Alarm message processing method and device, electronic equipment and storage medium

By building an alarm rule tree and a visual editing interface, the problem of inefficient alarm message processing in the enterprise operation and maintenance platform is solved, and automated identification and processing is realized, improving operation and maintenance efficiency and troubleshooting capabilities.

CN120342839APending Publication Date: 2025-07-18太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510544668.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, enterprise operation and maintenance platforms have problems of manual identification and inefficiency when processing alarm messages, resulting in a backlog of alarm messages and affecting operation and maintenance efficiency.

Method used

Build an alarm rule tree, and realize the automatic identification and processing of alarm messages through the conditional rules and processing nodes associated with the target alarm source, simplify the configuration process by using the visual conditional rule editing interface, and identify the alarm source type through access encoding, and automatically save the processing process.

Benefits of technology

It realizes the automatic identification and processing of alarm messages, improves the efficiency and reliability of enterprise management alarm messages, lowers personnel thresholds, and improves troubleshooting efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342839A_ABST
    Figure CN120342839A_ABST
Patent Text Reader

Abstract

The invention provides an alarm message processing method and device, electronic equipment and a storage medium. The method comprises the following steps: distributing condition nodes according to condition rules associated with a target alarm source and an association relationship among the condition rules, and configuring corresponding processing nodes for the condition nodes to construct an alarm rule tree, wherein the processing nodes are used for indicating data processing operation needing to be executed when condition rules of the corresponding condition nodes are triggered, and the processing nodes are mounted on the corresponding condition nodes in the form of an ordered single linked list; receiving an alarm message from a target alarm source; and traversing each condition node in the alarm rule tree in sequence, and in response to the alarm message, triggering a condition rule of the currently traversed condition node, and executing each data processing operation of each processing node corresponding to the currently traversed condition node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application mainly relates to the field of IT operation and maintenance technology, and particularly relates to a method, device, electronic device, and storage medium for processing alarm messages. Background Art

[0002] In the process of centralized collection and processing of alarm messages by an enterprise operation and maintenance platform, monitoring personnel need to manually identify and judge the generated alarm messages, and then notify relevant operation and maintenance personnel for manual processing according to experience. In this scenario, it is easy to cause the problem that the correct operation and maintenance personnel cannot be notified due to the misjudgment of the monitoring personnel. Moreover, due to the low efficiency of manual processing, alarm messages are prone to be backlogged, affecting the operation and maintenance efficiency of the enterprise. Summary of the Invention

[0003] The purpose of this application is to provide a method, device, electronic device, and storage medium for processing alarm messages, which is used to improve the efficiency and reliability of enterprise management of alarm messages.

[0004] In a first aspect, a method for processing alarm messages is provided, including:

[0005] Allocate each condition node according to each condition rule associated with the target alarm source and the association relationship between the condition rules, and configure corresponding processing nodes for each condition node to construct an alarm rule tree, where the processing node is used to indicate the data processing operation required when the condition rule of the corresponding condition node is triggered, and the processing node is mounted on the corresponding condition node in the form of an ordered single linked list;

[0006] Receive an alarm message from the target alarm source;

[0007] Traverse each condition node in the alarm rule tree in sequence, where: in response to the alarm message triggering the condition rule of the currently traversed condition node, execute each data processing operation of the corresponding processing nodes of the currently traversed condition node.

[0008] In some embodiments, before allocating each condition node according to each condition rule associated with the target alarm source and the association relationship between the condition rules, it further includes:

[0009] Provide a condition rule editing interface for the target alarm source; the condition rule editing interface includes a condition factor, a comparison factor, and an association factor. The condition factor is used to indicate the parameters and assignments required to form a condition rule, the comparison factor is used to indicate the logical relationship between the parameters and the assignments, and the association factor is used to indicate the association relationship between the condition rules;

[0010] By editing the conditional factor, the comparison factor, and the association factor, each conditional rule associated with the target alarm source and the association relationship between the conditional rules are obtained.

[0011] In some embodiments, the alarm message includes an access code;

[0012] Before traversing each conditional node in the alarm rule tree in sequence, it further includes:

[0013] Identify the type of the target alarm source according to the access code.

[0014] In some embodiments, it further includes:

[0015] In response to the alarm message not triggering the conditional rule of the currently traversed conditional node, continue to traverse the alarm rule tree. During the continuous traversal process: skip all other conditional nodes that have an association relationship with the currently traversed conditional node.

[0016] In some embodiments, after performing each data processing operation of each processing node corresponding to the currently traversed conditional node, it further includes:

[0017] Determine the subordinate conditional node associated with the currently traversed conditional node in the alarm rule tree;

[0018] Judge whether the currently executed result data triggers the conditional rule of the subordinate conditional node;

[0019] If so, continue to perform each data processing operation of each processing node corresponding to the subordinate conditional node;

[0020] Otherwise, continue to traverse the alarm rule tree. During the continuous traversal process: skip all other conditional nodes that have an association relationship with the subordinate conditional node.

[0021] In some embodiments, the alarm message includes an identification field;

[0022] After performing each data processing operation of each processing node corresponding to the currently traversed conditional node, it further includes:

[0023] Generate an alarm identification value according to the identification field and the traversal result data;

[0024] Trigger a corresponding alarm action according to the alarm status and the alarm identification value.

[0025] In some embodiments, the triggering of the corresponding alarm action according to the alarm status and the alarm identification value includes:

[0026] In response to the alarm status being open and the alarm identification identifier value being unique, trigger the action of creating a new alarm according to the alarm message;

[0027] In response to the alarm status being open and the alarm identification identifier value not being unique, trigger the action of updating the alarm according to the alarm message;

[0028] In response to the alarm status being closed, trigger the action of restoring and closing the alarm according to the alarm message.

[0029] In a second aspect, there is provided an apparatus for processing an alarm message, including:

[0030] A rule tree construction module, configured to allocate each conditional node according to each conditional rule associated with a target alarm source and the association relationship between the conditional rules, and configure corresponding processing nodes for each conditional node to construct an alarm rule tree, where the processing node is used to indicate the data processing operation required when the conditional rule of the corresponding conditional node is triggered, and the processing node is mounted on the corresponding conditional node in the form of an ordered single linked list;

[0031] A receiving module, configured to receive an alarm message from the target alarm source;

[0032] A traversal module, configured to sequentially traverse each conditional node in the alarm rule tree, where: in response to the alarm message triggering the conditional rule of the currently traversed conditional node, execute each data processing operation of the corresponding processing nodes of the currently traversed conditional node.

[0033] In a third aspect, there is provided an electronic device, including:

[0034] One or more processors; and

[0035] One or more memories coupled to the one or more processors and storing instructions thereon, when the instructions are executed by the one or more processors alone or jointly, cause the electronic device to execute the method according to any one of the first aspect.

[0036] In a fourth aspect, there is provided a non-transitory computer-readable storage medium storing machine-executable instructions, where the machine-executable instructions, when executed by one or more processors of a machine, cause the machine to execute the method according to any one of the first aspect.

[0037] Compared with the prior art, the present application has the following advantages:

[0038] 1) This application constructs an alarm rule tree through the conditional rules associated with the target alarm source and the data processing operations that need to be executed by the conditional rules, and identifies and processes the currently received alarm messages by traversing the alarm rule tree, realizing the automatic identification and processing of alarm messages, thereby improving the efficiency and reliability of enterprise management of alarm messages.

[0039] 2) This application provides a visual conditional rule editing interface and editable conditional factors, comparison factors, and association factors, which can greatly simplify the configuration process of conditional rules, ensuring that operation and maintenance personnel can efficiently complete the configuration of conditional rules without relying on complex development work or script writing work, reducing the personnel threshold and improving the efficiency of enterprise operation and maintenance.

[0040] 3) This application identifies different types of alarm sources through access codes, quickly obtains the fault information of the IT assets associated with the identified alarm sources, and can automatically save the complete processing process of alarm messages by traversing the alarm rule tree, facilitating data backtracking, helping operation and maintenance personnel quickly locate the actual fault problems, and thus improving the efficiency of fault troubleshooting.

[0041] It should be understood that the content of the invention is not used to identify the key or basic features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Through the following

[0042] description, other features of the present disclosure will become easily understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Including the drawings is to provide a further understanding of the present application. They are incorporated and constitute a part of the present application. The drawings illustrate the embodiments of the present application and, together with this specification, serve to explain the principles of the present application. In the drawings:

[0044] Figure 1 is a flowchart of a method for processing alarm messages exemplarily provided by the present application;

[0045] Figure 2 is a schematic diagram of an alarm rule tree exemplarily provided by the present application;

[0046] Figure 3 is a schematic diagram of a conditional rule configuration interface exemplarily provided by the present application;

[0047] Figure 4 is a schematic diagram of a device for processing alarm messages exemplarily provided by the present application;

[0048] Figure 5 is a schematic diagram of an electronic device exemplarily provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] The principles of the present disclosure will now be described with reference to some embodiments. It should be understood that the description of these embodiments is for illustrative purposes only and helps those skilled in the art to understand and implement the present disclosure, without imposing any limitations on the scope of the present disclosure. The disclosure described herein may be implemented in a manner different from that described below.

[0050] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0051] References in this disclosure to "an embodiment", "embodiment", "exemplary embodiment", etc., indicate that the described embodiment may include a particular feature, structure, or characteristic, but not necessarily every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. In addition, when a particular feature, structure, or characteristic is described in connection with an exemplary embodiment, whether or not explicitly described, those skilled in the art will appreciate such feature, structure, or characteristic in connection with other embodiments.

[0052] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. The term "and / or" used herein includes any and all combinations of one or more of the listed terms.

[0053] The terms used herein are only for the purpose of describing particular embodiments and are not limiting of the exemplary embodiments. The singular forms "a", "an", and "the" used herein also include the plural forms unless the context clearly indicates otherwise. The term "a set of elements" or "a collection of elements" as used herein is intended to include one or more elements. It should also be understood that the terms "comprises", "comprising", "has", "having", "includes", and / or "including", when used herein, specify the presence of the described features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0054] Figure 1 is a flowchart 100 of a method for processing alarm messages provided exemplarily by this application. The execution subject of this method may be, for example, an enterprise operation and maintenance platform, including:

[0055] S101. Allocate each conditional node according to each conditional rule associated with the target alarm source and the association relationship between each conditional rule, and configure corresponding processing nodes for each conditional node to construct an alarm rule tree, where the processing node is used to indicate the data processing operation required when the conditional rule of the corresponding conditional node is triggered, and the processing nodes are mounted on the corresponding conditional node in the form of an ordered single linked list.

[0056] Specifically, the association relationship between each conditional rule refers to the branch relationship of the tree structure. Figure 2 This is a schematic example diagram 200 of an alarm rule tree provided exemplarily by this application. The alarm rule tree includes multiple conditional nodes (A - G) and multiple processing nodes (1 - 10). As Figure 2 , there is a branch relationship between conditional nodes C, D, E and conditional node A, a branch relationship between conditional node F and conditional node B, and a branch relationship between conditional node G and conditional node D. In other words, in this alarm rule tree, conditional nodes C, D, E are respectively the subordinate conditional nodes corresponding to conditional node A, conditional node F is the subordinate conditional node corresponding to conditional node B, and conditional node G is the subordinate conditional node corresponding to conditional node D. The root node in the tree structure can be a node for initialization.

[0057] Continue to refer to Figure 2 , in the alarm rule tree, mount processing nodes 1, 2 on conditional node A in the form of an ordered single linked list, mount processing node 3 on conditional node B in the form of an ordered single linked list, mount processing node 4 on conditional node C in the form of an ordered single linked list, mount processing nodes 5, 6 on conditional node D in the form of an ordered single linked list, mount processing nodes 7, 8 on conditional node E in the form of an ordered single linked list, mount processing node 9 on conditional node F in the form of an ordered single linked list, and mount processing node 10 on conditional node G in the form of an ordered single linked list.

[0058] In this way, when a certain conditional node is triggered, it is possible to further execute each processing node mounted in the form of an ordered single linked list, thereby realizing the automatic recognition and processing of alarm messages.

[0059] In some embodiments, the following method is provided to configure each conditional rule and the association relationship between each conditional rule:

[0060] Provide a conditional rule editing interface for the target alarm source; the conditional rule editing interface includes a conditional factor, a comparison factor, and an association factor. The conditional factor is used to indicate the parameters and assignments required to form a conditional rule, the comparison factor is used to indicate the logical relationship between the parameters and assignments, and the association factor is used to indicate the association relationship between each conditional rule;

[0061] By editing the condition factor, comparison factor, and association factor, each condition rule associated with the target alarm source and the association relationship between each condition rule are obtained.

[0062] In other words, the present application provides a visual condition rule editing interface to simplify the configuration process of condition rules. The condition rule editing interface includes a condition factor, a comparison factor, and an association factor, and the operation and maintenance personnel can freely edit the above factors to customize the required condition rules.

[0063] Figure 3 FIG. 300 is a schematic diagram of a condition rule configuration interface exemplarily provided by the present application. As Figure 3 , in this condition rule configuration interface, the condition factor includes, for example, the parameter "HOST_SERVICE_TYPE" required to identify a database server and the actual value "database server" of this parameter monitored; the comparison factor is, for example, "equal to", which together with the foregoing condition factor forms a corresponding condition rule A1; the association factor is, for example, "and", which is used to implement the nested use of this condition rule A1 and other condition rules A2. In this way, the nested condition rule A1 and condition rule A2 can be used as the complete condition rule corresponding to a condition node to implement complex condition judgment logic.

[0064] It will be understood that the specific contents of the condition factor, comparison factor, and association factor can also be configured and implemented by those skilled in the art according to the actual business, and are not limited by the above examples.

[0065] Further, for each processing node, the data processing operation can be any one of the following operations: association, assignment, truncation, splitting, replacement, escape, tagging, filtering, BASE decoding.

[0066] S102, receiving an alarm message from the target alarm source.

[0067] In some embodiments, the alarm message includes an admission code and an identification field.

[0068] The admission code is a field in the alarm message used to distinguish the type of the target alarm source, such as the unique code for database alarms. When receiving the alarm message, the type of the target alarm source is identified according to the admission code to realize the automatic classification of the currently received alarm message.

[0069] The identification field is used to generate the alarm identification value of the currently received alarm, and the corresponding alarm action is triggered according to the alarm status and the alarm identification value.

[0070] S103. Traverse each conditional node in the alarm rule tree in sequence, where: in response to an alarm message triggering the conditional rule of the currently traversed conditional node, perform each data processing operation of each processing node corresponding to the currently traversed conditional node.

[0071] In other words, if the alarm data object in the alarm message meets the conditional rule of the currently traversed conditional node, then the data processing operations of the processing nodes under this conditional node are sequentially executed.

[0072] Exemplarily, referring to Figure 2 , if the alarm data object triggers conditional node A, then the data processing operations of processing node 1 and processing node 2 are automatically executed sequentially.

[0073] In some embodiments, the method for processing an alarm message further includes:

[0074] In response to the alarm message not triggering the conditional rule of the currently traversed conditional node, continue to traverse the alarm rule tree. During the continuous traversal: skip all conditional nodes associated with the currently traversed conditional node.

[0075] In other words, if the alarm data object in the alarm message does not meet the conditional rule of the currently traversed conditional node, then skip all other conditional nodes having an associated relationship with this conditional node.

[0076] Exemplarily, referring to Figure 2 , if the alarm data object triggers conditional node D, then continue to traverse to conditional node E, and at the same time, no longer traverse conditional node G having an associated relationship with conditional node D.

[0077] In some embodiments, the method for processing an alarm message further includes:

[0078] Determine the subordinate conditional nodes associated with the currently traversed conditional node in the alarm rule tree;

[0079] Judge whether the currently executed result data triggers the conditional rule of the subordinate conditional node;

[0080] If so, continue to perform each data processing operation of each processing node corresponding to the subordinate conditional node;

[0081] Otherwise, continue to traverse the alarm rule tree. During the continuous traversal: skip all conditional nodes associated with the subordinate conditional node.

[0082] Exemplarily, if the alarm data object triggers conditional node A, then the data processing operations of processing node 1 and processing node 2 are automatically executed sequentially. Subsequently, use the currently executed result data corresponding to this data processing operation as a new alarm data object, and then judge whether the new alarm data object meets the conditional rule of conditional node C.

[0083] It will be understood that during the traversal process, all data processing operations that need to be executed can be executed in batches or in parallel, and there is no limitation on this.

[0084] In some embodiments, after the traversal of the alarm rule tree is completed, it further includes:

[0085] Generating an alarm identification flag value according to the identification field and the traversal result data; and,

[0086] Triggering a corresponding alarm action according to the alarm status and the alarm identification flag value.

[0087] In other words, for the currently received alarm message, a corresponding alarm identification flag value is generated according to its traversal result data and the identification field.

[0088] Furthermore, triggering a corresponding alarm action according to the alarm status and the alarm identification flag value specifically includes:

[0089] In response to the alarm status being open and the alarm identification flag value being unique, triggering an action to create a new alarm according to the alarm message;

[0090] In response to the alarm status being open and the alarm identification flag value not being unique, triggering an action to update the alarm according to the alarm message;

[0091] In response to the alarm status being closed, triggering an action to restore and close the alarm according to the alarm message.

[0092] Based on the above method, the present application can determine whether it is necessary to execute the actions of creating a new alarm, updating an alarm, or restoring an alarm after receiving the current alarm message according to the alarm identification flag value and the alarm status. In this way, the processing of alarm messages can be automatically processed by the enterprise operation and maintenance platform without manual judgment of the alarm processing method, thereby improving the efficiency and reliability of managing alarm messages.

[0093] Figure 4 It is a schematic diagram 400 of a device for processing alarm messages exemplarily provided by the present application. As Figure 4 , the device includes a rule tree construction module 401, a receiving module 402, and a traversal module 403.

[0094] The rule tree construction module 401 is used to allocate each condition node according to each condition rule associated with the target alarm source and the association relationship between each condition rule, and configure corresponding processing nodes for each condition node to construct an alarm rule tree, where the processing node is used to indicate the data processing operation required when the condition rule of the corresponding condition node is triggered, and the processing node is mounted on the corresponding condition node in the form of an ordered single linked list;

[0095] A receiving module 402, configured to receive alarm messages from a target alarm source;

[0096] A traversing module 403, configured to sequentially traverse each condition node in an alarm rule tree, where: in response to an alarm message triggering a condition rule of the currently traversed condition node, perform each data processing operation of each processing node corresponding to the currently traversed condition node.

[0097] In some embodiments, the rule tree construction module 401 is further configured to:

[0098] Provide a condition rule editing interface for the target alarm source; the condition rule editing interface includes a condition factor, a comparison factor, and an association factor, where the condition factor is used to indicate the parameters and assignments required to form a condition rule, the comparison factor is used to indicate the logical relationship between the parameters and assignments, and the association factor is used to indicate the association relationship between each condition rule;

[0099] Obtain each condition rule associated with the target alarm source and the association relationship between each condition rule by editing the condition factor, the comparison factor, and the association factor.

[0100] In some embodiments, the alarm message includes an admission code; the traversing module 403 is further configured to: identify the type of the target alarm source according to the admission code.

[0101] In some embodiments, the traversing module 403 is further configured to: in response to the alarm message not triggering the condition rule of the currently traversed condition node, continue to traverse the alarm rule tree, and during the continuous traversing process: skip all other condition nodes having an association relationship with the currently traversed condition node.

[0102] In some embodiments, the traversing module 403 is further configured to:

[0103] Determine a lower-level condition node associated with the currently traversed condition node in the alarm rule tree;

[0104] Judge whether the currently executed result data triggers the condition rule of the lower-level condition node;

[0105] If so, continue to perform each data processing operation of each processing node corresponding to the lower-level condition node;

[0106] Otherwise, continue to traverse the alarm rule tree, and during the continuous traversing process: skip all other condition nodes having an association relationship with the lower-level condition node.

[0107] In some embodiments, the alarm message includes an identification field; the traversing module 403 is further configured to:

[0108] Generate an alarm identification value according to the identification field and the traversal result data;

[0109] Trigger corresponding alarm actions according to the alarm status and the alarm identification flag value.

[0110] In some embodiments, to trigger corresponding alarm actions according to the alarm status and the alarm identification flag value, the traversal module 403 is used for:

[0111] In response to the alarm status being open and the alarm identification flag value being unique, trigger the action of creating a new alarm according to the alarm message;

[0112] In response to the alarm status being open and the alarm identification flag value not being unique, trigger the action of updating the alarm according to the alarm message;

[0113] In response to the alarm status being closed, trigger the action of restoring and closing the alarm according to the alarm message.

[0114] Furthermore, as Figure 5 , an exemplary embodiment of the present application further provides an electronic device 500, including one or more memories 501 and one or more processors 502. One or more memories 501 are coupled to one or more processors 502 and store instructions thereon. The instructions can be executed by one or more processors 502 alone or jointly, so that the electronic device executes the method according to any item of the first aspect.

[0115] It should be understood that the processor mentioned in the embodiments of the present application may be a CPU, or may also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0116] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory, dynamic random access memory, synchronous dynamic random access memory, double data rate synchronous dynamic random access memory, enhanced synchronous dynamic random access memory, synchronous link dynamic random access memory and direct memory bus random access memory.

[0117] The present application also provides a non-transitory computer-readable storage medium storing machine-executable instructions, which can be executed by one or more processors of a machine. The machine may include an electronic device as mentioned above. When the machine-executable instructions are executed by one or more processors, the machine is caused to execute any of the methods mentioned above.

[0118] The computer-readable storage medium may include a propagated data signal carrying computer program code therein, for example, on a baseband or as part of a carrier wave. The propagated signal may take various forms, including electromagnetic form, optical form, etc., or a suitable combination thereof. The computer-readable storage medium may be connected to an instruction execution system, apparatus, or device to effect communication, propagation, or transmission for use of the program. The program code located on the computer-readable storage medium may be propagated through any suitable medium, including radio, cable, fiber optic cable, radio frequency signal, or similar medium, or any combination of the above media.

[0119] The basic concepts have been described above. Obviously, for those skilled in the art, the above invention disclosure is only an example and does not constitute a limitation to the present application. Although not explicitly stated herein, those skilled in the art may make various modifications, improvements, and corrections to the present application. Such modifications, improvements, and corrections are proposed in the present application, so such modifications, improvements, and corrections still fall within the spirit and scope of the exemplary embodiments of the present application.

[0120] Meanwhile, the present application uses specific words to describe the embodiments of the present application. Such as "one embodiment", "an embodiment", and / or "some embodiments" mean a certain feature, structure, or characteristic related to at least one embodiment of the present application. Therefore, it should be emphasized and noted that the "one embodiment" or "an embodiment" or "an alternative embodiment" mentioned twice or more at different positions in this specification does not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the present application may be appropriately combined.

[0121] Some aspects of the present application can be executed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above-mentioned hardware or software can all be referred to as "data block", "module", "engine", "unit", "component" or "system". The processor can be one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DAPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, or combinations thereof. In addition, aspects of the present application may be embodied as a computer product located in one or more computer-readable media, which includes computer-readable program code. For example, the computer-readable media may include, but is not limited to, magnetic storage devices (such as hard disks, floppy disks, magnetic tapes...), optical discs (such as compact discs CD, digital versatile discs DVD...), smart cards, and flash memory devices (such as cards, sticks, key drives...).

[0122] The computer-readable media may contain a propagated data signal having computer program code embodied therein, for example, on a baseband or as part of a carrier wave. The propagated signal may take many forms, including electromagnetic form, optical form, etc., or a suitable combination thereof. The computer-readable media can be any computer-readable media other than a computer-readable storage media, which can communicate, propagate, or transport a program for use by being connected to an instruction execution system, apparatus, or device. The program code located on the computer-readable media can be propagated through any suitable media, including radio, cable, fiber optic cable, radio frequency signal, or similar media, or any combination of the above media.

[0123] Similarly, it should be noted that, in order to simplify the description of the present application disclosure and thus help the understanding of one or more embodiments of the invention, in the foregoing description of the embodiments of the present application, sometimes multiple features are combined into one embodiment, drawing, or description thereof. However, this disclosure method does not mean that the features required by the subject matter of the present application are more than those mentioned in the claims. In fact, the features of the embodiments are fewer than all the features of the single embodiment disclosed above.

[0124] In some embodiments, numbers are used to describe components and the quantity of attributes. It should be understood that such numbers used in the description of embodiments are, in some examples, modified by the modifiers "about", "approximate" or "substantially". Unless otherwise stated, "about", "approximate" or "substantially" indicate that the stated numbers allow a variation of ±20%. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, which may vary according to the characteristics required by individual embodiments. In some embodiments, the numerical parameters should consider the specified significant digits and adopt the method of retaining the general number of digits. Although the numerical ranges and parameters used in some embodiments of the present application to confirm the breadth of their scope are approximate values, in specific embodiments, such numerical settings are made as precise as possible within the feasible range.

[0125] Although the present application has been described with reference to the current specific embodiments, those of ordinary skill in the art should recognize that the above embodiments are only used to illustrate the present application, and various equivalent changes or substitutions can be made without departing from the spirit of the present application. Therefore, as long as the changes and modifications to the above embodiments are within the scope of the spirit of the present application, they will fall within the scope of the claims of the present application.

Claims

1. A method for processing alarm messages, characterized in that, It includes: All condition nodes are allocated according to each condition rule associated with the target alarm source and the association relationships between the condition rules. Each processing node corresponding to each condition node is configured to construct an alarm rule tree, where the processing node is used to indicate the data processing operations required to be executed when the condition rule of the corresponding condition node is triggered, and the processing nodes are mounted on the corresponding condition nodes in the form of an ordered singly linked list; Receive the alarm message from the target alarm source; Traverse each condition node in the alarm rule tree in sequence, where: in response to the alarm message triggering the condition rule of the currently traversed condition node, execute each data processing operation of each processing node corresponding to the currently traversed condition node.

2. The method according to claim 1, characterized in that, Before the step of allocating all condition nodes according to each condition rule associated with the target alarm source and the association relationships between the condition rules, it further includes: Provide a condition rule editing interface for the target alarm source; the condition rule editing interface includes a condition factor, a comparison factor, and an association factor. The condition factor is used to indicate the parameters and assignments required to form a condition rule, the comparison factor is used to indicate the logical relationship between the parameters and the assignments, and the association factor is used to indicate the association relationships between the condition rules; Obtain each condition rule associated with the target alarm source and the association relationships between the condition rules by editing the condition factor, the comparison factor, and the association factor.

3. The method according to claim 2, wherein The alarm message includes an admission code; Before the step of traversing each condition node in the alarm rule tree in sequence, it further includes: Identify the type of the target alarm source according to the admission code.

4. The method according to any one of claims 1-3, characterized in that, It also includes: In response to the alarm message not triggering the condition rule of the currently traversed condition node, continue to traverse the alarm rule tree. During the continuous traversal process: skip all other condition nodes having an association relationship with the currently traversed condition node.

5. The method according to any one of claims 1 to 3, characterized in that After the step of executing each data processing operation of each processing node corresponding to the currently traversed condition node, it further includes: Determine the subordinate condition nodes associated with the currently traversed condition node in the alarm rule tree; Judge whether the currently executed result data triggers the condition rule of the subordinate condition node; If so, continue to execute each data processing operation of each processing node corresponding to the subordinate condition node; Otherwise, continue to traverse the alarm rule tree. During the continuous traversal process: skip all other condition nodes having an association relationship with the subordinate condition node.

6. The method according to any one of claims 1-3, characterized in that, The alarm message includes an identification field; After the step of executing each data processing operation of each processing node corresponding to the currently traversed condition node, it further includes: Generate an alarm identification identifier value according to the identification field and the traversal result data; Trigger a corresponding alarm action according to the alarm status and the alarm identification identifier value.

7. The method according to claim 6, wherein The step of triggering a corresponding alarm action according to the alarm status and the alarm identification identifier value includes: In response to the alarm status being open and the alarm identification identifier value being unique, trigger the action of creating a new alarm according to the alarm message; In response to the alarm status being open and the alarm identification identifier value not being unique, trigger the action of updating the alarm according to the alarm message; In response to the alarm status being closed, trigger actions for restoring and closing the alarm according to the alarm message.

8. A processing device for alarm messages, characterized in that, Comprising: A rule tree construction module, configured to allocate each conditional node according to each conditional rule associated with a target alarm source and the association relationship between the conditional rules, and configure corresponding processing nodes for each conditional node to construct an alarm rule tree, where the processing node is used to indicate the data processing operations required to be executed when the conditional rule of the corresponding conditional node is triggered, and the processing nodes are mounted on the corresponding conditional nodes in the form of an ordered singly linked list; A receiving module, configured to receive an alarm message from the target alarm source; A traversal module, configured to sequentially traverse each conditional node in the alarm rule tree, where: in response to the alarm message triggering the conditional rule of the currently traversed conditional node, execute the respective data processing operations of the respective processing nodes corresponding to the currently traversed conditional node.

9. An electronic device, characterized in that, Comprising: One or more processors; And One or more memories coupled to the one or more processors and storing instructions thereon, which when executed by the one or more processors alone or jointly, cause the electronic device to execute the method according to any one of claims 1-7.

10. A non-transitory computer-readable storage medium storing machine-executable instructions, characterized in that, When the machine-executable instructions are executed by one or more processors of the machine, cause the machine to execute the method according to any one of claims 1-7.