Alarm root cause analysis method and device, electronic equipment, storage medium and program
By obtaining and generalizing the features in the alarm log and performing cluster analysis, the problem of difficulty in locating the root cause of alarms under massive alarms is solved, and the stability of the system is improved.
Patent Information
- Application Number
- CN202510633814.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-25
AI Technical Summary
In modern large distributed systems, when faced with massive alarms, it is difficult for operation and maintenance personnel to quickly locate and solve the root causes of the alarm of the business system, resulting in a decrease in system stability.
By obtaining the alarm log generated by the alarm event, extracting and generalizing the alarm characteristics, performing cluster analysis to output the alarm root cause, reducing the complexity of the alarm log and improving analysis efficiency.
It realizes rapid positioning and accurate analysis of the alarm root cause, and improves the stability of the business system.
Smart Images

Figure CN120378285A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer technology, and in particular, to a method, device, electronic device, storage medium and program for analyzing the root cause of alarms. Background Art
[0002] In modern large-scale distributed systems, the number of service entities has grown exponentially, and the system topology has evolved into a highly complex network of mesh dependencies. Once a service fails, the failure may spread in the infrastructure, triggering a chain reaction, resulting in cascading failures of upstream and downstream associated services, and ultimately may trigger a large number of service alarms.
[0003] As a key tool for recording the running state of application programs, logs are particularly important in business services. Usually, logs are used to record key operation points and detailed information when program execution errors occur. When a business system fails, operation and maintenance personnel usually first check the error logs to determine the cause of the failure.
[0004] In the process of implementing the present invention, the inventors found that the prior art has the following defects: with the continuous iteration of business logic, the number of dependent services and components accessed in the business system is increasing. Once the system fails, the magnitude of error logs will increase sharply. In extreme cases, the phenomenon of "massive error reporting" may occur. At this time, when operation and maintenance personnel face a large number of alarms, they often cannot clarify the logic in time, and it is difficult to locate the root cause of the alarm and solve the most core problem in the first place. Summary of the Invention
[0005] The embodiments of the present invention provide a method, device, electronic device, storage medium and program for analyzing the root cause of alarms, which can quickly locate and accurately analyze the root cause of alarms that cause business system failures, thereby improving the stability of the business system.
[0006] According to one aspect of the present invention, there is provided a method for analyzing the root cause of alarms, including:
[0007] Obtain the alarm logs generated by alarm events in the target system;
[0008] Extract the alarm features from the alarm logs, and perform generalization processing on the alarm features to obtain alarm feature generalization data;
[0009] Perform clustering analysis on the alarm feature generalization data, and output the root cause of the alarm event in the target system according to the clustering result.
[0010] According to another aspect of the present invention, there is provided an apparatus for analyzing the root cause of alarms, including:
[0011] An alarm log acquisition module, configured to acquire alarm logs generated by alarm events in a target system;
[0012] An alarm feature generalization data acquisition module, configured to extract alarm features from the alarm logs, and perform generalization processing on the alarm features to obtain alarm feature generalization data;
[0013] An alarm root cause output module, configured to perform clustering analysis on the alarm feature generalization data, and output the alarm root cause of the alarm event in the target system according to the clustering result.
[0014] According to another aspect of the present invention, there is provided an electronic device, including:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the alarm root cause analysis method according to any embodiment of the present invention.
[0018] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the alarm root cause analysis method according to any embodiment of the present invention when executed.
[0019] According to another aspect of the present invention, there is also provided a computer program product including a computer program that implements the alarm root cause analysis method according to any embodiment of the present invention when executed by a processor.
[0020] In the embodiments of the present invention, by acquiring alarm logs generated by alarm events in a target system, and extracting alarm features from the alarm logs, further, performing generalization processing on the alarm features to obtain alarm feature generalization data. After obtaining the alarm feature generalization data, performing clustering analysis on the alarm feature generalization data, and outputting the alarm root cause of the alarm event in the target system according to the clustering result. The above solution can reduce the complexity of the alarm logs by performing generalization processing on the alarm logs, improve the analysis efficiency of the alarm logs, solve the problem that the existing alarm analysis methods cannot quickly locate alarms, and can quickly locate and accurately analyze the alarm root cause, thereby improving the stability of the business system.
[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood from the following description. Description of the Drawings
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0023] Figure 1 It is a flowchart of a method for analyzing the root cause of alarms provided in the first embodiment of the present invention;
[0024] Figure 2 It is a flowchart of a method for analyzing the root cause of alarms provided in the second embodiment of the present invention;
[0025] Figure 3 It is a generalized hierarchical structure diagram of a computer room identifier provided in the second embodiment of the present invention;
[0026] Figure 4 It is a generalized hierarchical structure diagram of an environment identifier provided in the second embodiment of the present invention;
[0027] Figure 5 It is a generalized hierarchical structure diagram of a source of error provided in the second embodiment of the present invention;
[0028] Figure 6 It is a generalized hierarchical structure diagram of the key content of an alarm log provided in the second embodiment of the present invention;
[0029] Figure 7 It is a schematic diagram of an apparatus for analyzing the root cause of alarms provided in the third embodiment of the present invention;
[0030] Figure 8 It is a schematic structural diagram of an electronic device provided in the fourth embodiment of the present invention. Detailed Embodiments
[0031] In order to enable those skilled in the art to better understand the solutions of the present invention, the following clearly and completely describes the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "first", "second", "original", and "target" in the specification, claims, and the above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances, so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0033] Embodiment 1
[0034] Figure 1 It is a flowchart of a method for analyzing the root cause of an alarm provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of generalizing and analyzing to determine the root cause of an alarm based on the alarm log of an alarm event. This method can be executed by an alarm root cause analysis device, which can be implemented in a software and / or hardware manner and is generally integrated in an electronic device. The electronic device can be a terminal device or a server device, as long as it can execute the alarm root cause analysis method. The present invention does not limit the specific type of the electronic device. Correspondingly, as Figure 1 shown, the method includes the following operations:
[0035] S110. Obtain the alarm log generated by the alarm event in the target system.
[0036] Among them, the target system can be any type of business system that has an alarm failure. An alarm event can be an event that does not conform to the normal operating state in a computer system, network environment, application program, or other monitored objects. Exemplarily, the alarm event can include, but is not limited to, abnormal memory usage rate, service performance degradation, and the risk of data leakage, etc. The present invention does not limit the specific type of the alarm event. The alarm log can be a log record generated by the system or application program when detecting an alarm event.
[0037] In the embodiment of the present invention, when it is monitored that an alarm event occurs in the target system, the alarm log generated by the target system due to this alarm event can be obtained as reference data for alarm root cause positioning and analysis. It can be understood that the format specification of the alarm log generated when the same target system has an alarm event should be the same. Therefore, the format specifications of the alarm logs generated by the alarm events in the obtained target system are the same.
[0038] S120. Extract the alarm features from the alarm log, and perform generalization processing on the alarm features to obtain alarm feature generalization data.
[0039] Among them, the alarm feature can be the key information extracted from the alarm log. Exemplarily, the alarm feature can include but is not limited to the computer room identifier, environment identifier, error source, key content of the alarm log, and location of the fault, etc. The embodiments of the present invention do not limit the specific type of the alarm feature. The computer room identifier can be the information related to the computer room environment, equipment, or infrastructure in the alarm log. Through the computer room identifier, the physical location where the alarm event occurs can be quickly located. The environment identifier can be the attribute or information related to the running environment when the alarm event occurs in the alarm log. The error source can be the root cause or trigger point that causes the alarm event to occur. The key content of the alarm log can be the part of the alarm log that can reflect the core information of the alarm event. The location of the fault can be the physical or logical location that causes the alarm event to occur, for example, it can include but is not limited to the line number, interface, or class where the code that generates the alarm event is located. The alarm feature generalization data can be the data obtained after performing generalization processing on each alarm feature in the alarm log.
[0040] Correspondingly, after obtaining the alarm log generated by the alarm event in the target system, first, the alarm features to be extracted can be determined according to the type of the target system. After determining the alarm features to be extracted, the alarm features can be extracted from the alarm log, and generalization processing is performed on the extracted alarm features, so that the alarm feature generalization data corresponding to each alarm feature can be obtained. It can be understood that the operation and maintenance personnel can customize the alarm features required for alarm root cause analysis extracted from the alarm log according to the type of the target system.
[0041] S130. Perform clustering analysis on the alarm feature generalization data, and output the alarm root cause of the alarm event in the target system according to the clustering result.
[0042] Among them, the clustering result can be the result obtained by performing clustering analysis on the alarm feature generalization data. The alarm root cause can be the most fundamental reason that causes the alarm event to occur in the target system.
[0043] Correspondingly, after obtaining the alarm feature generalization data, clustering analysis can be performed on the alarm feature generalization data, and the alarm events with similar features are merged to obtain the clustering result, thereby revealing the internal relationship between the alarm events. Further, the alarm root cause of the alarm event in the target system can be output according to the clustering result. In a specific example, when the target system has a network latency alarm event and a service timeout alarm event, by analyzing the coincidence degree of indicators such as the occurrence time, associated service nodes, and resource occupancy rate of the two, they can be included in the same clustering cluster to realize the intelligent merging of alarm events with similar features.
[0044] It can be seen that in the embodiments of the present invention, by extracting the features of the alarm logs generated by alarm events and generalizing each alarm feature, the alarm feature generalization data corresponding to each alarm feature is obtained, and the association relationship between each alarm feature is established, thereby reducing the complexity of the data in the alarm logs and improving the data parsing and processing efficiency. After obtaining the alarm feature generalization data corresponding to each alarm feature, clustering analysis can be performed on the alarm feature generalization data to classify alarm events with similar features into one category, thereby helping the operation and maintenance personnel quickly locate the root cause of the alarm, shortening the alarm recovery time, and further improving the stability of the business system.
[0045] In the embodiments of the present invention, by obtaining the alarm logs generated by alarm events in the target system and extracting the alarm features in the alarm logs, and further, generalizing the alarm features to obtain the alarm feature generalization data. After obtaining the alarm feature generalization data, clustering analysis is performed on the alarm feature generalization data, and the root cause of the alarm events in the target system is output according to the clustering result. The above solution can obtain the alarm feature generalization data by generalizing the alarm logs, reduce the complexity of the alarm logs, improve the analysis efficiency of the alarm logs, solve the problem that the existing alarm analysis methods cannot quickly locate the alarm, and can quickly locate and accurately analyze the root cause of the alarm that causes the failure of the business system, thereby improving the stability of the business system.
[0046] Embodiment 2
[0047] Figure 2 FIG. is a flowchart of an alarm root cause analysis method provided by Embodiment 2 of the present invention. This embodiment is a specific implementation based on the above embodiment. In this embodiment, various specific and optional implementation manners for performing clustering analysis on the alarm feature generalization data are given. Correspondingly, as Figure 2 shown, the method of this embodiment may include:
[0048] S210. Obtain the alarm logs generated by alarm events in the target system.
[0049] S220. Extract the alarm features in the alarm logs and generalize the alarm features to obtain the alarm feature generalization data.
[0050] In an optional embodiment of the present invention, the extracting the alarm features in the alarm logs and generalizing the alarm features to obtain the alarm feature generalization data may include: extracting each alarm feature in the alarm logs to obtain the original alarm feature data; constructing a generalization hierarchy of the alarm features according to the feature types of the alarm features; and loading the original alarm feature data into the generalization hierarchy to obtain the alarm feature generalization data.
[0051] Among them, the original alarm feature data can be the data obtained by extracting alarm features from alarm logs. The feature types of alarm features can be the data used to describe the attributes of different aspects of alarm events. The generalization hierarchy can be an architecture that organizes and classifies alarm features in the order from specific to abstract.
[0052] In the embodiment of the present invention, in the process of extracting alarm features from alarm logs and performing generalization processing on the alarm features to obtain alarm feature generalization data, first, the alarm features concerned by alarm root cause analysis can be extracted from alarm logs with a unified format specification, and the extraction result can be used as the original alarm feature data. Further, the generalization hierarchy of each alarm feature can be constructed according to the feature type of the alarm feature, so that the original alarm feature data can be loaded into the corresponding generalization hierarchy result to obtain the alarm feature generalization data.
[0053] Figure 3 It is a generalization hierarchy diagram of a machine room identifier provided in the second embodiment of the present invention. Figure 4 It is a generalization hierarchy diagram of an environment identifier provided in the second embodiment of the present invention. Figure 5 It is a generalization hierarchy diagram of an error source provided in the second embodiment of the present invention. Figure 6 It is a generalization hierarchy diagram of the key content of alarm logs provided in the second embodiment of the present invention. In a specific example, as Figure 3 shown, the generalization hierarchy of the machine room identifier can number all machine rooms, divided into Machine Room A, Machine Room B, and Machine Room C, etc. Further, the generalization hierarchy of Machine Room A can be refined into Service A1 of Machine Room A, Service A2 of Machine Room A, and Service A3 of Machine Room A, etc. The embodiment of the present invention does not limit the number of machine rooms and the service types of each machine room. As Figure 4 shown, the generalization hierarchy of the environment identifier can divide the environment identifier into two major types: online and offline. Further, the online type can be refined into a production environment and a pre-release environment, and the offline type can be refined into a test environment and a development environment. The embodiment of the present invention does not limit the specific classification of the generalization hierarchy of the environment identifier.
[0054] As Figure 5As shown in the figure, the generalization hierarchy of error sources can be divided into basic components, business dependencies, internal errors, etc. Further, the basic components can be refined into remote procedure calls, middleware, databases, etc. Furthermore, the remote procedure calls can be refined into efficient (Thrift) cross-language communication frameworks and Pigeon frameworks, etc.; the middleware can be refined into Mafka message queues, caches, elastic engineering, and key management systems (Key Management System, KMS); the database can be refined into Zebra routing, etc. At the same time, the business dependencies can be refined into public services and business line A, etc. Furthermore, the public services can be refined into account services, comment services, login services, etc.; the business line A can be refined into product centers, trading platforms, supplier information, etc. In addition, the internal errors can be refined into parameter verification, external interface exceptions, null pointer exceptions, etc. The embodiments of the present invention do not limit the specific classification of the generalization hierarchy of error sources.
[0055] As Figure 6 shown, the generalization hierarchy of the key content of the alarm log can be divided into system errors and other errors, etc. Further, the system errors can be refined into circuit breaker degradation, null pointer exception (Null Pointer Exception, NPE), timeout, and packet conflict / non-introduction, etc. The embodiments of the present invention do not limit the specific classification of the generalization hierarchy of the key content of the alarm log.
[0056] It should be noted that there is no need to construct a generalization hierarchy for the location of the fault. Each time of generalization, it is directly truncated upward along the package path until the system package name.
[0057] S230. Calculate the difference degree between the generalized data of each alarm feature, and merge the same alarm events according to the difference degree between the generalized data of each alarm feature.
[0058] Among them, the difference degree between the generalized data of alarm features can be used to measure the difference degree between different alarm features after generalization processing.
[0059] In the embodiments of the present invention, after obtaining the generalized data of alarm features, first, the dissimilarity, that is, the difference degree, can be calculated for the generalized data of alarm features of each alarm feature. Exemplarily, assume that x1 and x2 are two different values of the generalized data A i of a certain alarm feature. Then the dissimilarity between x1 and x2 is the length of the shortest path connecting x1 and x2 through a common parent node in the generalized data of this alarm feature. Specifically, the dissimilarity between two alarm events a1 and a2 can be calculated based on the following formula:
[0060]
[0061] Wherein, d(a1, a2) is the dissimilarity between two alarm events a1 and a2. The smaller d(a1, a2) is, the more similar the alarm events a1 and a2 are. n is the number of feature types of alarm features, i is the i-th alarm feature, and a1[A i is the value of the alarm feature generalization data of the i-th alarm feature in the alarm event a1, and a2[A i is the value of the alarm feature generalization data of the i-th alarm feature in the alarm event a2.
[0062] Furthermore, after calculating the dissimilarity between two alarm events a1 and a2, two alarm events with a dissimilarity not higher than the dissimilarity threshold can be regarded as the same alarm event, and the same alarm events can be merged. Exemplarily, the dissimilarity threshold can be 1.
[0063] S240. Update the alarm feature generalization data for the merged alarm events.
[0064] Correspondingly, after merging the same alarm events, the alarm feature generalization data can be updated according to the merged alarm events. Exemplarily, assuming that the alarm event a and the alarm event a' are the same, after merging the alarm event a and the alarm event a', a' is deleted from the alarm event list, and the alarm features are re-extracted from the alarm log of the merged alarm event, and the alarm features are generalized to obtain the alarm feature generalization data, thereby completing the update of the alarm feature generalization data.
[0065] S250. Determine whether the updated alarm feature generalization data meets the clustering termination condition. If so, execute S290; otherwise, execute S260.
[0066] In an optional embodiment of the present invention, determining that the updated alarm feature generalization data meets the clustering termination condition may include: determining the number of alarm root causes of the alarm event and / or the second reference attribute value of the updated alarm feature generalization data; when determining that the number of alarm root causes of the alarm event is less than or equal to a preset alarm root cause threshold, and / or, the second reference attribute value of the updated alarm feature generalization data is greater than or equal to a preset reference attribute threshold, it is determined that the updated alarm feature generalization data meets the clustering termination condition.
[0067] Among them, the clustering termination condition can be a condition used to determine when to stop the clustering iteration during the execution of the clustering algorithm. The second reference attribute value can be the number of alarm events covered by the merged alarm events in the updated alarm feature generalization data. The preset alarm root cause threshold can be a reference number of alarm events included in the preset alarm root cause. For example, it can be 20. The preset reference attribute threshold can be a reference value min_size of the number of alarm events covered by the generalized alarm events. For example, min_size can be 5.
[0068] In the embodiment of the present invention, during the process of determining whether the updated alarm feature generalization data meets the clustering termination condition, first, the number of alarm events included in the output alarm root cause and the number of alarm events covered by the merged generalized alarm events after merging the same alarm events can be determined. Further, in the case where the number of alarm events included in the output alarm root cause is less than or equal to the preset alarm root cause threshold or the number of alarm events covered by the merged generalized alarm events reaches the preset reference attribute threshold, it can be determined that the updated alarm feature generalization data meets the clustering termination condition, and thus stop clustering the updated alarm feature generalization data. For example, clustering can be stopped when the number of alarm events included in the alarm root cause is less than or equal to 20 or the number of alarm events covered by the merged generalized alarm events is greater than or equal to 5.
[0069] It should be noted that the operation and maintenance personnel can adaptively adjust the preset alarm root cause threshold and the preset reference attribute threshold according to the number of alarm logs. The embodiment of the present invention does not limit the specific values of the preset alarm root cause threshold and the preset reference attribute threshold.
[0070] In a specific example, assume that the alarm log set L is:
[0071]
[0072] Assume that for this alarm log set, min_size = 2, the generalization hierarchy of the type attribute is G_type: {"CPU": "Hardware", "Memory": "Hardware"}, and the generalization hierarchy of the value attribute is G_value: {80: "High", 85: "High", 90: "High"}. Then the process of determining the alarm root cause can be divided into the following steps:
[0073] Step 1: After initialization, save the alarm log set to table T:
[0074]
[0075] Among them, count (quantity) is used to record the number of alarm events currently covered by the alarm event, that is, the number of alarm events covered by the generalized alarm event after merging. Traverse each alarm event in table T and initialize its count attribute to 1, indicating that the number of currently covered alarm events is 1.
[0076] Step 2: Select the type attribute for generalization:
[0077]
[0078] Specifically, each alarm event a in table T can be traversed, and the generalization data A i of its alarm characteristics is generalized to the value of its parent node in the corresponding generalization hierarchy G i . If there are the same alarm events a and a', the count attribute of alarm event a can be increased by the value of the count attribute of a', and a' can be deleted from table T. It should be noted that when the count attributes of all alarm events in table T are less than min_size, continue to perform the generalization operation on the alarm characteristic generalization data.
[0079] Step 3: Since the count attribute value of {id:1} is 2, reaching min_size, the loop ends, and finally the qualified generalized alarm events are output. The operation and maintenance personnel can determine the root cause of the alarm based on the qualified generalized alarm events.
[0080] S260. Calculate the first reference attribute value of the alarm characteristic generalization data.
[0081] Among them, the first reference attribute value can be the number of alarm events corresponding to the feature value with the highest occurrence frequency in each alarm characteristic.
[0082] In the embodiment of the present invention, in the case where it is determined that the updated alarm characteristic generalization data does not meet the clustering termination condition, first, based on the formula, the number of alarm events with the value v in the alarm characteristic generalization data A i of each alarm characteristic in table T can be counted:
[0083] f i (v) = SELECT sum(count) FROM T WHERE A i = v
[0084] Among them, f i (v) is the number of alarm events with the value v in the alarm characteristic generalization data A i of each alarm characteristic, and SELECT is to select A iAn alarm event with a median value of v, count is the number of alarm events covered by the merged generalized alarm events, and sum(count) is to calculate the generalized data A of alarm features that meet the conditions i The sum of count in it, FROM T means query from table T, WHERE A i =v means query A i For alarm events with a median value of v in it.
[0085] Then the following formula can be used to count the number of alarm events corresponding to the attribute value with the highest frequency of occurrence in the generalized data A of each alarm feature i in it, and use it as the first reference attribute value:
[0086] F i = max{f i (v) | v ∈ Dom(A i )}
[0087] Among them, F i is the number of alarm events corresponding to the attribute value with the highest frequency of occurrence in the generalized data A of each alarm feature, Dom(A i ) is the value range of the generalized data A of alarm features, that is, the set of all possible values in A i , max{f i (v) | v ∈ Dom(A i )} is to traverse each value v in Dom(A i ), calculate f i (v), and find the maximum value from a series of values of f i (v). i (v), and find the maximum value from a series of values of f i (v).
[0088] S270. Screen the target attribute value from the first reference attribute value, and perform generalization processing on the generalized data of alarm features corresponding to the target attribute value again to obtain updated generalized data of alarm features.
[0089] Among them, the target attribute value can be the first reference attribute value that meets the preset requirements. The updated generalized data of alarm features can be the data obtained after performing generalization processing on the generalized data of alarm features.
[0090] Correspondingly, after calculating the first reference attribute value of the alarm feature generalization data, the target attribute value can be screened from the first reference attribute values corresponding to the alarm feature generalization data of each alarm feature. For example, the smallest first reference attribute value can be selected as the target attribute value. A small first reference attribute value means that there is no particularly prominent (with a very high occurrence frequency) attribute value dominating in the alarm feature generalization data of the alarm feature. Taking the smallest first reference attribute value as the target attribute value and performing generalization processing on the alarm feature generalization data corresponding to the target attribute value again can make the originally scattered elements in the alarm feature generalization data of the alarm feature easier to cluster after the generalization processing.
[0091] In an optional embodiment of the present invention, the performing generalization processing on the alarm feature generalization data corresponding to the target attribute value again may include: determining the alarm feature generalization data corresponding to the parent node of the alarm feature generalization data corresponding to the target attribute value; replacing the alarm feature generalization data corresponding to the target attribute value with the alarm feature generalization data corresponding to the parent node.
[0092] Among them, the alarm feature generalization data corresponding to the parent node may be the alarm feature generalization data corresponding to the upper-layer node of the alarm feature generalization data corresponding to the target attribute value.
[0093] In the embodiment of the present invention, assuming that the alarm feature generalization data of each alarm feature is a tree, in the process of performing generalization processing on the alarm feature generalization data corresponding to the target attribute value again, first, the alarm feature generalization data corresponding to the upper-layer node of the alarm feature generalization data corresponding to the target attribute value can be determined as the alarm feature generalization data corresponding to the parent node. Further, the alarm feature generalization data corresponding to the target attribute value can be replaced with the alarm feature generalization data corresponding to the parent node.
[0094] In a specific example, assuming that the alarm feature generalization data corresponding to the target attribute value is A1 and A2, and the alarm feature generalization data corresponding to its parent node is A, then A1 and A2 can be replaced with A.
[0095] S280. Merge the alarm events according to the updated alarm feature generalization data.
[0096] Specifically, after performing generalization processing on the alarm feature generalization data corresponding to the target attribute value again to obtain the updated alarm feature generalization data, the dissimilarity between each alarm event can be calculated according to the updated alarm feature generalization data, and two alarm events with a dissimilarity not higher than the dissimilarity threshold are regarded as the same alarm event, so that the same alarm events can be merged.
[0097] Further, after merging the alarm events based on the updated alarm feature generalization data, S240 can be executed again to update the alarm feature generalization data for the merged alarm events until it is determined that the updated alarm feature generalization data meets the clustering termination condition.
[0098] S290. Output the alarm root cause of the alarm event in the target system according to the clustering result.
[0099] In the embodiment of the present invention, the alarm log generated by the alarm event in the target system is obtained, and the alarm features in the alarm log are extracted. Further, the alarm features are generalized to obtain the alarm feature generalization data. After obtaining the alarm feature generalization data, the difference degree between the alarm feature generalization data is calculated, and the same alarm events are merged according to the difference degree between the alarm feature generalization data, and the alarm feature generalization data is updated for the merged alarm events. Further, it can be determined whether the updated alarm feature generalization data meets the clustering termination condition. When it is determined that the updated alarm feature generalization data does not meet the clustering termination condition, the first reference attribute value of the alarm feature generalization data is calculated, and the target attribute value is screened from the first reference attribute value, and then the alarm feature generalization data corresponding to the target attribute value is generalized again to obtain the updated alarm feature generalization data. After obtaining the updated alarm feature generalization data, the alarm events are merged according to the updated alarm feature generalization data, and the operation of updating the alarm feature generalization data for the merged alarm events is returned until it is determined that the updated alarm feature generalization data meets the clustering termination condition. When it is determined that the updated alarm feature generalization data does not meet the clustering termination condition, the alarm root cause of the alarm event in the target system is output according to the clustering result. The above solution can reduce the complexity of the alarm log and improve the analysis efficiency of the alarm log by generalizing the alarm log to obtain the alarm feature generalization data, solves the problem that the existing alarm analysis method cannot quickly locate the alarm, and can quickly locate and accurately analyze the alarm root cause that causes the failure of the business system, thereby improving the stability of the business system.
[0100] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processing all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0101] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, analysis data, etc.) involved in the present disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of the relevant data comply with the relevant laws, regulations, and standards in the relevant regions.
[0102] It should be noted that any permutation and combination of the technical features in the above embodiments also fall within the protection scope of the present invention.
[0103] Embodiment 3
[0104] Figure 7 is a schematic diagram of an alarm root cause analysis device provided in Embodiment 3 of the present invention. As Figure 7 shown, the device includes: an alarm log acquisition module 310, an alarm feature generalization data acquisition module 320, and an alarm root cause output module 330, where:
[0105] The alarm log acquisition module 310 is used to acquire the alarm log generated by the alarm event in the target system.
[0106] The alarm feature generalization data acquisition module 320 is used to extract the alarm features in the alarm log and perform generalization processing on the alarm features to obtain alarm feature generalization data.
[0107] The alarm root cause output module 330 is used to perform clustering analysis on the alarm feature generalization data and output the alarm root cause of the alarm event in the target system according to the clustering result.
[0108] In the embodiment of the present invention, the alarm log generated by the alarm event in the target system is acquired, and the alarm features in the alarm log are extracted. Further, the alarm features are subjected to generalization processing to obtain alarm feature generalization data. After obtaining the alarm feature generalization data, clustering analysis is performed on the alarm feature generalization data, and the alarm root cause of the alarm event in the target system is output according to the clustering result. The above solution can reduce the complexity of the alarm log and improve the analysis efficiency of the alarm log by performing generalization processing on the alarm log, solves the problem that the existing alarm analysis method cannot quickly locate the alarm, and can quickly locate and accurately analyze the alarm root cause that causes the failure of the business system, thereby improving the stability of the business system.
[0109] Optionally, the alarm features include at least one of a computer room identifier, an environment identifier, an error source, key content of the alarm log, and a fault location; the alarm feature generalization data acquisition module 320 is specifically used for: extracting each alarm feature in the alarm log to obtain original alarm feature data; constructing a generalization hierarchy of the alarm features according to the feature types of the alarm features; and loading the original alarm feature data into the generalization hierarchy to obtain the alarm feature generalization data.
[0110] Optionally, the alarm root cause output module 330 is specifically configured to: calculate the difference degrees between the generalized alarm feature data, merge the same alarm events according to the difference degrees between the generalized alarm feature data; and update the generalized alarm feature data for the merged alarm events.
[0111] Optionally, the above device may further include a secondary generalization processing module, configured to: calculate a first reference attribute value of the generalized alarm feature data when it is determined that the updated generalized alarm feature data does not meet the clustering termination condition; screen target attribute values from the first reference attribute values, and perform generalization processing on the generalized alarm feature data corresponding to the target attribute values again to obtain updated generalized alarm feature data; merge the alarm events according to the updated generalized alarm feature data; and return to perform the operation of updating the generalized alarm feature data for the merged alarm events until it is determined that the updated generalized alarm feature data meets the clustering termination condition.
[0112] Optionally, the secondary generalization processing module is specifically configured to: determine the generalized alarm feature data corresponding to the parent node of the generalized alarm feature data corresponding to the target attribute value; and replace the generalized alarm feature data corresponding to the target attribute value with the generalized alarm feature data corresponding to the parent node.
[0113] Optionally, the secondary generalization processing module is further configured to: determine the number of alarm root causes of the alarm event and / or a second reference attribute value of the updated generalized alarm feature data; and determine that the updated generalized alarm feature data meets the clustering termination condition when it is determined that the number of alarm root causes of the alarm event is less than or equal to a preset alarm root cause threshold, and / or, the second reference attribute value of the updated generalized alarm feature data is greater than or equal to a preset reference attribute threshold.
[0114] The above alarm root cause analysis device can execute the alarm root cause analysis method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method. For technical details not described in detail in this embodiment, reference can be made to the alarm root cause analysis method provided in any embodiment of the present invention.
[0115] Since the above-introduced alarm root cause analysis device is a device that can execute the alarm root cause analysis method in the embodiment of the present invention, based on the alarm root cause analysis method introduced in the embodiment of the present invention, those skilled in the art can understand the specific implementation manners and various variations of the alarm root cause analysis device in this embodiment. Therefore, the implementation of how the alarm root cause analysis device implements the alarm root cause analysis method in the embodiment of the present invention will not be described in detail here. As long as the device adopted by those skilled in the art to implement the alarm root cause analysis method in the embodiment of the present invention belongs to the scope to be protected by this application.
[0116] Example 4
[0117] Figure 8 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital processors, cellular telephones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0118] As Figure 8 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0119] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0120] The processor 11 can be various general-purpose and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the alarm root cause analysis method.
[0121] In some embodiments, the alarm root cause analysis method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the alarm root cause analysis method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the alarm root cause analysis method by any other suitable means (e.g., by means of firmware).
[0122] Optionally, the alarm root cause analysis method may include: obtaining the alarm log generated by the alarm event in the target system; extracting the alarm features from the alarm log and performing generalization processing on the alarm features to obtain alarm feature generalization data; performing clustering analysis on the alarm feature generalization data, and outputting the alarm root cause of the alarm event in the target system according to the clustering result.
[0123] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0124] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processors of general-purpose computers, special-purpose computers, or other programmable data processing devices, such that when the computer programs are executed by the processors, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0125] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0126] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0127] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0128] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0129] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and no limitations are imposed herein.
[0130] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. An alarm root cause analysis method, characterized in that, Including: Obtain the alarm logs generated by alarm events in the target system; Extract the alarm features in the alarm logs, and perform generalization processing on the alarm features to obtain alarm feature generalization data; Perform clustering analysis on the alarm feature generalization data, and output the alarm root cause of the alarm events in the target system according to the clustering result.
2. The method according to claim 1, characterized in that, The alarm features include at least one of a computer room identifier, an environment identifier, an error source, key content of the alarm log, and a fault location; The extracting the alarm features in the alarm logs and performing generalization processing on the alarm features to obtain alarm feature generalization data includes: Extract each alarm feature in the alarm logs to obtain original alarm feature data; Construct a generalization hierarchy of the alarm features according to the feature types of the alarm features; Load the original alarm feature data into the generalization hierarchy to obtain the alarm feature generalization data.
3. The method according to claim 1, wherein The performing clustering analysis on the alarm feature generalization data includes: Calculate the difference degrees between the alarm feature generalization data, and merge the same alarm events according to the difference degrees between the alarm feature generalization data; Update the alarm feature generalization data for the merged alarm events.
4. The method according to claim 3, characterized in that, After the updating the alarm feature generalization data for the merged alarm events, it further includes: In the case where it is determined that the updated alarm feature generalization data does not meet the clustering termination condition, calculate the first reference attribute value of the alarm feature generalization data; Screen target attribute values from the first reference attribute values, and perform generalization processing on the alarm feature generalization data corresponding to the target attribute values again to obtain updated alarm feature generalization data; Merge the alarm events according to the updated alarm feature generalization data; Return to execute the operation of updating the alarm feature generalization data for the merged alarm events until it is determined that the updated alarm feature generalization data meets the clustering termination condition.
5. The method according to claim 4, characterized in that, The performing generalization processing on the alarm feature generalization data corresponding to the target attribute values again includes: Determine the alarm feature generalization data corresponding to the parent node of the alarm feature generalization data corresponding to the target attribute values; Replace the alarm feature generalization data corresponding to the target attribute values with the alarm feature generalization data corresponding to the parent node.
6. The method according to claim 4, wherein The determining that the updated alarm feature generalization data meets the clustering termination condition includes: Determine the number of alarm root causes of the alarm events and / or the second reference attribute value of the updated alarm feature generalization data; In the case where it is determined that the number of alarm root causes of the alarm events is less than or equal to a preset alarm root cause threshold, and / or, the second reference attribute value of the updated alarm feature generalization data is greater than or equal to a preset reference attribute threshold, determine that the updated alarm feature generalization data meets the clustering termination condition.
7. An alarm root cause analysis device, characterized in that, Including: An alarm log acquisition module, configured to acquire the alarm logs generated by alarm events in the target system; An alarm feature generalization data acquisition module, configured to extract the alarm features in the alarm logs, and perform generalization processing on the alarm features to obtain alarm feature generalization data; An alarm root cause output module, which is used to perform clustering analysis on the alarm feature generalization data and output the alarm root cause of the alarm event in the target system according to the clustering result.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the alarm root cause analysis method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the alarm root cause analysis method according to any one of claims 1-6 when executed by a processor.
10. A computer program product, comprising a computer program / instructions, wherein, When the computer program / instructions are executed by a processor, the alarm root cause analysis method according to any one of claims 1-6 is implemented.