Alarm event processing method and device

By obtaining the event information and mapping relationship of the alarm event, determining and suppressing invalid alarm reporting, the invalid alarm problem reported by network equipment is solved, and efficient and accurate alarm event handling is achieved.

CN120358126APending Publication Date: 2025-07-22HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410091419.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the prior art, the alarm events reported on the network equipment include invalid alarms, resulting in complex marking operations and low accuracy, which can easily lead to missed alarms.

Method used

By obtaining the event information of the alarm event, using the mapping relationship between resource and status changes to determine the alarm event as an invalid alarm, and suppressing its reporting, including obtaining the mapping relationship between the alarm event, resource and status changes, determining the alarm event as an invalid alarm based on the event information, and suppressing its reporting.

Benefits of technology

The number of alarm events to be reported is effectively controlled, the network maintenance pressure is reduced, and the recognition accuracy and processing efficiency of alarm events are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358126A_ABST
    Figure CN120358126A_ABST
Patent Text Reader

Abstract

The invention discloses an alarm event processing method and device, and belongs to the technical field of computers. The method comprises the following steps: acquiring event information of an alarm event triggered by a resource occurrence state change, wherein the event information is used for describing a resource triggering the alarm event and the state change of the resource occurrence; and according to the event information, determining that the alarm event is an invalid alarm, and inhibiting reporting of the alarm event. The number of reported alarm events is effectively controlled, and the network maintenance pressure is reduced. The alarm event can be determined as the invalid alarm through the event information, and the determination process is low in complexity and high in efficiency. Invalid alarms needing to be ignored are reported and suppressed, suppression of event granularity is realized, and the accuracy is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method and device for processing alarm events. Background Art

[0002] With the development of computer technology, the network has become an inalienable part of daily life, and the network may malfunction during operation. When a network failure occurs, it is necessary to be able to report the alarm event corresponding to the failure to the operation and maintenance object in a timely manner, so that the operation and maintenance object can perform fault location, diagnosis, and complete corresponding maintenance operations for the alarm event.

[0003] In related technologies, when a user issues business configurations layer by layer, the network devices involved in the process of issuing business configurations are marked. Subsequently, when the collector receives an alarm event reported by a network device, if the alarm event is reported by a marked network device, since the network device is a network device involved in business configuration, the alarm event reported by the network device may be triggered by an operation performed during the business configuration process. And the alarm events triggered by business configuration do not need to be processed. Based on this, the collector will ignore the alarm events reported by the marked network devices.

[0004] However, the operation of marking network devices has a high complexity, and ignoring all alarm events triggered by the marked network devices is likely to cause alarm underreporting and low accuracy. Summary of the Invention

[0005] This application provides a method and device for processing alarm events to solve the problems existing in related technologies. The technical solutions are as follows:

[0006] In a first aspect, a method for processing alarm events is provided. The method includes: obtaining event information of an alarm event triggered by a change in the state of a resource, where the event information is used to describe the resource that triggers the alarm event and the state change that occurs to the resource; and determining, according to the event information, that the alarm event is an invalid alarm and suppressing the reporting of the alarm event.

[0007] This method determines that the alarm event is an invalid alarm through the event information, and the determination process has a low complexity and high efficiency. In addition, when the alarm event is an invalid alarm, the reporting of the alarm event will be suppressed, realizing suppression at the event granularity and high accuracy. Moreover, by suppressing the reporting of alarm events that belong to invalid alarms, the number of alarm events to be reported is effectively controlled, and the network maintenance pressure is reduced.

[0008] In a possible implementation, obtaining event information of an alarm event triggered by a change in the state of a resource includes: obtaining the mapping relationship between the alarm event, the resource, and the state change of the resource, where the mapping relationship indicates at least one alarm event triggered by any state change of any resource; determining the resource that triggers the alarm event and the state change that occurs to the resource according to the mapping relationship to obtain the event information of the alarm event. By pre-maintaining the mapping relationship between the alarm event, the resource, and the state change of the resource, the event information of the alarm event can be determined by subsequent searching in the mapping relationship. The process of obtaining the event information is simple and efficient.

[0009] In a possible implementation, determining that the alarm event is an invalid alarm according to the event information includes: obtaining at least one operation information that has been executed, where the at least one operation information is used for service deployment; when the at least one operation information includes operation information for changing the state of the resource, determining that the alarm event is an invalid alarm. Among them, service deployment refers to configuring and arranging each link in the service process according to the user's intention. Since service deployment reflects the user's intention, judging that the alarm event is an invalid alarm through service deployment realizes accurate screening of invalid alarms based on the user's intention.

[0010] In a possible implementation, obtaining at least one operation information that has been executed includes: obtaining at least one protocol request that has been executed for service deployment, where the protocol request includes at least one of a service identifier or a device identifier and the operation information; for any protocol request, when the service identifier included in any protocol request indicates the service currently being deployed, determining that any protocol request is a valid request, and / or when the device identifier included in any protocol request indicates a first device for managing network devices, determining that any protocol request is a valid request, where the network device is used to process the alarm event; obtaining the operation information included in the valid requests among the at least one protocol request to obtain at least one operation information. By screening the validity of the protocol request through at least one of the service identifier or the device identifier, and using the operation information included in the screened protocol request as the operation information involved in subsequent determination that the alarm event is an invalid alarm. Since the accuracy of the screened protocol request is high, the accuracy of the determined invalid alarm based on the protocol request with high accuracy is higher.

[0011] In a possible implementation, the method further includes: determining that the alarm event is a valid alarm according to the event information and allowing the reporting of the alarm event. For an alarm event that belongs to a valid alarm, it will be reported normally to achieve fault location and network maintenance corresponding to the alarm event through reporting the alarm event, and ensure timely repair of the alarm event.

[0012] In a possible implementation, the reporting of an alarm event includes sending alarm information corresponding to the alarm event. Suppressing the reporting of an alarm event includes: adding an identifier corresponding to the alarm event to the alarm information corresponding to the alarm event, and sending the added alarm information. The identifier is used for the module that receives the added alarm information to ignore the alarm event when determining that the alarm event is an invalid alarm based on the identifier; or canceling the sending of the alarm information corresponding to the alarm event. This method has a high degree of flexibility and generality because it does not limit the way of suppressing the reporting of alarm events.

[0013] In a possible implementation, after obtaining the event information of an alarm event triggered by a change in the state of a resource, it further includes: sending an alarm notification. The alarm notification is used for a second device that manages a network device to obtain the alarm events processed by the network device after receiving the alarm notification. The second device is different from the first device that controls the change in the state of the resource. Since the second device manages the network device and the second device does not control the change in the state of the resource corresponding to the alarm event of the network device, the second device does not obtain the change in the state of the resource of the network device. By sending the alarm notification, the second device can obtain the resource state of the network device in a timely manner. And only sending the alarm notification to the second device without sending the alarm notification to the first device reduces the number of alarm notifications sent and lowers the data transmission cost.

[0014] In a second aspect, there is provided a processing device for an alarm event. The device includes: an obtaining module, configured to obtain event information of an alarm event triggered by a change in the state of a resource, where the event information is used to describe the resource that triggers the alarm event and the state change that occurs to the resource; and a processing module, configured to determine that the alarm event is an invalid alarm according to the event information and suppress the reporting of the alarm event.

[0015] In a possible implementation, the obtaining module is configured to obtain a mapping relationship between an alarm event, a resource, and a state change of the resource, where the mapping relationship indicates at least one alarm event triggered by any state change that occurs to any resource; and determine the resource that triggers the alarm event and the state change that occurs to the resource according to the mapping relationship to obtain the event information of the alarm event.

[0016] In a possible implementation, the processing module is configured to obtain at least one piece of operation information that has been executed, where the at least one piece of operation information is used for service deployment; and determine that the alarm event is an invalid alarm when the at least one piece of operation information includes operation information for changing the state of the resource.

[0017] In a possible implementation, a processing module is configured to obtain at least one executed protocol request for service deployment. The protocol request includes at least one of a service identifier or a device identifier and operation information. For any protocol request, when the service identifier included in any protocol request indicates the service currently being deployed, determine that any protocol request is a valid request, and / or when the device identifier included in any protocol request indicates a first device for managing network devices, determine that any protocol request is a valid request. The network device is used to process alarm events. Obtain the operation information included in the valid requests among at least one protocol request to obtain at least one piece of operation information.

[0018] In a possible implementation, the processing module is further configured to determine, based on event information, that an alarm event is a valid alarm and allow the reporting of the alarm event.

[0019] In a possible implementation, the reporting of an alarm event includes sending alarm information corresponding to the alarm event. The processing module is configured to add an identifier corresponding to the alarm event to the alarm information corresponding to the alarm event and send the added alarm information. The identifier is used for the module that receives the added alarm information to ignore the alarm event when determining that the alarm event is an invalid alarm based on the identifier; or cancel sending the alarm information corresponding to the alarm event.

[0020] In a possible implementation, the processing module is further configured to send an alarm notification. The alarm notification is used for a second device that manages network devices to obtain the alarm events processed by the network device after receiving the alarm notification. The second device is different from the first device whose state changes with the control resource.

[0021] In a third aspect, a device for processing alarm events is provided. The device includes a processor configured to load and execute at least one instruction to cause the device for processing alarm events to execute the method in the first aspect or any possible implementation manner of the first aspect.

[0022] In a possible implementation, the device includes a memory coupled to the processor, and the memory stores at least one instruction.

[0023] In a fourth aspect, a computer-readable storage medium is provided. At least one instruction is stored in the computer-readable storage medium, and the instruction is loaded and executed by a processor to implement the method for processing alarm events in the first aspect or any possible implementation manner of the first aspect.

[0024] In a fifth aspect, a computer program (product) is provided. The computer program (product) includes computer programs / instructions, and the computer programs / instructions are executed by a processor to cause a computer to implement the method for processing alarm events in the first aspect or any possible implementation manner of the first aspect.

[0025] In a sixth aspect, a communication device is provided, which includes a transceiver, a memory, and a processor. Among them, the transceiver, the memory, and the processor communicate with each other through an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. And when the processor executes the instructions stored in the memory, the processor is caused to execute the method in the first aspect or any possible implementation manner of the first aspect.

[0026] Optionally, there is one or more processors and one or more memories.

[0027] Optionally, the memory may be integrated with the processor, or the memory and the processor are separately arranged.

[0028] In a specific implementation process, the memory may be a non-transitory memory, such as a read only memory (ROM), which may be integrated with the processor on the same chip or may be separately arranged on different chips. The present application does not limit the type of the memory and the setting manner of the memory and the processor.

[0029] In a seventh aspect, a chip is provided, including a processor, which is used to call and run the running program instructions or codes stored in the memory, so that a communication device installed with the chip executes the methods in the above aspects.

[0030] In an eighth aspect, another chip is provided, including an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is used to execute the code in the memory, and when the code is executed, the processor is used to execute the methods in the above aspects.

[0031] It should be understood that for the beneficial effects obtained by the technical solutions and corresponding possible implementation manners of the second aspect to the eighth aspect of the present application, reference may be made to the technical effects of the first aspect and its corresponding possible implementation manners described above, and details are not described herein again. Description of the Drawings

[0032] Figure 1 It is a schematic diagram of an implementation environment provided by an embodiment of the present application;

[0033] Figure 2 It is a network topology structure diagram provided by an embodiment of the present application;

[0034] Figure 3 It is a schematic diagram of another implementation environment provided by an embodiment of the present application;

[0035] Figure 4 A flowchart of a method for processing an alarm event provided by an embodiment of the present application;

[0036] Figure 5 An architecture scenario diagram of an alarm event provided by an embodiment of the present application;

[0037] Figure 6 A schematic structural diagram of a device for processing an alarm event provided by an embodiment of the present application;

[0038] Figure 7 A schematic structural diagram of a network device provided by an embodiment of the present application;

[0039] Figure 8 A schematic structural diagram of another network device provided by an embodiment of the present application. Detailed implementation manners

[0040] The terms used in the implementation manners part of the present application are only used to explain the specific embodiments of the present application, rather than aiming to limit the present application. To make the purpose, technical solutions and advantages of the present application clearer, the following will further describe the implementation manners of the present application in detail with reference to the accompanying drawings.

[0041] With the development of computer technology, the usage frequency of the network is getting higher and higher, and the maintenance of the network has become increasingly important. When a fault occurs in the network operation and triggers an alarm event, it is necessary to generate the alarm information of the alarm event in a timely manner and report the alarm information to the operation and maintenance object. So that the operation and maintenance object can locate and diagnose the fault according to the alarm information, and perform corresponding maintenance operations according to the location and diagnosis results.

[0042] In related art one, for the alarm events triggered during operation, the network device reports all the alarm information of the triggered alarm events to the collector of the network management system. After the collector receives and analyzes the alarm information, it obtains the analysis result and feeds back the analysis result to the operation and maintenance object. The operation and maintenance object identifies the analysis and processing result to determine which alarm events are caused by the operations of service deployment, that is, which alarm events are caused by the operations of configuring and arranging each link in the service process according to the user's intention, and then ignores these alarm events. The process of processing alarm events described above requires manual confirmation by the operation and maintenance object, and the efficiency is low.

[0043] In Related Art 2, when a user issues a configuration related to a service, the network devices involved are marked. Subsequently, after the collector receives the alarm information reported by the network devices, if the received alarm information comes from the marked network devices, it is determined that the alarm event reported by the network devices is an alarm event triggered by the service configuration issuance, and the alarm event is ignored. During the configuration issuance process, it is difficult for the user to know the network devices involved, the complexity of marking the network devices is high, and the marking efficiency is low. Moreover, ignoring all the alarm events reported by the marked network devices will cause alarm omission and the accuracy rate is low.

[0044] An embodiment of the present application provides a method for processing alarm events. Please refer to Figure 1 , which shows a schematic diagram of the implementation environment of the method for processing alarm events provided by the embodiment of the present application. The implementation environment includes a network device 01 and a collector 02. A communication connection can be established between the network device 01 and the collector 02 through a wired or wireless network. For an alarm event triggered by a change in the state of a resource, the network device 01 will first obtain the event information of the alarm event, determine that the alarm event is an invalid alarm according to the event information, and then suppress the reporting of the alarm event by adjusting the interaction with the collector 02. Among them, the collector 02 is used to receive alarm information and belongs to the alarm receiving module in the network management system.

[0045] In a possible implementation, network device 01 can be any device with data processing capabilities. Taking a software defined network (SDN) system as an example, the SDN system includes an orchestrator, controllers, and network elements. The orchestrator can be connected to one or more controllers, and the controllers can also be connected to one or more network elements. Among them, the orchestrator is used to deploy services to the controllers. The orchestrator can use a network configuration model to indicate to the controllers how to configure each part of the service. The northbound interface (NBI) of the orchestrator can be configured based on a specific service model. The protocol used between the orchestrator and the controllers is, for example, the Network Configuration Protocol (NETCONF) / Representational State Transfer Configuration Protocol (RESTCONF). Among them, both NETCONF and RESTCONF are network management protocols driven by the Yet Another Next Generation (YANG) model. The controller uses a device configuration model to set the configuration parameters on each network element to issue configuration execution operations to the network elements, thereby implementing the configuration of each part of the service, and the network elements execute the configuration execution operations issued by the controller. The network element can be a switch, router, firewall, or access point (AP), etc. The network element can also be a terminal device such as a desktop computer, laptop, smartphone, or Internet of Things (IoT) terminal, or any data server, such as a central server, edge server, or local server in a local data center. The server can be a physical server or a cloud server providing cloud computing services, etc.

[0046] Figure 2 shows the structural diagram of the SDN system. Refer to Figure 2 , the SDN system includes orchestrator 0, controller 1, controller 2, controller 3, network element 1, network element 2, network element 3, and network element 4. Figure 2 Taking the example that orchestrator 0 is connected to controller 1, controller 2, and controller 3 for the time being, controller 1 is connected to one network element 1, controller 2 is connected to network elements 2 and 3, and controller 3 is connected to network element 4.

[0047] In an SDN system, a controller or an orchestrator can send protocol requests to the connected network elements or controllers to control the network elements or controllers to perform relevant operations. In a possible scenario, the protocol request includes a device identifier and a service identifier. The device identifier is used to indicate the device that sends the protocol request, and the service identifier is used to indicate the service for which the protocol request is used. Among them, the device identifier is, for example, a parent-identity document (parent-id), and the service identifier is, for example, a trace-identity document (trace-id). Optionally, the device identifiers of devices at the same level are different, that is, the device identifiers of different network elements are different, the device identifiers of different controllers are different, and the device identifiers of different orchestrators are different. And the device identifiers of devices at different levels can be the same or different. See Figure 2 , the device identifiers of both controller 1 and network element 1 are 1, and the device identifiers of controller 1 and network element 1 are the same.

[0048] When the alarm event processing method provided by the embodiments of the present application is applied to an SDN system, Figure 1 the network device 01 in can be any one of an orchestrator, a controller, or a network element. For example Figure 3 as shown, Figure 3 , communication connections are established between orchestrator 0, controller 1, controller 2, controller 3, network element 1, network element 2, network element 3, and network element 4 and collector 02, and orchestrator 0, controller 1, controller 2, controller 3, network element 1, network element 2, network element 3, and network element 4 can all act as network device 01 to report the detected alarm events, for example, send the alarm information of the alarm events to collector 02. When network element 1 acts as network device 01 to report an alarm event, the reported alarm event is a device-level fault. When controller 1 acts as network device 01 to report an alarm event, the reported alarm event is a network-level fault. In addition, collector 02 and controller 1, controller 2, and controller 3 can be Figure 3 independent of each other as shown, or integrated on the same device. In this case, the function of collector 02 is implemented by the collection module included in the device, the function of the controller is implemented by the control module included in the device, and the information interaction between the collection module and the control module is realized through an internal switching interface.

[0049] The alarm event processing method provided by the embodiments of the present application can be applied to the above Figure 1 , Figure 2 or Figure 3 shown implementation environment. The flowchart of this method is as Figure 4 shown, including S401 - S402.

[0050] S401, Obtain the event information of the alarm event triggered by the change in the state of the resource. The event information is used to describe the resource that triggers the alarm event and the state change that occurs to the resource.

[0051] Since the processes of different network devices for handling alarm events are similar, in the embodiments of the present application, when introducing the process of handling alarm events, the network device is taken as an example of a network element in the SDN system for illustration. The processes of other network devices for handling alarm events are the same and will not be elaborated here. Optionally, during the operation of the network element, there may be some resources whose state changes trigger alarm events. Among them, the resources can be the hardware or software of the network device. Taking the hardware as an example, the resources can be the interfaces provided by the network element, the connected links, and the included memories, etc. Taking the software as an example, the resources can be the programs, services, or protocols run by the network element. The state change refers to the change in the state of the same resource. For example, whether the interface as a resource is enabled changes from yes (true) to no (false), and the running state of the service as a resource changes from normal to abnormal.

[0052] In a possible case, the change in the state of the resource may trigger an alarm event. Taking the resource as the service as an example, the service has an abnormality during operation, triggering a log alarm and sending an alarm instruction indicating the service abnormality to the network element. The network element determines the triggered alarm event as a service abnormality according to the received alarm instruction. Among them, the alarm event can be an alarm or an incident. Incident refers to the accidental interruption of network services, the degradation of network service quality, or the sub-health of network services caused by alarm or abnormal events. Incident can be the root cause alarm generated after the aggregation of multiple alarms. That is, the alarm event in the embodiments of the present application refers to any abnormal situation triggered by the change in the state of the resource, including but not limited to alarm and incident.

[0053] Optionally, triggering an alarm event means that the network element perceives the abnormal situation corresponding to the alarm event. The perception method can be receiving the alarm instruction shown in the above embodiments or active detection. For example, when the network element detects that it has not received the signal of the interface of the peer within the interaction time, it determines that there is an abnormality in the connection with the interface of the peer, thereby triggering an alarm event for connection abnormality. The interaction time can be any time length set based on experience and the implementation environment.

[0054] Regardless of how an alarm event is triggered, after detecting the trigger of the alarm event, the network element will obtain the alarm information of the alarm event, so as to determine which resource has undergone which state change to trigger the alarm event. In a possible scenario, the process for the network element to obtain event information includes: obtaining the mapping relationship between the alarm event, the resource, and the state change of the resource, where the mapping relationship is used to indicate the alarm event triggered by any state change of any resource; determining the resource that triggers the alarm event and the state change of the resource according to the mapping relationship to obtain the event information of the alarm event.

[0055] In a possible implementation manner, the mapping relationship reflects what kind of state change of a certain resource may trigger what kind of alarm event, that is, the mapping relationship is the relationship among the alarm event, the resource, and the state change of the resource. For example, for an interface, the change in the administrative status of the interface (admin status), including whether it is enabled from true to false, may trigger an alarm event of the interface being down, and may also trigger alarm events of other protocols / services bound to this interface. Then, there is a mapping relationship between the alarm event of the interface being down, the interface, and whether the interface is enabled from true to false, and there is also a mapping relationship between the alarm events of other protocols / services bound to the interface, the interface, and whether the interface is enabled from true to false. In addition, the mapping relationship can be a one-to-many mapping relationship where the state change of a resource triggers multiple alarm events as shown above. In this case, the multiple alarm events triggered by the state change of the resource can be represented in the form of an alarm event list. The mapping relationship can also be a one-to-one mapping relationship where the state change of a resource triggers one alarm event, or a many-to-one mapping relationship where the state changes of multiple resources trigger one alarm event. Taking the alarm event of service failure as an example, the service failure can be that whether the interface bound to the service is enabled changes from true to false, or the connectivity state of the transmission link of the service data of the service changes from connected to interrupted, etc. In addition, the mapping relationship can be any data structure, including but not limited to mapping tables and structure diagrams. For example, Table 1 is a mapping table provided in an embodiment of the present application.

[0056] Table 1

[0057]

[0058] In Table 1, "resources" refers to the resources whose current state has changed. " / if:interfaces / if:interface / if:enabled" refers to an XPath (Extensible Markup Language Path Language) path under the interface model obtained by modeling the interface using YANG. "alarm / incidentlist" refers to the alarm events that may be triggered by the state change of the resources. When the configuration data in the "resources" column changes, such as from "true" to "false", or from "able" to "disable", the state change of the resources can be determined based on the change of the configuration data, and then the alarm events triggered by this state change can be determined. Referring to Table 1, when the enablement status of a resource changes from "true" to "false", it may trigger alarm events such as "interface down", "VPN tunnel disconnected" of the connection of this resource, and "BGP link down" of the connection of this resource.

[0059] The embodiments of this application do not limit the process of obtaining the mapping relationship between alarm events and resource changes. The mapping relationship can be manually input. For example, the network element provides information input control, and the operation and maintenance object inputs the mapping relationship between alarm events, resources, and the state changes of resources according to experience. The network element receives and stores the mapping relationship input through the information input control. The mapping relationship can also be obtained by the network element analyzing and learning historical training data, learning the historical patterns and trends in the historical training data. Exemplarily, the network element obtains the historical repair log as the historical training data. For example, it accesses an open-source database or an enterprise database, or obtains the historical repair log through methods such as questionnaire surveys. Then, the network element learns the mapping relationship between resources, the state changes of resources, and alarm events in the historical repair log. The network element can implement analysis and learning through artificial intelligence (AI) / machine learning (ML).

[0060] Regardless of how the network element obtains the mapping relationship, it can search for the mapping relationship based on the triggered alarm event to obtain the status change of at least one candidate resource corresponding to the alarm event. The candidate resource is a resource that may trigger the alarm event; detect the current status of at least one candidate resource, and determine the resource that triggers the alarm event and the status change that occurs to the resource from the status changes of at least one candidate resource according to the detection result, so as to obtain the event information of the alarm event. For example, based on the alarm event being service failure, searching for the mapping relationship determines that the service failure may be triggered by an interface going down or a link being disconnected. In this case, the interface and the link are candidate resources. The network element further detects the current status of the link and the interface. Since the enable status of the interface is false, and the connection status of the link is connected, the network element determines that the resource that triggers the alarm event is the interface, and the status change that occurs to the resource is that the enable status changes from true to false. In addition, the above embodiments only take the status change of one resource triggering the alarm event as an example. In actual applications, it is possible that the statuses of multiple resources change, triggering the same alarm event. The embodiments of the present application do not limit this.

[0061] In a possible implementation manner, for the case where the alarm event is triggered by sending an alarm instruction, the alarm instruction may carry event information. In this case, the network element can parse the received alarm instruction to extract the event information in the alarm instruction. Continuing with the example where the enable status of the interface changes from true to false, the sent alarm instruction is an interface disable (enable set to false) instruction, and the instruction carries the identifier of the interface that has changed. The network element determines which interface has changed according to the interface identifier, and determines the status change that has occurred as the enable status changing from true to false according to the interface disable instruction, so as to obtain the event information of the alarm event. The network element can choose to obtain the event information of the alarm event in either the way of searching for the mapping relationship or parsing the alarm instruction, or can choose to comprehensively use the above two ways to obtain the event information of the alarm event, that is, use the event information carried in the alarm instruction as the verification value of the event information obtained by searching for the mapping relationship, to implement the verification of the event information obtained by searching for the mapping relationship. By verifying the event information, the accuracy rate of the obtained event information is guaranteed.

[0062] S402, according to the event information, determine that the alarm event is an invalid alarm, and suppress the reporting of the alarm event.

[0063] Exemplarily, an invalid alarm refers to an alarm that does not need to be repaired. In a possible scenario, invalid alarms can be classified according to whether they are related to service deployment. Service deployment is executed according to the user's intention. For example, a user needs to run some services, and the service can be the creation of a virtual private network (VPN). During the process of layer-by-layer deploying the service based on the user's intention, it may be necessary to change the status of some resources, such as deleting an interface on a network element. However, since the change in the status of the resource belongs to the user's own intention, the alarm event triggered by the change in the status of the resource is meaningless to the user, and there is no need for notification and repair. Therefore, alarms related to service deployment belong to invalid alarms.

[0064] In a possible implementation manner, for the case where an invalid alarm is related to service deployment, the process of determining an alarm event as an invalid alarm includes but is not limited to: obtaining at least one operation information that has been executed, where the at least one operation information is used for service deployment; when the at least one operation information includes operation information for changing the status of a resource, determining the alarm event as an invalid alarm.

[0065] Among them, service deployment refers to configuring and arranging each link in the service process. The operation information involved in service deployment includes at least one of operation information for allocating services, operation information for configuration distribution, and operation information for describing services. For example Figure 5 as shown Figure 5 the operation information sent by orchestrator A to controller B, indicating the part of the service that controller B needs to be responsible for, belongs to the operation information for allocating services. The operation information sent by controller B to network element D, indicating the configuration operation that network element D needs to execute, belongs to the operation information for configuration distribution. In addition, orchestrator A will also receive operation information, such as operation information for describing services input by the user, so as to determine the relevant content of the service to be deployed. That is, whether it is an orchestrator, a controller, or a network element, it can obtain operation information for service deployment. In addition, during the service deployment process, in addition to sending operation information, other information interactions will also be involved, such as querying the running status of the service or feeding back the running results of the service.

[0066] Next, continue to take the network element as an example to illustrate the process of executing S402. Optionally, the network element can directly receive the operation information sent by the controller, perform relevant configuration operations according to the operation information, and store the executed operation information to obtain at least one piece of operation information. In the case where the operation information is transmitted together with other data, the network element will also determine the validity of the operation information based on the other data, so as to obtain at least one piece of valid operation information. In one possible implementation, the operation information is transmitted through a protocol request, and the network element will obtain at least one protocol request for service deployment that has been executed. The protocol request includes at least one of a service identifier or a device identifier and the operation information.

[0067] Exemplarily, if the information interaction between the orchestrator, the controller, and the network element is implemented through the NETCONF and RESTCONF protocols, then the protocol request can be a protocol request for network management of NETCONF and RESTCONF. The protocol request includes edit-config, trace-identity document (trace-id), and parent-identity document (parent-id). Among them, edit-config is the operation information in the protocol request, which can indicate the configuration operation from the controller to the network element or the service allocation from the orchestrator to the controller. Trace-id is the service identifier, indicating the service for which the configuration operation is deployed. Parent-id is the device identifier, used to indicate the source device of these configuration operations. Taking the configuration operation executed by the network element as an example, then parent-id is the controller identifier. Taking the configuration operation executed by the controller as an example, then parent-id is the orchestrator identifier. Continuing with Figure 3 as an example, Figure 3 in the protocol request sent by the orchestrator 0 to the controller 1, the included trace-id is 1 and the parent-id is 0. The controller 1 sends a protocol request to the network element 1 based on the received protocol request. Since the service for which the protocol request sent to the network element 1 is used for configuration is the same as the service orchestrated by the orchestrator 0, therefore, the trace-id included in the protocol request is 1, and the device identifier of the parent-id as the controller 1 is equal to 1. Taking the configuration where the controller issues a configuration to disable the interface board ethernet1 / 0 / 0 as an example, the sample message of the protocol request in extensible markup language (XML) fragment is as follows:

[0068]

[0069]

[0070] Regarding racestate=rojo="00f067aa0ba902b7,congo=t61rcWkgMzE" in the protocol request, the trace state (tracestate) is an optional field, which mainly uses a set of name (name) / value (value) pairs to represent the manufacturer-specific data to extend the trace parent object (trace parent), which is used to give respective identifications to the two source devices rojo and congo. Rojo and congo are used to distinguish different source devices. Regarding traceparent="00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01", 00 is the version number, 4bf92f3577b34da6a3ce929d0e0e4736 is the trace id, which can be understood as the service identifier associated with a service delivery, 0f067aa0ba902b7 is the parent-id indicating the device identifier of the controller that initiated the request, and 01 is the flag bit. In addition, the above example is intended to illustrate an optional format of the protocol request, rather than to limit the protocol request adopted in the embodiment of the present application. Different protocols can be used to send and receive protocol requests for different network devices that process alarm events.

[0071] In the case where the operation information is information carried by the protocol request, after obtaining the protocol request sent by the controller, the network element parses the protocol request and performs the configuration operation that the network element needs to perform during the deployment of the service according to the operation information of the parsed protocol request. The received protocol request is stored and recorded, and based on the triggering of the alarm event, the recorded executed protocol requests are counted, and valid requests are screened out from the protocol request, and the operation information included in the valid request is extracted as the operation message to be matched with the event information. Among them, the valid request can refer to at least one situation that the service corresponding to the protocol request is valid or that the device corresponding to the protocol request is valid. The network element can determine the valid request in the following two ways, including but not limited to.

[0072] Mode 1: When the service identifier included in any protocol request indicates a currently deployed service, any protocol request is determined to be a valid request.

[0073] The first method is to determine whether any protocol request is a valid request based on whether the service corresponding to the protocol request is service-valid. Exemplarily, the currently deployed service refers to the service for which a deployment operation has been performed within the reference period, and the reference period can be any duration set according to experience. For example, based on experience, the reference period is set to 10 minutes. Continuing with the XML fragment shown in the above embodiment, the network element determines the service associated with the protocol request according to the trace id, determines the deployment time of the service, and when the deployment time is within the reference period, for example, the deployment time is 5 minutes ago, it determines that the service is valid and the protocol request is a valid request. The network element can also maintain a set of service identifiers of the services deployed within the reference period, query the set of service identifiers according to the service identifier in the protocol request, and when the service identifier in the protocol request is the service identifier included in the set of service identifiers, it determines that the service identifier indicates the currently deployed service, the service of the protocol request is valid, and the protocol request is a valid request. By restricting the reference period, it is determined in which periods the configuration operations performed may trigger an alarm event at the current moment, avoiding misidentifying the operation information of the historical service that has ended running as the operation information for changing the state of the resource.

[0074] The second method: When the device identifier included in any protocol request indicates the first device for managing the network device, it is determined that any protocol request is a valid request.

[0075] The second method is to determine whether any protocol request is a valid request based on whether the superior device corresponding to any protocol request is device-valid. Among them, the network device is used to process alarm events, and the network device is, for example, the execution entity network element of the current method for processing alarm events. In this case, the first device for managing the network device is, for example, Figure 5 the controller B shown. The network element obtains the device identifier in the protocol request and the device identifiers of the connected controllers. When the device identifiers of the controllers do not include the device identifier in the protocol request, since the controller to which the protocol request is sent is not the controller that controls the network element, therefore, the protocol request should not be sent to the network element either. The sending of the protocol request is an incorrect sending, the device of the protocol request is invalid, and the protocol request belongs to an invalid request. And when the device identifiers of the controllers include the device identifier in the protocol request, it is determined that the device identifier included in any protocol request indicates the first device, the superior device corresponding to any protocol request is device-valid, and the protocol request belongs to a valid request.

[0076] The network element can select any one of Method 1 or Method 2 to screen out valid requests from multiple executed protocol requests, or can also combine Method 1 and Method 2. In this case, for any protocol request, when the service identifier indicates the currently deployed service and the first device indicated by the device identifier is used to manage network devices, that is, when both the service and the device of any protocol request are valid, this any protocol request is a valid request. It can also be that when the service identifier indicates the currently deployed service, or the first device indicated by the device identifier is used to manage network devices, that is, when at least one of the service or the device of any protocol request is valid, this any protocol request is a valid request.

[0077] Regardless of the method based on which the network element determines valid requests from at least one protocol request, it can obtain the operation information included in the valid requests in at least one protocol request to obtain at least one piece of operation information. And determine whether the alarm event is an invalid alarm according to at least one piece of operation information. In a possible case, the operation information describes a status change that requires a resource to execute. The network element matches the status change of the resource described in the operation information with the status change of the resource in the event information. When the status change of the resource described in the operation information is the same as the status change of the resource in the event information, it is determined that this operation information is used to change the status of this resource, that is, at least one piece of operation information includes operation information for changing the status of the resource. Since at least one piece of operation information is used for service deployment, therefore, the status change of the resource belongs to the normal change of service deployment, meets the intention of the user who issues the service, and the alarm event triggered by the status change of this resource does not need to be notified and maintained, and belongs to an invalid alarm.

[0078] The network element can determine that the alarm event is an invalid alarm according to the event information of the alarm event as shown in the above embodiment. In a possible implementation manner, the network element can also determine an invalid alarm in the following way: determine the alarm type of the alarm event, and the alarm type includes valid alarms and invalid alarms; determine whether this alarm event is an invalid alarm according to the alarm type of the alarm event. Corresponding to the meaning of an invalid alarm, a valid alarm refers to an alarm to be repaired. The network element can determine that the alarm type of the alarm event is a valid alarm when at least one piece of operation information does not include operation information for changing the status of the resource. When the status change of the resource described in each piece of operation information is not the status change of the resource in the event information, it means that the status change of the resource does not occur based on service deployment. In this case, the status change of the resource does not meet the intention of the user and needs to be notified and maintained. The network element thus determines that the alarm event triggered by the status change of this resource belongs to a valid alarm.

[0079] Optionally, in the process of first screening valid requests through Method 1 or Method 2 and then determining whether an alarm event is an invalid alarm based on the operation information of the valid requests, in addition to making a judgment based on the operation information, a judgment will also be made based on at least one of the device identifier or service identifier, rather than being used to limit the judgment order. The network element can first screen the operation information through the device identifier and service identifier as shown in the above embodiments, and then use the screened operation information to determine whether the alarm event is an invalid alarm. It is also possible to first match the operation information and event information. When the operation information is used to change the state of the resource described by the event information, further determine the validity of the operation information according to the device identifier or service identifier corresponding to the operation information. When the operation information is valid, determine that the alarm event is an invalid alarm. When the operation information is invalid, determine that the alarm event is a valid alarm.

[0080] Exemplarily, when the alarm event is an invalid alarm, the network element suppresses the reporting of the alarm event. The embodiments of the present application do not limit the process of suppressing the reporting of the alarm event. When reporting the alarm event includes sending the alarm information corresponding to the alarm event, the network element can implement the suppression of the reporting of the alarm event through at least the following two suppression methods.

[0081] Suppression Method 1: Add the identifier corresponding to the alarm event to the alarm information corresponding to the alarm event, and send the added alarm information. The identifier is used for the module that receives the added alarm information to ignore the alarm event when it determines that the alarm event is an invalid alarm according to the identifier.

[0082] Exemplarily, the identifier corresponding to the alarm event can be at least one of the device identifier or service identifier in the above embodiments. By adding an identifier to the alarm information, the module that receives the alarm information with the added identifier can determine that the state change of the resource that triggers the alarm event is a normal change of service deployment according to the identifier, so as to determine that the alarm event is an invalid alarm and ignore the alarm event. Ignoring the alarm event can mean canceling the reporting of the alarm event to the operation and maintenance object, or canceling operations such as analyzing the alarm event and fault location.

[0083] In a possible case, the module of the network element that sends the alarm information can be the collector as Figure 5 shown, Figure 5 In the figure, during the process of service deployment, network devices such as orchestrator A, controller B, network element C, and network element D will send protocol requests for service deployment to the collector based on the OpenTelemetry Protocol (OTLP). The collector determines the services to be deployed and the network devices involved in the service deployment according to the received protocol requests. After receiving the alarm information, it detects the identifier in the alarm information and determines whether the alarm event indicated by the alarm information belongs to an invalid alarm according to the identifier. The alarm information carrying the identifier is, for example:

[0084]

[0085]

[0086] Among them, 4bf92f3577b34da6a3ce929d0e0e4736 is the service identifier, and 0f067aa0ba902b7 is the device identifier. Next, the process of identifying invalid alarms based on the service identifier and the device identifier will be introduced separately. When the identifier carried in the alarm information is the service identifier, the collector matches the service identifier in the received protocol request and the service identifier in the alarm information. When the service identifier in the protocol request is the same as the service identifier in the alarm information, it indicates that the resource status change of this alarm event is caused by service deployment, and this alarm event belongs to the invalid alarm triggered by service deployment. Taking the identifier as the device identifier as an example, the collector matches the device identifier in the protocol request and the device identifier in the alarm information. When the device identifier in the protocol request is the same as the device identifier in the alarm information, it indicates that the resource status change of this alarm event is caused by the normal configuration distribution of the controller and belongs to the invalid alarm triggered by service deployment.

[0087] Suppression method 2: Cancel sending the alarm information corresponding to the alarm event.

[0088] Since the alarm implementation belongs to the invalid alarm triggered by service deployment, the network element determines that there is no need to process this alarm event, cancels reporting this alarm event, and no longer sends the alarm information of this alarm event to the collector. By canceling the sending of the alarm information of the invalid alarm, the data volume of the alarm information transmitted in the network is reduced, and the utilization rate of transmission resources is improved.

[0089] Optionally, the network element can select any one of suppression method 1 or suppression method 2 to suppress the reported alarm event, so as to reduce the number of alarm events to be processed and reduce the network maintenance burden. For the alarm events belonging to valid alarms, the network element will allow the reporting of the alarm events. The process of allowing reporting is, for example, to normally send the alarm information to the collector. Since the status change of the resources corresponding to the alarm events belonging to valid alarms has nothing to do with service deployment, there is no corresponding identifier for this alarm event, and the sent alarm information does not contain the identifier corresponding to this alarm event. In addition, for the case where there are multiple levels of collectors, such as the collector includes a single-domain collector and a cross-domain collector, the network domain can report to the collectors layer by layer.

[0090] In a possible scenario, for an alarm event, in addition to reporting to the collector, the network element also needs to report to the upper-level device, which is the device that manages the network element, such as a controller that controls the configuration operations of the network element, so that the controller can obtain the status change of the resource corresponding to the alarm event, and then perform configuration distribution according to the status change of the resource. Optionally, when there are multiple devices in the upper-level device that manages the network element, among the multiple devices, there is a first device that controls the resource to have a status change, and a second device that does not control the resource to have this status change. In this case, the network device can send an alarm notification to the second device, and this alarm notification is used for the second device that manages the network device to obtain the alarm event processed by this network device after receiving the alarm notification. Refer to Figure 3 , the network element 3 is managed by multiple controllers, such as Figure 3 shown, the multiple controllers include controller 2 and controller 3. Among them, the network element 3 executes the operation information sent by controller 2, changes whether interface A is enabled from true to false, and triggers an alarm event for interface down. In this case, controller 2 is the first device that controls the resource to have a status change, and controller 3 is the second device that does not control the resource to have this status change. Figure 3 The network element 3 in

[0091] sends an alarm notification to controller 3. Optionally, the network element synchronizes the alarm event to the controller so that the controller can obtain the latest resource status of the network element, and perform configuration distribution according to the latest status, to avoid calling the already changed resource in the subsequent process of performing configuration distribution according to the service. For the controllers connected to the network element, including the first device and the second device, since the first device already knows the status change of the resource that triggers the alarm event, and the first device includes a scenario of integrated network management for control and collection, the first device has already obtained the status change of the resource that occurs on the network element. The network element does not need to send an alarm notification to the first device, and only needs to send an alarm notification to the second device, so that the second device can know whether interface A of the network element is enabled and changed from true to false. And, since the purpose of the network element sending the alarm notification to the second device is to make the second device know the status change of the resource of the network element, the second device does not need to know the reason for the status change. Therefore, the alarm notification sent by the network element may not carry the identifier corresponding to the alarm event. Continuing with the example of the XML format of the alarm information shown in the above embodiment, the corresponding alarm notification is, for example:

[0092]

[0093] The service identifier 4bf92f3577b34da6a3ce929d0e0e4736 and the device identifier 0f067aa0ba902b7 included in the alarm information are not carried in the above alarm notification. By sending an alarm notification without a identifier, the data volume of the alarm notification is reduced. Moreover, the alarm notification is only sent to the second device, and no alarm notification is sent to the first device, controlling the number of alarm notifications to be sent and improving the data transmission efficiency.

[0094] In summary, for the method for processing an alarm event provided by the embodiment of the present application, after a network device discovers a triggered alarm event, it determines the resource that triggers the alarm event and the status change that occurs to the resource, and determines that the resource change is an invalid alarm according to the status change that occurs to the resource, inhibits the reporting of the alarm event, controls the number of reported alarm events, reduces the network maintenance pressure, does not require manual confirmation, and has high processing efficiency. In addition, for an alarm event that can be determined as an invalid alarm through event information, the complexity of the identification process of the invalid alarm is low and the efficiency is high. Furthermore, by suppressing the alarm event that is an invalid alarm, event-level suppression is achieved with high accuracy. Subsequently, during the process of sending an alarm notification, the first device that causes the alarm event is not sent repeatedly, but is sent to a second device that manages other network devices, reducing the amount of information exchanged between devices and improving resource utilization.

[0095] The above introduces the method for processing an alarm event of the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides a device for processing an alarm event. Figure 6 It is a schematic structural diagram of a device for processing an alarm event provided by the embodiment of the present application. Based on Figure 6 the following multiple modules shown, the Figure 6 device for processing an alarm event shown can execute all or part of the operations of the network device shown above Figure 4 . It should be understood that the device may include more additional modules than the shown modules or omit some of the shown modules, and the embodiment of the present application does not limit this. As Figure 6 shown, the device includes:

[0096] An obtaining module 601, configured to obtain event information of an alarm event triggered by a status change of a resource, where the event information is used to describe the resource that triggers the alarm event and the status change that occurs to the resource;

[0097] A processing module 602, configured to determine, according to the event information, that the alarm event is an invalid alarm and inhibit the reporting of the alarm event.

[0098] In a possible implementation, an obtaining module 601 is configured to obtain a mapping relationship between an alarm event, a resource, and a status change of the resource, where the mapping relationship indicates at least one alarm event triggered by any status change of any resource; determine, according to the mapping relationship, the resource that triggers the alarm event and the status change that occurs to the resource, so as to obtain event information of the alarm event.

[0099] In a possible implementation, a processing module 602 is configured to obtain at least one piece of operation information that has been executed, where the at least one piece of operation information is used for service deployment; and determine that the alarm event is an invalid alarm when the at least one piece of operation information includes operation information for changing the resource status.

[0100] In a possible implementation, a processing module 602 is configured to obtain at least one protocol request for service deployment that has been executed, where the protocol request includes at least one of a service identifier or a device identifier and operation information; for any protocol request, determine that the any protocol request is a valid request when the service identifier included in the any protocol request indicates the service currently being deployed, and / or determine that the any protocol request is a valid request when the device identifier included in the any protocol request indicates a first device for managing a network device, where the network device is used to process the alarm event; and obtain the operation information included in the valid requests among the at least one protocol request, so as to obtain at least one piece of operation information.

[0101] In a possible implementation, the processing module 602 is further configured to determine, according to the event information, that the alarm event is a valid alarm and allow the reporting of the alarm event.

[0102] In a possible implementation, the reporting of the alarm event includes sending alarm information corresponding to the alarm event. The processing module 602 is configured to add an identifier corresponding to the alarm event to the alarm information corresponding to the alarm event and send the added alarm information. The identifier is used for a module that receives the added alarm information to ignore the alarm event when determining that the alarm event is an invalid alarm according to the identifier; or cancel sending the alarm information corresponding to the alarm event.

[0103] In a possible implementation, the processing module 602 is further configured to send an alarm notification, where the alarm notification is used for a second device for managing the network device to obtain the alarm event processed by the network device after receiving the alarm notification, and the second device is different from the first device whose control resource has a status change.

[0104] For the alarm events triggered by the change in the resource occurrence status, the above device will first obtain the event information of the alarm event, and then determine whether the resource with the changed status needs to be repaired according to the status change of the resource described in the event information, that is, whether the alarm event is an invalid alarm. In the case of an invalid alarm event, the reporting of the alarm event is suppressed, effectively controlling the number of reported alarm events and reducing the network maintenance pressure. Determining whether an alarm event is an invalid alarm through event information has a low complexity and high efficiency in the determination process. Suppressing the invalid alarms that need to be ignored realizes event-level suppression with high accuracy.

[0105] It should be understood that when the above Figure 6 provided device implements its functions, only the above division of each functional module is used as an example for illustration. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device provided in the above embodiment and the method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be elaborated here.

[0106] See Figure 7 , Figure 7 shows a schematic structural diagram of a network device 700 provided by an exemplary embodiment of the present application. Figure 7 The shown network device 700 is used to perform the operations involved in the above Figure 4 shown alarm event processing method. The network device 700 is, for example, a switch, a router, etc., and the network device 700 can be implemented by a general bus architecture.

[0107] As Figure 7 shown, the network device 700 includes at least one processor 701, a memory 703, and at least one communication interface 704.

[0108] The processor 701 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of this application. For example, the processor 701 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logic blocks, modules, and circuits described in connection with the disclosed content of the embodiments of this application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.

[0109] Optionally, the network device 700 further includes a bus. The bus is used to transfer information between the components of the network device 700. The bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.

[0110] The memory 703 is, for example, a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, such as a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, such as an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 703 is, for example, independent and connected to the processor 701 through a bus. The memory 703 can also be integrated with the processor 701.

[0111] The communication interface 704 uses any device such as a transceiver to communicate with other devices or communication networks, which can be an Ethernet, a radio access network (RAN) or a wireless local area network (WLAN), etc. The communication interface 704 can include a wired communication interface and can also include a wireless communication interface. Specifically, the communication interface 704 can be an Ethernet interface, a fast ethernet (FE) interface, a gigabit ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface or a combination thereof. In the embodiments of the present application, the communication interface 704 can be used for the network device 700 to communicate with other devices.

[0112] In a specific implementation, as an embodiment, the processor 701 can include one or more CPUs, such as Figure 7 CPU0 and CPU1 shown therein. Each of these processors can be a single-CPU processor or a multi-CPU processor. Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0113] In a specific implementation, as an example, the network device 700 may include multiple processors, such as Figure 7 the processor 701 and the processor 705 shown in Figure 7 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0114] In a specific implementation, as an example, the network device 700 may further include an output device and an input device. The output device communicates with the processor 701 and can display information in various ways. For example, the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device communicates with the processor 701 and can receive user input in various ways. For example, the input device may be a mouse, a keyboard, a touch screen device, or a sensing device, etc.

[0115] In some embodiments, the memory 703 is used to store the program code 710 for executing the solution of this application, and the processor 701 can execute the program code 710 stored in the memory 703. That is, the network device 700 can implement the processing method of the alarm event provided in the method embodiment through the processor 701 and the program code 710 in the memory 703. The program code 710 may include one or more software modules. Optionally, the processor 701 itself may also store the program code or instructions for executing the solution of this application.

[0116] In a specific embodiment, the network device 700 of the embodiment of this application may correspond to the network device in each of the above method embodiments, such as a network element, etc.

[0117] Among them, Figure 4 each step of the processing method of the alarm event shown is completed by the integrated logic circuit of the hardware in the processor of the network device 700 or the instructions in software form. The steps of the method disclosed in combination with the embodiments of this application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by the combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0118] See Figure 8 , Figure 8 which shows a schematic structural diagram of a network device 800 provided by another exemplary embodiment of the present application. Figure 8 The network device 800 shown is used to perform all or part of the operations involved in the above-mentioned Figure 4 alarm event processing method. The network device 800 is, for example, a switch, a router, etc., and the network device 800 can be implemented by a general bus architecture.

[0119] As Figure 8 shown, the network device 800 includes: a main control board 810 and an interface board 830.

[0120] The main control board is also called a main processing unit (MPU) or a route processor card. The main control board 810 is used for controlling and managing each component in the network device 800, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 810 includes: a central processor 811 and a memory 812.

[0121] The interface board 830 is also called a line processing unit (LPU), a line card, or a service board. The interface board 830 is used to provide various service interfaces and implement packet forwarding. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc. The Ethernet interface is, for example, a Flexible Ethernet Clients (FlexE Clients). The interface board 830 includes: a central processor 831, a network processor 832, a forwarding table entry memory 834, and a physical interface card (PIC) 833.

[0122] The central processor 831 on the interface board 830 is used to control and manage the interface board 830 and communicate with the central processor 811 on the main control board 810.

[0123] The network processor 832 is used to implement the forwarding processing of packets. The form of the network processor 832 can be a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 832 is used to forward the received packets based on the forwarding table entries stored in the forwarding table entry memory 834. If the destination address of the packet is the address of the network device 800, the packet is sent to the CPU (such as the central processor 831) for processing; if the destination address of the packet is not the address of the network device 800, the next hop and the outgoing interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the outgoing interface corresponding to the destination address. Among them, the processing of the upstream packets can include: the processing of the packet incoming interface, and the forwarding table lookup; the processing of the downstream packets can include: the forwarding table lookup, etc. In some embodiments, the central processor can also perform the functions of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that there is no need for a forwarding chip in the interface board.

[0124] The physical interface card 833 is used to implement the docking function of the physical layer. The original traffic enters the interface board 830 from here, and the processed packets are sent out from the physical interface card 833. The physical interface card 833 is also called a daughter card and can be installed on the interface board 830. It is responsible for converting the optical and electrical signals into packets, performing a legality check on the packets, and then forwarding them to the network processor 832 for processing. In some embodiments, the central processor 831 can also perform the functions of the network processor 832, such as implementing software forwarding based on a general-purpose CPU, so that there is no need for the network processor 832 in the physical interface card 833.

[0125] Optionally, the network device 800 includes multiple interface boards. For example, the network device 800 further includes an interface board 840, and the interface board 840 includes: a central processor 841, a network processor 842, a forwarding table entry memory 844, and a physical interface card 843. The functions and implementation manners of the components in the interface board 840 are the same as or similar to those of the interface board 830, and will not be described in detail here.

[0126] Optionally, the network device 800 further includes a switch fabric board 820. The switch fabric board 820 can also be called a switch fabric unit (SFU). In the case where the network device 800 has multiple interface boards, the switch fabric board 820 is used to complete the data exchange between the interface boards. For example, the interface board 830 and the interface board 840 can communicate through the switch fabric board 820.

[0127] The main control board 810 is coupled with the interface board. For example, the main control board 810, interface boards 830 and 840, and the switching fabric board 820 are interconnected through a system bus and a system backplane. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 810 and interface boards 830 and 840, and communication is carried out between the main control board 810 and interface boards 830 and 840 through the IPC channel.

[0128] Logically, the network device 800 includes a control plane and a forwarding plane. The control plane includes the main control board 810 and the central processing unit 811, and the forwarding plane includes various components that perform forwarding, such as the forwarding table entry memory 834, the physical interface card 833, and the network processor 832. The control plane executes functions such as acting as a router, generating a forwarding table, processing signaling and protocol messages, and configuring and maintaining the status of the network device. The control plane distributes the generated forwarding table to the forwarding plane. In the forwarding plane, the network processor 832 looks up the table and forwards the packets received by the physical interface card 833 based on the forwarding table distributed by the control plane. The forwarding table distributed by the control plane can be stored in the forwarding table entry memory 834. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.

[0129] It should be noted that there may be one or more main control boards. When there are multiple main control boards, they may include an active main control board and a standby main control board. There may be one or more interface boards. The stronger the data processing capacity of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching fabric board, or there may be one or more switching fabric boards. When there are multiple switching fabric boards, they can jointly achieve load sharing and redundant backup. In a centralized forwarding architecture, the network device may not require a switching fabric board, and the interface board undertakes the function of processing the service data of the entire system. In a distributed forwarding architecture, the network device may have at least one switching fabric board, and data exchange between multiple interface boards is realized through the switching fabric board, providing a large-capacity data exchange and processing capacity. Therefore, the data access and processing capacity of the network device with a distributed architecture is greater than that of the network device with a centralized architecture. Optionally, the form of the network device can also be a single board card, that is, there is no switching fabric board, and the functions of the interface board and the main control board are integrated on this single board card. At this time, the central processing unit on the interface board and the central processing unit on the main control board can be combined into one central processing unit on this single board card to execute the functions after the superposition of the two. The data exchange and processing capacity of this form of network device is relatively low (for example, network devices such as low-end switches or routers). Which architecture to specifically adopt depends on the specific networking deployment scenario and is not limited here.

[0130] In a specific embodiment, the network device 800 corresponds to the aboveFigure 6 A processing device for the warning events shown. In some embodiments, Figure 6 The processing module 602 in the processing device for the warning events shown is equivalent to the central processing unit 811 or the network processor 832 in the network device 800.

[0131] Embodiments of the present application further provide a communication device, which includes: a transceiver, a memory, and a processor. Among them, the transceiver, the memory, and the processor communicate with each other through an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. And when the processor executes the instructions stored in the memory, the processor is caused to execute the processing method for warning events.

[0132] It should be understood that the above-mentioned processor may be a CPU, or may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the advanced RISC machines (ARM) architecture.

[0133] Further, in an alternative embodiment, the above-mentioned memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.

[0134] The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory may be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0135] An embodiment of the present application further provides a processing device for an alarm event. The device includes a processor, and the processor is configured to load and run at least one instruction, so that the processing device for the alarm event implements the processing method for the alarm event provided by the embodiment of the present application. Optionally, the device further includes a memory, and the memory is coupled to the processor, and the memory is configured to store at least one instruction.

[0136] An embodiment of the present application further provides a computer-readable storage medium, in which at least one instruction is stored, and the instruction is loaded and executed by a processor, so that a computer implements the processing method for the alarm event described in any one of the above.

[0137] An embodiment of the present application further provides a computer program (product), when the computer program is executed by a computer, it may cause the processor or the computer to execute the corresponding steps and / or processes in the above method embodiments.

[0138] An embodiment of the present application further provides a chip, the chip includes a processor, which is configured to call and run the instruction stored in the memory from the memory, so that a communication device installed with the chip executes the processing method for the alarm event described in any one of the above.

[0139] Another chip provided by an embodiment of the present application includes: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute the code in the memory. When the code is executed, the processor is configured to execute the processing method of any one of the above warning events.

[0140] In the above embodiment, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media integrated. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk).

[0141] It should be noted that the information (including but not limited to user equipment information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions. For example, the event information involved in the present application is obtained under full authorization.

[0142] Those of ordinary skill in the art can realize that, in combination with the method steps and modules described in the embodiments disclosed herein, they can be implemented in software, hardware, firmware, or any combination thereof. To clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0143] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a disk, an optical disc, etc.

[0144] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiments of the present application can be described in the context of machine-executable instructions, such as program modules executed in devices included in a target real or virtual processor. Generally speaking, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In each embodiment, the functions of the program modules can be merged or split among the described program modules. The machine-executable instructions for the program modules can be executed within local or distributed devices. In a distributed device, the program modules can be located in both local and remote storage media.

[0145] The computer program code for implementing the method of the embodiments of the present application can be written in one or more programming languages. These computer program codes can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable alarm event processing devices, so that when the program code is executed by the computer or other programmable alarm event processing devices, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the computer, partially on the computer, as an independent software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.

[0146] In the context of the embodiments of the present application, the computer program code or related data can be carried by any suitable carrier, so that the device, apparatus, or processor can execute the various processes and operations described above. Examples of the carrier include signals, computer-readable media, etc.

[0147] Examples of signals can include electrical, optical, radio, acoustic, or other forms of propagated signals, such as carrier waves, infrared signals, etc.

[0148] A machine-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More detailed examples of machine-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0149] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0150] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the shown or discussed couplings, direct couplings, or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or modules, and can also be electrical, mechanical, or other forms of connections.

[0151] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they can be located in one place, or can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the objectives of the embodiments of the present application.

[0152] In addition, in each embodiment of the present application, the functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules.

[0153] When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.

[0154] In this application, terms such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various described examples, the first image can be referred to as the second image, and similarly, the second image can be referred to as the first image. Both the first image and the second image can be images, and in some cases, they can be separate and different images.

[0155] It should also be understood that in various embodiments of this application, the magnitudes of the sequence numbers of each process do not mean the order of execution is prior or subsequent. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0156] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "multiple" refers to two or more. For example, multiple second messages refer to two or more second messages. In this article, the terms "system" and "network" are often used interchangeably.

[0157] It should be understood that the terms used in the description of various described examples in this article are only for describing specific examples and are not intended to be restrictive. As used in the description of various described examples and the appended claims, the singular forms "a", "an", and "the" are also intended to include the plural forms unless the context clearly indicates otherwise.

[0158] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a relational term describing an association between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this application generally indicates that the associated objects before and after are in an "or" relationship.

[0159] It should also be understood that the term "comprises" (also referred to as "includes", "including", "comprises", and / or "comprising") when used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groupings.

[0160] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" ("when" or "upon") or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined..." or "if [the stated condition or event] is detected" can be interpreted to mean "when it is determined..." or "in response to determining..." or "when [the stated condition or event] is detected" or "in response to detecting [the stated condition or event]".

[0161] It should be understood that determining B based on A does not mean determining B solely based on A, and B can also be determined based on A and / or other information.

[0162] It should also be understood that the "one embodiment", "an embodiment", "a possible implementation" mentioned throughout the specification means that the specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of this application. Therefore, the "in one embodiment" or "in an embodiment", "a possible implementation" that appear throughout the specification do not necessarily refer to the same embodiment. Additionally, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner.

Claims

1. A method for processing an alarm event, characterized in that, The method includes: Obtaining event information of an alarm event triggered by a change in the state of a resource, where the event information is used to describe the resource that triggers the alarm event and the state change that occurs to the resource; Determining, based on the event information, that the alarm event is an invalid alarm and suppressing the reporting of the alarm event.

2. The method according to claim 1, characterized in that, The obtaining event information of the alarm event triggered by a change in the state of a resource includes: Obtaining a mapping relationship among the alarm event, the resource, and the state change of the resource, where the mapping relationship indicates at least one alarm event triggered by any state change that occurs to any resource; Determining, based on the mapping relationship, the resource that triggers the alarm event and the state change that occurs to the resource, to obtain the event information of the alarm event.

3. The method according to claim 1 or 2, characterized in that, The determining, based on the event information, that the alarm event is an invalid alarm includes: Obtaining at least one piece of operation information that has been executed, where the at least one piece of operation information is used for service deployment; Determining that the alarm event is an invalid alarm when the at least one piece of operation information includes operation information for changing the state of the resource.

4. The method according to claim 3, characterized in that, The obtaining at least one piece of operation information that has been executed includes: Obtaining at least one protocol request that has been executed for service deployment, where the protocol request includes at least one of a service identifier or a device identifier and operation information; For any protocol request, when the service identifier included in the any protocol request indicates the service currently being deployed, determining that the any protocol request is a valid request, and / or when the device identifier included in the any protocol request indicates a first device for managing network devices, determining that the any protocol request is a valid request, where the network device is used to process the alarm event; Obtaining the operation information included in the valid requests among the at least one protocol request to obtain the at least one piece of operation information.

5. The method according to any one of claims 1-4, characterized in that The method further includes: Determining, based on the event information, that the alarm event is a valid alarm and allowing the reporting of the alarm event.

6. The method according to any one of claims 1-5, characterized in that, The reporting of the alarm event includes sending alarm information corresponding to the alarm event, and the suppressing the reporting of the alarm event includes: Adding an identifier corresponding to the alarm event to the alarm information corresponding to the alarm event and sending the added alarm information, where the identifier is used for a module that receives the added alarm information to ignore the alarm event when determining, based on the identifier, that the alarm event is an invalid alarm; Or, canceling the sending of the alarm information corresponding to the alarm event.

7. The method according to any one of claims 1 to 6, characterized in that, After obtaining the event information of the alarm event triggered by a change in the state of a resource, it further includes: Sending an alarm notification, where the alarm notification is used for a second device for managing network devices to obtain, after receiving the alarm notification, the alarm event processed by the network device, and the second device is different from the first device that controls the resource to undergo the state change.

8. An apparatus for processing an alarm event, characterized in that, The apparatus includes: An obtaining module, configured to obtain event information of an alarm event triggered by a change in the state of a resource, where the event information is used to describe the resource that triggers the alarm event and the state change that occurs to the resource; A processing module, configured to determine, according to the event information, that the alarm event is an invalid alarm, and suppress the reporting of the alarm event.

9. The device according to claim 8, characterized in that, The obtaining module is configured to obtain a mapping relationship between an alarm event, a resource, and a status change of the resource, where the mapping relationship indicates at least one alarm event triggered by any status change of any resource. According to the mapping relationship, determine the resource that triggers the alarm event and the status change of the resource, to obtain the event information of the alarm event.

10. The device according to claim 8 or 9, characterized in that, The processing module is configured to obtain at least one piece of operation information that has been executed, where the at least one piece of operation information is used for service deployment; in the case where the at least one piece of operation information includes operation information for changing the status of the resource, determine that the alarm event is an invalid alarm.

11. The device according to claim 10, characterized in that, The processing module is configured to obtain at least one protocol request for service deployment that has been executed, where the protocol request includes at least one of a service identifier or a device identifier and operation information. For any protocol request, in the case where the service identifier included in the any protocol request indicates the service currently being deployed, determine that the any protocol request is a valid request, and / or, in the case where the device identifier included in the any protocol request indicates a first device for managing a network device, determine that the any protocol request is a valid request, where the network device is used to process the alarm event. Obtain the operation information included in the valid requests among at least one protocol request, to obtain the at least one piece of operation information.

12. The device according to any one of claims 8-11, characterized in that, The processing module is further configured to determine, according to the event information, that the alarm event is a valid alarm, and allow the reporting of the alarm event.

13. The device according to any one of claims 8-12, characterized in that, The reporting of the alarm event includes sending alarm information corresponding to the alarm event. The processing module is configured to add an identifier corresponding to the alarm event to the alarm information corresponding to the alarm event, and send the added alarm information. The identifier is used for a module that receives the added alarm information to ignore the alarm event in the case where it is determined that the alarm event is an invalid alarm according to the identifier; or cancel sending the alarm information corresponding to the alarm event.

14. The device according to any one of claims 8-13, characterized in that, The processing module is further configured to send an alarm notification, where the alarm notification is used for a second device that manages a network device to obtain the alarm event processed by the network device after receiving the alarm notification, and the second device is different from the first device that controls the resource to undergo the status change.