Root cause positioning method and device for abnormal event, equipment and program product

By defining a single causal link and suppression time relationship in the rule base, the challenge of knowledge graph maintenance difficulty and rapid identification of core problems is solved, and the effect of simplifying topology and reducing alarms is achieved.

CN120301757APending Publication Date: 2025-07-11TP-LINK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510673799.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, general expert knowledge graphs are difficult to adapt to the complex and changeable topological structure of users on site, resulting in increased difficulty in maintaining knowledge graphs. In addition, a single root may cause a large number of derivative events, making it difficult for operation and maintenance personnel to quickly identify core problems.

Method used

By defining a single causal link, including a single root cause event and a single derived event in the rule base, the corresponding relationship between the preset causal link and the suppression time is used to determine the causal link and event type of the target event, and event suppression is performed.

Benefits of technology

Simplified topological structure analysis, reduced reporting of unimportant events, helped quickly identify core issues, reduced data maintenance costs, and effectively reduced the number of alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301757A_ABST
    Figure CN120301757A_ABST
Patent Text Reader

Abstract

The invention relates to the field of equipment management, in particular to an abnormal event root cause analysis method and device, equipment and a program product. The method comprises the steps of obtaining a target event of equipment; according to a root cause event and a derivative event included in a causal link in a preset rule base, determining the causal link to which the target event belongs, determining the event type of the target event, and according to the corresponding relation between the preset causal link and the inhibition duration, determining the inhibition duration of the target event. And determining a target suppression duration corresponding to a target causal link to which the target event belongs, and performing event suppression according to the target suppression duration and the event type. According to the method, an event topological structure can be effectively simplified, maintenance is easier, reporting of unimportant events can be greatly reduced, and core problems can be rapidly identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of device management, and particularly to a method, apparatus, device, and program product for root cause analysis of abnormal events. Background Art

[0002] During the operation of a device, network anomalies may occur. The device can report a diagnostic request for a network anomaly event. Through a root cause location system formed by an expert knowledge base for cloud service failures established, starting from the device that receives the diagnostic request, multiple target events involved in the diagnostic object are determined, and at least one target node device associated with the target event among multi-level node devices is determined to form an event propagation path. This process requires pruning using the topological relationship of node devices and problem location using a knowledge graph.

[0003] However, in network management software, a general expert knowledge graph may not conform to the complex and changeable topological structure of the user's site. Moreover, as the types of devices increase, the difficulty of maintaining the graph also increases. And a single root cause event may generate a large number of derivative events, making it easy for operation and maintenance personnel to be overwhelmed by a large number of alarms and difficult to quickly identify the core problem. Summary of the Invention

[0004] In view of this, embodiments of this application provide a method, apparatus, device, and program product for root cause analysis of abnormal events to solve the problems in the prior art that the difficulty of maintaining the graph increases and it is difficult to quickly identify the core event.

[0005] The first aspect of the embodiments of this application provides a method for root cause analysis of abnormal events. The method includes:

[0006] Obtain the target event of the device;

[0007] According to the root cause event and derivative event included in the causal link in the preset rule library, determine the causal link to which the target event belongs and determine the event type of the target event. Wherein, a single causal link includes a single root cause event and a single derivative event, and the root cause event in the causal link causes the occurrence of the derivative event;

[0008] According to the corresponding relationship between the preset causal link and the suppression duration, determine the target suppression duration corresponding to the target causal link to which the target event belongs, and perform event suppression according to the target suppression duration and the event type.

[0009] Combined with the first aspect, in the first possible implementation manner of the first aspect, according to the corresponding relationship between the preset causal link and the suppression duration, determine the target suppression duration corresponding to the target causal link to which the target event belongs, and perform event suppression according to the target suppression duration and the event type, including:

[0010] When, in the causal link to which the target event belongs in the rule base, the event type of the target event includes a derivative event, search for the causal link to which the target event belongs when it is a derivative event;

[0011] According to the preset correspondence between the causal link and the suppression duration, determine the target suppression duration corresponding to the found causal link and the first occurrence time of the event in the causal link;

[0012] According to the target suppression duration and the first occurrence time of the event in the causal link, determine the first suppression time window of the target event;

[0013] Suppress the target event according to the first suppression time window.

[0014] Combined with the first possible implementation manner of the first aspect, in the second possible implementation manner of the first aspect,

[0015] Suppressing the target event according to the first suppression time window includes:

[0016] Detect whether the root cause event corresponding to the target event as a derivative event is received within the first suppression time window. If the root cause event is received within the first suppression time window, then suppress the target event.

[0017] Combined with the first possible implementation manner of the first aspect, in the third possible implementation manner of the first aspect, determining the first suppression time window of the target event according to the target suppression duration and the first occurrence time of the event in the causal link includes:

[0018] When the target event is a derivative event of multiple causal links, determine multiple suppression time sub-windows of the target event according to multiple target suppression durations and multiple first occurrence times of the events;

[0019] Determine the first suppression time window according to the union of the multiple suppression time sub-windows.

[0020] Combined with the first possible implementation manner of the first aspect, in the fourth possible implementation manner of the first aspect, that the event type of the target event includes a derivative event in the causal link to which the target event belongs in the rule base includes:

[0021] In the causal link to which the target event belongs in the rule base, the event types of the target event are all derivative events;

[0022] In the causal link to which the target event belongs in the rule base, the event type of the target event includes a derivative event and a root cause event.

[0023] In combination with the first aspect, in the fifth possible implementation manner of the first aspect, according to the correspondence relationship between the preset causal link and the suppression duration, determine the target suppression duration corresponding to the target causal link to which the target event belongs, and perform event suppression according to the target suppression duration and the event type, including:

[0024] When, among the causal links to which the target event belongs in the rule base, the event types of the target event are all root cause events, determine the derivative events in the causal link to which the target event belongs in the rule base, and the suppression duration corresponding to the causal link to which it belongs;

[0025] Report the target event, and perform event suppression on the derivative event according to the suppression duration.

[0026] In combination with the fifth possible implementation manner of the first aspect, in the sixth possible implementation manner of the first aspect, determine the derivative events in the causal link to which the target event belongs in the rule base, and the suppression duration corresponding to the causal link to which it belongs, including:

[0027] When there are multiple causal links in the rule base with the target event as the root cause event, determine the derivative events in each causal link, and the suppression duration corresponding to each causal link;

[0028] Performing event suppression on the derivative event according to the suppression duration includes:

[0029] According to the occurrence time of the target event, combine the suppression durations corresponding to each causal link to determine the suppression time window corresponding to each causal link;

[0030] Perform event suppression on the corresponding derivative event according to the suppression time window corresponding to each causal link.

[0031] The second aspect of the embodiments of the present application provides a root cause analysis method for abnormal events, and the method includes:

[0032] A target event acquisition unit, configured to acquire a target event of a device;

[0033] A causal link determination unit, configured to determine the causal link to which the target event belongs, and determine the event type of the target event according to the root cause event and the derivative event included in the causal link in the preset rule base, where a single causal link includes a single root cause event and a single derivative event, and the root cause event in the causal link causes the occurrence of the derivative event;

[0034] An event suppression unit, configured to determine a target suppression duration corresponding to a target causal link to which the target event belongs according to a preset correspondence between the causal link and the suppression duration, and perform event suppression according to the target suppression duration and the event type.

[0035] In a third aspect of the embodiments of the present application, a root cause analysis device for abnormal events is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the root cause analysis device for abnormal events implements the method according to any one of the first aspects.

[0036] In a fourth aspect of the embodiments of the present application, a computer program product is provided, which, when running on a computer, causes the computer to execute the method in the first aspect or its various implementation manners.

[0037] In a fifth aspect of the embodiments of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of the first aspects are implemented.

[0038] In a sixth aspect of the embodiments of the present application, a chip is provided for implementing the methods in the various implementation manners in the first aspect. Specifically, the above chip includes: a processor, configured to call and run a computer program from a memory, so that a device installed with the above chip executes the method according to the first aspect or its various implementation manners.

[0039] The beneficial effects of the embodiments of the present application compared with the prior art are as follows: For the target event of the device obtained in the embodiments of the present application, a causal link is searched in a preset rule library, and the target event is compared with the root cause event and the derivative event in the causal link to determine the causal link to which the target event belongs, and the event type of the target event in each causal link to which it belongs. Since only a single root cause event and a single derivative event are included in a single causal link, the topological structure is simple and maintenance is easier. According to the correspondence between the causal link and the suppression duration, the target suppression duration corresponding to the causal link to which the target event belongs can be determined, and event suppression is performed on the event according to the target suppression duration and the event type, which can greatly reduce the reporting of unimportant events and is beneficial to quickly identifying the core problem. Description of the Drawings

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0041] Figure 1 It is a schematic diagram of the implementation scenario of a root cause analysis method for abnormal events provided by an embodiment of the present application;

[0042] Figure 2 It is a schematic diagram of the implementation process of a root cause analysis method for abnormal events provided by an embodiment of the present application;

[0043] Figure 3 It is a schematic diagram of an alarm rule configuration provided by an embodiment of the present application;

[0044] Figure 4 It is a schematic diagram of the causal link of a rule library provided by an embodiment of the present application;

[0045] Figure 5 It is a schematic diagram of a root cause analysis device for abnormal events provided by an embodiment of the present application;

[0046] Figure 6 It is a schematic diagram of a root cause analysis device for abnormal events provided by an embodiment of the present application. Detailed implementation manners

[0047] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0048] In order to illustrate the technical solutions described in the present application, the following will be described through specific embodiments.

[0049] During the operation of the device, network abnormality problems may occur. To solve these problems, the device can report a diagnosis request for network abnormal events. By using a root cause location system constructed based on a cloud service failure expert knowledge base, starting from the device that receives the diagnosis request, multiple target events are determined, as well as at least one target node device associated with the target events among the multi-level node devices, thereby forming an event propagation path. This process needs to prune with the help of the topological relationship of the node devices and use a knowledge graph to complete problem location.

[0050] However, the general expert knowledge graph in the network management software may not be able to adapt to the complex and changeable topological structure of the user site. As the types of devices increase, the maintenance difficulty of the knowledge graph is also increasing. In addition, a single root cause event may trigger a large number of derivative events, causing the operation and maintenance personnel to be inundated with a huge amount of alarm information and making it difficult to quickly identify the core problem.

[0051] To solve the above problems, an embodiment of the present application proposes a root cause analysis method for abnormal events. Figure 1 It is a schematic diagram of the implementation scenario of this method. In this implementation scenario, it includes a management platform and multiple devices. Figure 1 In the example of, the devices include Device A, Device B, and Device C. Among them, each device has a corresponding event capability set. The event capability set is a set of various events (Event) that the device can recognize, process, and respond to during operation. After the device recognizes an event, it will send the event to the management platform through active reporting or platform polling.

[0052] A rule library is maintained in the management platform, and causal links are stored in the rule library. Each causal link includes a single root cause event and a single derivative event. Among them, the root cause event is the reason for the generation of the derivative event, and the derivative event is the result of the root cause event. The management platform can be used to obtain the target event of the device; determine the causal link to which the target event belongs and the event type of the target event according to the root cause event and the derivative event included in the causal link in the preset rule library; determine the target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and perform event suppression according to the target suppression duration and the event type, including releasing the target event or suppressing the target event. Releasing the target event may include generating an alarm message for the target event, and suppressing the target event includes ignoring the alarm message of the target event.

[0053] Figure 2 It is a schematic diagram of the implementation process of a root cause analysis method for abnormal events provided by an embodiment of the present application, which is described in detail as follows:

[0054] In S201, obtain the target event of the device.

[0055] When obtaining the target event of the device, it is usually achieved through two methods: active reporting by the device or active polling by the cloud. For example, a certain switch triggers Event A due to the CPU utilization rate exceeding the threshold and reports it to the management platform through SNMP (Simple Network Management Protocol). The event content includes metadata such as timestamp, device ID, and event type, which is marked as a "target event" to be processed after being parsed by the cloud. When obtaining the target event through the active polling method of the cloud, the events can be queried at a predetermined time interval to obtain the event information in each device.

[0056] In S202, determine the causal link to which the target event belongs and the event type of the target event according to the root cause event and the derivative event included in the causal link in the preset rule library.

[0057] Among them, a single causal link includes a single root cause event and a single derivative event, and the root cause event in the causal link causes the occurrence of the derivative event.

[0058] For the obtained target event, the system needs to determine whether the target event belongs to a part of a preset causal link. Analyze according to the root cause events and derivative events included in the causal links of the preset rule base. Among them, the logical relationship between the root cause event and the derivative event is a causal relationship. The root cause event is the reason for the occurrence of the derivative event, and the derivative event is the result caused by the root cause event.

[0059] The event types in the embodiments of this application include root cause events and derivative events. The same target event may belong to different event types in different causal links. For example, the rule base includes event A, event B, and event C. Among them, event A and event B form a causal link, expressed as "event A → event B", indicating that event A is the root cause event of event B, and event B is the derivative event of event A. In addition, event B and event C form a causal link, expressed as "event B → event C", indicating that event B is the root cause event of event C, and event C is the derivative event of event B. In this example, event B can be either a root cause event or a derivative event in the rule base. For example, in the causal link of event B → event C, event B is the root cause event, and in the causal link of event A → event B, event B is the derivative event.

[0060] For the above propagation link event A → event B → event C, the causal link event A → event C can be supplemented so that each level of event has a causal relationship only with the adjacent event.

[0061] Through the design of the above causal link, the link analysis work is effectively simplified. For the original root cause graph structure learning and parameter learning to be processed, it can be directly bypassed. The causal relationship of each event only needs to understand the adjacent events. In addition, the causal link effectively improves the robustness of the root cause analysis function. In a complex network topology, device events may not be reported in a timely manner, that is, it cannot be assumed that the device has the ability to detect event B and event B will definitely be reported to the cloud. Through the supplemented causal link, directly according to the causal link of event A and event C, after obtaining event C and event A, it can be determined that the root cause of event C is event A.

[0062] In the rule base, the event types of some events may only be root cause events. For example, the causal link in the rule base includes the causal link of event D as event D → event E and event D → event F. Event D only exists as a root cause event in the rule base.

[0063] In addition, the event types of some events may only be derivative events. For example, in the causal links in the rule base, the causal links including event G are event H → event G and event I → event G. Event G only exists as a derivative event in the rule base.

[0064] Affected by the perfection degree of the rule base, some events may not have corresponding causal links in the rule base. In this case, if the target event fails to match the corresponding causal link in the rule base, that is, among all the causal links in the rule base, the target event is neither a root cause event nor a derivative event, then the target event can be released. For example, for the target event actively reported by the device or the target event obtained through polling, alarm information can be generated according to the target event.

[0065] In the embodiments of the present application, the management platform can preset rules for event conversion to alarms according to network operation and maintenance experience or knowledge accumulation, such as Figure 3 As shown, in the rule base for event conversion to alarms, it is possible to set the core switch device offline event A and the core switch device offline alarm A', the CPU usage rate exceeding the threshold event B and the CPU usage rate exceeding 90% alarm B', etc. Users can add, delete alarm rules or modify the detection threshold according to their own needs, such as Figure 3 As shown, it is possible to add a new alarm B" for the CPU usage rate exceeding 80%. Multiple alarms can be configured for one event, and multiple different events can also be configured as the same alarm.

[0066] In the embodiments of the present application, for scenarios where the existing causal links in the rule base do not meet the detection requirements or reporting requirements, new causal links can be added and incorporated into the rule base.

[0067] In S203, according to the corresponding relationship between the preset causal link and the suppression duration, determine the target suppression duration corresponding to the target causal link to which the target event belongs, and perform event suppression according to the target suppression duration and the event type.

[0068] The rule base in the embodiments of the present application can be set to a structure of a bucket + a linear list. Among them, the root cause events in all causal links are set in the bucket, and the derivative events corresponding to each root cause event are associated with the root cause events in the bucket through a linear list outside the bucket. In the linear list, each derivative event associated with each root cause event is associated with the suppression duration. Through the form of the bucket + the linear list, the dimensionality of the causal link structure can be reduced, the structure of the analysis graph can be disassembled and reduced in dimension, the coupling relationship between complex root cause rules can be reduced, and it is beneficial to reduce the data maintenance cost. As Figure 4 As shown in the schematic diagram of the structure of the root cause event and the derivative event, each root cause event (such as Figure 4Among events A, B, C, and D), corresponding derivative events of the root cause event can be mounted (for example, for root cause event A, the corresponding derivative events include event C and event D, etc.). The causal link determined by each root cause event and derivative event corresponds to an inhibition duration. For example Figure 4 As shown, for the causal link determined by root cause event A and derivative event C, the inhibition duration corresponding to this causal link is T1, and the inhibition duration for the causal link determined by root cause event A and derivative event D is T2. The inhibition duration for root cause event B and derivative event E is T3, the inhibition duration for root cause event C and derivative event B is T4, and the inhibition duration for root cause event D and derivative event A is T5. For event F, no corresponding causal link is found in the rule library.

[0069] It can be seen from Figure 4 that when matching the obtained target event in the rule library, the same target event may include the following three situations.

[0070] Situation 1: Such an event is not found for the target event, and the target event can be directly released. For example Figure 4 event F in

[0071] Situation 2: In the causal links belonging to the rule library, the event type of the target event includes derivative events. In the causal links to which it belongs, all of the target events can be derivative events, or some can be derivative events and some can be root cause events. For example Figure 4 As shown, events B, C, and D in the rule library can exist in the causal link as root cause events or as derivative events. Event E in the rule library is all derivative events.

[0072] Situation 3: In the causal links belonging to the rule library, the event types of the target events are all root cause events. For example Figure 4 event A shown, which only exists as a root cause event in the causal link.

[0073] If the target event belongs to Situation 2, it means that the currently detected target event can be either a root cause event or a derivative event. In this case, based on the causal link to which the target event belongs as a derivative event and the inhibition duration corresponding to the causal link, the target inhibition duration corresponding to the causal link can be found. Based on the first occurrence time of the events in the causal link and combined with the target inhibition duration, the first inhibition time window of the target event is determined. According to this first inhibition time window, it is determined whether the target event needs to be inhibited, that is, to release the target event or inhibit the target event.

[0074] For example, in the causal link where the target event exists as a derivative event, and the first occurrence time of the nearest event that can be found is t1, and the target suppression duration corresponding to this causal link is T, the determined first suppression time window can be [t1 - T, t1 + T], indicating that within the 2T time range before and after the occurrence time of the root cause event, the alarm of the target event is suppressed. Among them, suppressing the alarm of the target event can include that when the occurrence time of the target event is within this time range, only the alarm of the first target event is generated, or no alarm of the target event is generated.

[0075] If possible, the target event may be a derivative event and belong to multiple causal links. In this case, multiple target suppression durations can be determined according to the multiple causal links. Based on the multiple target suppression durations and the first occurrence times of the events in the multiple causal links, multiple suppression time sub-windows are determined respectively. For example, when the target event is a derivative event, it belongs to three causal links. According to the target suppression durations (T2, T3, and T4) corresponding to the three causal links, and the first occurrence times (t2, t3, and t4) of the events in the three causal links, three suppression time sub-windows can be determined, namely suppression time sub-window 1, suppression time sub-window 2, and suppression time sub-window 3, which are respectively expressed as: [t2 - T2, t2 + T2], [t2 - T3, t3 + T3], and [t4 - T4, t4 + T4]. The first suppression time window is determined according to the union of the multiple suppression time sub-windows, and the target event is suppressed. If the target event belongs to this first suppression time window, the target event is suppressed; otherwise, the target event is released.

[0076] In a possible implementation manner, in the causal link to which the target event belongs in the rule base, the event types of the target event are all root cause events. In this case, the suppression duration of the target event can be determined according to the causal link to which the target event belongs, and the derivative events in the causal link are suppressed according to the suppression duration.

[0077] For example, it is detected that the target event A belongs to the causal link event A → event B in the rule base, event A is the root cause event, and event B is the derivative event. The suppression duration corresponding to this causal link is Ta. The suppression time window of event B is determined as [ta - T, ta + T] according to the occurrence time ta of the target event A. Event B is suppressed within this time range.

[0078] In a possible implementation, when the same event is the root cause event, it may correspond to multiple derivative events. At this time, multiple causal links determined by the root cause event and the multiple derivative events can be used to determine the suppression duration corresponding to each causal link and the derivative events of each causal link. According to the occurrence time of the target event and in combination with the suppression durations of each causal link, suppression time windows corresponding to the multiple causal links can be obtained. Through each suppression time window, the corresponding derivative events are suppressed.

[0079] For example, the derivative events associated with the target event A include event B and event C, which are causal link 1 and causal link 2 respectively, and the corresponding suppression durations are Tb and Tc respectively. The occurrence time of the target event A is Ta. Then the suppression time window of causal link 1 is [Ta - Tb, Ta + Tb], and the suppression time window corresponding to causal link 2 is [Ta - Tc, Ta + Tc]. Event B is suppressed through the suppression time window [Ta - Tb, Ta + Tb], and event C is suppressed through the suppression time window [Ta - Tc, Ta + Tc].

[0080] In the embodiment of the present application, the derivative events are suppressed through the suppression time window, which means that if the derivative event is within the suppression time window, the derivative event is suppressed; if it is outside the suppression time window, a new suppression time window is opened, and suppression judgment is made according to the new suppression time window. If more than two suppression time windows suppress the same event, as long as the conclusion drawn from any one of the suppression time windows is suppression, the event will be suppressed.

[0081] In addition, in the embodiment of the present application, after determining the target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, if the target event is obtained again within the suppression time window determined by the target suppression duration, that is, the target event is repeatedly obtained, and the target event includes derivative events in the causal link, it can be judged whether the root cause event in the causal link is received within the target suppression duration. If the root cause event in the causal link where the target event is located is received, the target event within the target suppression duration is suppressed.

[0082] In the embodiment of the present application, by disassembling and dimension-reducing the structure of the analysis graph, the coupling relationship between complex root cause rules is reduced, the maintenance cost of the data structure in the software is reduced, and the causal links in the rule library can be customized, which is beneficial to adapting to various network topologies and user requirements. Through the corresponding relationship between the suppression duration corresponding to the causal link, the event is suppressed, which can effectively reduce the number of event alarms and is beneficial to more effectively determining the root cause event. In addition, the alarm rules of the event can be set to perform real-time detection on the reported data during the operation of the software, which helps to detect potential problems early and control the risk of major faults.

[0083] It should be understood that the sequence numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0084] Figure 5 The figure is a schematic diagram of a root cause analysis device for abnormal events provided by an embodiment of the present application. The device includes:

[0085] A target event acquisition unit 501, configured to acquire a target event of a device;

[0086] A causal link determination unit 502, configured to determine the causal link to which the target event belongs and determine the event type of the target event according to the root cause event and derivative event included in the causal link in a preset rule library. Wherein, a single causal link includes a single root cause event and a single derivative event, and the root cause event in the causal link causes the occurrence of the derivative event;

[0087] An event suppression unit 503, configured to determine a target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and perform event suppression according to the target suppression duration and the event type.

[0088] Figure 5 The root cause analysis device for abnormal events shown Figure 2 corresponds to the root cause analysis method for abnormal events shown.

[0089] Figure 6 The figure is a schematic diagram of a root cause analysis device for abnormal events provided by an embodiment of the present application. As Figure 6 shown, the root cause analysis device 6 for abnormal events in this embodiment includes: a processor 60, a memory 61, and a computer program 62 stored in the memory 61 and executable on the processor 60, such as a root cause analysis program for abnormal events. When the processor 60 executes the computer program 62, the steps in the above embodiments of the root cause analysis method for abnormal events are implemented. Or, when the processor 60 executes the computer program 62, the functions of each module / unit in the above device embodiments are implemented.

[0090] Exemplarily, the computer program 62 can be divided into one or more modules / units. The one or more modules / units are stored in the memory 61 and executed by the processor 60 to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program 62 in the root cause analysis device 6 for abnormal events.

[0091] The root cause analysis device 6 for the abnormal event may be a computing device such as a desktop computer, a notebook, a palmtop computer, or a cloud server. The root cause analysis device for the abnormal event may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art can understand that Figure 6 This is only an example of the root cause analysis device 6 for an abnormal event, and does not constitute a limitation on the root cause analysis device 6 for the abnormal event. It may include more or fewer components than those shown in the figure, or combine some components, or different components. For example, the root cause analysis device for the abnormal event may further include input / output devices, network access devices, buses, etc.

[0092] The so-called processor 60 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0093] The memory 61 may be an internal storage unit of the root cause analysis device 6 for the abnormal event, such as the hard disk or memory of the root cause analysis device 6 for the abnormal event. The memory 61 may also be an external storage device of the root cause analysis device 6 for the abnormal event, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the root cause analysis device 6 for the abnormal event. Further, the memory 61 may also include both the internal storage unit and the external storage device of the root cause analysis device 6 for the abnormal event. The memory 61 is used to store the computer program and other programs and data required by the root cause analysis device for the abnormal event. The memory 61 may also be used to temporarily store the data that has been output or will be output.

[0094] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and do not limit the protection scope of this application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.

[0095] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0096] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in the form of hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0097] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.

[0098] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0099] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0100] If the above integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, all or part of the processes in the above method embodiments of the present application can also be completed by hardware related to computer program instructions. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0101] In addition, the embodiments of the present application also provide a computer program product, which when running on a computer, causes the computer to execute the methods in the above implementation manners.

[0102] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A root cause analysis method for abnormal events, characterized in that, The method includes: Obtaining a target event of a device; Determining the causal link to which the target event belongs and determining the event type of the target event according to the root cause event and derivative event included in the causal link in a preset rule base, where a single causal link includes a single root cause event and a single derivative event, and the root cause event in the causal link causes the occurrence of the derivative event; Determining a target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and performing event suppression according to the target suppression duration and the event type.

2. The method according to claim 1, characterized in that, Determining a target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and performing event suppression according to the target suppression duration and the event type, including: When the event type of the target event includes a derivative event in the causal link to which the target event belongs in the rule base, searching for the causal link to which the target event belongs when the target event is a derivative event; Determining the target suppression duration corresponding to the found causal link and the first occurrence time of the event in the causal link according to the corresponding relationship between the preset causal link and the suppression duration; Determining a first suppression time window of the target event according to the target suppression duration and the first occurrence time of the event in the causal link; Performing event suppression on the target event according to the first suppression time window.

3. The method according to claim 2, characterized in that Performing event suppression on the target event according to the first suppression time window, including: Detecting whether the root cause event corresponding to the target event as a derivative event is received within the first suppression time window, and if the root cause event is received within the first suppression time window, suppressing the target event.

4. The method according to claim 2, wherein Determining a first suppression time window of the target event according to the target suppression duration and the first occurrence time of the event in the causal link, including: When the target event belongs to derivative events of multiple causal links, determining multiple suppression time sub-windows of the target event respectively according to multiple target suppression durations and multiple first occurrence times of the events; Determining the first suppression time window according to the union of the multiple suppression time sub-windows.

5. The method according to claim 2, wherein When the event type of the target event includes a derivative event in the causal link to which the target event belongs in the rule base, including: The event types of the target event are all derivative events in the causal link to which the target event belongs in the rule base; The event type of the target event includes a derivative event and a root cause event in the causal link to which the target event belongs in the rule base.

6. The method according to claim 1, characterized in that Determining a target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and performing event suppression according to the target suppression duration and the event type, including: When the event types of the target event are all root cause events in the causal link to which the target event belongs in the rule base, determining the derivative event in the causal link to which the target event belongs in the rule base and the suppression duration corresponding to the causal link. Report the target event and perform event suppression on the derived event according to the suppression duration.

7. The method according to claim 6, wherein Determine the derived event in the causal link to which the target event belongs in the rule base, and the suppression duration corresponding to the causal link to which it belongs, including: When there are multiple causal links in the rule base with the target event as the root cause event, determine the derived events in each causal link and the suppression duration corresponding to each causal link; Perform event suppression on the derived event according to the suppression duration, including: According to the occurrence time of the target event, combined with the suppression duration corresponding to each causal link, determine the suppression time window corresponding to each causal link; Perform event suppression on the corresponding derived event according to the suppression time window corresponding to each causal link.

8. A root cause analysis method for abnormal events, characterized in that, The method includes: A target event acquisition unit for acquiring the target event of the device; A causal link determination unit for determining the causal link to which the target event belongs and determining the event type of the target event according to the root cause event and the derived event included in the causal link in the preset rule base, where a single causal link includes a single root cause event and a single derived event, and the root cause event in the causal link causes the occurrence of the derived event; An event suppression unit for determining the target suppression duration corresponding to the target causal link to which the target event belongs according to the corresponding relationship between the preset causal link and the suppression duration, and performing event suppression according to the target suppression duration and the event type.

9. A root cause analysis device for abnormal events, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the root cause analysis device of the abnormal event implements the method according to any one of claims 1-7.

10. A computer program product, comprising computer program instructions, characterized in that, When the computer program is run, the method according to any one of claims 1-7 is executed.