Alarm suppression method, device, equipment and medium

By using Pearson correlation and Granger causality analysis, the method identifies and suppresses alarms with underlying associations, reducing excessive alert rates in alarm management systems.

CN120321098APending Publication Date: 2025-07-15BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510468407.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The existing alarm merging method cannot effectively merge potentially related alarms, resulting in high alarm rates and cannot be reduced from the root.

Method used

The correlation coefficient matrix of the alarm log is calculated by Pearson's correlation coefficient algorithm, and the alarm suppression relationship is determined in combination with the causal test algorithm to achieve intelligent merger of potential alarm associations.

Benefits of technology

Effectively merge potentially related alarm information to reduce alarm volume, improve system stability, reduce fatigue and confusion among operation and maintenance personnel, and ensure that the system operates normally under high load conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321098A_ABST
    Figure CN120321098A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm suppression method and device, equipment and a medium, and relates to the technical field of computers. The alarm suppression method comprises the steps of obtaining alarm log sample data of a target monitoring object; based on a Pearson's correlation coefficient algorithm, calculating a first correlation coefficient matrix and a second correlation coefficient matrix of the alarm log sample data; according to the first correlation coefficient matrix and the second correlation coefficient matrix, screening out to-be-processed log data from the alarm log sample data; and according to a causal test algorithm and the to-be-processed log data, determining alarm suppression relation data, and based on the alarm suppression relation data, performing alarm merging processing on the alarm data of the target monitoring object. According to the technical scheme provided by the embodiment of the invention, the alarm information with potential alarm association can be intelligently merged, and the alarm quantity is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to an alarm suppression method, device, equipment and medium. Background Art

[0002] With the development of computer technology, the number of network elements in communication networks has also increased rapidly, causing alarm management components to receive a vast amount of alarm data in real time.

[0003] Currently, alarms are mainly merged by the same alarm rules, or by alarm tags, or by time range for duplicate alarms. However, existing alarm merging methods can only perform simple merging based on surface information and cannot effectively merge alarms with potential associations. There is an urgent need to find an effective intelligent alarm suppression method to merge alarms with potential alarm associations, so as to reduce the alarm rate at the source. Summary of the Invention

[0004] The present invention provides an alarm suppression method, device, equipment and medium to solve the problem of inability to intelligently merge alarm information with potential alarm associations.

[0005] According to one aspect of the present invention, an alarm suppression method is provided, including:

[0006] Obtaining alarm log sample data of a target monitoring object;

[0007] Based on the Pearson correlation coefficient algorithm, calculating a first correlation coefficient matrix and a second correlation coefficient matrix of the alarm log sample data;

[0008] According to the first correlation coefficient matrix and the second correlation coefficient matrix, screening out log data to be processed from the alarm log sample data;

[0009] According to the causal test algorithm and the log data to be processed, determining alarm suppression relationship data, and based on the alarm suppression relationship data, performing alarm merging processing on the alarm data of the target monitoring object.

[0010] According to another aspect of the present invention, an alarm suppression device is provided, including:

[0011] A sample data acquisition module, configured to obtain alarm log sample data of a target monitoring object;

[0012] A correlation coefficient analysis module, configured to calculate a first correlation coefficient matrix and a second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm;

[0013] A data screening module, configured to screen out log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix;

[0014] An alarm merging module, configured to determine alarm suppression relationship data according to a causality test algorithm and the log data to be processed, and perform alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data.

[0015] According to another aspect of the present invention, there is provided an electronic device, which includes:

[0016] At least one processor; and

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the alarm suppression method according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the alarm suppression method according to any embodiment of the present invention when executed.

[0020] The technical solution of the embodiment of the present invention obtains the alarm log sample data of the target monitoring object, calculates the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm, and then screens out the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix. Further, according to the causality test algorithm and the log data to be processed, the alarm suppression relationship data is determined, and based on the alarm suppression relationship data, the alarm data of the target monitoring object is subjected to alarm merging processing. In this solution, the alarm logs with reliable strong correlations can be screened out based on the first correlation coefficient matrix and the second correlation coefficient matrix calculated by the Pearson correlation coefficient algorithm, and further, the causal relationship between the screened-out alarm logs is analyzed based on the causality test algorithm, so as to obtain the alarm suppression relationship data reflecting the potential alarm associations, and the alarm information with potential alarm associations is merged based on the alarm suppression relationship data, solving the problem that the alarm information with potential alarm associations cannot be intelligently merged, being able to intelligently merge the alarm information with potential alarm associations, and reducing the amount of alarms.

[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood from the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0023] Figure 1 Flowchart of an alarm suppression method provided for Embodiment 1 of the present invention;

[0024] Figure 2 Flowchart of an alarm suppression method provided for Embodiment 2 of the present invention;

[0025] Figure 3 Schematic structural diagram of an alarm suppression device provided for Embodiment 4 of the present invention;

[0026] Figure 4 Schematic structural diagram of an electronic device that can be used to implement the embodiments of the present invention is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0029] Embodiment 1

[0030] Figure 1 The figure is a flowchart of an alarm suppression method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of intelligently suppressing alarms. This method can be executed by an alarm suppression device, which can be implemented in the form of hardware and / or software, and the alarm suppression device can be configured in an electronic device. The electronic device can include, but is not limited to, a computer or a server, etc. As Figure 1 shown, the method includes:

[0031] Step 110: Obtain the alarm log sample data of the target monitoring object.

[0032] Among them, the target monitoring object can be a monitoring object that needs to suppress alarms. The monitoring object can include, but is not limited to, a host, a process, and an execution program, etc. Optionally, at least one monitoring object of a network element device can be used as the target monitoring object, or at least one monitoring object of different network element devices can be used as the target monitoring object. Exemplarily, the host and process under at least one network element device can be used as the target monitoring object, and the host under at least one network element device can also be used as the target monitoring object. The alarm log sample data can be the historical alarm log data of the monitoring object that needs to suppress alarms.

[0033] In the embodiment of the present invention, the target monitoring object can be determined first, and then the historical alarm logs related to the target monitoring object can be obtained, and based on the historical alarm logs related to the target monitoring object, the alarm log sample data matching the target monitoring object can be generated.

[0034] Step 120: Calculate the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm.

[0035] Among them, the first correlation coefficient matrix can be used to describe the strength and direction of the linear correlation between variables. The second correlation coefficient matrix can be used to describe the statistical significance of the correlation coefficient. Exemplarily, the second correlation coefficient matrix can include, but is not limited to, a P-value matrix.

[0036] In the embodiment of the present invention, the Pearson correlation coefficient algorithm can be used to perform a correlation analysis on the alarm log sample data of the target monitoring object to obtain the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data.

[0037] Step 130: Screen out the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix.

[0038] Among them, the log data to be processed can be the log data in the alarm log sample data that meets the requirements of correlation and statistical significance.

[0039] In an embodiment of the present invention, based on the first correlation coefficient matrix and the second correlation coefficient matrix, the to-be-processed log data that meets the requirements of correlation and statistical significance can be screened out from the alarm log sample data.

[0040] Step 140: Determine the alarm suppression relationship data according to the causality test algorithm and the to-be-processed log data, and based on the alarm suppression relationship data, perform alarm merging processing on the alarm data of the target monitoring object.

[0041] Among them, the causality test algorithm can be any existing algorithm for analyzing causal relationships. Exemplarily, the causality test algorithm may include, but is not limited to, the Granger causality algorithm. The alarm suppression relationship data can be used to describe the potential association relationship between alarm logs for alarm suppression management of alarm logs. The alarm merging processing can be used to merge alarm information to reduce the alarm rate.

[0042] In an embodiment of the present invention, the causality test algorithm can be used to analyze the causal relationship between the to-be-processed log data, determine the potential alarm association relationship, so as to obtain the alarm suppression relationship data, and then based on the alarm suppression relationship data, perform alarm merging processing on the alarm data of the target monitoring object to reduce the alarm rate.

[0043] The technical solution of the embodiment of the present invention obtains the alarm log sample data of the target monitoring object, calculates the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm, then screens out the to-be-processed log data from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix, further determines the alarm suppression relationship data according to the causality test algorithm and the to-be-processed log data, and performs alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data. In this solution, based on the first correlation coefficient matrix and the second correlation coefficient matrix calculated by the Pearson correlation coefficient algorithm, the alarm logs with reliable strong correlations can be screened out, and further, the causal relationship between the screened alarm logs is analyzed based on the causality test algorithm, so as to obtain the alarm suppression relationship data reflecting the potential alarm associations, and based on the alarm suppression relationship data, the alarm information with potential alarm associations is merged, solving the problem that the alarm information with potential alarm associations cannot be intelligently merged, and being able to intelligently merge the alarm information with potential alarm associations and reduce the alarm volume.

[0044] Embodiment Two

[0045] Figure 2The flowchart of an alarm suppression method provided in the second embodiment of the present invention. This embodiment is a specific implementation based on the above embodiment, and provides a specific optional implementation manner for screening the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix. As Figure 2 shown, the method includes:

[0046] Step 210, obtain the alarm log sample data of the target monitoring object.

[0047] Step 220, calculate the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm.

[0048] In an optional embodiment of the present invention, calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm may include: cleaning the alarm log sample data to obtain log cleaning data; analyzing the correlation of the log cleaning data according to the Pearson correlation coefficient algorithm to obtain the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data.

[0049] Among them, the log cleaning data may be the data obtained by cleaning the alarm log sample data.

[0050] In the embodiment of the present invention, the alarm log sample data may be cleaned according to the preset data cleaning rules (such as invalid data elimination and key data extraction, etc.) to obtain the log cleaning data.

[0051] Step 230, obtain the first correlation coefficient threshold and the second correlation coefficient threshold.

[0052] Among them, the first correlation coefficient threshold may be a threshold for comparing the degree of association between variables. The second correlation coefficient threshold may be a threshold for comparing the degree of statistical significance.

[0053] In the embodiment of the present invention, the first correlation coefficient threshold and the second correlation coefficient threshold set by the user based on the correlation analysis requirements of the alarm log may be obtained.

[0054] Step 240, determine the first screening factor pair according to the first correlation coefficient matrix and the first correlation coefficient threshold, and determine the second screening factor pair according to the second correlation coefficient matrix and the second correlation coefficient threshold.

[0055] Among them, the first screening element pair can be a pair of monitoring indicators corresponding to the elements in the first correlation coefficient matrix that are greater than the first correlation coefficient threshold. The second screening element pair can be a pair of monitoring indicators corresponding to the elements in the second correlation coefficient matrix that are greater than the second correlation coefficient threshold. The monitoring indicators of the alarm log can include, but are not limited to, the CPU (Central Processing Unit) usage rate, the average response time, and the total transaction volume, etc. The pair of monitoring indicators can be called an element pair, and the monitoring indicator can be called an element.

[0056] In the embodiment of the present invention, each element in the first correlation coefficient matrix can be compared with the first correlation coefficient threshold, and the pair of monitoring indicators corresponding to the elements in the first correlation coefficient matrix that are greater than the first correlation coefficient threshold can be used as the first screening element pair. Each element in the second correlation coefficient matrix can be compared with the second correlation coefficient threshold, and the pair of monitoring indicators corresponding to the elements in the second correlation coefficient matrix that are greater than the second correlation coefficient threshold can be used as the second screening element pair.

[0057] Step 250: Screen out the log data to be processed from the alarm log sample data according to the first screening element pair and the second screening element pair.

[0058] In the embodiment of the present invention, the common element pairs in the first screening element pair and the second screening element pair can be determined, and then, from the alarm log sample data, the alarm log sample data corresponding to the determined common element pairs can be screened out to obtain the log data to be processed.

[0059] Step 260: Determine the alarm suppression relationship data according to the causality test algorithm and the log data to be processed, and perform alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data.

[0060] In an alternative embodiment of the present invention, determining the alarm suppression relationship data according to the causality test algorithm and the log data to be processed may include: performing forward causality analysis and reverse causality analysis on the element pairs in the log data to be processed according to the causality test algorithm to obtain target causality relationship data; determining the alarm suppression relationship data according to the target causality relationship data.

[0061] Among them, the forward causality analysis and the reverse causality analysis can be two opposite causality analyses for the same element pair. Exemplarily, assuming that the element pair includes element a and element b, taking element a as the cause and element b as the result to perform the causality existence analysis is the forward causality analysis. Taking element b as the cause and element a as the result to perform the causality existence analysis is the reverse causality analysis. The target causality relationship data can be the data describing the causality relationship between the elements of the element pairs corresponding to the log data to be processed.

[0062] In an embodiment of the present invention, a causality test algorithm can be used to perform forward causality analysis and reverse causality analysis on the same element pairs in the log data to be processed, so as to obtain target causality data. Then, the element (abbreviated as the source element) that is the result in the target causality data is set as the inhibitory element of the element that is the cause in the same element pair. Thus, the source element and the inhibitory element with a causal relationship are paired and recorded as alarm suppression relationship data.

[0063] In an alternative embodiment of the present invention, performing forward causality analysis and reverse causality analysis on the element pairs in the log data to be processed according to the causality test algorithm to obtain target causality data may include: performing forward causality analysis on the log data to be processed according to the causality test algorithm according to the target lag order, and determining the forward causality element pairs with statistical significance; performing reverse causality analysis on the forward causality element pairs to obtain target causality data.

[0064] Among them, the target lag order can be a preset lag order. Exemplarily, the target lag order can be the lag order with the best alarm suppression selected from 1 to 5. The forward causality element pairs can be the element pairs in the log data to be processed for forward causality analysis.

[0065] In an embodiment of the present invention, the parameters of the causality test algorithm can be initialized based on the target lag order, and then the causality test algorithm with the parameters initialized is used to perform forward causality analysis on the log data to be processed to obtain forward causality element pairs with statistical significance, and perform reverse causality analysis on the forward causality element pairs to obtain target causality data.

[0066] Optionally, when performing forward causality analysis and reverse causality analysis on the log data to be processed, whether there is statistical significance can be further considered to obtain target causality data with statistical significance.

[0067] In an alternative embodiment of the present invention, after determining the alarm suppression relationship data according to the target causality data, it may further include: updating the alarm log sample data, and returning to execute the operation of calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm until the alarm suppression relationship data is stable.

[0068] In an embodiment of the present invention, the alarm log sample data can be updated based on the alarm data reported in real time by the target monitoring object, and the operations of calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm are returned until the alarm suppression relationship data is stable, that is, the corresponding relationship between the source element and the suppression element in the alarm suppression relationship data is stable.

[0069] In an alternative embodiment of the present invention, the alarm merging process for the alarm data of the target monitoring object based on the alarm suppression relationship data may include: determining the alarm source data and the alarm associated data in the alarm data of the current monitoring object in the target monitoring object according to the alarm suppression relationship data; and performing alarm merging on the alarm source data and the alarm associated data in the alarm data of the current monitoring object.

[0070] Wherein, the current monitoring object may be the monitoring object that needs to perform the alarm merging process in the target monitoring object. The alarm source data may be the alarm data corresponding to the element as the cause in the element pair that matches the alarm suppression relationship data. The alarm associated data may be the alarm data corresponding to the element as the result in the element pair that matches the alarm suppression relationship data.

[0071] In an embodiment of the present invention, based on the alarm suppression relationship data, the element pair that matches the alarm suppression relationship data can be determined, and then, from the alarm data of the current monitoring object, the alarm source data associated with the element as the cause that matches the alarm suppression relationship data is screened out, and from the alarm data of the current monitoring object, the alarm associated data associated with the element as the result that matches the alarm suppression relationship data is screened out. Then, the alarm source data in the alarm data of the current monitoring object is subjected to alarm merging, that is, only the alarm operation is performed on the alarm source data, and the alarm associated data is displayed without triggering an additional alarm operation.

[0072] In the technical solution of the embodiment of the present invention, by obtaining the alarm log sample data of the target monitoring object, based on the Pearson correlation coefficient algorithm, the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data are calculated, and then the first correlation coefficient threshold and the second correlation coefficient threshold are obtained. According to the first correlation coefficient matrix and the first correlation coefficient threshold, the first screening factor pair is determined, and according to the second correlation coefficient matrix and the second correlation coefficient threshold, the second screening factor pair is determined. Further, according to the first screening factor pair and the second screening factor pair, the log data to be processed is screened out from the alarm log sample data. Then, according to the causal test algorithm and the log data to be processed, the alarm suppression relationship data is determined, and based on the alarm suppression relationship data, the alarm data of the target monitoring object is subjected to alarm merging processing. In this solution, the alarm logs with reliable strong correlations can be screened out based on the first correlation coefficient matrix and the second correlation coefficient matrix calculated by the Pearson correlation coefficient algorithm. Further, the causal relationship between the screened alarm logs is analyzed based on the causal test algorithm, so as to obtain the alarm suppression relationship data reflecting the potential alarm association, and the alarm information with potential alarm association is merged based on the alarm suppression relationship data, which solves the problem that the alarm information with potential alarm association cannot be intelligently merged, and can intelligently merge the alarm information with potential alarm association, reducing the amount of alarms.

[0073] Embodiment III

[0074] The present invention is embodied in a specific manner based on the above embodiments, and a specific example of alarm intelligent merging is given.

[0075] Exemplarily, the historical alarm logs of different monitoring objects can be stored in different partitions of the memory. The following content takes the target monitoring object as the host as an example to introduce the processing of alarm intelligent merging.

[0076] Suppose that based on the Pearson correlation coefficient algorithm, the first correlation coefficient matrix obtained by calculating the alarm log sample data is shown in Table 1, and the second correlation coefficient matrix is shown in Table 2.

[0077] Table 1 First correlation coefficient matrix

[0078] CPU Usage Rate Average Response Time Total Transaction Volume CPU Usage Rate 1.000 0.797 -0.234 Average Response Time 0.797 1.000 -0.240 Total Transaction Volume -0.234 -0.240 1.000

[0079] Table 2 Second correlation coefficient matrix

[0080] CPU Usage Rate Average Response Time Total Transaction Volume CPU Usage Rate - 1.07e-08 0.137 Average Response Time 1.07e-08 - 0.123 Total Transaction Volume 0.137 0.123 -

[0081] If the first correlation coefficient threshold is 0.5 and the second correlation coefficient threshold is 0.05, in the first correlation coefficient matrix, '+' indicates a positive correlation and '-' indicates a negative correlation. Based on Table 1 and Table 2, it can be seen that the CPU usage rate and the average response time are strongly positively correlated, and the corresponding P-value is less than 0.05, that is, the two have significant statistics, indicating that the higher the CPU usage rate, the longer the average response time. The CPU usage rate and the total transaction volume are weakly correlated, and the corresponding P-value is greater than 0.05, that is, the two do not have significant statistics, indicating that the relationship between the CPU usage rate and the total transaction volume is not obvious. By analogy, analyze the strength of the correlation and whether there is significant statistics for all element pairs, and the element pair for causal relationship test is the CPU usage rate and the average response time. Further, determine whether the CPU usage rate is the cause of the average response time (positive causal relationship analysis), and whether the average response time is the cause of the CPU usage rate (reverse causal relationship analysis), and combine the degree of statistical significance to obtain the alarm suppression relationship data.

[0082] The target lag order used in causal analysis can be set to 2. Assume that the total transaction volume is the Granger cause of the CPU usage rate (lag 2, P = 0.008), the total transaction volume is the Granger cause of the average response time (lag 2, P = 0.001), and the average response time is the Granger cause of the CPU usage rate (lag 2, P = 0.043). A lag of 2 means that the current variable is affected by the variables at the previous two time points. For example, the CPU usage rate may be affected by the transaction volume in the previous two minutes. Finally, the alarm suppression relationship data can be obtained: when the total transaction volume is the source element, the CPU usage rate is the suppression element; when the total transaction volume is the source element, the average response time is the suppression element; when the average response time is the source element, the CPU usage rate is the suppression element. In a specific example, after monitor 3 issues an alarm when the total transaction volume in the last 5 minutes is less than 100, monitor 1 does not issue an alarm when the CPU usage rate in the last 5 minutes is greater than 90%. After monitor 3 issues an alarm when the total transaction volume in the last 5 minutes is less than 100, monitor 2 does not issue an alarm when the average response delay in the last 5 minutes is greater than 5 seconds. After monitor 2 issues an alarm when the average response delay in the last 5 minutes is greater than 5 seconds, monitor 1 does not issue an alarm when the CPU usage rate in the last 5 minutes is greater than 90%.

[0083] The alarms suppressed by the alarm suppression relationship data can be synchronously displayed with the source alarm data when the source alarm data issues an alarm, which is convenient for users to view. Alarm data can be continuously collected to ensure the stability of the alarm suppression relationship data.

[0084] This solution objectively evaluates the relationships between monitoring metrics to avoid blind alarms. When causal relationships are found among certain monitoring metrics, the alarm situation can be reasonably evaluated based on historical data, and corresponding suppression can be carried out to reduce the fatigue and confusion of operation and maintenance personnel, and improve the overall stability of the system. Through precise causal analysis, it is ensured that the system can still operate normally under high load, avoiding misjudgment of non-fault states, ensuring that the system health and performance are not affected by excessive alarms, ensuring that operation and maintenance personnel can troubleshoot problems more efficiently, realizing data-driven intelligent decision-making, and ensuring the continuity and stability of the business process. Keeping the system running normally in a high-risk environment helps to improve customer satisfaction and business reputation.

[0085] Embodiment 4

[0086] Figure 3 It is a schematic structural diagram of an alarm suppression device provided in Embodiment 4 of the present invention. As Figure 3 shown, the device includes:

[0087] A sample data acquisition module 310, configured to acquire alarm log sample data of a target monitoring object.

[0088] A correlation coefficient analysis module 320, configured to calculate a first correlation coefficient matrix and a second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm.

[0089] A data screening module 330, configured to screen out log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix.

[0090] An alarm merging module 340, configured to determine alarm suppression relationship data according to a causal test algorithm and the log data to be processed, and perform alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data.

[0091] In the technical solution of the embodiment of the present invention, by obtaining the alarm log sample data of the target monitoring object, based on the Pearson correlation coefficient algorithm, the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data are calculated. Then, according to the first correlation coefficient matrix and the second correlation coefficient matrix, the log data to be processed is screened out from the alarm log sample data. Further, according to the causality test algorithm and the log data to be processed, the alarm suppression relationship data is determined, and based on the alarm suppression relationship data, the alarm data of the target monitoring object is subjected to alarm merging processing. In this solution, based on the first correlation coefficient matrix and the second correlation coefficient matrix calculated by the Pearson correlation coefficient algorithm, the alarm logs with reliable strong correlations can be screened out. Further, based on the causality test algorithm, the causal relationship between the screened alarm logs is analyzed, so as to obtain the alarm suppression relationship data reflecting the potential alarm association, and based on the alarm suppression relationship data, the alarm information with potential alarm association is merged, solving the problem that the alarm information with potential alarm association cannot be intelligently merged, and being able to intelligently merge the alarm information with potential alarm association and reduce the amount of alarms.

[0092] Optionally, the correlation coefficient analysis module 320 is specifically configured to: clean the alarm log sample data to obtain log cleaning data; analyze the correlation of the log cleaning data according to the Pearson correlation coefficient algorithm to obtain the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data.

[0093] Optionally, the data screening module 330 is specifically configured to obtain a first correlation coefficient threshold and a second correlation coefficient threshold; determine a first screening element pair according to the first correlation coefficient matrix and the first correlation coefficient threshold, and determine a second screening element pair according to the second correlation coefficient matrix and the second correlation coefficient threshold; screen out the log data to be processed from the alarm log sample data according to the first screening element pair and the second screening element pair.

[0094] Optionally, the alarm merging module 340 is specifically configured to perform forward causal relationship analysis and reverse causal relationship analysis on the element pairs in the log data to be processed according to the causality test algorithm to obtain target causal relationship data; determine the alarm suppression relationship data according to the target causal relationship data.

[0095] Optionally, the alarm merging module 340 is specifically configured to perform forward causal relationship analysis on the log data to be processed according to the causality test algorithm according to the target lag order, and determine the forward causal relationship element pairs with statistical significance; perform reverse causal relationship analysis on the forward causal relationship element pairs to obtain the target causal relationship data.

[0096] Optionally, the alarm suppression device further includes a data iterative processing module, configured to update the alarm log sample data, and return to perform operations of calculating a first correlation coefficient matrix and a second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm until the alarm suppression relationship data is stable.

[0097] Optionally, the alarm merging module 340 is specifically configured to determine, according to the alarm suppression relationship data, alarm source data and alarm associated data in the alarm data of the current monitored object in the target monitored object; and perform alarm merging on the alarm source data and the alarm associated data in the alarm data of the current monitored object.

[0098] The alarm suppression device provided by an embodiment of the present invention can execute the alarm suppression method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.

[0099] Embodiment Five

[0100] Figure 4 The figure shows a schematic structural diagram of an electronic device that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital assistant, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0101] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to at least one processor 11, such as ROM 12, RAM 13, etc. Among them, the memory stores a computer program executable by at least one processor, and the processor 11 can execute various appropriate actions and processes according to the computer program stored in the ROM 12 or the computer program loaded from the storage unit 18 into the RAM 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The I / O interface 15 is also connected to the bus 14. The ROM 12 is a read-only memory, the RAM 13 is a random access memory, and the I / O interface 15 is an input / output interface.

[0102] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0103] The processor 11 can be various general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the alarm suppression method.

[0104] In some embodiments, the alarm suppression method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the alarm suppression method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the alarm suppression method by any other suitable means (e.g., by means of firmware).

[0105] The various embodiments of the systems and technologies described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general programmable processor, that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0106] A computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0107] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a RAM, a ROM, an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0108] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0109] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend, middleware, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0110] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of traditional physical hosts and VPS servers, such as high management difficulty and weak business scalability.

[0111] An embodiment of the present application also discloses a computer program product, which includes a computer program that, when executed by a processor, implements the alarm suppression method provided in any embodiment of the present application. This program product and the alarm suppression methods disclosed in the embodiments of the present application belong to the same inventive concept, and thus will not be elaborated herein.

[0112] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.

[0113] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. An alarm suppression method, characterized in that, Including: Obtain the alarm log sample data of the target monitoring object; Calculate the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm; Filter out the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix; Determine the alarm suppression relationship data according to the causality test algorithm and the log data to be processed, and perform alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data.

2. The method according to claim 1, characterized in that, The step of calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm includes: Clean the alarm log sample data to obtain log cleaning data; Analyze the correlation of the log cleaning data according to the Pearson correlation coefficient algorithm to obtain the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data.

3. The method according to claim 1, characterized in that, The step of filtering out the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix includes: Obtain the first correlation coefficient threshold and the second correlation coefficient threshold; Determine the first screening factor pair according to the first correlation coefficient matrix and the first correlation coefficient threshold, and determine the second screening factor pair according to the second correlation coefficient matrix and the second correlation coefficient threshold; Filter out the log data to be processed from the alarm log sample data according to the first screening factor pair and the second screening factor pair.

4. The method according to claim 1, wherein The step of determining the alarm suppression relationship data according to the causality test algorithm and the log data to be processed includes: Perform forward causality analysis and reverse causality analysis on the factor pairs in the log data to be processed according to the causality test algorithm to obtain the target causality data; Determine the alarm suppression relationship data according to the target causality data.

5. The method according to claim 4, wherein The step of performing forward causality analysis and reverse causality analysis on the factor pairs in the log data to be processed according to the causality test algorithm to obtain the target causality data includes: Perform forward causality analysis on the log data to be processed according to the causality test algorithm according to the target lag order, and determine the forward causality factor pairs with statistical significance; Perform reverse causality analysis on the forward causality factor pairs to obtain the target causality data.

6. The method according to claim 4, characterized in that, After determining the alarm suppression relationship data according to the target causality data, it further includes: Update the alarm log sample data, and return to execute the operation of calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm until the alarm suppression relationship data is stable.

7. The method according to claim 1, characterized in that, The step of performing alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data includes: Determine the alarm source data and the alarm association data in the alarm data of the current monitoring object in the target monitoring object according to the alarm suppression relationship data; Merge the alarm source data and the alarm correlation data in the alarm data of the current monitoring object.

8. An alarm suppression device, characterized in that, It includes: A sample data acquisition module for acquiring the alarm log sample data of the target monitoring object; A correlation coefficient analysis module for calculating the first correlation coefficient matrix and the second correlation coefficient matrix of the alarm log sample data based on the Pearson correlation coefficient algorithm; A data screening module for screening out the log data to be processed from the alarm log sample data according to the first correlation coefficient matrix and the second correlation coefficient matrix; An alarm merging module for determining the alarm suppression relationship data according to the causality test algorithm and the log data to be processed, and performing alarm merging processing on the alarm data of the target monitoring object based on the alarm suppression relationship data.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the alarm suppression method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to execute the alarm suppression method according to any one of claims 1-7 when executed.