Alarm information management method, system and device and storage medium
By converting the alarm information into a key-value pair structure and establishing a feature tree, obtaining the template matching degree and sorting and matching, the problem of alarm information processing under different devices and protocols is solved, and an efficient unified display and low maintenance cost alarm management is achieved.
Patent Information
- Application Number
- CN202510569887.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-08
AI Technical Summary
The prior art requires the development of special alarm analysis modules for each device model, resulting in high switching costs and maintenance complexity, making it difficult to effectively deal with alarm information under different equipment sources and protocols.
Convert the original message into key-value pair structure alarm data, establish a feature tree for feature extraction, obtain the degree of matching of the alarm decomposition template, and select the template according to the sorting results for matching and processing, and use the alarm mapping template to uniformly display the data processing results.
It realizes unified display of alarm information under different devices and protocols, reduces computing resource consumption, simplifies maintenance process, and improves execution efficiency and flexibility.
Smart Images

Figure CN120281630A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular, to a method, system, device, and storage medium for managing alarm information. Background Art
[0002] With the rapid development of information technology, a large number of hardware resources such as servers, storage devices, and network devices, as well as various software resources such as operating systems, databases, and middleware, are integrated inside the data center. While these software and hardware resources provide efficient and reliable computing and storage services, they also generate a large amount of alarm information, which is of great significance for ensuring the stable operation of the data center and promptly discovering and handling potential faults. However, the forms of alarms are diverse and may include hardware failure alarms, software exception alarms, performance bottleneck alarms, and security threat alarms, etc. Since the sources of alarm information are extensive and may originate from different components such as servers, storage devices, and network devices, using different protocols, the processing methods of alarms show diverse characteristics. And it is also necessary to solve the problem of unified display of differentiated alarms.
[0003] In some current solutions, a customized alarm adaptation solution for models is adopted. By analyzing the characteristics, communication protocols, and alarm information formats of different device models, a dedicated alarm parsing module is developed for each device or device type, and a dedicated coding system for alarms is established to ensure the accuracy and integrity of alarm information. However, such a solution requires developing a dedicated alarm parsing module for each device model, resulting in a large amount of human and time costs. When there are a large number of device types, the development cost will increase significantly. And with the update of device models and the upgrade of firmware versions, it is also necessary to continuously update and maintain the alarm parsing module, increasing the maintenance complexity.
[0004] In summary, how to effectively handle alarm information under different device sources and different protocols, and reduce the switching cost and the maintenance complexity is an urgent technical problem that needs to be solved by those skilled in the art currently. Summary of the Invention
[0005] This application provides a method, system, device, and storage medium for managing alarm information to at least solve the problem of high switching cost in related technologies that need to handle alarm information under different device sources and different protocols.
[0006] This application provides a method for managing alarm information, including:
[0007] Receiving the original message of the alarm and converting the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of alarm data reflects the path information of the alarm data;
[0008] Build a first feature tree for reflecting the path information of the keys in each piece of the alarm data, and perform feature extraction on the first feature tree to obtain a feature set;
[0009] Obtain the matching degree of each alarm decomposition template with the feature set, and sort them in descending order to obtain the sorting result of the alarm decomposition templates;
[0010] For each piece of the alarm data, select alarm decomposition templates in the order of the sorting result to perform key data matching on the alarm data. When the matching is successful, perform data processing on the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data;
[0011] For any one of the data processing results, fill the data processing result into the matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
[0012] This application also provides an alarm information management system, including:
[0013] A preprocessing module, configured to receive the original message of the alarm and convert the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of the alarm data reflects the path information of the alarm data;
[0014] A feature extraction module, configured to build a first feature tree for reflecting the path information of the keys in each piece of the alarm data, and perform feature extraction on the first feature tree to obtain a feature set;
[0015] A sorting module, configured to obtain the matching degree of each alarm decomposition template with the feature set, and sort them in descending order to obtain the sorting result of the alarm decomposition templates;
[0016] A decomposition module, configured to, for each piece of the alarm data, select alarm decomposition templates in the order of the sorting result to perform key data matching on the alarm data. When the matching is successful, perform data processing on the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data;
[0017] A mapping module, configured to, for any one of the data processing results, fill the data processing result into the matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
[0018] This application also provides an alarm information management device, including:
[0019] A memory, configured to store a computer program;
[0020] A processor for executing the computer program to implement the steps of the alarm information management method as described above.
[0021] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the alarm information management method as described above are implemented.
[0022] In the solution of the present application, after receiving the original alarm message, the original message will be converted into a unified structure for subsequent analysis and processing, so as to effectively cope with the wide range of sources and diverse protocols of alarm information. Specifically, the original message is uniformly converted into each piece of alarm data in a key-value pair structure, and the key in each piece of alarm data reflects the path information of the alarm data. Subsequently, in order to facilitate matching with the alarm decomposition template, feature extraction will be performed on each piece of alarm data. Specifically, a first feature tree for reflecting the path information of the keys in each piece of alarm data is established, and feature extraction is performed on the first feature tree to obtain a feature set. It should be noted that for each piece of alarm data, only the alarm decomposition template matching its key data is needed to process the data of this piece of alarm data. However, if traversed one by one, the efficiency is relatively low. Therefore, in the solution of the present application, the matching degree of each alarm decomposition template and the feature set will be obtained, and sorted in descending order to obtain the sorting result of the alarm decomposition template. When matching, the alarm decomposition template is selected in the order of the sorting result to match the alarm data. And it can be understood that the higher the matching degree of a certain alarm decomposition template and the feature set, the greater the possibility that the alarm decomposition template can successfully match the key data of the alarm data. Therefore, it means that the solution of the present application can quickly locate the alarm decomposition template matching the alarm data, ensuring the execution efficiency of the solution of the present application and saving computing resources. After the data processing result of the alarm data is obtained through the successfully matched alarm decomposition template, finally the data processing result can be filled into the matching alarm mapping template. Since the data processing result is displayed in the format specified by the alarm mapping template, the problem of unified display of differential alarms can be solved.
[0023] In summary, the solution of the present application can effectively cope with alarm information from different device sources and different protocols, achieve unified display, and the execution process is efficient, saving computing resources. In addition, it can be seen that the solution of the present application realizes the processing and display of alarm information based on the alarm decomposition template and the alarm mapping template. Therefore, the situation where a bound alarm parsing module needs to be developed for each device model in the traditional solution will not occur. When encountering iterative updates of alarms, only the relevant templates need to be updated, which is simple and convenient to operate, has high flexibility, and low maintenance complexity. Description of the Drawings
[0024] To more clearly illustrate the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other accompanying drawings can be obtained based on these drawings without creative efforts.
[0025] Figure 1 It is a flowchart of the implementation of the method for managing alarm information provided by a specific embodiment of the present invention;
[0026] Figure 2 It is a schematic diagram of the construction process of the first feature tree created in a specific embodiment of the present invention;
[0027] Figure 3 It is a schematic diagram of a single initial decomposition template in a specific embodiment of the present invention;
[0028] Figure 4 It is a schematic diagram of an alarm mapping template in a specific embodiment of the present invention;
[0029] Figure 5 It is a schematic diagram of the structure of the alarm information management system provided by a specific embodiment of the present invention;
[0030] Figure 6 It is a schematic diagram of the structure of the alarm information management device provided by a specific embodiment of the present invention;
[0031] Figure 7 It is a schematic diagram of the structure of a computer-readable storage medium of the present invention. Specific Embodiment
[0032] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0033] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and not to describe a specific order or sequence.
[0034] To enable those skilled in the art of the present technology to better understand the solution of this application, the following provides a further detailed description of this application in conjunction with the accompanying drawings and specific embodiments.
[0035] Please refer to Figure 1 , Figure 1 which is the implementation flowchart of the management method for alarm information provided by a specific embodiment of the present invention. The management method for alarm information may include the following steps:
[0036] Step S101: Receive the original message of the alarm and convert the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of alarm data reflects the path information of the alarm data.
[0037] In the solution of this application, it is necessary to receive alarms from different device sources and under different protocols and achieve unified display. Therefore, the solution of this application will preprocess the original message of the received alarm. Specifically, the original message is converted into each piece of alarm data in a key-value pair structure, which is convenient for subsequent analysis and processing, so as to effectively cope with the wide range of sources and diverse protocols of alarm information.
[0038] Converting the original message into each piece of alarm data in a key-value pair structure, that is, converting it into each piece of alarm data in a Key-Value structure. The key (Key) therein reflects the path information of this piece of alarm data, while the value (Value) is the specific alarm content under this path information. In addition, it should be noted that since the path information is relatively long and has a hierarchical structure, for the key (Key) in the alarm data, the hierarchical structure of the key (Key) is usually constructed using a preset hierarchical separator. The form of the preset hierarchical separator can be set and adjusted as needed. For example, it is “.”, and “.” is also used as an example of the hierarchical separator in the following text for illustration.
[0039] In a specific embodiment of the present invention, step S101 may specifically include:
[0040] Receive the original message of the alarm, and based on the type of the original message, use the corresponding conversion rule to convert the original message into each piece of alarm data in a key-value pair structure.
[0041] This embodiment takes into account that for alarms from different device sources and under different protocols, it is necessary to uniformly convert them into each piece of alarm data in a key-value pair structure. A more convenient implementation method is to use the corresponding conversion rule based on the type of the original message, so as to facilitate the conversion and not prone to errors.
[0042] Further, in a specific embodiment of the present invention, the original alarm message is received, and corresponding conversion rules are used based on the type of the original message to convert the original message into each piece of alarm data in key-value pair structure, which may specifically include:
[0043] Receive the original alarm message;
[0044] When the original message is an original message of object identifier type, use the object identifier of the original message as the key, and use the alarm content in the original message as the value to obtain each piece of alarm data in key-value pair structure;
[0045] When the original message is an original message of request type, generate a key based on the path structure of the original message, and use the corresponding content of the key as the value to obtain each piece of alarm data in key-value pair structure;
[0046] When the original message is an original message of software development kit type, generate a key based on the class path and class fields of the original message, and use the corresponding content of the key as the value to obtain each piece of alarm data in key-value pair structure.
[0047] This embodiment takes into account that the types of original messages can usually be divided into three categories, namely, original messages of object identifier type, original messages of request type, and original messages of software development kit type. In this embodiment, for these three different types of original messages, corresponding conversion rules are adopted to convert them into each piece of alarm data in key-value pair structure.
[0048] The object identifier type is also the OID (Object Identifier) type. The original messages of this type usually comply with the standard SNMP protocol. Therefore, in practical applications, SNMP tools can be used to monitor and receive such original messages. After receiving, they can be parsed, and the OID itself can be directly used as the key, that is, the object identifier of the original message can be directly used as the key, and the alarm content corresponding to the key is used as the value. And the OID itself already has a hierarchical structure, so there is no need to process its format additionally.
[0049] For example, in one case, the original message of OID type is specifically "1.3.6.1.2.1.1.1.0 = Systemdescription". After converting it into key-value pair structure, the obtained alarm data is specifically: "1.3.6.1.2.1.1.1.0: System description". Among them, "1.3.6.1.2.1.1.1.0" is the key, and "Systemdescription" is the value.
[0050] The request type is usually of the HTTP (Hypertext Transfer Protocol) type and is a JSON-formatted message. Therefore, keys can be generated according to the path structure of the JSON object. Alerts of this type usually use the standard Redfish interface or a customized alert receiving interface, and the alerts are reported via HTTP requests.
[0051] Specifically, the nested structure of the JSON object can be recursively traversed, and then the paths at each level are connected with the level separator ".", forming a complete key, and the corresponding alert content is used as the value. For example, in one scenario, for the original message "{ "body": { "event": { "id": 1, "message": "Alert triggered"}}}", the result is "body.event.id: 1, body.event.message: Alert triggered", that is, 2 key-value pair-structured alert data are obtained in this example, where one alert data is "body.event.id: 1" and the other alert data is "body.event.message: Alert triggered".
[0052] For messages of the SDK (Software Development Kit) type, some alerts require third parties to provide an SDK for integrated calls. When in use, the interfaces related to SDK alerts can be called to obtain device alerts.
[0053] When the original message is of the SDK type, keys (Keys) can be generated based on the hierarchical relationship of the class path and class fields of the SDK. Specifically, the class path and class field information can be obtained according to the metadata interface provided by the SDK, and the class path and the name of the class field are connected with the hierarchical separator ".", forming a key (Key), and the corresponding alarm content is used as the value (Value). For example, for the io.s.SDKAlarm object with the "name" field being "alert" and the "version" field being "1.0", after preprocessing, the result obtained is "io.spring.Application.name: alert, io.spring.Application.version: 1.0", that is, 2 key-value pair-structured alarm data are obtained in this example. One of the alarm data is "io.spring.Application.name: alert", and the other alarm data is "io.spring.Application.version: 1.0".
[0054] Step S102: Establish a first feature tree for reflecting the path information of the keys in each piece of alarm data, and perform feature extraction on the first feature tree to obtain a feature set.
[0055] For one piece of original message, after converting the original message into alarm data in the key-value pair structure, one or more pieces of alarm data can be obtained. For example, in one case, for one piece of original message, after converting the original message into the key-value pair structure, a total of 5 pieces of alarm data are obtained. Then, based on these 5 pieces of alarm data, a first feature tree for reflecting the path information of the keys (Keys) in these 5 pieces of alarm data can be established, and feature extraction is performed on the first feature tree to obtain a feature set.
[0056] The operation of this step is to perform feature extraction on the alarm data, so as to facilitate the matching of the alarm decomposition template in the follow-up. The specific implementation of establishing the first feature tree and performing feature extraction on the first feature tree can be set and adjusted according to actual needs, as long as the feature extraction can be effectively achieved. For example, in a specific embodiment of the present invention, the establishment of the first feature tree for reflecting the path information of the keys in each piece of alarm data described in step S102 may specifically include:
[0057] Create an empty node and use it as the root node of the first feature tree;
[0058] For each piece of alarm data, add the key of the alarm data to the first feature tree by using the hierarchical structure of the key of the alarm data as a node in the first feature tree;
[0059] Among them, in different alarm data, the same hierarchical structure corresponds to the same node in the first feature tree.
[0060] This implementation method takes into account that for one original message, after converting the original message into alarm data of a key-value pair structure, one or more alarm data can be obtained, so an empty node can be created first, for example, recorded as "root", the root node of the first feature tree. Figure 2 , is a schematic diagram of the construction process of the first feature tree created in a specific implementation, and its root node is "root". And for example Figure 2 In the example, a total of three alarm data are obtained for one original message, where the first alarm data is, for example, "io.spring.Application.name: alert", the second alarm data is, for example, "io.spring.Application.version: 1.0", and the third alarm data is, for example, "body.event.id: 1".
[0061] For each piece of alarm data, the hierarchical structure of the key of the alarm data needs to be used as a node in the first feature tree, and the key of the alarm data needs to be added to the first feature tree. In other words, for each piece of alarm data, when a certain hierarchical structure of its key does not exist in a node in the first feature tree, the node is created in the first feature tree. In practical applications, each piece of alarm data can be traversed in turn to complete the construction of the first feature tree.
[0062] by Figure 2 For example, for the first alarm data, you can first use the hierarchical structure "io" in the key as the child node of the root node "root", and then use the hierarchical structure "spring" in the key as the child node of "io", and then use the hierarchical structure "Application" in the key as the child node of "spring", and finally use the hierarchical structure "name" in the key as the child node of "Application". At this point, the key of the first alarm data has been added.
[0063] Then you can traverse the key (Key) of the second alarm data. Specifically, "io", "spring" and "Application" in the key (Key) of the second alarm data all exist in the nodes of the first feature tree. Therefore, you only need to add the hierarchical structure "version" in the key (Key) as a child node of "Application", and the key (Key) of the second alarm data will be added.
[0064] Finally, in this example, the key of the third alarm data is traversed, and the "body", "event" and "id" in the key of the third alarm data are added to the first feature tree in turn. At this point, the keys of the three alarm data have been traversed, and the construction of the first feature tree has been completed. Figure 2 The first feature tree obtained in this example is also shown in FIG. 8 , which has a total of 8 nodes except the root node “root”.
[0065] In this implementation, the construction of the first feature tree is realized in a simple and easy-to-implement manner, and the first feature tree can effectively reflect the hierarchical structure of the keys of the alarm data, that is, effectively reflect the characteristics of the alarm data. The first feature tree is deduplicated, which is also conducive to facilitating subsequent feature extraction operations.
[0066] In a specific implementation of the present invention, the feature extraction of the first feature tree described in step S102 to obtain a feature set may specifically include:
[0067] Delete the root node of the first feature tree;
[0068] Each child node under the root node of the first feature tree is used as the starting node of each recursive path;
[0069] For any recursive path, when there is no bifurcation in the recursive path, the recursive path is taken as a feature path in the feature set;
[0070] For any recursive path, when there is a fork in the recursive path, the path content from the starting node of the recursive path to the node where the fork occurs for the first time is taken as a feature path in the feature set.
[0071] This implementation takes into account that, for the first feature tree, the characteristics of the first feature tree can be reflected through the path, and the main path should be considered, and the branch situation can be ignored, so that the obtained feature set can effectively reflect the characteristics of the first feature tree.
[0072] Specifically, since the root node "root" is an empty node added previously, the root node "root" can be directly deleted during feature extraction. Then, each child node under the root node "root" needs to be used as the starting node of each recursive path. For example, in one case, there is only one child node "io" under the root node "root", then there is only one recursive path in this example, and the child node "io" is the starting node of the recursive path.
[0073] Still Figure 2Taking it as an example, there are 2 child nodes under the root node "root", namely the child node "io" and the child node "body". After deleting the root node "root" of the first feature tree, these 2 child nodes can be used as the starting nodes of the 2 recursive paths respectively.
[0074] For the recursive path where the node "io" is located, this recursive path has a fork. Specifically, the fork occurs for the first time at the position of the node "Application". Therefore, in this recursive path, the path content from the starting node "io" of the recursive path to the node "Application" where the fork occurs for the first time needs to be used as a feature path in the feature set. That is, this feature path can be represented as "io.spring.Application".
[0075] For Figure 2 In the example, for the recursive path where the node "body" is located, this recursive path has no fork. Therefore, this recursive path can be used as a feature path in the feature set. That is, this feature path can be represented as "body.event.id".
[0076] Therefore Figure 2 In the example, the obtained feature set T can be represented as T = {t1, t2}. Here, t1 is the first feature path in the feature set T, that is, "io.spring.Application" described above, and t2 here is the second feature path in the feature set T, that is, "body.event.id" described above.
[0077] Step S103: Obtain the matching degree of each alarm decomposition template with the feature set respectively, and sort them in descending order to obtain the sorting result of the alarm decomposition templates.
[0078] After obtaining the feature set, it is necessary to obtain the matching degree of each alarm decomposition template with the feature set respectively, and then sort the matching degrees in descending order, that is, the sorting of the alarm decomposition templates is realized, and the sorting result of the alarm decomposition templates is obtained.
[0079] There can be various specific implementation methods for matching a certain alarm decomposition template with the feature set. For example, in a specific embodiment of the present invention, the obtaining of the matching degree of each alarm decomposition template with the feature set described in step S103 may specifically include:
[0080] For each alarm decomposition template, obtain the feature extraction result of each alarm decomposition template respectively;
[0081] For any one alarm decomposition template, by The calculation method is used to obtain the matching degree between the alarm decomposition template and the feature set;
[0082] Among them, S represents the matching degree between the alarm decomposition template and the feature set, T represents the feature set, represents the feature extraction result of the alarm decomposition template; is the intersection operator, is the union operator, and the operator represents the size of the set.
[0083] In this implementation, it is necessary to perform feature extraction on the alarm decomposition template to obtain the feature extraction result of the alarm decomposition template , and then compare the feature extraction result of the alarm decomposition template with the feature set T to obtain the intersection quantity and union quantity of the two, and then the matching degree S between the alarm decomposition template and the feature set can be simply and conveniently determined.
[0084] The operator represents the size of the set. For example, the feature extraction result of the alarm decomposition template includes 10 feature paths, the feature set T includes 3 feature paths, and 1 of the 3 feature paths is the same as 1 of the 10 feature paths of, so it can be determined , and .
[0085] In addition, it should be pointed out that there are various specific implementation methods for determining whether two feature paths are the same. For example, a simple determination method is that only when the two feature paths are exactly the same, it will be determined that the two feature paths are the same, otherwise it is considered that the two feature paths are different. In a specific implementation of the present invention, when determining the size of the intersection of the feature extraction result of the alarm decomposition template and the feature set T, that is, when performing calculation, specifically based on it is considered that the feature paths are the same when, and when it is considered that the feature paths are the same, the calculation is implemented. Here, t n can refer to any feature path in the feature set T, and t m can refer to any feature path in the feature extraction result .
[0086] For easy understanding, still taking the above Figure 2Taking the feature set T obtained from the example as an example, and specifically taking the feature path "body.event.id" as an example, if in the feature extraction result there is a certain feature path that is also "body.event.id", it can be shown that the feature path in the feature extraction result is exactly the same as the feature path "body.event.id" in the feature set T, that is, it belongs to the situation described above , so these 2 feature paths are regarded as the same. Another example is that in the feature extraction result there is a certain feature path that is specifically "body.event", which belongs to the situation described above , that is, it can be determined that the feature path "body.event" in the feature extraction result is the same as the feature path "body.event.id" in the feature set T, so these 2 feature paths are regarded as the same.
[0087] It can be seen that in this implementation, it is not required that the 2 feature paths are exactly the same, but for the above situation, the 2 feature paths can also be regarded as the same, which can more reasonably reflect the consistency between different feature paths, that is, make the obtained matching degree S more accurate and reasonable.
[0088] In a specific implementation manner of the present invention, for each alarm decomposition template, the respective feature extraction results of each alarm decomposition template are obtained, including:
[0089] For any alarm decomposition template, obtain the alarm key data in each decomposition rule in the alarm decomposition template;
[0090] Based on the alarm key data in each decomposition rule, establish a second feature tree for reflecting the path information of each alarm key data, and perform feature extraction on the second feature tree to obtain the feature extraction result of the alarm decomposition template.
[0091] In the solution of the present application, it is necessary to obtain the respective feature extraction results of each alarm decomposition template. There can be various specific feature extraction methods. For example, in this implementation manner, the feature extraction result of the alarm decomposition template can be obtained based on the same principle as obtaining the feature set T .
[0092] Specifically, an alarm decomposition template will include one or more decomposition rules, and each decomposition rule has alarm key data for that decomposition rule. According to the same principle as above, a feature tree can be established based on the alarm key data of each decomposition rule in the alarm decomposition template. To distinguish it from the above, it is called the second feature tree. After obtaining the second feature tree, feature extraction can be performed according to the same principle as above, and the result obtained is the feature extraction result of the alarm decomposition template. It can be seen that in this implementation manner, the same principle is used for feature extraction of the alarm decomposition template and for feature extraction of each piece of alarm data converted from the original message, which improves the implementation convenience of the solution of this application.
[0093] In a specific implementation manner of the present invention, step S103 may specifically include
[0094] Obtain the matching degree of each alarm decomposition template with the feature set respectively, delete the matching degrees with a value of 0, and based on the remaining matching degrees, establish a matching degree threshold;
[0095] Retain each matching degree with a matching degree higher than the matching degree threshold, and sort the alarm decomposition templates corresponding to the retained matching degrees in descending order of the matching degree to obtain the sorting result of the alarm decomposition templates.
[0096] In practical applications, usually using the first alarm decomposition template in the sorting result or using the second alarm decomposition template in the sorting result can effectively complete the key data matching of each piece of alarm data. Therefore, in this implementation manner, after obtaining the matching degree of each alarm decomposition template with the feature set respectively, for the matching degree with a value of 0, the corresponding alarm decomposition template usually does not need to be used. That is, even if the alarm decomposition templates with high matching degrees cannot achieve key data matching with a certain piece of alarm data, then these alarm decomposition templates corresponding to the matching degree of 0 also cannot perform key data matching with this piece of alarm data. Therefore, the matching degrees with a value of 0 can be directly deleted.
[0097] Furthermore, in this implementation manner, not only the matching degrees with a value of 0 will be deleted, but also for the matching degrees with relatively low values, considering that the corresponding alarm decomposition templates usually do not need to be used either, the matching degrees not higher than the matching degree threshold will also be deleted. Only the matching degrees higher than the matching degree threshold need to be retained, and then the alarm decomposition templates corresponding to these retained matching degrees are sorted in descending order of the matching degree to obtain the sorting result of the alarm decomposition templates.
[0098] In this implementation manner, the deletion of some matching degrees is considered. In a small number of cases, due to software and hardware version updates and the failure to update relevant alarm decomposition templates in a timely manner, etc., for a certain alarm data, there may be a situation where no alarm decomposition template can successfully match its key data. Therefore, for such a situation, if all alarm decomposition templates in the sorting result are traversed, the time consumption will be relatively small. Moreover, for the cases where the matching degree is 0 and the matching degree is lower than the matching degree threshold, it is usually difficult for relevant alarm decomposition templates to successfully match the key data of alarm data. Therefore, this implementation manner of deleting some matching degrees can effectively reduce the number of alarm decomposition templates in the sorting result. When the special situation described in this implementation manner occurs, since the number of alarm decomposition templates in the sorting result is small, even if all alarm decomposition templates in the entire sorting result are traversed, the time consumption is relatively shorter.
[0099] In addition, the matching degree threshold can be a preset fixed value or a dynamically set value. For example, in a specific implementation manner of the present invention, based on the remaining respective matching degrees, establishing a matching degree threshold may specifically include:
[0100] Based on the remaining respective matching degrees after deleting the matching degrees with a value of 0, through a calculation method, establish a matching degree threshold;
[0101] wherein, threshold represents the established matching degree threshold, u and respectively represent the average value and standard deviation of the remaining respective matching degrees after deleting the matching degrees with a value of 0, and k is a preset proportionality coefficient.
[0102] In this implementation manner, for the remaining respective matching degrees after deleting the matching degrees with a value of 0, calculate the average value and record it as u, and add it to the standard deviation and a superimposing coefficient can be set. Of course, for the sake of simplifying the setting, k is usually set to 1. In other specific implementation manners, the value of k can also be adjusted according to needs. It can be seen that the matching degree threshold is dynamically set in this implementation manner. Compared with the fixed setting of the matching degree threshold, the set matching degree threshold will be more reasonable, can effectively eliminate the lower matching degrees accordingly, retain the higher matching degrees, and is not likely to have the situation where the matching degree threshold is unreasonable in some occasions due to the fixed setting of the matching degree threshold.
[0103] Step S104: For each piece of alarm data, select alarm decomposition templates in the order of the sorting result to perform key data matching of the alarm data. When the matching is successful, perform data processing of the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data.
[0104] After obtaining the sorting result of the alarm decomposition templates, it is necessary to select the alarm decomposition templates in the order of the sorting result to perform key data matching for the alarm data. For example, the matching degree of each alarm decomposition template with the feature set is denoted as {S1, S2,..., S N}, where N is the total number of alarm decomposition templates. For example, the maximum value is S3, that is, the matching degree of the 3rd alarm decomposition template with the feature set is the largest, indicating that the matching degree of the 3rd alarm decomposition template with the feature set is the highest. However, it should be emphasized that this means that for each piece of alarm data converted from the original message, the probability of successful key data matching with the 3rd alarm decomposition template is the largest, but it is not necessarily successfully matched with the key data of the 3rd alarm decomposition template.
[0105] For example, a specific piece of alarm data is "io.spring.Application.name: alert" described above. In this example, when performing matching, it is first necessary to select the 3rd alarm decomposition template to perform key data matching for this alarm data. The specific matching method is to traverse each decomposition rule in the 3rd alarm decomposition template. Whenever the alarm key data (Key) in a certain decomposition rule is the same as the key data (Key) of this alarm data, it means that the 3rd alarm decomposition template is matched with the key data of this alarm data, and specifically, this decomposition rule is matched.
[0106] Conversely, for example, after traversing each decomposition rule in the 3rd alarm decomposition template, if the alarm key data of any one decomposition rule is not "io.spring.Application.name", it can be determined that the 3rd alarm decomposition template does not match the key data of this alarm data, and then it is necessary to continue to select the next alarm decomposition template to perform key data matching for this alarm data. For example, the second largest value except S3 is S5, that is, the matching degree of the 5th alarm decomposition template with the feature set is the second largest, and it is necessary to perform key data matching between the 5th alarm decomposition template and the key data of this alarm data.
[0107] In practical applications, usually using the first two alarm decomposition templates in the sorting result can effectively complete the key data matching of each piece of alarm data, effectively ensuring the execution efficiency of the solution of this application and reducing the calculation consumption.
[0108] When the key data matching is successful, through the alarm decomposition template with successful matching, the data processing of the alarm data can be carried out. Specifically, it is based on the decomposition rule in the alarm decomposition template that is successfully matched with the key data of the alarm data to perform the data processing of the alarm data, and the data processing result of the alarm data is obtained.
[0109] In a specific embodiment of the present invention, it may further include:
[0110] Obtain each initial decomposition template; wherein, a single initial decomposition template includes one or more decomposition rules; each decomposition rule includes preset alarm key data, a preset processing method for alarm value data, and a preset alarm metadata label;
[0111] Group each initial decomposition template according to the classification method of dividing into the same group according to the same manufacturer to obtain a first grouped set;
[0112] Determine the central template of each group in the first grouped set; wherein for any group, the central template of the group represents the initial decomposition template with the highest matching degree among all the initial decomposition templates in the group;
[0113] Using each central template as a clustering center, group each initial decomposition template again to obtain a second grouped set;
[0114] Take the second grouped set as the final grouped set, and merge and deduplicate each initial decomposition template in the same group in the final grouped set, and use the obtained result as each obtained alarm decomposition template;
[0115] Wherein, in the process of merging and deduplicating each initial decomposition template in the same group in the final grouped set, when there are two or more decomposition rules with the same alarm key data, only one of the decomposition rules is retained.
[0116] This embodiment takes into account that the initial decomposition templates are usually set by staff in advance. A simple implementation method is to directly use these initial decomposition templates as the alarm decomposition templates required by the solution. Another example is to simply classify and merge these initial decomposition templates as the alarm decomposition templates required by the solution. However, this embodiment further takes into account that such a simple processing method cannot well classify similar decomposition rules into the same alarm decomposition template, resulting in a relatively similar matching degree between each alarm decomposition template and the alarm data during matching, which is not conducive to ensuring the execution efficiency of the solution of the present application.
[0117] Therefore, in this embodiment, some operations such as classification and merging will be performed on the initial decomposition templates, which can make the finally obtained alarm decomposition templates achieve the effect of well classifying similar decomposition rules into the same alarm decomposition template, thereby ensuring the execution efficiency of the solution of the present application and reducing the calculation amount.
[0118] Specifically, reference can be made to Figure 3, which is a schematic diagram of a single initial decomposition template in a specific embodiment. The initial decomposition template can be a json file and records the manufacturer and model, that is, it indicates that the decomposition rules in the initial decomposition template are applicable to this manufacturer and this model. And Figure 3 in the example of
[0119] each decomposition rule includes preset alarm key data, a preset processing method for alarm value data, and a preset alarm metadata label. For example, for Figure 3 the initial decomposition template in the example, the first decomposition rule it includes is specifically:
[0120] "key": "1.3.6.1.4.1.37945.1.1.26";
[0121] "method":
[0122] {"method": "replace", "args": ["@String.class", "_@String.class"]}
[0123] {"method": "upperCase"}];
[0124] "flag": "location".
[0125] Among them, the content of "key" is the alarm key data, specifically "1.3.6.1.4.1.37945.1.1.26", and the content of "method" is the processing method for alarm value data. For example, "replace" is used to replace specified characters in the value of the alarm data, and "upperCase" is used to convert the value of the alarm data to uppercase letters. The alarm metadata label includes a special marker "flag" and an alarm metadata field, and the alarm metadata field is the smallest unit for describing alarm data and is unique.
[0126] For example, the second decomposition rule is specifically:
[0127] "key": "1.3.6.1.4.1.37945.1.1.38";
[0128] "method": [{"method": ;
[0129] "flag": "descripion".
[0130] For these initial decomposition templates, they can be grouped according to the classification method of dividing them into the same group by the same manufacturer for easy description. Denote the obtained first grouping set as G = {G1, G2,..., Gk}, where each grouping includes several initial decomposition templates with the same manufacturer. For example, for Gk in the first grouping set, it includes several initial decomposition templates of the same manufacturer.
[0131] After that, it is necessary to determine the central template of each grouping in the first grouping set. Still taking the grouping Gk in the first grouping set as an example, and for instance, if Gk includes 20 initial decomposition templates, then it is necessary to determine the central template of these 20 initial decomposition templates. The determination method is that the central template is the initial decomposition template with the highest matching degree among all the initial decomposition templates in this grouping compared with the remaining initial decomposition templates in the group.
[0132] Taking the 1st initial decomposition template among these 20 initial decomposition templates as an example, it is necessary to perform feature extraction for each of the 20 initial decomposition templates respectively. The implementation method can refer to the description above to implement feature extraction based on the feature tree. After that, based on the feature extraction results of the 1st initial decomposition template and the feature extraction results of the 2nd initial decomposition template, the matching degree between the 1st initial decomposition template and the 2nd initial decomposition template can be obtained. Similarly, the matching degree between the 1st initial decomposition template and the 3rd initial decomposition template can be obtained, the matching degree between the 1st initial decomposition template and the 4th initial decomposition template can be obtained, and so on. After obtaining the matching degrees between the 1st initial decomposition template and the remaining 19 initial decomposition templates respectively, sum them up. The result obtained is the matching degree between the 1st initial decomposition template and the remaining initial decomposition templates in the group.
[0133] Based on the same logic, the matching degree between the 2nd initial decomposition template and the remaining initial decomposition templates in the group can be obtained, the matching degree between the 3rd initial decomposition template and the remaining initial decomposition templates in the group can be obtained, and so on. And for example, the maximum value among them is the matching degree between the 15th initial decomposition template and the remaining initial decomposition templates in the group. Therefore, the 15th initial decomposition template is the central template of the grouping Gk determined this time.
[0134] For each grouping in the first grouping set G, the central template of this grouping can be obtained according to the description above. Then, taking these central templates as clustering centers, the initial decomposition templates are grouped again to obtain the second grouping set. Still taking the 15th initial decomposition template above as an example, after taking it as one of the clustering centers, for a certain initial decomposition template that is not a clustering center, when the matching degree between this initial decomposition template and the 15th initial decomposition template is higher than the matching degree between this initial decomposition template and other clustering centers, it can be understood that this initial decomposition template will be divided into the grouping where the 15th initial decomposition template is located.
[0135] In this embodiment, after regrouping to obtain the second grouping set, the second grouping set can be used as the final grouping set. It can be understood that the final grouping set includes multiple groupings, and each grouping includes one or more initial decomposition templates. In this application, the various initial decomposition templates in the same grouping will be merged and duplicate data removed, and the result obtained will be used as the obtained alarm decomposition templates. It can be seen that in this embodiment, the number of alarm decomposition templates obtained is the number of groupings in the second grouping set.
[0136] When merging and removing duplicate data, only one copy of the same alarm key data will be retained. For example, in the above example, in the first decomposition rule of an initial decomposition template, the alarm key data "key" is specifically "1.3.6.1.4.1.37945.1.1.26", and for example, in a certain decomposition rule of another initial decomposition template in the same group, its alarm key data "key" is also "1.3.6.1.4.1.37945.1.1.26", then only one of these two decomposition rules will be retained. For example, one can be randomly retained. Such a scheme for merging and removing duplicate data can avoid the situation where the same alarm key data "key" appears in multiple decomposition rules. That is to say, when performing data processing on alarm data to obtain the data processing result of alarm data, the uniquely determined decomposition rule that matches the alarm data successfully can be used to perform data processing on the alarm data.
[0137] Furthermore, in a specific embodiment of the present invention, it may further include:
[0138] After obtaining the second grouping set, extract the groupings in the second grouping set where the number of templates within the group is equal to 1, and place them into the to-be-completed grouping set;
[0139] Take the remaining content after extraction as the third grouping set;
[0140] For each grouping in the third grouping set where the number of templates exceeds the threshold range, use the initial decomposition template with the lowest matching degree to the central template of the grouping as the new central template;
[0141] Use the central template of each grouping in the third grouping set and each new central template as the clustering centers, and regroup the various initial decomposition templates in the third grouping set to obtain the fourth grouping set;
[0142] Correspondingly, using the second grouping set as the final grouping set includes:
[0143] Take the fourth grouping set and the to-be-completed grouping set as the final grouping set.
[0144] This implementation further takes into account that the grouping adjustment of the second grouping set can be continued to make the final grouping set more reasonable. Specifically, after obtaining the second grouping set, when there is only 1 initial decomposition template in a certain grouping, this grouping and the initial decomposition template in the grouping can be directly placed into the to-be-completed grouping set without participating in subsequent calculations. The remaining groupings form the third grouping set.
[0145] For the groupings in the third grouping set, the number of groupings with the number of templates exceeding the threshold range will be selected for splitting. Specifically, the threshold range can be a fixed value or a dynamic threshold range. For example, based on the groupings in the third grouping set, [μ - 2α, μ + 2α] can be used as the threshold range, where μ is the average number of initial decomposition templates included in each grouping in the third grouping set, and α is the standard deviation. For example, a certain grouping in the third grouping set includes a relatively large number of initial decomposition templates, higher than μ + 2α, so it needs to be split. The specific splitting method is to use the initial decomposition template with the lowest matching degree with the central template of this grouping as the new central template.
[0146] After the grouping splitting, the original central templates of each grouping in the third grouping set and each new central template can be used as the clustering centers, and then the initial decomposition templates in the third grouping set are regrouped to obtain the fourth grouping set. In this implementation, the fourth grouping set is used as the final grouping set. It can be seen that in this implementation, for the groupings with too many or too few (the number of templates is greater than 1) templates, splitting will be performed, which can effectively improve the diversity of the groupings in the final grouping set, thereby improving the rationality of the groupings in the final grouping set. When calculating the matching degree between the alarm decomposition template and the alarm data subsequently, it can make the matching degrees of different alarm decomposition templates show a certain difference, thereby improving the execution efficiency of the solution of this application.
[0147] Of course, in some implementations, 1 round or multiple rounds of iteration can be further performed according to the principle of this implementation. That is, after obtaining the fourth grouping set, according to the principle of this implementation, the groupings with the number of templates equal to 1 in the group are extracted and placed into the to-be-completed grouping set, and the remaining content is used as a new grouping set. For each grouping with the number of templates exceeding the threshold range, continue to perform grouping splitting, and then regroup based on the clustering centers to obtain the corresponding grouping set. When the number of iterations reaches the threshold, or during a certain iteration process, there is no grouping with the number of templates exceeding the threshold range, the iteration can be ended to obtain the most reasonable final grouping set required.
[0148] Step S105: For any data processing result, fill the data processing result into a matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
[0149] As described above, when the key data of a certain alarm data is successfully matched, the data processing of this alarm data can be performed through the successfully matched alarm decomposition template. Specifically, based on the decomposition rule in the alarm decomposition template that is successfully matched with the key data of the alarm data, the data processing of the alarm data is performed to obtain the data processing result of the alarm data. When using this decomposition rule to perform the data processing of the alarm data, the data processing of the alarm data can be performed based on the preset alarm value data processing method in the decomposition rule, and the alarm metadata label in the decomposition rule is added to obtain the data processing result of the alarm data.
[0150] In addition, it should also be noted that if a certain alarm data fails to match the key data of each alarm decomposition template in the sorting result, no additional processing may be required, and only the key-value data of the alarm data needs to be retained. That is, the alarm data itself is directly used as the data processing result of the obtained alarm data.
[0151] For the data processing result of any alarm data, it is necessary to fill it into a matching alarm mapping template, so as to display the data processing result in the format specified by the alarm mapping template and achieve a unified standard for alarm display. Of course, the specific form of the alarm mapping template can be set and adjusted according to actual needs.
[0152] In a specific embodiment of the present invention, step S105 may specifically include:
[0153] For any data processing result, retrieve from each alarm mapping template the alarm mapping template whose alarm identifier matches the data processing result;
[0154] Fill the data processing result into the alarm description of the alarm mapping template to display the data processing result in the format specified by the alarm mapping template;
[0155] Among them, the display content of the alarm mapping template includes an alarm identifier, an alarm name, an alarm level, and an alarm description.
[0156] This embodiment takes into account that the alarm mapping template may include specific template header data and template value data composed of alarm metadata spliced together. The template header data may include a special "alarm identifier" metadata field, based on which the matching of the data processing result is performed. Refer to Figure 4 , which is a schematic diagram of the alarm mapping template in a specific embodiment, and Figure 4The manufacturer model numbers shown in the examples refer to the fact that in actual applications, alarm mapping templates can be classified and managed according to the manufacturer model numbers, and Figure 4 shows two specific alarm mapping templates. Different alarm mapping templates have different alarm identifiers.
[0157] It is possible to traverse the alarm identifiers of each alarm mapping template. When an alarm identifier is consistent with the relevant content in the data processing result, it can be determined that the alarm identifier matches the data processing result. For example, the alarm identifier of a certain alarm mapping template is specifically 1.3.6.1.4.1.37945.1.1.205, and this alarm identifier is consistent with the alarm metadata field in the data processing result. Then it can be determined that the alarm mapping template where this alarm identifier is located is the alarm mapping template that needs to be used. Furthermore, the data processing result is filled into the alarm description of the alarm mapping template. Specifically, based on the special marker "flag" and the alarm metadata field in the data processing result, the corresponding content is filled into the corresponding position in the alarm description of the alarm mapping template, thereby generating one alarm.
[0158] In addition, for any data processing result, if no matching alarm mapping template can be found, the data processing result can be marked and filled into a pre-set general alarm mapping template to generate one alarm.
[0159] In the solution of this application, after receiving the original alarm message, the original message will be converted into a unified structure for subsequent analysis and processing, so as to effectively cope with the wide range of sources and diverse protocols of alarm information. Specifically, the original message is uniformly converted into each piece of alarm data in the key-value pair structure, and the key in each piece of alarm data reflects the path information of the alarm data. Subsequently, in order to facilitate matching with the alarm decomposition template, feature extraction will be performed on each piece of alarm data. Specifically, a first feature tree is established to reflect the path information of the keys in each piece of alarm data, and feature extraction is performed on the first feature tree to obtain a feature set. It should be noted that for each piece of alarm data, only the alarm decomposition template that matches its key data is needed to process the data of this alarm data. However, if traversed one by one, the efficiency is relatively low. Therefore, in the solution of this application, the matching degree of each alarm decomposition template and the feature set will be obtained and sorted in descending order to obtain the sorting result of the alarm decomposition template. When matching, the alarm decomposition template is selected in the order of the sorting result to match the alarm data. And it can be understood that the higher the matching degree of a certain alarm decomposition template and the feature set, the greater the possibility that the alarm decomposition template can successfully match the key data of the alarm data. Therefore, it also means that the solution of this application can quickly locate the alarm decomposition template that matches the alarm data, ensuring the execution efficiency of the solution of this application and saving computing resources. After processing the data of the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data, finally, the data processing result can be filled into the corresponding alarm mapping template. Since the data processing result is displayed in the format specified by the alarm mapping template, the unified display problem of differential alarms can be solved.
[0160] In summary, the solution of this application can effectively cope with alarm information from different device sources and different protocols, achieve unified display, and the execution process is efficient, saving computing resources. In addition, it can be seen that the solution of this application realizes the processing and display of alarm information based on the alarm decomposition template and the alarm mapping template. Therefore, the situation where a bound alarm parsing module needs to be developed for each device model in the traditional solution will not occur. When encountering iterative updates of alarms, only the relevant templates need to be updated, which is simple and convenient to operate, has high flexibility, and low maintenance complexity.
[0161] Corresponding to the above method embodiment, the embodiment of the present invention also provides an alarm information management system, which can be mutually referred to with the above text.
[0162] Refer to Figure 5 , the alarm information management system may include:
[0163] The preprocessing module 501 is configured to receive the original alarm message and convert the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of the alarm data reflects the path information of the alarm data;
[0164] The feature extraction module 502 is configured to establish a first feature tree for reflecting the path information of the keys in each piece of the alarm data, and perform feature extraction on the first feature tree to obtain a feature set;
[0165] The sorting module 503 is configured to obtain the matching degree of each alarm decomposition template with the feature set, and sort them in descending order to obtain the sorting result of the alarm decomposition templates;
[0166] The decomposition module 504 is configured to, for each piece of the alarm data, select an alarm decomposition template in the order of the sorting result to perform key data matching on the alarm data. When the matching is successful, perform data processing on the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data;
[0167] The mapping module 505 is configured to, for any one of the data processing results, fill the data processing result into a matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
[0168] Corresponding to the above method and system embodiments, the embodiments of the present invention further provide a management device for alarm information, a computer-readable storage medium, and a computer program product, which can be correspondingly referred to the above.
[0169] See Figure 6 As shown, the device may include:
[0170] A memory 601 for storing computer programs;
[0171] A processor 602 for executing the computer program to implement the steps of the method for managing alarm information in any of the above embodiments.
[0172] The computer program product includes computer programs / instructions, and when the computer programs / instructions are executed by the processor, the steps of the method for managing alarm information in any of the above embodiments are implemented.
[0173] See for reference Figure 7, a computer program 71 is stored on the computer-readable storage medium 70. When the computer program 71 is executed by a processor, it implements the steps of the management method of alarm information in any of the above embodiments. The computer-readable storage medium 70 mentioned here includes RAM (Random Access Memory), memory, ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), registers, hard disks, removable disks, or any other form of storage medium known in the technical field.
[0174] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0175] Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the technical solution and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
Claims
1. A method for managing alarm information, characterized in that, It includes: Receiving the original alarm message and converting the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of the alarm data reflects the path information of the alarm data; Establishing a first feature tree for reflecting the path information of the keys in each piece of the alarm data, and performing feature extraction on the first feature tree to obtain a feature set; Obtaining the matching degree of each alarm decomposition template with the feature set, and sorting them in descending order to obtain the sorting result of the alarm decomposition templates; For each piece of the alarm data, selecting alarm decomposition templates in the order of the sorting result to perform key data matching on the alarm data. When the matching is successful, performing data processing on the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data; For any one of the data processing results, filling the data processing result into a matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
2. The management method of the warning information according to claim 1, wherein Receiving the original alarm message and converting the original message into each piece of alarm data in a key-value pair structure, including: Receiving the original alarm message, and based on the type of the original message, using the corresponding conversion rule to convert the original message into each piece of alarm data in a key-value pair structure.
3. The management method of the warning information according to claim 2, wherein Receiving the original alarm message, and based on the type of the original message, using the corresponding conversion rule to convert the original message into each piece of alarm data in a key-value pair structure, including: Receiving the original alarm message; When the original message is an original message of the object identifier type, using the object identifier of the original message as the key and the alarm content in the original message as the value to obtain each piece of alarm data in a key-value pair structure; When the original message is an original message of the request type, generating a key based on the path structure of the original message and using the corresponding content of the key as the value to obtain each piece of alarm data in a key-value pair structure; When the original message is an original message of the software development kit type, generating a key based on the class path and class fields of the original message and using the corresponding content of the key as the value to obtain each piece of alarm data in a key-value pair structure.
4. The management method of the warning information according to claim 1, characterized in that, Establishing a first feature tree for reflecting the path information of the keys in each piece of the alarm data, including: Creating an empty node as the root node of the first feature tree; For each piece of the alarm data, adding the key of the alarm data to the first feature tree by using the hierarchical structure of the key of the alarm data as a node in the first feature tree; Wherein, in different pieces of the alarm data, the same hierarchical structure corresponds to the same node in the first feature tree.
5. The management method of the alarm information according to claim 4, wherein Performing feature extraction on the first feature tree to obtain a feature set, including: Deleting the root node of the first feature tree; Taking each child node under the root node of the first feature tree as the starting node of each recursive path; For any one of the recursive paths, when the recursive path has no bifurcation, taking the recursive path as a feature path in the feature set; For any one of the recursive paths, when there is a fork in the recursive path, the path content from the starting node of the recursive path to the node where the fork first occurs is used as a feature path in the feature set.
6. The management method of the warning information according to claim 1, wherein Obtain the matching degree of each alarm decomposition template with the feature set, including: For each alarm decomposition template, obtain the feature extraction result of each alarm decomposition template; For any one of the alarm decomposition templates, through the calculation method, obtain the matching degree between the alarm decomposition template and the feature set; Among them, S represents the matching degree between the alarm decomposition template and the feature set, and T represents the feature set. represents the feature extraction result of the alarm decomposition template; is the intersection operator, is the union operator, and the operator represents the size of the set.
7. The management method of the alarm information according to claim 6, wherein, For each alarm decomposition template, obtaining the feature extraction result of each alarm decomposition template includes: For any one of the alarm decomposition templates, obtain the alarm key data in each decomposition rule of the alarm decomposition template; Based on the alarm key data in each decomposition rule, establish a second feature tree for reflecting the path information of each alarm key data, and perform feature extraction on the second feature tree to obtain the feature extraction result of the alarm decomposition template.
8. The management method of alarm information according to claim 1, characterized in that Obtain the matching degree of each alarm decomposition template with the feature set, and sort them in descending order to obtain the sorting result of the alarm decomposition templates, including: Obtain the matching degree of each alarm decomposition template with the feature set, delete the matching degrees with a value of 0, and based on the remaining matching degrees, establish a matching degree threshold; Retain the matching degrees higher than the matching degree threshold, and sort the alarm decomposition templates corresponding to the retained matching degrees in descending order of the matching degree to obtain the sorting result of the alarm decomposition templates.
9. The management method of the alarm information according to claim 8, wherein Based on the remaining matching degrees, establish a matching degree threshold, including: Based on each remaining matching degree after deleting the matching degrees with a value of 0, through the calculation method, a matching degree threshold is established; Among them, threshold represents the established matching degree threshold, and u and respectively represent the average value and standard deviation of each remaining matching degree after deleting the matching degrees with a value of 0, and k is a preset proportionality coefficient.
10. The management method of alarm information according to claim 1, characterized in that For any one of the data processing results, fill the data processing result into the matching alarm mapping template to display the data processing result in the format specified by the alarm mapping template, including: For any one of the data processing results, retrieve from each alarm mapping template the alarm mapping template whose alarm identifier matches the data processing result; Fill the data processing result into the alarm description of the alarm mapping template to display the data processing result in the format specified by the alarm mapping template; Among them, the display content of the alarm mapping template includes an alarm identifier, an alarm name, an alarm level, and an alarm description.
11. The management method of alarm information according to any one of claims 1 to 10, characterized in that It also includes: Obtain each initial decomposition template; where a single initial decomposition template includes one or more decomposition rules; each decomposition rule includes preset alarm key data, a preset alarm value data processing method, and a preset alarm metadata label; Group each of the initial decomposition templates according to the classification method of dividing them into the same group according to the same manufacturer to obtain a first grouping set; Determine the central template of each group in the first grouping set; where for any one group, the central template of the group represents the initial decomposition template with the highest matching degree among all the initial decomposition templates in the group; Using each of the central templates as a clustering center, group each of the initial decomposition templates again to obtain a second grouping set; Take the second grouped set as the final grouped set, and merge and deduplicate the initial decomposition templates in the same group in the final grouped set, and use the obtained result as each obtained alarm decomposition template; Among them, in the process of merging and deduplicating the initial decomposition templates in the same group in the final grouped set, when there are two or more decomposition rules with the same alarm key data, only one of the decomposition rules is retained.
12. The management method of the warning information according to claim 11, characterized in that, It also includes: After obtaining the second grouped set, extract the groups in the second grouped set where the number of templates in the group is equal to 1, and place them in the to-be-completed grouped set; Take the remaining content after extraction as the third grouped set; For each group in the third grouped set where the number of templates exceeds the threshold range, use the initial decomposition template with the lowest matching degree with the central template of the group as the new central template; Take the central template of each group in the third grouped set and each of the new central templates as the clustering centers, and re-group the initial decomposition templates in the third grouped set to obtain the fourth grouped set; Correspondingly, taking the second grouped set as the final grouped set includes: Take the fourth grouped set and the to-be-completed grouped set as the final grouped set.
13. A management system for alarm information, characterized in that, It includes: A preprocessing module for receiving the original message of the alarm and converting the original message into each piece of alarm data in a key-value pair structure; wherein, the key in each piece of alarm data reflects the path information of the alarm data; A feature extraction module for establishing a first feature tree for reflecting the path information of the keys in each piece of alarm data, and performing feature extraction on the first feature tree to obtain a feature set; A sorting module for obtaining the matching degree of each alarm decomposition template with the feature set respectively, and sorting them in descending order to obtain the sorting result of the alarm decomposition templates; A decomposition module for, for each piece of alarm data, selecting alarm decomposition templates in the order of the sorting result to perform key data matching on the alarm data, and when the matching is successful, performing data processing on the alarm data through the successfully matched alarm decomposition template to obtain the data processing result of the alarm data; A mapping module for, for any one of the data processing results, filling the data processing result into the corresponding alarm mapping template to display the data processing result in the format specified by the alarm mapping template.
14. A management device for alarm information, characterized in that, It includes: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the alarm information management method according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, The computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, it implements the steps of the alarm information management method according to any one of claims 1 to 12.