Data detection method and device, electronic equipment, storage medium and program product
By dynamically adjusting the data detection process, based on the detection results of the target data labels in different time periods, the problems of unstable data detection results and high maintenance costs are solved, and more efficient and accurate data detection is achieved.
Patent Information
- Application Number
- CN202510443489.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, the data detection methods have problems such as unstable detection results, high information configuration costs and high maintenance costs, especially when data application scenarios change, it is difficult to adjust the detection rules in a timely manner.
By determining multiple target data tags in response to the data detection request, and dynamically adjusting the detection process according to the detection results of these tags in different time periods, including determining the preliminary detection results of the first time period and further detection of the second time period, dynamically determining the detection depth and reducing unnecessary resource consumption.
It improves the accuracy and reliability of data detection, reduces the probability of misjudgment and misjudgment, reduces resource waste, and improves the flexibility and effectiveness of detection.
Smart Images

Figure CN120277471A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer processing technologies, and in particular, to a data detection method, apparatus, electronic device, storage medium, and program product. Background Art
[0002] In the context of the rapid development of information technology, various data systems are widely used in various industries, and their stable operation plays a crucial role in ensuring service continuity and improving the user experience. To ensure the reliable operation of business systems, data detection has become an indispensable technical means.
[0003] In data detection in related technologies, it is usually necessary to manually perform targeted information configuration for a single business scenario under a single interface, and most detection methods rely on preset fixed thresholds. However, in actual applications, the performance of data is unstable as the application peaks and troughs change. Therefore, it is difficult to detect anomalies in a timely and accurate manner through fixed thresholds. When covering large business systems or launching large requirements, a large amount of manpower needs to be invested, resulting in a high information configuration cost for data detection. When the situation of the application scenario corresponding to data detection changes or the data processing logic is iterated, the data detection rules may become invalid. If the configuration is not maintained and modified in a timely manner, the accuracy and noise situation will continue to deteriorate. However, the method of modifying the detection threshold item by item often requires a high maintenance cost. Summary of the Invention
[0004] Embodiments of the present disclosure provide a data detection method, apparatus, electronic device, storage medium, and program product to solve the technical problems of unstable detection results, high information configuration cost, and high maintenance cost existing in the data detection methods in related technologies, and achieve the technical effect of improving the accuracy and reliability of data detection.
[0005] In a first aspect, embodiments of the present disclosure provide a data detection method, the method including:
[0006] In response to a data detection request, determining a plurality of target data tags corresponding to the data detection request; wherein, the target data tags are used to indicate the data to be detected;
[0007] Determining a plurality of arrays corresponding to a first time period according to the plurality of target data tags, and respectively determining a first detection result of each of the arrays within the first time period;
[0008] In response to an event that the first detection result satisfies a first preset condition, determining a second time period corresponding to the array, and determining an array detection result of the array according to preset type data of the array within the first time period and the second time period.
[0009] Second aspect, embodiments of the present disclosure further provide a data detection device, which includes:
[0010] A data detection request module, configured to determine a plurality of target data tags corresponding to the data detection request in response to the data detection request; wherein the target data tags are used to indicate the data to be detected;
[0011] A first time period detection module, configured to determine a plurality of arrays corresponding to a first time period according to the plurality of target data tags, and respectively determine first detection results of each of the arrays within the first time period;
[0012] A detection result determination module, configured to determine a second time period corresponding to the array in response to an event that the first detection result meets a first preset condition, and determine an array detection result of the array according to preset type data of the array within the first time period and the second time period.
[0013] Third aspect, embodiments of the present disclosure further provide an electronic device, which includes:
[0014] One or more processors;
[0015] A storage device, configured to store one or more programs,
[0016] When the one or more programs are executed by the one or more processors, the one or more processors implement the data detection method as described in any one of the embodiments of the present disclosure.
[0017] Fourth aspect, embodiments of the present disclosure further provide a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute the data detection method as described in any one of the embodiments of the present disclosure when executed by a computer processor.
[0018] Fifth aspect, embodiments of the present disclosure further provide a computer program product, including a computer program, and the computer program implements the data detection method as described in any one of the embodiments of the present disclosure when executed by a processor.
[0019] The technical solution of the embodiment of the present disclosure determines multiple target data tags corresponding to the data detection request in response to the data detection request. Since the target data tags are used to indicate the data to be detected, it can accurately locate the content to be detected, avoid detecting unnecessary data, improve the pertinence and efficiency of data detection, and reduce the waste of detection resources; by determining multiple arrays corresponding to the first time period according to the multiple target data tags, and respectively determining the first detection results of each array within the first time period, detection is carried out from the perspective of multiple arrays, refining the detection dimension. It is possible to analyze data characteristics in different dimensions, making the detection results more comprehensive and accurate; by responding to the event that the first detection result meets the first preset condition, determining the second time period corresponding to the array, and determining the array detection result of the array according to the preset type data of the array in the first time period and the second time period, it is possible to dynamically decide whether to perform more in-depth detection according to the situation of the first detection result. When the first detection result shows that the data is abnormal or has potential problems (meeting the first preset condition), a second detection is performed, avoiding the resource consumption and increased time cost caused by performing in-depth detection on all data, while being able to perform in-depth analysis on key data, improving the flexibility and effectiveness of detection. The combination of the preset type data of the first time period and the second time period can more comprehensively discover problems in the data, reduce the probability of misjudgment and missed judgment, thereby improving the accuracy and reliability of the array detection result. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original components and elements are not necessarily drawn to scale.
[0021] Figure 1 It is a flowchart of a data detection method provided by an embodiment of the present disclosure;
[0022] Figure 2 It is a flowchart of another data detection method provided by an embodiment of the present disclosure;
[0023] Figure 3 It is a flowchart of another data detection method provided by an embodiment of the present disclosure;
[0024] Figure 4 It is an optional flowchart of another data detection method provided by an embodiment of the present disclosure;
[0025] Figure 5 It is a structural diagram of a data detection device provided by an embodiment of the present disclosure;
[0026] Figure 6 A structural schematic diagram of an electronic device for implementing the embodiments of the present disclosure provided by the embodiments of the present disclosure. Detailed implementation manners
[0027] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0028] It should be understood that the various steps recorded in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0029] The term "including" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0030] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions executed by these devices, modules or units or the interdependent relationship.
[0031] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".
[0032] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0033] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the users and the authorization of the users should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0034] For example, when responding to an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application, a server, or a storage medium that performs the operations of the present disclosure's technical solution based on the prompt message.
[0035] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user may be, for example, in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0036] It can be understood that the above notification and obtaining user authorization process is only illustrative and does not constitute a limitation on the implementation manner of the present disclosure. Other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0037] It can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of corresponding laws, regulations, and related regulations.
[0038] Figure 1 It is a schematic flowchart of a data detection method provided by an embodiment of the present disclosure. The embodiment of the present disclosure is applicable to scenarios where specified data or detection indicators are detected, especially applicable to scenarios where data risks are detected. This method can be executed by a data detection device, and the device can be implemented in the form of software and / or hardware. Optionally, it is implemented by an electronic device, and the electronic device can be a mobile terminal, a PC, or a server, etc. As Figure 1 shown, the method of this embodiment may specifically include:
[0039] S110. In response to a data detection request, determine a plurality of target data tags corresponding to the data detection request; wherein, the target data tags are used to indicate the data to be detected.
[0040] In an embodiment of the present disclosure, a data detection request can be understood as an instruction or operation for requesting to execute a preset data detection process. The data detection request can be triggered by a user or a measurement system, and is used to perform a preset detection operation on specific data to obtain performance data on expected metrics. There can be multiple ways to trigger a data detection request. For example, it can be triggered based on a preset trigger condition and / or based on a preset operation, etc. Exemplarily, the preset trigger condition can include at least one of the following conditions: reaching a preset detection time point; the time interval from the previous detection time reaching a preset time interval; detecting a preset detection trigger event (such as receiving target data and / or a change in the state of a target interface, etc.); receiving detection notification information sent by a target terminal; etc. The preset operation can include at least one of the following operations: a recording operation for expected voice control data; an operation of inputting an expected action; a control trigger operation for a preset detection trigger control; a setting operation for a data detection task; etc.
[0041] In an embodiment of the present disclosure, the data detection request specifically includes a task execution request for the data detection task. As an alternative implementation, before responding to the data detection request, it further includes: receiving a task setting operation, and determining a data detection task according to the task setting operation, where the data detection task includes an identification setting operation and / or a label setting operation. The identification setting operation is used to set a task identifier corresponding to the data detection task, and the label setting operation is used to set a target data label corresponding to the data detection task. By adopting this technical solution, flexible setting of the data detection task can be achieved to meet the data detection requirements of diverse application scenarios, and it can better meet the differentiated data detection requirements in one or more application scenarios, improve the flexibility of data detection, and broaden the applicability of this data detection method.
[0042] As an alternative technical solution of the embodiments of the present disclosure, the receiving task setting operation determines a data detection task according to the task setting operation, which may specifically include: displaying a plurality of preset data tags, receiving a tag selection operation for the plurality of preset data tags, and determining a target data tag according to the tag selection operation; determining a task identifier, and determining a data detection task according to the task identifier and the target data tag. Further, determining the task identifier may include: generating a task identifier according to a preset identifier generation rule, or receiving an identifier setting operation and generating a task identifier according to the set information, etc. Among them, the preset data tags may be set according to a tag setting operation, or may be extracted from the operation data of the detection scenario according to a preset tag extraction rule. In short, the preset data tags are associated with the data detection task. Specifically, the preset data tags are associated with the data detection object or the data detection index. The data detection index is used to indicate the data detection content and / or scope, etc.
[0043] As described above, the target data tag can be used to indicate the data to be detected. Different target data tags can be used to characterize data in different dimensions. In other words, the target data tag can correspond to a preset data dimension and be used to indicate the data of the preset data dimension. In practical applications, the target data tag can specifically be used to characterize data with different contents or meanings. Taking the detection of access data as an example, exemplarily, the target data tag may include at least one of data such as execution object data, operated object data, access path data, access object data, interaction mode data, and response status data. More specifically, the target data tag may include a data identifier of one or more types of data such as the interface name, interface error code, and caller information for characterizing the program data interface called.
[0044] In some embodiments of the present disclosure, optionally, determining a plurality of target data tags corresponding to the data detection request includes: obtaining a plurality of target data tags preset corresponding to the data detection request. Specifically, a task identifier of a data detection task corresponding to the data detection request may be determined, and a plurality of target data tags corresponding to the data detection request are determined according to the task identifier and the correspondence between the task identifier and the data tag preset in advance. By adopting this technical solution, the pre-configuration of the target data identifier can be supported, and a plurality of target data tags corresponding to the data detection request can be quickly determined when needed, improving the determination efficiency of the target data tag.
[0045] In some embodiments of the present disclosure, optionally, determining a plurality of target data tags corresponding to the data detection request includes: receiving a tag setting operation, and determining a plurality of target data tags corresponding to the data detection request according to the tag setting operation. As mentioned above, the tag setting operation is used to configure data tags. The tag setting operation includes a tag input operation and / or a tag selection operation, etc. By adopting this technical solution, flexible setting of data tags can be realized to meet different data detection requirements.
[0046] It should be noted that the tag setting operation can be executed before the data detection request is initiated, or after the data detection request is initiated. Exemplarily, in response to the data detection request, tag configuration information can be displayed, an information configuration operation for the tag configuration information can be received, and a plurality of target data tags corresponding to the data detection request can be determined according to the information configuration operation. It can also be to display a data detection interface, where a plurality of candidate data tags are displayed in the data detection interface; a tag selection operation for the candidate data tags is received, and a plurality of target data tags corresponding to the data detection request are determined according to the candidate data tags and the tag selection operation. Among them, the candidate data tags can be pre-set optional identification data corresponding to data of a preset type.
[0047] S120. Determine a plurality of arrays corresponding to the first time period according to the plurality of target data tags, and respectively determine a first detection result of each array within the first time period.
[0048] In the embodiments of the present disclosure, the array can be a set of data including attribute data of a plurality of the target data tags. One array can be used to describe a service scenario or a type of event, etc. Different arrays can be used to describe different service scenarios or different events, etc. The attribute data of the plurality of target data tags can be pre-set attribute data for characterizing preset data meanings, or attribute data extracted from application scenario data within a preset time period (that is, actually occurred attribute data). The first time period can be understood as a preset data detection cycle, which is used to define the time range of data detection. The first detection result can be understood as a phased detection conclusion obtained by analyzing the data corresponding to the array in a preset manner, and is used to preliminarily judge the state of the service scenario or different events represented by the array, including an execution state and / or a response state, etc.
[0049] As an alternative implementation of the embodiments of the present disclosure, determining a plurality of arrays corresponding to the first time period according to the plurality of target data tags may specifically include: obtaining a plurality of attribute data corresponding to each of the target data tags, and constructing a plurality of arrays according to the plurality of target data tags and their corresponding plurality of attribute data, that is, the plurality of arrays corresponding to the first time period. Specifically, the plurality of target data tags and their corresponding plurality of attribute data may be combined to obtain the plurality of arrays corresponding to the first time period. By adopting this technical solution, various application scenarios can be characterized by data combinations (arrays) including the attribute data of a plurality of target data tags, thereby realizing targeted analysis of different application scenarios or events.
[0050] Optionally, the obtaining a plurality of attribute data corresponding to each of the target data tags includes: obtaining a plurality of preset attribute data corresponding to each of the target data tags; and / or extracting attribute data corresponding to the target data tags from the service scenario data (business scenario data) within the first time period. Constructing arrays using the preset attribute data can make the generated arrays more comprehensively cover various service conditions, thereby improving the comprehensiveness of data detection. Constructing arrays using the attribute data extracted from the service scenario data within the first time period can make the arrays more suitable for this application scenario, and can reduce the analysis of redundant arrays, saving the computing amount. More importantly, it is especially applicable to scenarios where the scenes corresponding to the target data tags cannot be predicted, improving the flexibility and scenario adaptability of array construction.
[0051] As an alternative implementation of the embodiments of the present disclosure, determining the first detection result of each of the arrays within the first time period may include: for a single array, using the sliding window technique to divide the first time period into a plurality of overlapping or non-overlapping windows; calculating the statistical features (such as mean, variance, trend, etc.) of the array within each window. According to the statistical features within the window, comprehensively determine the first detection result of the array within the first time period. By adopting this technical solution, the time dynamic changes of the data can be captured, which is applicable to time series data, and by adjusting the window size and step length, it can flexibly adapt to the requirements of different scenarios.
[0052] As another alternative implementation of the embodiments of the present disclosure, determining the first detection result of each of the arrays within the first time period may include: for a single array, performing clustering analysis on the feature data corresponding to the array within the first time period, and determining the first detection result according to the clustering result. By adopting this technical solution, potential patterns and outliers in the data can be discovered. It is especially applicable to the analysis of high-dimensional arrays or complex data structures.
[0053] As another alternative implementation of the embodiments of the present disclosure, determining the first detection result of each of the arrays in the first time period may include: for a single array, defining a set of rules (such as threshold rules, logical rules, etc.) to detect the characteristic data corresponding to the array; determining the first detection result of the array in the first time period according to the rule matching result. In this technical solution, the rule definition is flexible and can be quickly adjusted according to business requirements, and is applicable to scenarios that require clear rule constraints.
[0054] As another alternative implementation of the embodiments of the present disclosure, determining the first detection result of each of the arrays in the first time period may include: for a single array, training a machine learning model (such as a regression model, a classification model, etc.) to predict or classify the characteristic data corresponding to the array; determining the first detection result of the array in the first time period according to the model output. By adopting this technical solution, complex non-linear relationships can be processed, it is applicable to high-precision detection requirements, and different data characteristics can be adapted through model training.
[0055] As yet another alternative implementation of the embodiments of the present disclosure, determining the first detection result of each of the arrays in the first time period may include: for a single array, calculating the quantiles (such as 25%, 50%, 75% quantiles) of the characteristic data of the array in the first time period; determining the distribution characteristics of the array in the first time period according to the quantile statistical result. By adopting this technical solution, the overall distribution of the characteristic data of the array can be reflected, and it is applicable to non-normal distribution data.
[0056] S130. In response to an event that the first detection result meets a first preset condition, determine a second time period corresponding to the array, and determine the array detection result of the array according to the preset type data of the array in the first time period and the second time period.
[0057] In the embodiments of the present disclosure, the first preset condition may be a condition preset for determining whether the first detection result triggers subsequent operations. Exemplarily, the first preset condition may be a threshold range corresponding to the first detection result or other detection rules, etc. The preset type data may be understood as data preset corresponding to the target type. Specifically, the preset type data may be, in the process of data processing or analysis, data types or data attributes predefined according to specific requirements or objectives. These data types are usually closely related to business scenarios, analysis objectives or technical requirements, and are used to guide the processes of data extraction, processing and analysis. Exemplarily, the preset type data may include detection result data and / or time data. Specifically, the time data may be time data for recording the occurrence time of the array. It can be understood that the first preset condition and the preset type data can be set according to actual needs, and no specific limitation is made here.
[0058] Optionally, the second time period is different from the first time period, and the second time period may be a time period preset for comparative analysis with the first time period. In other words, the second time period is a time range associated with the first time period, and is usually used for further analyzing or verifying the first detection result. Specifically, the time length of the second time period may be greater than or equal to the time length of the first time period. At least some time points in the second time period are earlier than the start time point of the first time period. In one embodiment, the time length of the second time period may be the same as the time length of the first time period, and the end time of the second time period is the same as the start time of the first time period.
[0059] In some embodiments of the present disclosure, optionally, determining the second time period corresponding to the array may specifically include: determining time reference information according to the first time period, and determining the second time period according to the time reference information. Wherein, the time reference information includes at least one of a start time, an end time and a time length. Exemplarily, a time period with a preset duration before and adjacent to the first time period may be determined as the second time period. For example, if the first time period represents the current detection cycle, then the second time period may be the previous one or several data detection cycles of the current detection cycle. By adopting this technical solution, the relevance between the second time period and the first time period can be ensured, thereby improving the accuracy and reliability of the result obtained by detecting the array.
[0060] As an alternative technical solution of the embodiments of the present disclosure, when the preset type of data includes detection result data, the determining of the array detection result of the array according to the preset type of data of the array in the first time period and the second time period may specifically include: obtaining a second detection result of the array in the first time period, and determining the array detection result of the array according to the difference data between the first detection result and the second detection result. By adopting this technical solution, the difference data of the detection results of the first time period relative to the second time period can be effectively identified, and the first detection result of the second time period is used as a dynamic reference basis, so that the detection result of the array is more in line with the scene change and more accurate and reliable.
[0061] In the embodiments of the present disclosure, when the preset type of data includes detection result data, the specific implementation manner of obtaining the second detection result of the array in the first time period may be the same as the manner of determining the first detection result of the first time period. That is, a plurality of arrays corresponding to the second time period may be determined according to a plurality of the target data tags, and the second detection result of each of the arrays in the second time period may be determined respectively. The specific implementation process may refer to the manner of determining the first detection result of the first time period, which will not be elaborated here.
[0062] Optionally, the determining of the array detection result of the array according to the difference data between the first detection result and the second detection result may specifically include: determining the difference data between the first detection result and the second detection result, and determining the array detection result of the array according to the data volume corresponding to the difference data. Further, it may be to determine the array detection result of the array according to the data volume corresponding to the difference data and a preset data volume threshold; or, to determine the array detection result of the array according to the offset of the data volume corresponding to the difference data relative to the data volume of the first detection result; or, to determine the array detection result of the array according to the offset of the data volume corresponding to the difference data relative to the data volume of the second detection result, etc.
[0063] In an alternative example, the first detection result may be a first detection value, and the second detection result may be a second detection value. Specifically, the difference between the first detection value and the second detection value may be calculated to obtain a detection value difference; the array detection result of the array may be determined according to the detection value difference and a preset difference threshold, or the array detection result of the array may be determined according to the ratio of the detection value difference to the first detection value or the second detection value, etc.
[0064] As another alternative technical solution of the embodiments of the present disclosure, when the preset type of data includes time data and the time data is used to record the occurrence time of the array, the determining the array detection result of the array according to the preset type of data of the array in the first time period and the second time period may specifically include: determining a first occurrence time of the array in the first time period and a second occurrence time corresponding to the array in the second time period, and determining the array detection result of the array according to the first occurrence time and the second occurrence time. Wherein, the second occurrence time is the latest occurrence time of the array within the preset time period before and including the second time period. Specifically, the time difference between the first occurrence time and the second occurrence time may be determined, and the array detection result of the array may be determined according to the time difference and a preset difference threshold. By adopting this technical solution, it can be identified whether the array has occurred within the preset time period, that is, whether the array is a newly emerged array in the first time period, so as to quickly identify the array newly added relative to the second time period, make the detection of the array more specific, and locate the array detection result of the array more accurately.
[0065] As an optional technical solution of the embodiments of the present disclosure, the array detection result may specifically be used to indicate whether the array is in an abnormal state. Further, after determining the array detection result of the array according to the preset type of data of the array in the first time period and the second time period, it may further include: in response to an event that the array detection result includes that the array is in an abnormal state, generating a status prompt message corresponding to the array, and displaying the status prompt message. Exemplarily, the status prompt message may at least be used to prompt that the characteristic data of the array is in an abnormal state. Further, the status prompt message may also be used to prompt the abnormal type of the array and / or the data. Exemplarily, the status prompt message may include, but is not limited to, one or more types of prompt messages such as a sound prompt message, an image prompt message, a video prompt message, and a text prompt message. Correspondingly, displaying the status prompt message may include: playing the status prompt message; or, displaying the status prompt message. By adopting this technical solution, it is possible to prompt in a timely manner when an abnormal array is detected, so as to quickly respond to the abnormality corresponding to the array.
[0066] The technical solution of the embodiment of the present disclosure, by responding to a data detection request, determines a plurality of target data tags corresponding to the data detection request. Since the target data tags are used to indicate the data to be detected, it can accurately locate the content to be detected, avoid detecting unnecessary data, improve the pertinence and efficiency of data detection, and reduce the waste of detection resources; by determining a plurality of arrays corresponding to the first time period according to the plurality of target data tags, and respectively determining the first detection results of each of the arrays within the first time period, detection is carried out from the perspective of multiple arrays, refining the detection dimension. It is possible to analyze data characteristics in different dimensions, making the detection results more comprehensive and accurate; by responding to an event that the first detection result satisfies a first preset condition, determining a second time period corresponding to the array, and determining the array detection result of the array according to the preset type data of the array within the first time period and the second time period, it is possible to dynamically decide whether to perform more in-depth detection according to the situation of the first detection result. When the first detection result shows that the data is abnormal or has potential problems (satisfies the first preset condition), then perform a second detection, avoiding the resource consumption and increased time cost caused by performing in-depth detection on all data, while being able to perform in-depth analysis on key data, improving the flexibility and effectiveness of detection. The combination of the preset type data of the first time period and the second time period can more comprehensively discover problems in the data, reduce the probability of misjudgment and missed judgment, thereby improving the accuracy and reliability of the array detection result.
[0067] Figure 2 It is a schematic flowchart of another data detection method provided by the embodiment of the present disclosure. The technical solution of this embodiment further refines the construction method of the array on the basis of the above embodiment. Optionally, the determining a plurality of arrays corresponding to the first time period according to the plurality of target data tags includes: obtaining the attribute data of the target data tags within the first time period, and constructing a plurality of arrays corresponding to the first time period according to the plurality of target data tags and their attribute data. For the specific implementation method, reference may be made to the description of this embodiment. Among them, the technical features that are the same as or similar to those of the foregoing embodiment will not be described in detail again. As Figure 2 shown, the method of this embodiment may specifically include:
[0068] S210. Respond to a data detection request, and determine a plurality of target data tags corresponding to the data detection request; wherein, the target data tags are used to indicate the data to be detected.
[0069] S220. Obtain the attribute data of the target data label within the first time period, construct multiple arrays corresponding to the first time period according to the multiple target data labels and their attribute data, and respectively determine the first detection result of each array within the first time period.
[0070] In the embodiments of the present disclosure, the attribute data of the target data label can be used to determine the characteristic information of the data corresponding to the target data label. The characteristic information may include at least one of information such as meaning, significance, and status. Different attribute data of the same target data label can be used to characterize the meaning of the data corresponding to the target data label. For example, if the attribute data of the target data label is an error code, the attribute value corresponding to the error code can be used to indicate one or more of information such as error type, error cause, and error consequence.
[0071] Optionally, obtaining the attribute data of the target data label within the first time period includes: obtaining the attribute data corresponding to the target data label from the first data within the first time period. Wherein, the first data includes the second data to be detected in the data detection task. For example, the first data may be data related to a specified object or data including a preset string, etc.
[0072] As an optional implementation manner of the embodiments of the present disclosure, the constructing multiple arrays according to the multiple target data labels and their attribute data may specifically include: for each target data label, constructing an attribute set corresponding to the target data label according to the attribute data of the target data label within the first time period; performing a Cartesian product operation on the attribute sets corresponding to the multiple target data labels to obtain multiple arrays corresponding to the first time period. By adopting this technical solution, through the Cartesian product operation between the attribute sets, the elements of different sets can be combined into ordered arrays, realizing the operation of all possible element combinations of multiple attribute sets. The result is a new set containing all ordered pairs or row combinations, which can not only combine the real-scene data of the first time period but also cover different scenarios, enriching the data detection dimension and realizing the refined division of different data detection scenarios.
[0073] For example, the target data labels include data label 1, data label 2, data label 3,..., data label n. The attribute data of data label 1 has 2, the attribute data of data label 2 has 3, the attribute data of data label 3 has 4,..., and the attribute data of data label n has m. At this time, there are 2 * 3 * 4 *... * m arrays to cover different business scenarios.
[0074] For ease of understanding, taking 3 target data tags as an example for more specific illustration, the target data tags include data tag 1, data tag 2, and data tag 3, representing 3 business dimensions. At this time, the total number of groups of the constructed array is the Cartesian product of the number of attribute data of the data tags. For example, if there are 2 pieces of attribute data for data tag 1, 3 pieces of attribute data for data tag 2, and 4 pieces of attribute data for data tag 3, then there are 2 * 3 * 4 = 24 groups of data at this time, that is, 24 arrays. For example, if data tag 1, data tag 2, and data tag 3 are account number, channel value, and error code respectively, the attribute values of the account number include A1 and A2, the attribute values of the channel value include B1, B2, and B3, and the attribute values of the error code include C1, C2, C3, and C4. Then the 24 arrays generated include: [account number = A1, channel value = B1, error code = C1], [account number = A1, channel value = B1, error code = C2], [account number = A1, channel value = B1, error code = C3], [account number = A1, channel value = B1, error code = C4], [account number = A1, channel value = B2, error code = C1], [account number = A1, channel value = B2, error code = C2], [account number = A1, channel value = B2, error code = C3], [account number = A1, channel value = B2, error code = C4], [account number = A1, channel value = B3, error code = C1], [account number = A1, channel value = B3, error code = C2], [account number = A1, channel value = B3, error code = C3], [account number = A1, channel value = B3, error code = C4], [account number = A2, channel value = B1, error code = C1], [account number = A2, channel value = B1, error code = C2], [account number = A2, channel value = B1, error code = C3], [account number = A2, channel value = B1, error code = C4], [account number = A2, channel value = B2, error code = C1], [account number = A2, channel value = B2, error code = C2], [account number = A2, channel value = B2, error code = C3], [account number = A2, channel value = B2, error code = C4], [account number = A2, channel value = B3, error code = C1], [account number = A2, channel value = B3, error code = C2], [account number = A2, channel value = B3, error code = C3], and, [account number = A2, channel value = B3, error code = C4].
[0075] S230. In response to an event where the first detection result meets the first preset condition, determine a second time period corresponding to the array, and determine the array detection result of the array according to the preset type data of the array in the first time period and the second time period.
[0076] The technical solution of the embodiment of the present disclosure obtains the attribute data of the target data tag within the first time period, so that the collected data closely surrounds the actual requirements of the first time period, excludes the interference of data in other irrelevant time periods, and greatly improves the data processing efficiency. Compared with obtaining a large amount of data without discrimination and then filtering, this method significantly reduces the amount of data processing, reduces the consumption of system resources, and improves the system operation performance. An array is constructed according to multiple target data tags and their attribute data, realizing the structured organization of data. By integrating related data into the array, the relationships between different data tags and their attributes are clearly presented, which can more accurately describe the events occurring in the actual application scenario and provide great convenience for subsequent data processing and analysis.
[0077] Figure 3 It is a schematic flowchart of another data detection method provided by the embodiment of the present disclosure. On the basis of the above embodiment, the technical solution of this embodiment further refines the method of detecting the array through the data within a single time period. Optionally, the first time period includes a first sub-time period and at least one second sub-time period; the step of respectively determining the first detection result of each array within the first time period includes: for a single array, obtaining the first processing volume corresponding to the array within the first sub-time period of the first time period and the second processing volume corresponding to the array within at least one second sub-time period of the first time period, and determining the first detection result of the array within the first time period according to the first processing volume and the second processing volume. The specific implementation can refer to the description of this embodiment. Among them, the technical features that are the same as or similar to the foregoing embodiments will not be described herein again. As Figure 3 shown, the method of this embodiment may specifically include:
[0078] S310. In response to a data detection request, determine a plurality of target data tags corresponding to the data detection request; wherein, the target data tags are used to indicate the data to be detected.
[0079] S320. Determine a plurality of arrays corresponding to the first time period according to the plurality of target data tags, wherein the first time period includes a first sub-time period and at least one second sub-time period.
[0080] In the embodiment of the present disclosure, the first time period can be further divided into multiple sub-time periods, which can be divided into a first sub-time period and a second sub-time period according to their uses. The number of second sub-time periods can be one or more. The second sub-time period can be a time period with a preset length located between the first sub-time periods in the first time period.
[0081] Optionally, the second sub - time period may include data that is in the same time period as the first time period. Here, the same time period may be a time period with preset time characteristics. Exemplarily, the first time period may be the previous 3 minutes, previous 5 minutes, or previous 20 minutes before the current moment. Taking the current moment as 18:30 as an example, a time period can be determined accordingly. For example, the time period from 18:20 to 18:30. The same time periods in the previous 48 hours and previous 24 hours can be the time periods from 18:20 to 18:30 in the previous 48 hours and previous 24 hours.
[0082] By dividing the first time period into a first sub - time period and at least one second sub - time period, segmented analysis of the first time period can be achieved. It can not only accurately capture the effective data characteristics of the first time period, but also reduce the amount of data processing and improve data processing efficiency.
[0083] S330. For a single said array, obtain a first processing volume corresponding to the array within the first sub - time period of the first time period and a second processing volume corresponding to the array within at least one second sub - time period of the first time period.
[0084] In the embodiments of the present disclosure, the processing volume corresponding to the array can be used to indicate the number of times or frequency of the appearance of the array. Exemplarily, the processing volume corresponding to the array may include the Queries Per Second (QPS) corresponding to the array. The Queries Per Second is a key indicator for evaluating the performance of a service system or business system, indicating the number of query requests that the server or database can process per second. This indicator directly reflects the throughput capacity and response speed of the system.
[0085] As an optional technical solution of the embodiments of the present disclosure, obtaining the first processing volume corresponding to the array within the first sub - time period of the first time period may be obtaining the first processing volumes corresponding to the array at multiple time points (moments) within the first sub - time period of the first time period. Similarly, obtaining the second processing volume corresponding to the array within at least one second sub - time period of the first time period includes: for each of the second sub - time periods within the first time period, obtaining the second processing volumes corresponding to the array at multiple time points (moments) within the first sub - time period of the first time period. Among them, the processing volume corresponding to the array at each moment can be the sum of the processing volumes corresponding to the array obtained within the time interval between this moment and the previous moment. The advantage of adopting this technical solution is that multiple processing volumes corresponding to the array can be obtained, which supports more flexible processing and multi - dimensional processing of the processing volume, and can support more complex and refined data detection methods.
[0086] S340. Determine the first detection result of the array within the first time period according to the first processing volume and the second processing volume.
[0087] Specifically, the determining the first detection result of the array within the first time period according to the first processing volume and the second processing volume may include: determining a first eigenvalue according to the first processing volume in the first sub-time period, and for a single second sub-time period, determining a second eigenvalue according to the second processing volume in the second sub-time period; determining the first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue in the second sub-time period. Wherein, the eigenvalue may include at least one of eigenvalues such as the sum of the processing volumes at multiple moments, the processing volume sequence arranged in time, the average processing volume, and the change amount of the processing volume. By adopting this technical solution, the accuracy and reliability of the first detection result can be improved by combining the eigenvalues of multiple sub-time periods and automatically adapting to the processing volume fluctuation law.
[0088] Exemplarily, in the case where the first eigenvalue includes the sum of the processing volumes at multiple moments or the processing volume sequence arranged in time, in response to an event that the first processing volume is greater than or equal to a first threshold and the second processing volume is less than or equal to a second processing volume threshold, determine a preset first risk value as the first detection result of the array within the first time period; wherein, the first processing volume threshold is greater than the second processing volume threshold; the first risk value is at least used to indicate that the array has a risk. Optionally, in response to an event that the first processing volume is less than the first threshold or the second processing volume is greater than the second processing volume threshold, determine a preset second risk value as the first detection result of the array within the first time period; wherein, the first processing volume threshold is greater than the second processing volume threshold; the first risk value is at least used to indicate that the array has a risk. The risk level corresponding to the second risk value is lower than that of the first risk value. The second risk value can be used to indicate that the array has no risk.
[0089] In some embodiments of the present disclosure, the first eigenvalue packet may include a first average processing volume, and the second eigenvalue may include a second average processing volume. On this basis, determining the first detection result of the array in the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: in response to an event that the second average processing volumes of the second sub-time period are all greater than or equal to a first processing volume threshold, determining a second processing volume threshold according to the second average processing volume and a first preset multiple, and determining the first detection result of the array in the first time period according to the first average processing volume and the second processing volume threshold. Wherein, the first processing volume threshold can be set according to actual requirements, and its specific data is not limited herein. The second processing volume threshold may be higher than the first processing volume threshold. By adopting this technical solution, it can be used to identify an array in which the data in the second time period is all less than the threshold, the data in the first sub-time period of the first time period exceeds the threshold, and the data exceeds a first preset multiple of the maximum value within the deviation time period. In practical applications, it can identify an array with a relatively low processing volume (the threshold is within an acceptable range), but there is a risk of failure that may be caused by exceeding the determined second processing volume threshold.
[0090] Optionally, determining the second processing volume threshold according to the second average processing volume and the first preset multiple specifically includes: multiplying the second average processing volume by the first preset multiple to obtain the second processing volume threshold; or multiplying the second average processing volume, the first preset multiple, and an adjustable coefficient corresponding to the first preset multiple to obtain the second processing volume threshold. Further, in response to a coefficient adjustment operation for the adjustable coefficient corresponding to the first preset multiple, the second processing volume threshold is updated. By adopting this technical solution, flexible adjustment of the second processing volume threshold can be achieved.
[0091] Optionally, determining the first detection result of the array in the first time period according to the first average processing volume and the second processing volume threshold may specifically include: in response to an event that the first average processing volume is greater than or equal to the second risk threshold, determining the first average processing volume as the first detection result of the array in the first time period. At this time, the first average processing volume is used to indicate that the array has an abnormal risk.
[0092] Optionally, determining the first detection result of the array in the first time period according to the first average processing volume and the second processing volume threshold may specifically include: in response to an event that the first average value is less than the second risk threshold, determining preset information as the first detection result of the array in the first time period. At this time, the preset information can be used to indicate that the array has no abnormal risk and is in a normal state.
[0093] In some embodiments of the present disclosure, when the first eigenvalue may include a first average processing volume and the second eigenvalue may include a second average processing volume, determining a first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period may include: in response to an event that the first average processing volume and the second average processing volume meet a preset condition, determining the first detection result of the array within the first time period according to the first average processing volume; wherein, the preset condition includes at least one of that the first average processing volume of the first sub-time period is greater than the second average processing volume of the second sub-time period adjacent to the first sub-time period, the first average processing volume is greater than a third processing volume threshold, the second average processing volume of the second sub-time period is less than the third processing volume threshold, and the first average processing volume is greater than a second preset multiple of the second average processing volume. By adopting the technical solution, it can be used to identify an array in which the data in the second time period are all less than the threshold, the data in the first sub-time period of the first time period exceed the threshold, the first sub-time period of the first time period shows an upward trend compared with the second sub-time period and its data exceed the data of the second sub-time period by a second preset multiple. In practical applications, sudden increases in error codes within expectations, such as error code mismatches and / or external exceptions, can be found.
[0094] In the embodiments of the present disclosure, the determination method of the second average processing volume may be: according to a preset sliding window, calculate the mean value of the processing volume corresponding to each sliding window within each second sub-time period respectively, and determine the maximum value among the multiple window processing volume mean values as the second average processing volume. Further, before determining the window processing volume corresponding to the second sub-time period, the sequence of the processing volumes at multiple time points within the second sub-time period may also be smoothed, for example, the maximum value and / or the minimum value of the processing volumes at multiple time points within the second sub-time period may be removed.
[0095] In some other embodiments of the present disclosure, the first eigenvalue may include a first variation amount of a first throughput, and the second eigenvalue may include a second average throughput and a second variation amount of the second throughput. On this basis, determining the first detection result of the array in the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: determining an average offset magnification according to the second average throughput of the second throughput, and determining a third variation amount according to the average offset magnification and the second variation amount; in response to an event that the first variation amount of the first throughput is greater than a preset variation amount threshold and greater than the third variation amount, determining the first detection result of the array in the first time period according to the first variation amount. By adopting the technical solution of the present disclosure, it can be used to identify an array whose data change rate in the first sub-time period of the first time period is greater than a preset change rate and greater than the maximum data change rate corresponding to the second sub-time period. In practical applications, it can quickly and effectively identify the abnormal progressive growth caused by business volume increase and peak traffic.
[0096] Optionally, determining the average offset magnification according to the second average throughput of the second throughput and according to the average offset magnification specifically includes: calculating the mean value of the throughput of each second sub-time period respectively, and further determining the average offset magnification according to the mean values of the throughput of multiple second sub-time periods. For example, it may be that the mean values of the throughput of multiple second sub-time periods are summed and then multiplied by a preset multiple to obtain the average offset magnification.
[0097] In the embodiments of the present disclosure, a preset algorithm may be used to respectively determine a first slope corresponding to the throughput of the first sub-time period and a second slope corresponding to the throughput of the second sub-time period. Wherein, the preset algorithm includes a linear regression algorithm and the like. The slope is used to characterize the change of the throughput within its sub-time period. That is, the first slope is used to characterize the variation amount of the throughput in the first sub-time period, and the second slope is used to characterize the variation amount of the throughput in the first sub-time period.
[0098] Optionally, determining the third variation amount according to the average offset magnification and the second variation amount includes: multiplying the average offset magnification and the second variation amount to obtain the third variation amount.
[0099] S350. In response to an event that the first detection result meets a first preset condition, determine a second time period corresponding to the array, and determine the array detection result of the array according to the preset type data of the array in the first time period and the second time period.
[0100] The technical solution of the embodiment of the present disclosure realizes accurate comparison of the processing amounts of a same array in multiple sub - time periods of a first time period by respectively obtaining the first processing amount of a first sub - time period and the second processing amounts of at least one second sub - time period. It can capture the subtle changes in data during the first time period. Compared with relying only on data of a single time period or simple overall data statistics, it can more accurately reflect the data characteristics of the array within the first time period, greatly improving the accuracy and reliability of the array detection result, and providing a solid data basis for subsequent decisions based on the detection result.
[0101] Figure 4 It is a schematic flowchart of an optional example of a data detection method provided by an embodiment of the present disclosure. In this example, taking the anomaly detection of business interface metrics as an example for introduction. As Figure 4 shown, the data detection method may specifically include: setting business interface metrics (i.e., the task identifier of the data detection task), determining multiple data tags corresponding to the business interface metrics, such as interface identifier, error code, account information, and service type, etc. Through the combined calculation of the above data tags, refined monitoring data covering each business scenario dimension is obtained. Then, for the processed data, detection algorithms corresponding to various data anomaly types are used to calculate whether there is a risk in the current period. When there is a risk, the risk is recorded and compared with the historical risks of the same type within the period (such as 7 days). When the risk value in the current period deviates from the historical risk within the period, it is determined that there is a data anomaly, and a data anomaly reminder is sent.
[0102] Specifically, obtain the business interface metrics to be detected and the data tags corresponding to multiple business dimensions to be queried. For example, for metric A {data tag 1 = attribute data 1, data tag 2 = attribute data 2, data tag 3 = attribute data 3,..., data tag n = attribute data n}. Query the business data for the previous 10 minutes, as well as the same time periods (these 10 minutes) of the previous 1 day and the previous 2 days according to the above metrics and business dimensions, so as to facilitate the comparison of the data of the previous 1 day and the previous 2 days in subsequent algorithms. Group the queried data according to the attribute data of the data tags corresponding to the business dimensions, that is, the multi-tuple [data tag 1, data tag 2, data tag 3,..., data tag n] describes a set of dimension information, and the total number of groups is the Cartesian product of the number of attribute data of the data tags. For example, if there are 2 attribute data for data tag 1, 3 attribute data for data tag 2, 4 attribute data for data tag 3,..., and m attribute data for data tag n, then there are 2 * 3 * 4 *... * m arrays at this time, so as to cover different business scenarios. Use a preset detection algorithm to detect each array and obtain a risk value of floating-point type. Multiple preset detection algorithms can correspond to multiple risk values. If there is a risk value greater than the preset value (such as 0), it is determined that there is a risk for this array, and this risk record (including the array, the latest occurrence time of this array, and the risk value) is persistently saved. Compare this risk record with the historical risks of the same dimension within the period. If the current risk value deviates from the historical risk value, it is considered that this risk is abnormal and an anomaly report is made.
[0103] When detecting the risk situation of each array, a detection algorithm is required. Here, four detection algorithms are taken as examples for introduction to cover different types of anomalies, including new anomaly, threshold anomaly, sudden increase anomaly, and trend anomaly. The following gives examples of these four types of anomalies and their corresponding detection algorithms respectively:
[0104] When identifying each type of anomaly, it is necessary to first obtain the query rate per second of the first sub-period within the first time period for each of the arrays, and the query rate per second of multiple second sub-periods within the first time period. Specifically, multiple second sub-periods within the first time period (current period) can include at least some time periods such as the same time periods of the previous 48 hours and the previous 24 hours, and the previous 10 minutes, etc. The first sub-period can be at least one of time periods such as within the last 3 minutes, within the last 5 minutes, and within the last 10 minutes, etc. Exemplarily, taking the current time as 18:30 as an example, a time period can be determined accordingly. For example, the time period from 18:20 to 18:30. The same time periods of the previous 48 hours and the previous 24 hours can be the time period from 18:20 to 18:30 of the previous 48 hours and the previous 24 hours.
[0105] 1. New exceptions can be used to identify arrays that first appear within a preset time period in multiple arrays, or arrays whose time intervals of appearance exceed the preset time interval. In short, when the exception corresponding to an array first appears within a cycle, it is determined as a new exception type. Specifically, when detecting interface metrics, record the latest time of appearance of each array. When the time interval of appearance of an array exceeds the set interval (such as 7 days), it is identified as a new exception. Specifically, count the number of elements with a value of 0 in a floating-point slice array. Exemplarily, if the data (queries per second rate) of the same time period in the first 48 hours and the first 24 hours of the first time period (current cycle) of this array, and the queries per second rate from the 10th to the 3rd minute before are all 0, and the queries per second rate of this array is not all 0 within the last 3 minutes, at this time, the risk value corresponding to this array is set to 1, indicating that this array has a risk of belonging to a new exception. Otherwise, the risk value corresponding to this array is set to 0, indicating that the risk of a new exception is low, or in other words, it does not belong to a new exception. Further, in the case where an array has a risk of a new exception, it can be determined whether the array actually has a new exception according to whether the time interval of appearance of the array is greater than the preset time interval. If so, it is determined that the array actually has a new exception; otherwise, it is determined that there is no new exception. Optionally, it can be determined whether the time interval of appearance of the array is greater than the preset time interval according to the latest appearance time and the previous appearance time corresponding to the array; or, according to whether the risk value of the array in the second time period is 0 or 1 to determine whether the time interval of appearance of the array is greater than the preset time interval. This detection method can discover newly added error exceptions when there are upstream business or external channel accesses or other changes from scratch.
[0106] 2. Threshold anomaly, which can be used to identify an array where the data in the second time period is all less than the threshold, the data in the first sub-time period of the first time period exceeds the threshold, and the data exceeds the first preset multiple of the maximum value within the deviation time period. Specifically, the first query rate average can be calculated based on the per-second query rates at multiple time points in the first sub-time period. Then, according to the preset sliding window, the window query rate average corresponding to each sliding window in each second sub-time period is calculated respectively, and the maximum value among the multiple window query rate averages is determined. Before determining the window query rate corresponding to the second sub-time period, the sequence of per-second query rates at multiple time points in the second sub-time period can also be smoothed. For example, the maximum value and / or minimum value in the per-second query rates at multiple time points in the second sub-time period can be removed. Exemplarily, the average value of the per-second query rates in the most recent 3 minutes (the first query rate average) can be determined, and the maximum value among the window request rate values in the same time period in the previous 48 hours, the maximum value among the window request rate values in the same time period in the previous 24 hours, and the maximum value among the window request rate values corresponding to the previous 5 minutes in the previous 10 to the previous 3 minutes are determined respectively. Then, the maximum value among these 3 maximum values is determined as the historical maximum average. If the historical maximum average is less than the preset risk threshold, it is determined that there is no risk of threshold anomaly occurring. If the historical maximum average is greater than or equal to the preset risk threshold, at this time, the second risk value can be determined according to the historical maximum average, the first preset multiple, and the adjustment coefficient corresponding to the first preset multiple. The first preset multiple can be set to a value greater than 1, such as 10 times. If the query rate average in the most recent 3 minutes is greater than or equal to the second risk value, it is determined that there is a risk of threshold anomaly occurring in this array. At this time, the risk value corresponding to this array can be set to the first query rate average, that is, the query rate average in the most recent 3 minutes. Further, it can be determined whether threshold anomaly has occurred in this array by comparing the difference data of the query rate averages in the most recent 3 minutes in the first time period and the second time period. This detection method can identify anomalies that may cause failures when the daily traffic is low (the threshold is within the acceptable range of the business) and exceeds the normal range.
[0107] 3. Sudden increase anomaly is used to identify an array where the data in the second time period are all less than a threshold, the data in the first sub - time period of the first time period exceed the threshold, the first sub - time period of the first time period shows an upward trend compared to the second sub - time period and its data exceed the second preset multiple of the data in the second sub - time period. In short, when the sudden increase in the abnormal query rate per second of a certain business dimension significantly deviates from the normal range within a cycle, it can be determined that there is a risk of sudden increase anomaly. The risk point of the abnormal increase in data can be accurately judged through the comparison of the means of the recent 3 minutes and 5 minutes, the determination of the risk threshold, and the detection of the anomaly multiple of the maximum mean value in the historical sliding window, and the corresponding risk value is returned. Specifically, the first query rate mean can be calculated based on the query rates per second at multiple time points in the first sub - time period. Then, according to the preset sliding window, the window query rate means corresponding to each sliding window in each second sub - time period are calculated respectively, and the maximum value among the multiple window query rate means is determined. Before determining the window query rate corresponding to the second sub - time period, the sequence of the query rates per second at multiple time points in the second sub - time period can also be smoothed, for example, the maximum value and / or the minimum value in the query rates per second at multiple time points in the second sub - time period can be removed. Exemplarily, the mean of the query rates per second in the recent 3 minutes (the first query rate mean) and the mean of the query rates per second in the recent 5 minutes can be determined, and the maximum values of the window request rate values in the same time period in the previous 48 hours, the maximum values of the window request rate values in the same time period in the previous 24 hours, and the maximum value of the window request rate value corresponding to the previous 5 minutes in the previous 10 to the previous 3 minutes are determined respectively. If the maximum values of the 3 window request rate values corresponding to these 3 second sub - time periods are all less than the preset risk threshold, the mean of the query rates per second in the recent 3 minutes is greater than the mean of the query rates per second in the recent 5 minutes, the mean of the query rates per second in the recent 3 minutes is greater than or equal to the preset risk threshold, and the mean of the query rates per second in the recent 3 minutes is greater than or equal to the second preset multiple of the maximum value of the window request rate value in each second sub - time period, it is determined that there is a risk of sudden increase anomaly in this array. At this time, the risk value corresponding to this array can be set to the first query rate mean, that is, the query rate mean in the recent 3 minutes. Further, it can be determined whether this array has a sudden increase anomaly by comparing the difference data of the query rate means in the recent 3 minutes in the first time period and the second time period. This detection method can discover the sudden increase problem of the expected error codes, such as error code mismatch and / or external anomaly, etc.
[0108] 4. Trend anomaly can be used to identify an array in which the data change rate of the first sub-period in the first time period is greater than the preset change rate and a number, and greater than the maximum data change rate corresponding to the second sub-period. In short, when the growth trend of the query rate per second of a certain array significantly deviates from the normal range within the period, it can be determined as a trend anomaly. For example, data 10 minutes ago, 24 hours ago, and 48 hours ago can be pulled for fitting. When the growth trend of the data in the most recent 3 minutes deviates from the fitting result, it can be determined that there is a risk of trend anomaly. Specifically, by comparing the deviation between the current trend slope and the historical trend slope, an abnormally rising trend can be accurately captured and a risk value can be returned. Exemplarily, the mean of the query rate per second for each second sub-period and the slope of its trend change curve can be calculated respectively. Then, based on the mean of the query rate per second for multiple second sub-periods, the average deviation multiple can be determined, and the maximum slope among the trend change curves of the query rate per second for multiple second sub-periods, that is, the historical maximum slope, can be determined. Determine the slope of the trend change curve of the query rate per second in the most recent 5 minutes and the slope of the trend change curve of the query rate per second in the most recent 10 minutes. If the slope of the trend change curve of the query rate per second in the most recent 5 minutes is greater than or equal to the preset risk threshold, greater than three times the preset multiple of the historical maximum slope, and greater than the slope of the trend change curve of the query rate per second in the first 5 minutes of the most recent 10 minutes (the second 5 minutes of the most recent first 5 minutes), it is determined that there is a risk of trend anomaly for this array. At this time, the slope of the trend change curve of the query rate per second in the most recent 5 minutes can be determined as the risk value. If the slope of the trend change curve of the query rate per second in the most recent 5 minutes is less than the preset risk threshold, less than or equal to three times the preset multiple of the historical maximum slope, or less than or equal to the slope of the trend change curve of the query rate per second in the first 5 minutes of the most recent 10 minutes (the second 5 minutes of the most recent first 5 minutes), then determine whether the slope of the trend change curve of the query rate per second in the most recent 10 minutes satisfies being greater than or equal to the preset risk threshold and greater than three times the preset multiple of the historical maximum slope. If it is satisfied, it is determined that there is a risk of trend anomaly for this array. At this time, the slope of the trend change curve of the query rate per second in the most recent 10 minutes can be determined as the risk value. Further, by comparing the difference data of the risk values within the first time period and the second time period, it can be determined whether there is a trend anomaly for this array. This detection method can quickly and effectively identify the gradually increasing anomalies caused by business volume expansion and peak traffic.
[0109] The technical solution of the embodiment of the present disclosure can perform risk detection on single data for new addition, threshold, sudden increase, and abnormal trend types, covering common abnormal types, and can solve the problem that it is difficult to detect abnormalities in small traffic scenarios; through the combination of attribute data of data tags, different business scenarios can be automatically covered, solving the problem that it is difficult to cover abnormal detection due to complex business scenarios. Moreover, the step of manually sorting out detailed business scenarios and writing rules one by one to configure conventional alarms is omitted, and the coverage of business scenario detection capabilities can be quickly completed at low cost; a comparison and judgment of historical risks within the fault cycle is made for the array with risks, realizing the identification adaptive to traffic, filtering out the noise risks brought by normal traffic jitters, getting rid of the dependence on traffic size and traffic waveform. Even if the scenario traffic changes after business iteration, risk information will be adaptively accumulated without frequent configuration adjustment. At the same time, only a limited number of abnormalities will be reported within one indicator cycle, thus solving the technical problems of high maintenance cost and a large amount of noise.
[0110] Figure 5 is a schematic structural diagram of a data detection device provided by an embodiment of the present disclosure, as Figure 5 shown. The data detection device includes: a data detection request module 510, a first time period detection module 520, and a detection result determination module 530. Among them, the data detection request module 510 is configured to determine a plurality of target data tags corresponding to the data detection request in response to the data detection request; wherein the target data tags are used to indicate the data to be detected; the first time period detection module 520 is configured to determine a plurality of arrays corresponding to the first time period according to the plurality of target data tags, and respectively determine the first detection results of each of the arrays within the first time period; the detection result determination module 530 is configured to determine a second time period corresponding to the array in response to an event that the first detection result meets a first preset condition, and determine the array detection result of the array according to the preset type data of the array within the first time period and the second time period.
[0111] The technical solution of the embodiment of the present disclosure determines a plurality of target data tags corresponding to the data detection request through the data detection request module 510 in response to the data detection request. Since the target data tags are used to indicate the data to be detected, the content to be detected can be accurately located, the detection of unnecessary data can be avoided, the pertinence and efficiency of data detection are improved, and the waste of detection resources is reduced; the first time period detection module 520 determines a plurality of arrays corresponding to the first time period according to the plurality of target data tags, and respectively determines the first detection results of each of the arrays within the first time period. Detection is carried out from the perspective of multiple arrays, and the detection dimension is refined. The data characteristics of different dimensions can be analyzed, making the detection results more comprehensive and accurate; the detection result determination module 530 determines a second time period corresponding to the array in response to the event that the first detection result meets the first preset condition, and determines the array detection result of the array according to the preset type data of the array in the first time period and the second time period. It is possible to dynamically decide whether to perform more in-depth detection according to the situation of the first detection result. When the first detection result shows that the data has anomalies or potential problems (meeting the first preset condition), a second detection is performed, avoiding resource consumption and increased time costs caused by performing in-depth detection on all data, while being able to perform in-depth analysis on key data, improving the flexibility and effectiveness of detection. The combination of the preset type data of the first time period and the second time period can more comprehensively discover problems in the data, reduce the probability of misjudgment and missed judgment, thereby improving the accuracy and reliability of the array detection result.
[0112] Based on any optional technical solution of the embodiment of the present disclosure, optionally, the first time period detection module 520 is specifically configured to obtain the attribute data of the target data tags within the first time period, and construct a plurality of arrays corresponding to the first time period according to the plurality of target data tags and their attribute data.
[0113] Based on any optional technical solution of the embodiment of the present disclosure, optionally, the first time period detection module 520 includes an attribute set determination unit and an array determination unit. Among them, the attribute set determination unit is configured to construct an attribute set corresponding to each target data tag according to the attribute data of the target data tag within the first time period; the array determination unit is configured to perform a Cartesian product operation on the attribute sets corresponding to the plurality of target data tags to obtain a plurality of arrays corresponding to the first time period.
[0114] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the first time period includes a first sub-time period and at least one second sub-time period. Further, the first time period detection module 520 may specifically be configured to: for a single said array, obtain a first processing amount corresponding to the array in the first sub-time period of the first time period and a second processing amount corresponding to the array in at least one second sub-time period of the first time period, and determine a first detection result of the array in the first time period according to the first processing amount and the second processing amount.
[0115] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the first time period detection module 520 includes an eigenvalue determination unit and an array detection unit. Among them, the eigenvalue determination unit determines a first eigenvalue according to the first processing amount in the first sub-time period, and, for a single said second sub-time period, determines a second eigenvalue according to the second processing amount in the second sub-time period; wherein, the eigenvalue includes at least one of the sum of the processing amounts at multiple moments, the sequence of processing amounts arranged in time, the average processing amount, and the change amount of the processing amount; the array detection unit is configured to determine a first detection result of the array in the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period.
[0116] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the first eigenvalue includes a first average processing amount, the second eigenvalue includes a second average processing amount. Further, the first time period detection module 520 includes an eigenvalue determination unit and an array detection unit. Among them, the, in response to an event that the second average processing amount in the second sub-time period is greater than or equal to the first processing amount threshold, determines a second processing amount threshold according to the second average processing amount and a first preset multiple, and determines a first detection result of the array in the first time period according to the first average processing amount and the second processing amount threshold.
[0117] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the first eigenvalue includes a first average processing volume, and the second eigenvalue includes a second average processing volume; further, the first time period detection module 520 may specifically be configured to: in response to an event that the first average processing volume and the second average processing volume meet a preset condition, determine a first detection result of the array during the first time period according to the first average processing volume; wherein, the preset condition includes at least one of that the first average processing volume in the first sub-time period is greater than the second average processing volume in the second sub-time period adjacent to the first sub-time period, the first average processing volume is greater than a third processing volume threshold, the second average processing volume in the second sub-time period is less than the third processing volume threshold, and the first average processing volume is greater than a second preset multiple of the second average processing volume.
[0118] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the first eigenvalue includes a first change amount of a first processing volume, and the second eigenvalue includes a second average processing volume and a second change amount of the second processing volume; further, the first time period detection module 520 may specifically include: a change amount determination unit and a change amount detection unit. Wherein, the change amount determination unit is configured to determine an average offset magnification according to the second average processing volume of the second processing volume, and determine a third change amount according to the average offset magnification and the second change amount; the change amount detection unit is configured to, in response to an event that the first change amount of the first processing volume is greater than a preset change amount threshold and greater than the third change amount, determine a first detection result of the array during the first time period according to the first change amount.
[0119] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the detection result determination module 530 may specifically be configured to: determine difference data between the first detection result and the second detection result, and determine an array detection result according to the difference data.
[0120] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the array detection result is used to indicate whether the array is in an abnormal state. Further, the data detection device further includes: an abnormal state prompt module. Wherein, the abnormal state prompt module is configured to, after determining the array detection result of the array according to the preset type data of the array during the first time period and the second time period, in response to an event that the array detection result includes that the array is in an abnormal state, generate status prompt information corresponding to the array, and display the status prompt information.
[0121] Based on any optional technical solution of the embodiments of the present disclosure, optionally, the data detection request includes a task execution request for the data detection task; further, the data detection device further includes a detection task setting module. The detection task setting module is configured to receive a task setting operation before responding to the data detection request, and determine a data detection task according to the task setting operation. The data detection task includes an identification setting operation and / or a label setting operation. The identification setting operation is used to set a task identifier corresponding to the data detection task, and the label setting operation is used to set a target data label corresponding to the data detection task.
[0122] The data detection device provided by the embodiments of the present disclosure can execute the data detection method provided by any embodiment of the present disclosure, and has corresponding functional modules and beneficial effects for executing the data detection method.
[0123] It should be noted that the various units and modules included in the above device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the embodiments of the present disclosure.
[0124] Next, refer to Figure 6 , which shows a schematic structural diagram of an electronic device (such as a terminal device or a server) 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), vehicle terminals (such as vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0125] As Figure 6 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which can execute various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0126] Typically, the following devices can be connected to the I / O interface 605: input devices 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and a communication device 609. The communication device 609 can allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices can be implemented or had.
[0127] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.
[0128] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0129] The electronic device provided by the embodiments of the present disclosure and the data detection method provided by the above embodiments belong to the same inventive concept. Technical details not described in detail in the embodiments of the present disclosure can be seen in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0130] The embodiments of the present disclosure provide a computer storage medium, on which a computer program is stored, and when the program is executed by a processor, the data detection method provided by the above embodiments is implemented.
[0131] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0132] According to one or more embodiments of the present disclosure, [Example 1] provides a data detection method, including: in response to a data detection request, determining a plurality of target data tags corresponding to the data detection request; wherein the target data tags are used to indicate the data to be detected; determining a plurality of arrays corresponding to a first time period according to the plurality of target data tags, and respectively determining a first detection result of each array during the first time period; in response to an event that the first detection result meets a first preset condition, determining a second time period corresponding to the array, and determining an array detection result of the array according to preset type data of the array during the first time period and the second time period.
[0133] According to one or more embodiments of the present disclosure, [Example 2] provides the method of Example 1, further including: optionally, the determining a plurality of arrays corresponding to a first time period according to the plurality of target data tags includes: obtaining attribute data of the target data tags during the first time period, and constructing a plurality of arrays corresponding to the first time period according to the plurality of target data tags and their attribute data.
[0134] According to one or more embodiments of the present disclosure, [Example Three] provides the method of Example Two, further comprising: Optionally, constructing a plurality of arrays based on the plurality of target data tags and their attribute data, including: for each of the target data tags, constructing an attribute set corresponding to the target data tag according to the attribute data of the target data tag within the first time period; performing a Cartesian product operation on the attribute sets corresponding to the plurality of target data tags to obtain a plurality of arrays corresponding to the first time period.
[0135] According to one or more embodiments of the present disclosure, [Example Four] provides the method of Example One, further comprising: Optionally, the first time period includes a first sub-time period and at least one second sub-time period; the separately determining a first detection result of each of the arrays within the first time period includes: for a single array, obtaining a first processing amount corresponding to the array within the first sub-time period of the first time period and a second processing amount corresponding to the array within at least one second sub-time period of the first time period, and determining the first detection result of the array within the first time period according to the first processing amount and the second processing amount.
[0136] According to one or more embodiments of the present disclosure, [Example Five] provides the method of Example Four, further comprising: Optionally, the determining the first detection result of the array within the first time period according to the first processing amount and the second processing amount includes: determining a first eigenvalue according to the first processing amount of the first sub-time period, and, for a single second sub-time period, determining a second eigenvalue according to the second processing amount of the second sub-time period; wherein, the eigenvalue includes at least one of the sum of the processing amounts at multiple moments, the processing amount sequence arranged in time, the average processing amount, and the change amount of the processing amount; determining the first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period.
[0137] According to one or more embodiments of the present disclosure, [Example Six] provides the method of Example Five, further comprising: Optionally, the first eigenvalue includes a first average processing amount, and the second eigenvalue includes a second average processing amount; the determining the first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: in response to an event that the second average processing amount of the second sub-time period is greater than or equal to a first processing amount threshold, determining a second processing amount threshold according to the second average processing amount and a first preset multiple, and determining the first detection result of the array within the first time period according to the first average processing amount and the second processing amount threshold.
[0138] According to one or more embodiments of the present disclosure, [Example Seven] provides the method of Example Five, further including: Optionally, the first eigenvalue includes a first average processing volume, and the second eigenvalue includes a second average processing volume; determining the first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: in response to an event that the first average processing volume and the second average processing volume meet a preset condition, determining the first detection result of the array within the first time period according to the first average processing volume; wherein, the preset condition includes at least one of the first average processing volume of the first sub-time period being greater than the second average processing volume of the second sub-time period adjacent to the first sub-time period, the first average processing volume being greater than a third processing volume threshold, the second average processing volume of the second sub-time period being less than the third processing volume threshold, and the first average processing volume being greater than a second preset multiple of the second average processing volume.
[0139] According to one or more embodiments of the present disclosure, [Example Eight] provides the method of Example Five, further including: Optionally, the first eigenvalue includes a first change amount of a first processing volume, and the second eigenvalue includes a second average processing volume and a second change amount of the second processing volume; determining the first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: determining an average offset magnification according to the second average processing volume of the second processing volume, and determining a third change amount according to the average offset magnification and the second change amount; in response to an event that the first change amount of the first processing volume is greater than a preset change amount threshold and greater than the third change amount, determining the first detection result of the array within the first time period according to the first change amount.
[0140] According to one or more embodiments of the present disclosure, [Example Nine] provides the method of Example One, further including: Optionally, determining the array detection result according to the first detection result and the second detection result includes: determining difference data between the first detection result and the second detection result, and determining the array detection result according to the difference data.
[0141] According to one or more embodiments of the present disclosure, [Example Ten] provides the method of Example One, further including: Optionally, the array detection result is used to indicate whether the array is in an abnormal state; after determining the array detection result of the array according to the preset type data of the array within the first time period and the second time period, further including: in response to an event that the array detection result includes that the array is in an abnormal state, generating status prompt information corresponding to the array, and displaying the status prompt information.
[0142] According to one or more embodiments of the present disclosure, [Example XI] provides the method of Example I, further including: Optionally, the data detection request includes a task execution request for the data detection task; before responding to the data detection request, it further includes: receiving a task setting operation, and determining a data detection task according to the task setting operation, where the data detection task includes an identification setting operation and / or a label setting operation, the identification setting operation is used to set a task identification corresponding to the data detection task, and the label setting operation is used to set a target data label corresponding to the data detection task.
[0143] According to one or more embodiments of the present disclosure, [Example XII] provides a data detection device, including: a data detection request module, configured to determine a plurality of target data labels corresponding to the data detection request in response to the data detection request; where the target data label is used to indicate the data to be detected; a first time period detection module, configured to determine a plurality of arrays corresponding to a first time period according to the plurality of target data labels, and respectively determine a first detection result of each of the arrays within the first time period; a detection result determination module, configured to, in response to an event that the first detection result satisfies a first preset condition, determine a second time period corresponding to the array, and determine an array detection result of the array according to preset type data of the array within the first time period and the second time period.
[0144] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (for example, a communication network). Examples of communication networks include local area networks (“LAN”), wide area networks (“WAN”), the Internet (for example, the Internet), and end-to-end networks (for example, ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0145] The above computer-readable medium may be included in the above electronic device; or may exist separately without being assembled into the electronic device.
[0146] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: in response to a data detection request, determine a plurality of target data tags corresponding to the data detection request; wherein the target data tags are used to indicate the data to be detected; determine a plurality of arrays corresponding to a first time period according to the plurality of target data tags, and respectively determine first detection results of each of the arrays within the first time period; in response to an event that the first detection result satisfies a first preset condition, determine a second time period corresponding to the array, and determine an array detection result of the array according to preset type data of the array within the first time period and the second time period.
[0147] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0148] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0149] The units involved in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of a unit does not constitute a limitation to the unit itself in some cases. For example, the variation determination unit can also be described as "the unit for determining the average offset magnification and the third variation".
[0150] The functions described above in this article can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0151] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include electrical connections based on one or more wires, portable computer disks, hard disks, Random Access Memory (RAM), Read Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM or Flash Memory), optical fibers, portable compact disc read only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0152] The above description is only the preferred embodiments of the present disclosure and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.
[0153] Moreover, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these should not be construed as limitations on the scope of the present disclosure. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.
[0154] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. A data detection method, characterized in that Including: In response to a data detection request, determining a plurality of target data tags corresponding to the data detection request; wherein, the target data tags are used to indicate the data to be detected; Determining a plurality of arrays corresponding to a first time period according to the plurality of target data tags, and respectively determining first detection results of each of the arrays within the first time period; In response to an event that the first detection result meets a first preset condition, determining a second time period corresponding to the array, and determining an array detection result of the array according to preset type data of the array within the first time period and the second time period.
2. The data detection method according to claim 1, wherein The determining a plurality of arrays corresponding to a first time period according to the plurality of target data tags includes: Obtaining attribute data of the target data tags within the first time period, and constructing a plurality of arrays corresponding to the first time period according to the plurality of target data tags and their attribute data.
3. The data detection method according to claim 2, wherein The constructing a plurality of arrays according to the plurality of target data tags and their attribute data includes: For each of the target data tags, constructing an attribute set corresponding to the target data tag according to the attribute data of the target data tag within the first time period; Performing a Cartesian product operation on the attribute sets corresponding to the plurality of target data tags to obtain a plurality of arrays corresponding to the first time period.
4. The data detection method according to claim 1, wherein The first time period includes a first sub-time period and at least one second sub-time period; the respectively determining first detection results of each of the arrays within the first time period includes: For a single array, obtaining a first processing amount corresponding to the array within the first sub-time period of the first time period and a second processing amount corresponding to the array within at least one second sub-time period of the first time period, and determining a first detection result of the array within the first time period according to the first processing amount and the second processing amount.
5. The data detection method according to claim 4, wherein The determining a first detection result of the array within the first time period according to the first processing amount and the second processing amount includes: Determining a first eigenvalue according to the first processing amount of the first sub-time period, and for a single second sub-time period, determining a second eigenvalue according to the second processing amount of the second sub-time period; wherein, the eigenvalue includes at least one of the sum of the processing amounts at multiple moments, the processing amount sequence arranged in time, the average processing amount, and the change amount of the processing amount; Determining a first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period.
6. The data detection method according to claim 5, wherein The first eigenvalue includes a first average processing amount, and the second eigenvalue includes a second average processing amount; the determining a first detection result of the array within the first time period according to the first eigenvalue and the second eigenvalue of the second sub-time period includes: In response to an event that the second average processing volume in the second sub - time period is greater than or equal to the first processing volume threshold, determine a second processing volume threshold according to the second average processing volume and a first preset multiple, and determine a first detection result of the array in the first time period according to the first average processing volume and the second processing volume threshold.
7. The data detection method according to claim 5, wherein The first eigenvalue includes a first average processing volume, and the second eigenvalue includes a second average processing volume; determining the first detection result of the array in the first time period according to the first eigenvalue and the second eigenvalue in the second sub - time period includes: In response to an event that the first average processing volume and the second average processing volume meet a preset condition, determine the first detection result of the array in the first time period according to the first average processing volume; wherein, the preset condition includes at least one of the first average processing volume in the first sub - time period being greater than the second average processing volume in the second sub - time period adjacent to the first sub - time period, the first average processing volume being greater than a third processing volume threshold, the second average processing volume in the second sub - time period being less than the third processing volume threshold, and the first average processing volume being greater than a second preset multiple of the second average processing volume.
8. The data detection method according to claim 5, characterized in that The first eigenvalue includes a first change amount of the first processing volume, and the second eigenvalue includes a second average processing volume and a second change amount of the second processing volume; determining the first detection result of the array in the first time period according to the first eigenvalue and the second eigenvalue in the second sub - time period includes: Determine an average offset magnification according to the second average processing volume of the second processing volume, and determine a third change amount according to the average offset magnification and the second change amount; In response to an event that the first change amount of the first processing volume is greater than a preset change amount threshold and greater than the third change amount, determine the first detection result of the array in the first time period according to the first change amount.
9. The data detection method according to claim 1, characterized in that The preset type of data includes detection result data; determining the array detection result of the array according to the preset type of data of the array in the first time period and the second time period includes: Obtain a second detection result of the array in the first time period, and determine the array detection result of the array according to the difference data between the first detection result and the second detection result.
10. The data detection method according to claim 1, wherein The preset type of data includes time data; the time data is used to record the appearance time of the array; Determining the array detection result of the array according to the preset type of data of the array in the first time period and the second time period includes: Determine a first appearance time of the array in the first time period and a second appearance time corresponding to the array in the second time period, and determine the array detection result of the array according to the first appearance time and the second appearance time; wherein, the second appearance time is the latest appearance time of the array in the second time period and a preset time period before it.
11. The data detection method according to claim 1, wherein The array detection result is used to indicate whether the array is in an abnormal state; After determining the array detection result of the array according to the preset type data of the array in the first time period and the second time period, the following steps are further included: In response to the event that the array detection result includes that the array is in an abnormal state, generate a status prompt message corresponding to the array, and display the status prompt message.
12. The data detection method according to claim 1, wherein The data detection request includes a task execution request for a data detection task; before responding to the data detection request, the following steps are further included: Receive a task setting operation, and determine a data detection task according to the task setting operation, where the data detection task includes an identification setting operation and / or a label setting operation, the identification setting operation is used to set a task identification corresponding to the data detection task, and the label setting operation is used to set a target data label corresponding to the data detection task.
13. A data detection device, characterized in that, It includes: A data detection request module, configured to determine a plurality of target data labels corresponding to the data detection request in response to the data detection request; wherein, the target data label is used to indicate the data to be detected; A first time period detection module, configured to determine a plurality of arrays corresponding to the first time period according to the plurality of target data labels, and respectively determine a first detection result of each array in the first time period; A detection result determination module, configured to determine a second time period corresponding to the array in response to the event that the first detection result meets a first preset condition, and determine the array detection result of the array according to the preset type data of the array in the first time period and the second time period.
14. An electronic device, characterized in that, The electronic device includes: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the data detection method according to any one of claims 1-12.
15. A storage medium containing computer-executable instructions, characterized in that, The computer-executable instructions are used to execute the data detection method according to any one of claims 1-12 when executed by a computer processor.
16. A computer program product, comprising a computer program, characterized in that, The computer program implements the data detection method according to any one of claims 1-12 when executed by a processor.