operation and maintenance personnel, supporting multiple notification methods such as DingTalk, SMS, and email.

[0088] When there is no processing strategy in the preset knowledge base that highly matches the target information, push the alarm information to the operation and maintenance personnel to use the professional knowledge and experience of the operation and maintenance personnel to solve the problem. At the same time, update the processing strategy of the operation and maintenance personnel to the preset knowledge base, continuously enrich and improve the knowledge base, and improve the accuracy and efficiency of subsequent alarm processing.

[0089] The intelligent alarm analysis method for operation and maintenance scenarios disclosed in this application can quickly respond to alarm information through an automated parsing, matching, and processing process, reducing the time for manual alarm processing, especially when facing a large number of alarm information, the advantages are more obvious; comprehensively consider multiple relevance indicators to select the processing strategy, combining historical experience and real-time situation, improving the accuracy and applicability of the processing strategy, and reducing the risk of misprocessing; update the processing strategy of the operation and maintenance personnel to the preset knowledge base, making the knowledge base continuously enriched and improved, forming a virtuous cycle of knowledge accumulation, improving the intelligent level and processing ability of the entire operation and maintenance system; at the same time, it can effectively reduce the workload of manual alarm processing, reduce the dependence on the number and experience of operation and maintenance personnel, and thus reduce the operation and maintenance cost.

[0090] The intelligent alarm analysis method for operation and maintenance scenarios disclosed in this application can help new employees quickly adapt to operation and maintenance work, improve their ability to process complex alarm information, and build an efficient and intelligent alarm processing mechanism that can meet the intelligent analysis and processing of alarms in different operation and maintenance scenarios.

[0091] In this embodiment, the multiple relevance indicators include text similarity score, historical relevance score, and time relevance score.

[0092] Among them, the text similarity score should reflect the similarity degree between the text content of the target information and the text content related to the processing strategy. If the text similarity score is relatively high, it means that there is a high degree of consistency in terms of vocabulary, semantics, etc. between the text expression of the target information and the text expression involved in the processing strategy, indicating that this processing strategy may have a strong relevance to the target information at the content level and can be applied to process this target information; if the score is relatively low, it indicates that there are significant differences in the text content between the target information and the processing strategy, and the relevance at the content level is weak.

[0093] Historical relevance reflects the degree of association between the target information and the processing strategy in past data. If the historical relevance score is relatively high, it indicates that this processing strategy has had frequent and effective associations with the target information in the past and can be used as an important reference basis; if the score is relatively low, it indicates that the association between the two was weak historically.

[0094] Temporal relevance reflects the degree of matching between the generation time of the target information and the applicable time range of the processing strategy. A high score means a high degree of fit between the temporal characteristics of the target information and the processing strategy; a low score indicates a poor temporal match.

[0095] Refer to Figure 2 , the calculation method of the relevance score between the target information and each processing strategy specifically includes:

[0096] S310, if the text similarity score is greater than the first upper limit threshold, the historical relevance score is greater than the second upper limit threshold, and the temporal relevance score is greater than the third upper limit threshold, then perform a weighted sum of the text similarity score, historical relevance score, and temporal relevance score according to the preset text similarity weight, historical relevance weight, and temporal relevance weight to obtain the relevance score.

[0097] Suppose the first upper limit threshold is 0.8, the second upper limit threshold is 0.7, and the third upper limit threshold is 0.7. The text similarity score between the target information and a certain processing strategy is 0.85, the historical relevance score is 0.75, and the temporal relevance score is 0.72; first, it is judged that the text similarity score of 0.85 is greater than the first upper limit threshold of 0.8; then it is judged that the historical relevance score of 0.75 is greater than the second upper limit threshold of 0.7; then it is judged that the temporal relevance score of 0.72 is greater than the third upper limit threshold of 0.7; suppose the preset text similarity weight is 0.4, the historical relevance weight is 0.3, and the temporal relevance weight is 0.3. Then the relevance score = 0.85×0.4 + 0.75×0.3 + 0.72×0.3 = 0.781.

[0098] When each score is relatively high, it indicates that the relevance between the target information and the processing strategy is very strong. By comprehensively considering various indicators through weighted summation, this strong correlation can be accurately evaluated, providing a reliable basis for subsequent selection of processing strategies.

[0099] S320, if the text relevance score is not greater than the first lower threshold, the historical relevance score is not greater than the second lower threshold, and the time relevance score is not greater than the third lower threshold, determine that the relevance score is zero; the first lower threshold is less than the first upper threshold, the second lower threshold is less than the second upper threshold, and the third lower threshold is less than the third upper threshold.

[0100] Suppose the first lower threshold is 0.2, the second lower threshold is 0.1, and the third lower threshold is 0.1. The text similarity score between the target information and a certain processing strategy is 0.15, the historical relevance score is 0.08, and the time relevance score is 0.05. Since the text relevance score 0.15 is not greater than the first lower threshold 0.2, the historical relevance score 0.08 is not greater than the second lower threshold 0.1, and the time relevance score 0.05 is not greater than the third lower threshold 0.1, it is determined that the relevance score of this processing strategy and the target information is zero.

[0101] When all scores are very low, it indicates that the target information has little association with the processing strategy. Directly setting the relevance score to zero avoids ineffective calculations and incorrect strategy selections, improving the calculation efficiency and the accuracy of strategy selection.

[0102] S330, if the text relevance score is not greater than the first lower threshold, the historical relevance score is not greater than the second upper threshold and is greater than the second lower threshold, and the time relevance score is not greater than the third upper threshold and is not greater than the third lower threshold, dynamically update the text similarity score to zero.

[0103] S340, obtain the sum of the original weights of the historical relevance weight and the time relevance weight, and update the ratio of the original weight of the historical relevance weight to the sum of the original weights as the current historical relevance weight, and update the ratio of the original weight of the time relevance weight to the sum of the original weights as the current time relevance weight.

[0104] S350, perform a weighted sum of the historical relevance score and the time relevance score based on the current historical relevance weight and the current time relevance weight to obtain the relevance score.

[0105] Assume that the first lower threshold is 0.2, the first upper threshold is 0.8, the second lower threshold is 0.1, the second upper threshold is 0.7, the third lower threshold is 0.1, and the third upper threshold is 0.7. The text similarity score between the target information and a certain processing strategy is 0.15, the historical relevance score is 0.3, and the time relevance score is 0.2. Since the text relevance score of 0.15 is not greater than the first lower threshold of 0.2, the historical relevance score of 0.3 is not greater than the second upper threshold of 0.7 and is greater than the second lower threshold of 0.1, and the time relevance score of 0.2 is not greater than the third upper threshold of 0.7 and is greater than the third lower threshold of 0.1, the dynamically updated text similarity score is zero.

[0106] The preset historical relevance weight is 0.3, and the time relevance weight is 0.3. The sum of their original weights is 0.3 + 0.3 = 0.6. The updated historical relevance weight = 0.3 / 0.6 = 0.5, and the updated time relevance weight = 0.3 / 0.6 = 0.5; the relevance score = 0.3×0.5 + 0.2×0.5 = 0.25.

[0107] When the score of a certain indicator is too low, setting its score to zero and redistributing the weights of other indicators can more reasonably evaluate the relevance between the target information and the processing strategy. In this case, the role of other relatively more relevant indicators is highlighted, and the overall relevance evaluation is prevented from being overly affected by the low score of a certain indicator.

[0108] Furthermore, if the historical relevance score is not greater than the second lower threshold, the text relevance score is not greater than the first upper threshold and is greater than the first lower threshold, and the time relevance score is not greater than the third upper threshold and is not greater than the third lower threshold, the dynamically updated historical similarity score is zero;

[0109] Obtain the sum of the original weights of the text relevance weight and the time relevance weight, and update the ratio of the original weight of the text relevance weight to the sum of the original weights to the current text relevance weight, and update the ratio of the original weight of the time relevance weight to the sum of the original weights to the current time relevance weight;

[0110] Based on the current text relevance weight and the current time relevance weight, perform a weighted sum on the text relevance score and the time relevance score to obtain the relevance score.

[0111] Assume that the thresholds are the same as above. The text similarity score between the target information and a certain processing strategy is 0.3, the historical relevance score is 0.05, and the time relevance score is 0.2. Since the historical relevance score of 0.05 is not greater than the second lower threshold of 0.1, the text relevance score of 0.3 is not greater than the first upper threshold of 0.8 and greater than the first lower threshold of 0.2, and the time relevance score of 0.2 is not greater than the third upper threshold of 0.7 and greater than the third lower threshold of 0.1, the dynamically updated historical similarity score is zero points.

[0112] The preset text relevance weight is 0.4, and the time relevance weight is 0.3. The sum of their original weights is 0.4 + 0.3 = 0.7. The updated text relevance weight = 0.4 / 0.7 ≈ 0.57, and the updated time relevance weight = 0.3 / 0.7 ≈ 0.43; the relevance score = 0.3 × 0.57 + 0.2 × 0.43 = 0.257.

[0113] Similarly, when a certain indicator score is too low, the weights are readjusted to make the relevance score better reflect the actual association degree between the target information and the processing strategy, improving the accuracy of the evaluation.

[0114] Furthermore, if the time relevance score is not greater than the third lower threshold, the historical relevance score is not greater than the second upper threshold and greater than the second lower threshold, and the text relevance score is not greater than the first upper threshold and not greater than the first lower threshold, the dynamically updated time similarity score is zero points;

[0115] Obtain the sum of the original weights of the historical relevance weight and the text relevance weight, and update the ratio of the original weight of the historical relevance weight to the sum of the original weights as the current historical relevance weight, and update the ratio of the original weight of the text relevance weight to the sum of the original weights as the current text relevance weight;

[0116] Based on the current historical relevance weight and the current text relevance weight, perform a weighted sum of the historical relevance score and the text relevance score to obtain the relevance score.

[0117] In this embodiment, by setting different thresholds and dynamically adjusting the weights, considering different situations of various indicators comprehensively, it is possible to evaluate the relevance between the target information and the processing strategy more meticulously and accurately, avoiding the inaccurate problems that may be brought by the single weighted sum method; the accurate relevance score can provide a more reliable basis for subsequent selection of the processing strategy, making the selected processing strategy more in line with the actual situation, improving the success rate of alarm processing, being able to flexibly adjust the evaluation method according to the score situations of different indicators, adapting to various complex actual scenarios, and enhancing the practicability and robustness of the solution.

[0118] Refer to Figure 3, A method for obtaining the text similarity score between the target information and the processing strategy, including:

[0119] A100, splitting the target information into several first words;

[0120] Split the historical problem description in the processing strategy into several second words.

[0121] Assume the target information is "The server disk I / O utilization rate is too high". Use a word segmentation tool (such as the jieba library in Python) for word segmentation to obtain the first words: ["server", "disk", "I / O", "utilization rate", "too high"].

[0122] The historical problem description in the processing strategy is "The server disk read / write I / O usage rate is too high". Also use jieba word segmentation to obtain the second words: ["server", "disk", "read / write", "I / O", "usage rate", "too high"].

[0123] Splitting the text into words is the basis for text vector representation and similarity calculation. Through word segmentation, text information can be transformed into discrete and processable word units, which is convenient for subsequent vector representation using word vector models.

[0124] A200, using a word vector model to convert several first words into a first text vector and several second words into a second text vector.

[0125] Specifically, select a common word vector model such as Word2Vec; the word vector model converts words into vector representations, enabling text information to be processed in a vector space. Vector representations can capture semantic relationships between words. For example, words with similar semantics are closer in the vector space. By converting text into vectors, it is convenient for subsequent similarity calculation.

[0126] A300, calculate the norm of the first text vector, the norm of the second text vector, and the dot product of the first text vector and the second text vector.

[0127] The norm and dot product of vectors are key parameters for calculating vector similarity. The norm of a vector reflects the length of the vector, and the dot product reflects the similarity degree of two vectors in direction. By calculating these values, the text similarity score can be further obtained.

[0128] A400, obtain the text similarity score based on the norm of the first text vector, the norm of the second text vector, and the dot product.

[0129] Among them, the similarity score is X,

[0130] Among them, is the first text vector, is the second text vector, The norm of the first text vector is The norm of the second text vector is The norm represents the length of the vector.

[0131] A method for obtaining the text similarity score between the target information and the processing strategy disclosed in A100 - A400, which uses a word vector model and cosine similarity calculation, can capture the semantic relationship between texts, not just simple literal matching. For example, although the expressions "Disk I / O utilization is too high" and "Disk read / write I / O usage is too high" are not exactly the same, a high similarity score can be obtained through semantic analysis. The entire process can be automated without manual judgment of text similarity, improving the processing efficiency, especially suitable for the matching scenario of large - scale alarm information and processing strategies; at the same time, different word vector models and similarity calculation methods can be used for extension and optimization to adapt to different business requirements and data characteristics. For example, more advanced pre - trained language models (such as BERT) can be used to generate more accurate text vectors.

[0132] Refer to Figure 4 , a method for obtaining the historical relevance score between the target information and the processing strategy, includes:

[0133] B100, convert the target information into a first vector, and convert the historical problem description in the processing strategy into a second vector.

[0134] Converting text information into vector form can map text data into a vector space, providing a basis for subsequent similarity calculation using mathematical methods. Vector representation can capture the semantic information of the text, enabling the relationship between texts to be quantitatively analyzed at the numerical level, avoiding the complexity and ambiguity in directly processing texts. For example, different text expressions may have similar semantics, and this semantic similarity can be better reflected through vector representation.

[0135] B200, obtain the text similarity score between the first vector and the second vector.

[0136] Specifically include: calculating the Manhattan distance between the first vector and the second vector

[0137] Among them, the first vector the second vector

[0138] The text similarity score is W:

[0139] Through this transformation, the Manhattan distance is converted into a similarity score ranging from (0, 1]. The smaller the distance, the higher the similarity score, which conforms to our intuitive understanding of text similarity. This transformation makes the similarity score have good interpretability and is convenient for subsequent comprehensive consideration with other scores.

[0140] B300, extract the first key feature in the target information and the second key feature in the processing strategy; both the first key feature and the second key feature include the alarm source and the alarm type.

[0141] Key features (such as the alarm source and the alarm type) can highlight the core information of the text; when evaluating historical relevance, these features play an important guiding role. For example, target information and processing strategies with the same alarm source and alarm type often have higher relevance. Extracting key features can reduce the interference of irrelevant information, focus on the factors that have a greater impact on relevance, and improve the accuracy of the evaluation.

[0142] B400, obtain the feature matching degree scores of the first key feature and the second key feature.

[0143] Specifically, obtain the number of the same classification attributes in the first key feature and the second key feature; the feature matching degree score = the number of the same classification attributes / the total number of classification attributes in the first key feature.

[0144] The feature matching degree score quantifies the matching degree between key features by calculating the ratio of the number of the same classification attributes to the total number of classification attributes in the first key feature. This method is simple and direct, and can intuitively reflect the similarity between target information and processing strategies in terms of key features; moreover, this method does not depend on the specific expression of the text, but only focuses on the classification attributes of the features, enhancing the stability and reliability of the evaluation.

[0145] B500, perform weighted summation on the text similarity score and the feature matching degree score according to the preset weights of text similarity and the preset weights of feature matching degree to obtain the historical relevance score.

[0146] By comprehensively considering the text similarity score and the feature matching degree score in the way of weighted summation, the historical relevance between target information and processing strategies can be evaluated more comprehensively; different business scenarios may have different emphases on text similarity and feature matching degree, and the preset weights can be adjusted according to actual needs, making the calculation of the historical relevance score more flexible and personalized.

[0147] The method for obtaining the historical relevance score between the target information and the processing strategy disclosed in B100 - B500 comprehensively considers the semantic similarity of the text and the matching degree of key features, evaluates the historical relevance between the target information and the processing strategy from multiple perspectives, avoids the limitations of single - factor evaluation, and improves the accuracy and reliability of the evaluation results; it can flexibly adjust the preset weights of text similarity and feature matching according to different business requirements and data characteristics to adapt to various complex application scenarios; the calculation methods of each step are relatively simple, especially the calculation complexity of the Manhattan distance is low, and it can complete the historical relevance evaluation of large - scale data in a short time, improving the processing efficiency.

[0148] Refer to Figure 5 , the method for obtaining the time - relatedness score between the target information and the processing strategy includes:

[0149] C100, extracting the first time information from the target information.

[0150] Clarifying the time elements in the target information is the basis for subsequent time - relatedness analysis. Different target information may contain time information in different formats and meanings. Accurately extracting this information helps to unify its subsequent processing and analysis, providing a key basis for evaluating the association between the target information and the processing strategy in the time dimension.

[0151] C200, extracting the second time information from the processing strategy.

[0152] Similar to extracting the time information in the target information, the time information in the processing strategy is crucial for judging their time - relatedness. The processing strategy may be formulated for problems within a specific time period. By extracting its time information, it can be better compared and analyzed with the time of the target information.

[0153] C300, converting the first time information and the second time information into a unified format to obtain the first standardized time and the second standardized time.

[0154] In practical applications, time information may exist in various different formats, such as "March 12, 2025, 12:00", "3 / 12 / 2025 12:00 PM", etc. Converting them into a unified format can eliminate the interference caused by format differences, facilitate subsequent calculation and comparison of time differences, and the unified time format is also convenient for computer automated processing, improving processing efficiency and accuracy.

[0155] C400, obtaining the time - difference information between the first standardized time and the second standardized time.

[0156] Specifically, when both the first standardized time and the second standardized time are specific time points, convert the time points into timestamps and calculate the time difference between them;

[0157] When the first standardized time is a time point and the second standardized time is a time period, determine whether the time point falls within the time period. If not, calculate the minimum time difference between the time point and the boundaries of the time period.

[0158] When both the first standardized time and the second standardized time are time periods, use the overlapping degree of the two calculated time periods as the time difference information.

[0159] Time point vs. time point: Convert the time point to a timestamp to calculate the time difference. A timestamp is a common time representation method that can accurately calculate the interval between two time points, making the calculation of the time difference accurate and intuitive, and facilitating subsequent score evaluation based on the time difference.

[0160] Time point vs. time period: Determine whether the time point falls within the time period, and calculate the minimum time difference from the boundaries of the time period when it does not. This processing method takes into account the relative position relationship between the time point and the time period. Even if the time point is not within the time period, the minimum time difference can be calculated to measure their proximity in time, more comprehensively reflecting the time correlation.

[0161] Time period vs. time period: Calculate the overlapping degree of the two time periods as the time difference information. The overlapping degree can well reflect the coincidence of the two time periods in time. The higher the overlapping ratio, the stronger the time correlation between the two, providing a reasonable quantitative indicator for evaluating the time correlation.

[0162] C500, obtain the time correlation score based on the preset time score rule and the time difference information.

[0163] For the time point vs. time point case, the score is 100 points when the time difference is within 1 hour, 80 points when it is between 1 - 24 hours, and 20 points when it exceeds 24 hours; for the time period vs. time period case, the score is 100 points when the overlapping ratio reaches 80% or more, 80 points when it is between 50% - 80%, 50 points when it is between 20% - 50%, and 20 points when it is less than 20%.

[0164] The preset time score rule converts the time difference information into specific scores, enabling the time correlation to be presented in an intuitive numerical form. Different time difference ranges correspond to different scores, clearly reflecting the degree of association between the target information and the processing strategy in time. This quantified score facilitates subsequent comprehensive evaluation and decision-making, such as selecting the processing strategy with the strongest time correlation with the target information among multiple processing strategies.

[0165] Method for obtaining time correlation score of target information and processing strategy disclosed in C100 - C500. This method considers various combinations of time types (time point to time point, time point to time period, time period to time period), can comprehensively process different forms of time information, and ensures accurate evaluation of the time correlation between target information and processing strategy in various actual scenarios; by standardizing the time format and using an accurate time difference calculation method, the accuracy of time correlation evaluation is improved. At the same time, the preset scoring rules make the evaluation results have a clear quantitative standard, reducing the influence of subjective judgment; the finally obtained time correlation score can be directly applied to actual decision-making. For example, in an intelligent alarm processing system, according to the time correlation score, the processing strategy most relevant to the current alarm information in terms of time can be quickly screened out, improving the processing efficiency and effect.

[0166] Refer to Figure 6 , method for constructing a preset knowledge base, including:

[0167] S201, based on a large language model, screen out the official recommended solutions, expert recommended solutions, and forum recommended solutions corresponding to each alarm information from official documents, expert suggestions, and technical forums respectively.

[0168] Among them, official documents are documents released by equipment manufacturers and software developers, expert suggestions are suggestions from industry experts and technical consultants, and technical forums are experiences and solutions shared by users on technical forums.

[0169] Specifically, a web crawler tool (such as Scrapy) can be used to crawl official documents from the official websites of equipment manufacturers and software developers. For example, crawl documents about equipment failure alarms from the official website of Huawei equipment. At the same time, use a crawler to crawl the experiences and solutions shared by users from technical forums (such as Stack Overflow), and suggestions provided by industry experts and technical consultants can also be collected through online and offline meetings, emails, etc.

[0170] Organize all the collected data into text format and process it using a large language model (such as the WeTab AI large model). For each alarm information, such as "server disk I / O is too high alarm", use the prompt "Please find the corresponding processing strategy for [server disk I / O is too high alarm] from the following documents", and use the official documents, expert suggestions, and technical forum data as input to let the model screen out the corresponding solutions.

[0171] Obtaining data from multiple channels ensures the diversity and comprehensiveness of data sources, enabling the acquisition of strategies for processing alarm information from different perspectives; leveraging the powerful semantic understanding ability of large language models, it is capable of efficiently and accurately screening out solutions corresponding to alarm information from a large amount of data, saving the time and effort of manual screening.

[0172] S202, Determine the official document authority score, official document update time score, and official document integrity score according to the official recommended solution.

[0173] S203, Perform weighted summation on the official document authority score, official document update time score, and official document integrity score based on the preset official document authority weight, official document update time weight, and official document integrity weight to obtain the first score.

[0174] Specifically, for the official document authority score: It can be scored according to factors such as the reputation and industry status of the document publisher. For example, documents published by well-known manufacturers such as Huawei and Microsoft have relatively high authority and can be scored 8 - 10 points; documents published by some small manufacturers have relatively low authority and can be scored 3 - 6 points.

[0175] For the official document update time score: It can be scored according to the difference between the update date of the document and the current date. If the document was updated within the past 1 year, it can be scored 8 - 10 points; if it was updated within 1 - 3 years, it can be scored 4 - 7 points; if it has not been updated for more than 3 years, it can be scored 1 - 3 points.

[0176] For the official document integrity score: It can be evaluated whether the description of the solution in the document is detailed and comprehensive. If the document contains complete content such as alarm cause analysis, processing steps, and precautions, it can be scored 8 - 10 points; if part of the content is missing, it can be scored 3 - 7 points; if only a simple processing idea is provided, it can be scored 1 - 3 points.

[0177] Weighted summation: Assume that the official document authority weight is 0.4, the official document update time weight is 0.3, and the official document integrity weight is 0.3. If the authority score of a certain official document is 8 points, the update time score is 6 points, and the integrity score is 7 points, then the first score = 8×0.4 + 6×0.3 + 7×0.3 = 7.1 points.

[0178] In this step, by quantitatively evaluating multiple dimensions of the official document, it is possible to more objectively evaluate the reliability of the official recommended solution; the weighted summation method comprehensively considers the importance of each dimension, enabling the final first score to more accurately reflect the quality of the official recommended solution.

[0179] S204, Determine the expert popularity score, expert experience score, and expert historical evaluation accuracy score according to the expert recommended solution.

[0180] S205, based on the preset weights of expert popularity, expert experience, and expert historical evaluation accuracy, perform a weighted sum of the expert popularity score, expert experience score, and expert historical evaluation accuracy score to obtain the second score.

[0181] Specifically, for the expert popularity score: it can be scored according to factors such as the expert's popularity in the industry, whether they have won important awards, and whether they work in well-known enterprises. For example, an expert who has given multiple speeches at international renowned academic conferences can be scored 8 - 10 points; an expert with a certain popularity but less influence in the industry can be scored 3 - 6 points.

[0182] For the expert experience score: it can be scored according to the number of years the expert has worked in the relevant field. For example, if the working years exceed 10 years, it can be scored 8 - 10 points; 5 - 10 years, it can be scored 4 - 7 points; less than 5 years, it can be scored 1 - 3 points.

[0183] For the expert historical evaluation accuracy score: it can be scored by statistically calculating the accurate execution rate of the solutions provided by the expert in the past. If the execution rate exceeds 80%, it can be scored 8 - 10 points; the execution rate is between 50% - 80%, it can be scored 4 - 7 points; the execution rate is less than 50%, it can be scored 1 - 3 points.

[0184] Weighted sum: Assume the weight of expert popularity is 0.3, the weight of expert experience is 0.3, and the weight of expert historical evaluation accuracy is 0.4. If an expert's popularity score is 7 points, experience score is 8 points, and historical evaluation accuracy score is 9 points, then the second score = 7×0.3 + 8×0.3 + 9×0.4 = 8.1 points.

[0185] In this step, multiple aspects of the expert are evaluated, comprehensively considering the expert's ability and reliability, and avoiding evaluating the expert's recommended solution based on a single factor; the second score obtained through weighted sum can more accurately reflect the quality of the expert's recommended solution, providing a basis for subsequent screening of reliable strategies.

[0186] S206, determine the post like count score, post comment count score, and post reply time score according to the forum recommended solution;

[0187] S207, based on the preset weights of post like count, post comment count, and post reply time, perform a weighted sum of the post like count score, post comment count score, and post reply time score to obtain the third score.

[0188] Specifically, for the post like count score: it can be scored according to the number of likes of the post. For example, if the like count exceeds 100, it can be scored 8 - 10 points; the like count is between 50 - 100, it can be scored 4 - 7 points; the like count is less than 50, it can be scored 1 - 3 points.

[0189] Regarding the score for the number of post comments: The score can be given based on the number of comments on the post. For example, if the number of comments exceeds 50, a score of 8 - 10 can be given; if the number of comments is between 20 - 50, a score of 4 - 7 can be given; if the number of comments is less than 20, a score of 1 - 3 can be given.

[0190] Regarding the score for the post reply time: The score can be given according to the time of the first valid reply after the post is published. If there is a reply within 1 hour, a score of 8 - 10 can be given; if there is a reply within 1 - 24 hours, a score of 4 - 7 can be given; if there is no reply until more than 24 hours later, a score of 1 - 3 can be given.

[0191] Weighted summation: Assume that the weight of the number of post likes is 0.4, the weight of the number of post comments is 0.3, and the weight of the post reply time is 0.3. If a certain post has a like score of 7, a comment score of 6, and a reply time score of 8, then the third score = 7×0.4 + 6×0.3 + 8×0.3 = 7 points.

[0192] In this step, from the perspective of user feedback, a quantitative evaluation is carried out on the forum recommended solutions. The number of likes, comments, and reply time can reflect the degree of recognition and attention of other users to this solution; the third score obtained by weighted summation helps to screen out the solutions that are more concerned and recognized on the forum.

[0193] S208, Obtain several recommended solutions corresponding to the scores greater than the preset reliability threshold among the first score, the second score, and the third score, and record them as reliable strategies.

[0194] Assume that the preset reliability threshold is 7 points. In the above example, the first score of 7.1 points, the second score of 8.1 points, and the third score of 7 points are all greater than 7 points, then the official recommended solution, the expert recommended solution, and the forum recommended solution are all recorded as reliable strategies.

[0195] By setting the reliability threshold, it is possible to screen out recommended solutions with higher quality and stronger reliability, avoid using unreliable strategies to process alarm information, and improve the success rate of processing alarms.

[0196] S209, Based on the large prediction model, fuse several reliable strategies, and generate a processing strategy for the corresponding alarm information according to the strategy content and logical relationship;

[0197] All types of alarm information and the corresponding processing strategies constitute a preset knowledge base.

[0198] Specifically, the selected reliable strategies are input into the WeTab AI large model, with the prompt "Please generate a processing strategy for [Server Disk I / O High Alarm] based on the following reliable strategies". The large model will analyze the content and logical relationships of each reliable strategy and integrate them into a comprehensive and reasonable processing strategy. For example, strategies such as checking the disk hardware status recommended by the official, optimizing the disk read / write algorithm suggested by experts, and cleaning temporary disk files recommended by the forum are integrated to generate a complete processing strategy.

[0199] Utilizing the powerful integration ability of the large language model to fuse multiple reliable strategies can generate more comprehensive and effective processing strategies, avoiding the limitations of single strategies; the constructed preset knowledge base contains processing strategies for various types of alarm information, providing a unified and efficient reference basis for subsequent alarm handling, and improving the efficiency and accuracy of alarm handling.

[0200] The method for constructing the preset knowledge base disclosed in S201 - S209, by collecting data from multiple channels, quantitatively evaluating and screening solutions from different sources, and using the large language model to fuse reliable strategies, can generate more accurate and comprehensive processing strategies, improving the success rate of alarm handling; the automated data collection, screening, and processing process reduces the time and effort of manually searching for and analyzing solutions, improving work efficiency; as new official documents are released, experts provide new suggestions, and users share new experiences on the forum, the preset knowledge base can be continuously updated and optimized to ensure the timeliness and effectiveness of the processing strategies.

[0201] In this embodiment, the preset knowledge base supports automated update and manual optimization, that is, the solutions submitted by the operation and maintenance personnel will be automatically archived, knowledge base entries will be constructed and version management will be carried out. The administrator regularly reviews the entries and optimizes the content to improve accuracy and timeliness.

[0202] It should be noted that the steps for obtaining the first score, second score, and third score can be flexibly set and are all within the protection scope of this application.

[0203] Refer to Figure 7 , for "parsing the received alarm information to obtain target information" in S100, that is, the method for obtaining target information specifically includes:

[0204] S110, according to the type, source, and subsequent processing requirements of the alarm information, fields for parsing the alarm information are predefined in advance, and the fields include but are not limited to alarm time, alarm level, alarm device identifier, and alarm description.

[0205] Suppose we are in charge of a monitoring system for a large data center, which contains various devices such as servers and network equipment. For the alarm information generated by server devices, according to the monitoring requirements of the servers, the predefined fields are: alarm time (recording the specific time when the alarm occurs), alarm level (such as critical, important, general), alarm device identifier (the IP address or unique number of the server), and alarm description (detailed description of the specific situation of the alarm, such as high CPU usage, insufficient memory, etc.).

[0206] The clear field definitions provide clear guidance for subsequent alarm information parsing. Alarm information of different types and sources may contain different contents. By defining fields in advance, we can focus on the key information we care about and avoid confusion and omission during the parsing process. At the same time, these fields are determined according to subsequent processing requirements, ensuring that the parsed data can be directly used for subsequent analysis, decision-making, and other tasks.

[0207] S120 receives alarm information sent from different systems or devices, and the alarm information is presented in formats such as text, JSON, XML, etc.

[0208] Continuing with the example of the data center, the server may send alarm information through system logs (text format), for example: "2025-03-12 13:00:00 [Critical] Server 192.168.1.10 CPU usage reaches 95%".

[0209] This step enables the system to be compatible with various formats of alarm information sent from different systems or devices. In an actual IT environment, different devices and systems may use different communication protocols and data formats to send alarm information; by supporting the reception of multiple formats, it can be ensured that the system can collect all relevant alarm information and will not lose important alarm data due to format incompatibility.

[0210] S130 parses the received alarm information based on the predefined fields, using regular expression matching, data extraction tools, or parsing libraries to extract the content corresponding to the predefined fields from the alarm information.

[0211] For the server alarm information in the above text format "2025-03-12 13:00:00 [Severe] Server 192.168.1.10 CPU usage reaches 95%", regular expressions can be used to extract the content of each field. For example, use the regular expression (\d{4}-\d{2}-\d{2}\d{2}:\d{2}:\d{2})\[(\w+)\] Server (\S+)(.*) to match the alarm time, alarm level, alarm device identifier, and alarm description. For JSON-formatted alarm information, the json library in Python can be used for parsing. For XML-formatted alarm information, the xml.etree.ElementTree library in Python can be used for parsing.

[0212] By using methods such as regular expression matching, data extraction tools, or parsing libraries, predefined field content can be efficiently and accurately extracted from alarm information in different formats. These tools and methods provide specialized processing methods for different data formats, can make full use of the characteristics of various formats for parsing, and improve the efficiency and accuracy of parsing.

[0213] S140, combine the content of each parsed field to generate target information, and store the target information in the form of structured data.

[0214] Taking Python as an example, combine the content of each parsed field above into a dictionary and store it as structured data. This dictionary can be stored in a database (such as MySQL, MongoDB, etc.) for subsequent querying and analysis.

[0215] Combining the parsed field content into structured data and storing it makes the alarm information have good organization and readability. Structured data can be conveniently queried, statistically analyzed, for example, all alarm information within a certain time period can be filtered according to the alarm time, and alarms can be classified and statistically analyzed according to the alarm level. At the same time, structured data is also convenient for data interaction and sharing with other systems.

[0216] The method for obtaining target information disclosed in S110 - S140 realizes the unified management of alarm information from different sources and in different formats by predefined fields, parsing alarm information in different formats and converting it into structured data. This enables the system to centrally process and analyze all alarm information, improving data availability and management efficiency. This solution provides a set of standardized processes for obtaining and processing alarm information, reducing the need for manual intervention. The automated parsing and structured storage processes can quickly convert the original alarm information into available data, providing timely support for subsequent processing and decision - making. The structured target information provides a good basis for data analysis and decision - making. Various data analysis tools and algorithms can be used to mine and analyze the stored alarm information, such as finding frequently occurring alarm types, analyzing alarm trends, etc., thus providing valuable references for system optimization and maintenance.

[0217] Regarding "receiving the processing strategies of operation and maintenance personnel and updating them to the preset knowledge base" in S500, it specifically includes: Operation and maintenance personnel are divided into junior operation and maintenance personnel, intermediate operation and maintenance personnel, and senior operation and maintenance personnel according to their permission levels. Operation and maintenance personnel with different permission levels have different processing strategies: The processing strategies of junior operation and maintenance personnel include information confirmation, basic operations, and information recording and reporting; The processing strategies of intermediate operation and maintenance personnel include fault troubleshooting, configuration adjustment, and plan formulation and execution; The processing strategies of senior operation and maintenance personnel include system architecture optimization, strategy formulation and adjustment, and cross - departmental collaboration and decision - making.

[0218] When the operation and maintenance personnel are junior operation and maintenance personnel, their permission characteristics are that they can usually only handle some common and simple alarm situations, with relatively limited operation permissions, and are mainly responsible for basic information collection and preliminary processing.

[0219] Regarding the processing strategies for information confirmation include: 1) After receiving the alarm information, confirm with the alarm device or system within a preset time (such as 5 minutes) to check if there is really a problem. For example, for a server disk usage rate alarm, log in to the server to check the disk usage situation and confirm whether the alarm threshold is reached. 2) Communicate with relevant business departments or users to understand if there are any abnormal operations that caused the alarm. For example, for an application response timeout alarm, ask the business personnel using the application if there are any abnormal operation behaviors.

[0220] Regarding the processing strategies for basic operations include: 1) Perform simple restart operations; for example, in case of an alarm that a network device port is not accessible, try to restart the port; for an alarm that a service process exits abnormally, restart the corresponding service; 2) Clean up temporary files or caches. For an alarm of insufficient storage device space, clean up system temporary files or application caches.

[0221] The processing strategies for information recording and reporting include: 1) Detailedly record relevant information of the alarms, including alarm time, alarm level, alarm device identifier, preliminary inspection situation, etc., and organize them into a report according to a preset format; 2) Report the processing process and results to the superior operation and maintenance personnel or management personnel in a timely manner.

[0222] When the operation and maintenance personnel are intermediate operation and maintenance personnel, the characteristics of their permissions are that they have more in-depth technical knowledge and certain decision-making abilities, can handle relatively complex alarm situations, and have certain independent operation and configuration modification permissions.

[0223] The processing strategies for fault troubleshooting include: 1) Use professional tools to conduct in-depth troubleshooting of the faults. For example, for the alarm of database performance degradation, use database performance monitoring tools to analyze the execution situation of query statements, index usage, etc. 2) Analyze system logs and event records to find out the root causes that may lead to the alarms. For example, for the alarm of frequent server crashes, locate the problem by viewing the error codes and event times in the system logs.

[0224] The processing strategies for configuration adjustment include: 1) Appropriately adjust the configuration of the device or system according to the troubleshooting results. For example, for the alarm of insufficient network bandwidth, adjust the QoS (Quality of Service) configuration of the network device to give priority to key service traffic. 2) Optimize the parameters of the application program. For the alarm of slow application program response, adjust parameters such as the thread pool size and cache configuration of the application server.

[0225] The processing strategies for solution formulation and execution include: 1) Formulate a temporary solution to solve the alarm problem without affecting the normal operation of the business. For example, for the alarm of database server disk failure, formulate a temporary data migration and recovery plan. 2) Implement preventive maintenance measures to avoid similar alarms from occurring again. For example, regularly conduct inspections and maintenance on the server hardware.

[0226] When the operation and maintenance personnel are senior operation and maintenance personnel, the characteristics of their permissions are that they have the highest level of permissions, can conduct comprehensive management and decision-making on the entire system, and are responsible for formulating and adjusting the overall operation and maintenance strategy.

[0227] The processing strategies for system architecture optimization include: 1) Optimize and upgrade the system architecture according to the alarm situation and business development needs. For example, as the business volume grows and the database performance frequently shows bottleneck alarms, consider performing a distributed transformation on the database architecture. 2) Introduce new technologies and tools to improve the reliability and performance of the system. For example, to deal with the alarm of network attacks, introduce firewalls and intrusion detection systems.

[0228] The processing strategies for strategy formulation and adjustment include: 1) formulating and adjusting alarm rules and thresholds, and reasonably setting alarm levels and triggering conditions according to the actual operation situation and business requirements of the system. 2) Adjusting operation and maintenance processes and specifications to improve operation and maintenance efficiency and quality. For example, optimizing the fault handling process to reduce the fault recovery time.

[0229] The processing strategies for cross-departmental collaboration and decision-making include: 1) communicating and collaborating with other departments (such as development, testing, business, etc.) to jointly solve complex problems. For example, when handling fault alarms involving multiple systems, organizing cross-departmental meetings to coordinate resources from all parties. 2) Making decisions on major faults and incidents to determine whether to take emergency measures (such as system shutdown for maintenance).

[0230] When the operation and maintenance personnel successfully solve the problem and submit relevant solutions, the system will automatically add this information to the knowledge base as an important reference for subsequent analysis. The system supports version management of knowledge base entries to prevent newly added content from overwriting existing valid information.

[0231] Although the system can automatically update the knowledge base, the administrator or expert can regularly review the newly added entries and optimize and adjust them through the interface to ensure the efficiency and accuracy of the knowledge base.

[0232] The following combines specific operation and maintenance scenarios to analyze how the solution disclosed in this application solves the problems existing in the background technology:

[0233] Suppose a large enterprise has a complex enterprise information system covering multiple components such as server hardware, database software, and network devices; during daily operation, the system generates a large amount of alarm information, and the operation and maintenance team includes experienced old employees and newly recruited employees.

[0234] To solve problems such as the diversity and high complexity of alarm information, in this application, the received alarm information is parsed to obtain target information; specifically, in the enterprise information system, multiple alarm information may be received simultaneously, such as server hardware overheating alarm, database connection timeout alarm, and network packet loss alarm. By parsing these alarm information, the system can extract key target information, such as the specific number of the server, the connection parameters of the database, the location of the network device, etc. This step structures the complex and diverse alarm information, making subsequent analysis more targeted and solving the problems of diverse alarm information and difficulty in direct processing.

[0235] Secondly, in this application, a number of processing strategies associated with the target information are determined from a preset knowledge base, and relevance indicators are obtained. That is, for the parsed target information, the system can quickly screen out the relevant processing strategies from the knowledge base. For example, for an alarm about the server temperature being too high, the knowledge base may have processing strategies such as adjusting the server fan speed and checking the operation status of the computer room air conditioner. At the same time, the system will obtain multiple relevance indicators of the target information and each processing strategy, such as the frequency of the processing strategy solving similar problems in history, the time required to solve the problem, etc. These relevance indicators provide a basis for accurately evaluating the processing strategies subsequently and help to cope with the complex correlation relationships between alarm messages.

[0236] Then, by assigning preset weights to multiple relevance indicators, the relevance score of the target information and each processing strategy is calculated. For example, for an alarm about the server temperature being too high, if the frequency of adjusting the server fan speed to solve the problem is relatively high in history, then this processing strategy will account for a higher proportion in the calculation of the relevance score. This quantitative evaluation method can more accurately judge the relevance of each processing strategy to the current alarm message and avoid misjudgment caused by the complexity of the alarm message.

[0237] The processing strategies are sorted according to the level of the relevance score. If the highest relevance score is greater than the preset threshold, the system will take the processing strategy corresponding to the highest score as the target strategy and automatically process the alarm message. In the above enterprise information system scenario, new employees may not know where to start in the face of complex alarm messages, but the system can automatically select the most appropriate processing strategy for processing according to preset rules, reducing the processing delay caused by new employees' lack of experience and ensuring that system failures can be resolved in a timely manner.

[0238] If the highest relevance score is not greater than the preset threshold, it means that there is no completely matching processing strategy in the current knowledge base, and the system will push the alarm message to the operation and maintenance personnel. In this case, experienced old employees can provide processing strategies based on their experience. The system will receive the processing strategies of the operation and maintenance personnel and update them to the preset knowledge base. In this way, when new employees encounter similar problems again, the system can find more appropriate processing strategies from the updated knowledge base to help new employees process alarm messages quickly and accurately, reducing the threat to the stable operation of the system caused by new employees' lack of experience.

[0239] In summary, the solution disclosed in this application effectively solves the problems of diverse and highly complex alarm messages and the difficulty of new employees lacking experience in processing alarm messages mentioned in the background technology through steps such as parsing alarm messages, screening and evaluating processing strategies, automatic processing, and updating the knowledge base.

[0240] Second aspect, the present application discloses an intelligent alarm analysis system for an operation and maintenance scenario, which is used to execute the intelligent alarm analysis method for an operation and maintenance scenario disclosed in the first aspect of the present application, and specifically includes:

[0241] A parsing module, configured to parse the received alarm information to obtain target information;

[0242] An acquisition module, configured to determine a number of processing strategies associated with the target information from a preset knowledge base, and acquire multiple relevance indicators of the target information and each processing strategy, where the processing strategy includes historical problems and solutions;

[0243] A calculation module, configured to calculate the relevance score of the target information and each processing strategy based on multiple relevance indicators and the preset weights of each relevance indicator;

[0244] A processing module, configured to sort according to the level of the relevance score. If the highest relevance score is greater than a preset threshold, use the processing strategy corresponding to the highest relevance score as the target strategy, and automatically process the alarm information based on the target strategy;

[0245] An update module, configured to, if the highest relevance score is not greater than the preset threshold, push the alarm information to the operation and maintenance personnel, receive the processing strategy of the operation and maintenance personnel, and update it to the preset knowledge base.

[0246] According to an embodiment of the present disclosure, a computer device includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0247] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the intelligent alarm analysis method for an operation and maintenance scenario in the foregoing embodiments of the present disclosure.

[0248] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, in this embodiment, well-known structures such as communication buses and interfaces may also be included, and these well-known structures should also be included in the protection scope of the present disclosure.

[0249] As shown in Figure 8 FIG. Figure 8 is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiment of the present disclosure. Figure 8 The shown computer device is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0250] As shown in Figure 8 the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, the ROM, and the RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0251] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device; an output device including, for example, a display screen; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 8 the shown computer device has various devices, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0252] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by the processor, all or part of the steps of the intelligent alarm analysis method for the operation and maintenance scenario in the embodiment of the present disclosure are executed.

[0253] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not repeated herein.

[0254] According to an embodiment of the present disclosure, a computer-readable storage medium stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the intelligent alarm analysis method for the operation and maintenance scenario in the foregoing embodiments of the present disclosure are executed.

[0255] The above computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or removable hard disk), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0256] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0257] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the specific details disclosed above are only for illustrative purposes and for ease of understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0258] In the present disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0259] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a separate listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). In addition, the term "exemplary" does not mean that the described examples are preferred or better than other examples.

[0260] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.

[0261] Various changes, substitutions, and alterations to the techniques described herein may be made without departing from the teachings defined by the appended claims. Additionally, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Processes, machines, manufactures, compositions of events, means, methods, or acts that are currently available or later to be developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0262] The foregoing description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0263] The foregoing description has been presented for purposes of illustration and description. Additionally, this description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although numerous example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.

Claims

1. An intelligent alarm analysis method for operation and maintenance scenarios, characterized in that, Including: Parsing the received alarm information to obtain target information; Determining several processing strategies associated with the target information from a preset knowledge base, and obtaining multiple correlation indicators between the target information and each processing strategy, where the processing strategy includes historical problems and solutions; Calculating the correlation score between the target information and each processing strategy based on the multiple correlation indicators and the preset weights of each correlation indicator; Sorting according to the level of the correlation score. If the highest correlation score is greater than a preset threshold, taking the processing strategy corresponding to the highest correlation score as the target strategy, and automatically processing the alarm information based on the target strategy; If the highest correlation score is not greater than the preset threshold, pushing the alarm information to the operation and maintenance personnel, receiving the processing strategy of the operation and maintenance personnel, and updating it to the preset knowledge base.

2. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 1, wherein The multiple correlation indicators include text similarity score, historical correlation score, and time correlation score; The calculating the correlation score between the target information and each processing strategy based on the multiple correlation indicators and the preset weights of each correlation indicator includes: If the text similarity score is greater than a first upper threshold, the historical correlation score is greater than a second upper threshold, and the time correlation score is greater than a third upper threshold, performing weighted summation on the text similarity score, the historical correlation score, and the time correlation score according to the preset text similarity weight, historical correlation weight, and time correlation weight to obtain the correlation score; If the text correlation score is not greater than a first lower threshold, the historical correlation score is not greater than a second lower threshold, and the time correlation score is not greater than a third lower threshold, determining that the correlation score is zero; the first lower threshold is less than the first upper threshold, the second lower threshold is less than the second upper threshold, and the third lower threshold is less than the third upper threshold; If the text correlation score is not greater than the first lower threshold, the historical correlation score is not greater than the second upper threshold and is greater than the second lower threshold, and the time correlation score is not greater than the third upper threshold and is not greater than the third lower threshold, dynamically updating the text similarity score to zero; Obtaining the sum of the original weights of the historical correlation weight and the time correlation weight, and updating the ratio of the original weight of the historical correlation weight to the sum of the original weights to the current historical correlation weight, and updating the ratio of the original weight of the time correlation weight to the sum of the original weights to the current time correlation weight; Performing weighted summation on the historical correlation score and the time correlation score based on the current historical correlation weight and the current time correlation weight to obtain the correlation score.

3. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 2, wherein The method for obtaining the text similarity score between the target information and the processing strategy includes: Splitting the target information into several first words; Splitting the historical problem description in the processing strategy into several second words; Convert a number of the first words into a first text vector and a number of the second words into a second text vector using a word vector model; Calculate the norm of the first text vector, the norm of the second text vector, and the dot product of the first text vector and the second text vector; Obtain a text similarity score based on the norm of the first text vector, the norm of the second text vector, and the dot product; 4. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 2, characterized in that, The method for obtaining the historical relevance score between the target information and the processing strategy includes: Convert the target information into a first vector and convert the historical problem description in the processing strategy into a second vector; Obtain the text similarity score between the first vector and the second vector; Extract the first key features in the target information and the second key features in the processing strategy; both the first key features and the second key features include the alarm source and the alarm type; Obtain the feature matching score between the first key features and the second key features; Perform weighted summation on the text similarity score and the feature matching score according to the preset weights of text similarity and the preset weights of feature matching to obtain the historical relevance score; 5. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 2, wherein The method for obtaining the temporal relevance score between the target information and the processing strategy includes: Extract the first time information from the target information; Extract the second time information from the processing strategy; Convert the first time information and the second time information into a unified format to obtain a first standardized time and a second standardized time; Obtain the time difference information between the first standardized time and the second standardized time; Obtain the temporal relevance score based on a preset time score rule and the time difference information; 6. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 1, wherein The method for constructing the preset knowledge base includes: Based on a large language model, screen the official recommended solutions, expert recommended solutions, and forum recommended solutions corresponding to each alarm information from official documents, expert suggestions, and technical forums respectively; Determine the official document authority score, the official document update time score, and the official document integrity score according to the official recommended solution; Perform weighted summation on the official document authority score, the official document update time score, and the official document integrity score based on the preset official document authority weight, official document update time weight, and official document integrity weight to obtain a first score; Determine the expert popularity score, the expert experience score, and the expert historical evaluation accuracy score according to the expert recommended solution; Perform weighted summation on the expert popularity score, the expert experience score, and the expert historical evaluation accuracy score based on the preset expert popularity weight, expert experience weight, and expert historical evaluation accuracy weight to obtain a second score; Determine the post like count score, the post comment count score, and the post reply time score according to the forum recommended solution; Perform weighted summation on the post like count score, the post comment count score, and the post reply time score based on the preset post like count weight, post comment count weight, and post reply time weight to obtain a third score; Obtain several recommended solution corresponding to the scores greater than the preset reliability threshold among the first score, the second score, and the third score, and denote them as reliable strategies; Based on the large prediction model, fuse several of the reliable strategies, and generate a processing strategy for the corresponding alarm information according to the strategy content and logical relationship; All types of alarm information and the corresponding processing strategies constitute a preset knowledge base.

7. The intelligent alarm analysis method for operation and maintenance scenarios according to claim 1, characterized in that Parse the received alarm information to obtain target information, including: According to the type, source, and subsequent processing requirements of the alarm information, pre-define the fields for parsing the alarm information, and the fields include but are not limited to alarm time, alarm level, alarm device identifier, and alarm description; Receive alarm information sent from different systems or devices; Based on the pre-defined fields, parse the received alarm information, and use regular expression matching, data extraction tools, or parsing libraries to extract the content corresponding to the pre-defined fields from the alarm information; Combine the content of each field obtained by parsing to generate target information.

8. A computer device, characterized in that, The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the intelligent alarm analysis method for the operation and maintenance scenario according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, This computer-readable storage medium stores computer instructions for causing a computer to execute the intelligent alarm analysis method for the operation and maintenance scenario according to any one of claims 1-7.

10. A computer program product, comprising computer instructions, characterized in that, When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.

Citation Information

Patent Citations

  • Protective layer transfer sheet

    US20090068456A1

Cited By

  • BERT-based intelligent operation and maintenance alarm causal relationship analysis method

    CN121435174A

  • A bert-based intelligent operation and maintenance alarm causal relationship analysis method

    CN121435174B