Brain service integrated management system and method for enterprises and governments

By obtaining abnormal events in industrial indicators of enterprises and government systems, positioning the focus components in the service topology and their upstream and downstream related nodes, combining data blood information and a feature manifold search engine driven by big model, the problem of data silos and artificial experience dependence is solved, intelligent root cause diagnosis and automated handling is realized, and the handling efficiency and decision-making reliability of abnormal events are improved.

CN120494108AInactive Publication Date: 2025-08-15CHINA ACADEMY OF INFORMATION & COMM
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510684122.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When responding to abnormal industrial indicators, existing enterprises and government management systems have data silos, relying on manual experience, high false alarm rate, and lack of intelligent evaluation and solution suggestions, resulting in low efficiency in abnormal diagnosis and difficulty in quickly locate the root cause.

Method used

By obtaining abnormal events of industrial indicators, positioning the focus components and their upstream and downstream related nodes in the service topology, extracting key contexts based on data blood relationship information, performing semantic embedding encoding, converting unstructured log text into computable vector space representations, and using a large-modal feature manifold search engine to perform cross-modal association matching, and automatically generate intelligent diagnostic reports.

Benefits of technology

Cross-modal data association and intelligent semantic reasoning are realized, the efficiency of abnormal diagnosis and decision-making reliability are improved, the data silos and artificial experience dependence in traditional solutions can be broken through, and the root cause can be quickly located and intelligent reports are generated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120494108A_ABST
    Figure CN120494108A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise and government-oriented brain service integrated management system and method, and relates to the field of intelligent management, and the method comprises the steps: obtaining an industrial index abnormal event containing a multi-dimensional feature in real time, positioning a focus assembly in a service topology and upstream and downstream associated nodes thereof, and combining data blood relationship information to extract a key context; performing semantic embedding coding on an original log, and converting an unstructured log text into computable vector space representation; and finally, through a feature manifold search engine driven by a large model, cross-modal association matching is performed on the structured abnormal event features and the log semantic vectors, and an intelligent report is automatically generated. The system effectively solves the problems that in a traditional scheme, service link fault analysis and heterogeneous data association are difficult, and the dependence degree of artificial experience is too high, and the handling efficiency and decision-making reliability of abnormal events of a complex system are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of intelligent management, and more specifically, to an integrated brain service management system and method for enterprises and governments. Background Art

[0002] With the rapid development of information technology and the deepening of digital transformation, the IT systems faced by enterprises and government agencies are becoming increasingly complex, and the scale of business and data they carry are also experiencing explosive growth. These systems and services generate a vast number of industry operational indicators. Real-time monitoring, anomaly detection, and rapid response to these indicators are crucial for ensuring business continuity, improving operational efficiency, and assisting decision-making. Therefore, building an "integrated brain service management solution" that can uniformly manage various industry indicators, intelligently analyze them, and efficiently handle anomalies has become an urgent need for enterprises and governments to enhance their governance capabilities and competitiveness. This solution aims to achieve precise insight into the operational status of complex systems and enable agile intervention through centralized and intelligent means.

[0003] Currently, existing enterprise and government management systems often rely on traditional monitoring and alerting tools and manual experience to address anomalies in industry indicators. These systems may include decentralized log management platforms, indicator monitoring dashboards, and alert mechanisms based on fixed thresholds or simple rules. However, these solutions suffer from numerous flaws: First, data silos are prevalent, making it difficult to effectively integrate and correlate indicator and log data from disparate systems and sources, making it difficult to locate issues. Second, the anomaly diagnosis process relies heavily on manual experience, which is time-consuming and labor-intensive. Furthermore, manual troubleshooting is inefficient for complex, sporadic, and unknown anomaly patterns, making it difficult to quickly identify the root cause. Third, the alerts generated by traditional alert systems often lack context, resulting in high rates of false positives and false negatives, creating an "alarm storm" that interferes with operations and maintenance personnel's judgment. Finally, the lack of intelligent assessment of the impact and potential risks of an anomaly, as well as targeted solution recommendations, limits emergency response and decision support capabilities. These shortcomings severely hinder the ability of enterprises and governments to quickly and accurately handle anomalies in complex environments.

[0004] Therefore, an optimized integrated management solution for brain services for enterprises and governments is expected, which can achieve closed-loop automation from anomaly detection to root cause diagnosis by building an integrated management system that integrates service topology perception, cross-modal data association and intelligent semantic reasoning. Summary of the Invention

[0005] In order to solve the above technical problems, this application is proposed. According to one aspect of this application, a method for integrated management of brain services for enterprises and governments is provided, which includes:

[0006] Obtain industry indicator abnormal events, including event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID;

[0007] Extracting an indicator name from the abnormal event of the industry indicator, and querying a focus component from a service and resource knowledge base according to the indicator name;

[0008] Based on the service topology and data lineage information in the service and resource knowledge base, identifying upstream components and downstream components that are directly related to the focus component before and after the abnormality occurs, and extracting key context information of the abnormal event from the upstream components and the downstream components;

[0009] Obtaining a related log set from a unified log query platform based on the key context information of the abnormal event;

[0010] Performing semantic embedding coding on each original log in the associated log set to obtain a set of original log semantic embedding coding vectors;

[0011] Performing structured embedding coding on the abnormal events of the industry indicators to obtain structured embedding coding vectors of abnormal events of the industry indicators;

[0012] The set of the structured embedded coding vector of the abnormal event of the industrial indicator and the semantic embedded coding vector of the original log is input into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report.

[0013] According to another aspect of the present application, there is provided an integrated management system for brain services for enterprises and governments, which includes:

[0014] An industry indicator abnormal event acquisition module is used to acquire industry indicator abnormal events, wherein the industry indicator abnormal event includes event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID;

[0015] A focus component query module is used to extract the indicator name from the abnormal event of the industry indicator, and query the focus component from the service and resource knowledge base according to the indicator name;

[0016] An abnormal event extraction module is used to identify upstream components and downstream components that are directly related to the focus component before and after the abnormality occurs based on the service topology and data lineage information in the service and resource knowledge base, and extract key context information of the abnormal event from the upstream components and the downstream components;

[0017] A query module, configured to query and obtain a set of related logs from a unified log query platform based on the key context information of the abnormal event;

[0018] An associated log encoding module, configured to perform semantic embedding encoding on each original log in the associated log set to obtain a set of original log semantic embedding encoding vectors;

[0019] An abnormal event coding module, configured to perform structured embedding coding on the abnormal event of the industry indicator to obtain a structured embedded coding vector of the abnormal event of the industry indicator;

[0020] The diagnostic report generation module is used to input the set of the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded coding vector into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnostic report.

[0021] Compared with the existing technology, the present application provides an integrated management system and method for brain services for enterprises and governments. It obtains abnormal events of industrial indicators containing multi-dimensional features in real time, locates the focus components and their upstream and downstream related nodes in the service topology, and extracts key contexts in combination with data lineage information, breaking through the data island limitations of traditional monitoring tools; then semantic embedding encoding is performed on the original logs, converting the unstructured log text into a computable vector space representation, eliminating the inefficiency of manual analysis; finally, through a feature manifold search engine driven by a large model, the structured abnormal event features are cross-modally correlated and matched with the log semantic vectors, and an intelligent report containing root cause location, evidence chain and solution is automatically generated. This system effectively solves the pain points of service link fault analysis, difficulty in associating heterogeneous data, and high dependence on manual experience in traditional solutions, and upgrades abnormal diagnosis from discrete alarms to a causal reasoning process with service topology perception capabilities, greatly improving the efficiency of handling abnormal events in complex systems and the reliability of decision-making. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0023] Figure 1 This is a flowchart of an integrated management method of brain services for enterprises and governments according to an embodiment of the present application.

[0024] Figure 2 This is a flowchart of step S170 in the integrated management method of brain services for enterprises and governments according to an embodiment of the present application.

[0025] Figure 3This is a flowchart of step S171 in the integrated management method of brain services for enterprises and governments according to an embodiment of the present application.

[0026] Figure 4 This is a block diagram of an integrated management system for brain services for enterprises and governments according to an embodiment of the present application. DETAILED DESCRIPTION

[0027] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. While the drawings illustrate certain embodiments of the present disclosure, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0028] Therefore, in response to the above technical problems, the technical concept of this application is to obtain abnormal events of industrial indicators containing multi-dimensional features in real time, locate the focus components and their upstream and downstream related nodes in the service topology, and extract key contexts in combination with data lineage information to break through the data island limitations of traditional monitoring tools; then perform semantic embedding encoding on the original logs, convert the unstructured log text into a computable vector space representation, and eliminate the inefficiency of manual analysis; finally, through a feature manifold search engine driven by a large model, perform cross-modal correlation matching between the structured abnormal event features and the log semantic vectors, and automatically generate an intelligent report containing root cause location, evidence chain and solution. This system effectively solves the pain points of service link fault analysis, heterogeneous data association difficulties, and high dependence on manual experience in traditional solutions, and upgrades abnormal diagnosis from discrete alarms to a causal reasoning process with service topology perception capabilities, greatly improving the efficiency of handling abnormal events in complex systems and the reliability of decision-making.

[0029] Figure 1 Flowchart of the integrated management method of brain services for enterprises and governments according to the embodiment of the present application. Figure 1As shown, the brain service integrated management method for enterprises and governments includes: S110, obtaining industry indicator abnormal events, the industry indicator abnormal events including event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID; S120, extracting the indicator name from the industry indicator abnormal event, and querying the focus component from the service and resource knowledge base according to the indicator name; S130, based on the service topology and data lineage information in the service and resource knowledge base, identifying the upstream components and downstream components that are directly related to the focus component before and after the abnormality occurs, and querying the upstream components and downstream components from the upstream components and the downstream components Extract key context information of abnormal events; S140, obtain a set of related logs from a unified log query platform based on the key context information of the abnormal events; S150, perform semantic embedding coding on each original log in the related log set to obtain a set of original log semantic embedding coding vectors; S160, perform structured embedding coding vectors on the industry indicator abnormal events to obtain structured embedding coding vectors of industry indicator abnormal events; S170, input the set of structured embedding coding vectors of industry indicator abnormal events and the set of original log semantic embedding coding vectors into a large model-based abnormal pattern diagnosis engine to obtain an intelligent diagnosis report.

[0030] In step S110, obtain industry indicator abnormal events, which include event ID, indicator name, current value of indicator, indicator threshold, occurrence timestamp and related business ID. It should be understood that in the face of the complex IT environment of enterprises and governments and the massive industry operation indicators, traditional management methods are often stretched due to data dispersion, delayed analysis and inefficient response. When an abnormality occurs in an industry indicator, if the complete information of the abnormal event cannot be captured in a timely and accurate manner, subsequent fault location, impact assessment and decision support will be out of the question, or it will be difficult to rely heavily on manual experience for inefficient troubleshooting, resulting in delays in problem handling, and may even trigger a chain reaction, causing serious impact on business continuity and operational efficiency. In particular, the lack of a comprehensive grasp of the context of abnormal events makes it difficult for the management system to gain insight into the essence of the problem from isolated alarms, let alone intelligent root cause diagnosis and automated disposal, which is the bottleneck that the existing system urgently needs to break through. For this reason, obtain industry indicator abnormal events in this application. The "abnormal events of industrial indicators" here refer to specific quantitative indicators (such as transaction success rate, service response time, resource utilization, etc.) that reflect the operating status of key businesses or systems during the operation of enterprises or governments. They deviate from their preset normal ranges or thresholds, thereby triggering a structured event record. This record not only contains a unique event identifier (event ID) for tracking, clearly indicates the name of the indicator where the abnormality occurred, the current abnormal value and the preset normal threshold, but also accurately records the specific timestamp of the abnormality, which is crucial for subsequent time series analysis and related event backtracking. What is particularly critical is that it also contains relevant business IDs, which can directly link technical-level abnormalities with specific business processes or services, providing direct clues for understanding the business impact of the abnormality, thereby laying a solid data foundation and providing high-quality input for subsequent intelligent analysis and automated disposal processes.

[0031] Specifically, lightweight data collection agents need to be deployed in various business systems and underlying IT facilities. These agents continuously monitor the operating indicators of key nodes such as business transactions, service interfaces, and hardware resources. For example, in financial transaction systems, the transaction success rate and the duration of a single transaction are monitored, and in government cloud platforms, indicators such as server CPU utilization, memory occupancy, and network throughput are collected. When the real-time monitoring value of a certain indicator exceeds the preset threshold (such as the transaction success rate is less than 99% or the CPU utilization exceeds 85%), the system automatically triggers the abnormal event capture mechanism.

[0032] The event ID is assigned by a globally unique identifier generation algorithm and is used for tracking and tracing throughout the entire exception handling process. The indicator name is directly associated with the specific monitoring object (such as "payment interface response time" and "work order processing delay rate") to ensure that the anomaly can be accurately located at the business level. The comparison between the current value of the indicator and the threshold constitutes the core condition for the anomaly triggering. The threshold can be set dynamically based on statistical analysis of historical operating data (such as the 3σ principle) or business rules. For example, during an e-commerce promotion, the server resource threshold can be temporarily raised to adapt to peak traffic. The occurrence timestamp is recorded using high-precision clock synchronization technology (such as the NTP protocol) with millisecond accuracy, providing key time clues for subsequent timing analysis and event chain reconstruction.

[0033] To obtain relevant business IDs, a mapping relationship between indicators and business entities must be established. For example, in a government approval system, a processing timeout indicator at a process node can be linked to a specific approval item ID and applicant ID. In an enterprise resource planning (ERP) system, inventory turnover anomalies can be traced back to specific material codes and order numbers. This association is achieved through the metadata management module, which maintains a multi-dimensional mapping table between indicators and business objects. It supports automatic retrieval of the corresponding business ID field by indicator name and dynamically injects it when an abnormal event is generated.

[0034] During data transmission, the collected abnormal event data is transmitted in real time to the central data center through an encrypted channel (such as the SSL / TLS protocol) to ensure security and integrity during transmission. The central data center cleans and verifies the data, removes duplicate or invalid records, and supplements contextual metadata (such as the deployment location of the collection agent and the frequency of data collection), ultimately forming standardized records of abnormal events for industry indicators. These records are stored in a time series database, supporting efficient time range queries and aggregate analysis, laying the data foundation for subsequent steps such as focus component positioning and log correlation queries.

[0035] In step S120, the indicator name is extracted from the abnormal industry indicator event, and the focus component is queried from the service and resource knowledge base based on the indicator name. It is understandable that in today's increasingly complex and large-scale IT systems in enterprises and governments, various monitoring tools generate a large number of industry indicator alerts. However, while the "indicator names" in these alerts, such as "Database connection pool full" or "CPU usage too high," indicate abnormal phenomena, they often lack a direct and clear mapping to the specific business services or underlying IT resources that host these indicators. When operations personnel or managers receive such alerts, the primary challenge is determining which application system, service module, or even physical or virtual resource the indicator corresponds to. If the entity to which the abnormal indicator belongs cannot be quickly and accurately located, subsequent troubleshooting and impact analysis are not only time-consuming and labor-intensive, but also prone to misjudgment, delaying the optimal action time. Especially in modern IT architectures with dynamic changes and numerous components, the inefficiency and uncertainty of this correlation approach, which relies on manual experience or decentralized configuration information, has become a bottleneck restricting management effectiveness. Based on this, in this application, the indicator name is extracted from the abnormal event of the industry indicator, and the focus component is queried from the service and resource knowledge base according to the indicator name.

[0036] Specifically, first, after receiving an abnormal event of an industrial indicator containing multi-dimensional fields, the "indicator name" field is accurately extracted from the event structured field through regular expression matching or semantic parser in natural language processing (NLP) technology. For example, for the event "Event ID: 20250515001, Indicator Name: Database Connection Timeout Rate, Indicator Current Value: 85%, Threshold: 20%, Timestamp: 2025-05-1514:30:00, Business ID: S20250515001", the parser identifies the string "Database Connection Timeout Rate" corresponding to the "Indicator Name" through preset field separation rules (such as commas and colons). This process needs to have field robustness and be able to handle naming variations of indicator names in different business scenarios (such as the normalized recognition of "CPU utilization" and "central processing unit usage"), and achieve semantic unification through a synonym dictionary or named entity recognition (NER) model.

[0037] After the indicator name is extracted, it needs to be converted into a query index for the service and resource knowledge base. The knowledge base serves as the core metadata center and uses a graph database (such as Neo4j) or a relational database for storage to build a multi-dimensional association graph containing "indicator-component-business". Among them, each indicator name corresponds to at least one "indicator-component" mapping entry, which records the specific IT component monitored by the indicator (such as a database instance, application server process, middleware queue). For example, the indicator "payment interface response time" may be associated with the "Payment Service Cluster-PaymentServiceV3.2-Instance01" component of the e-commerce platform. This component records detailed metadata such as its deployment address, dependent middleware (such as RabbitMQ queue), and business line (online payment) in the knowledge base.

[0038] The query process uses a "fuzzy matching + priority sorting" strategy to deal with the complexity of the mapping between indicator names and components. When there are multiple possible mapping objects for an indicator name (such as the same indicator "transaction delay" may correspond to transaction service components of multiple business lines), the knowledge base calculates the matching priority through the following dimensions: First, time relevance, giving priority to matching components that are active before and after the time point of the exception; second, business relevance, filtering out components of the business domain according to the business ID carried by the event (such as when the business ID points to the government approval system, filtering out enterprise ERP-related components); third, historical matching frequency, giving priority to components that are frequently associated with historical exceptions as candidates. For example, the indicator "Server CPU Overload" corresponds to 10 physical servers and 20 virtual machine instances in the knowledge base. The 5 instances belonging to the "Government Cloud-Public Service Cluster" are filtered out through the business ID, and then combined with the real-time monitored CPU usage data, the 2 instances with the highest current load are selected as focus component candidates.

[0039] To ensure the accuracy and timeliness of the knowledge base, a dynamic maintenance mechanism needs to be established. On the one hand, change events in the IT environment (such as new service deployment, component version upgrades, and resource migration) are synchronized through automated tools (such as CMDB interfaces). For example, when a microservice is migrated from Kubernetes cluster A to cluster B, the knowledge base automatically updates the component address and topology relationship corresponding to the service. On the other hand, a manual verification process is introduced to periodically audit the automated mapping results and correct mapping errors caused by the failure to synchronize system changes in a timely manner. For example, the operation and maintenance team conducts a monthly sampling inspection of the "indicator-component" mapping in the knowledge base to ensure that the mapping accuracy of key business indicators remains above 99%.

[0040] At the technical implementation level, the query process achieves low-latency response through the API interface. When the indicator name is passed into the knowledge base query engine, the engine first performs word segmentation on it (such as splitting "order creation failure rate" into "order", "creation", and "failure rate"), and then performs an inverted index search in the index fields of the knowledge base (such as component name, indicator alias, business label), and returns a list of matching components and associated scores. For example, a full-text index is built using the Lucene search engine, which supports millisecond-level fuzzy queries to ensure that the target component can be quickly located in massive metadata. For complex query scenarios (such as indicator names involving cross-layer component associations), the path query function of the graph database is used to traverse the topological relationship of "indicator-component-parent component-child component" to generate an extended candidate set containing upstream and downstream components, but the component with the highest matching score is always used as the focus component.

[0041] The key value of this step is to realize the "concretization of abstract indicators", establish a deterministic association between user-visible business indicators (such as "work order processing timeout rate") and underlying technical components (such as the "work order allocation service-QueueConsumerModule" of the government approval system), and avoid the problem of "indicator alarms and component failures being disconnected" in traditional management. For example, when a company's "inventory turnover rate" indicator is abnormal, it can be directly located to the "inventory data synchronization service" component of the ERP system through a knowledge base query, rather than a general alarm of "inventory module abnormality", so that operation and maintenance personnel can directly conduct in-depth analysis of the logs and performance data of the service, reducing ineffective troubleshooting time. At the same time, this precise positioning provides a clear starting point for subsequent service topology analysis and log correlation queries, enabling abnormal diagnosis to shift from "blind trial and error" to "targeted analysis", greatly improving handling efficiency.

[0042] It is worth noting that this step needs to deal with the ambiguity of indicator names. For example, different business lines may use indicators with the same name but point to different components (such as the human resources system and the financial system both have the "data synchronization delay" indicator, but they correspond to different ETL job components). To this end, the knowledge base uses the "Indicator-Business Domain" label to isolate and, when querying, enforces filtering based on the business ID or context parameters (such as tenant ID, system name) in the event to ensure the uniqueness of the mapping results. For example, when an event carries "Business ID: FIN202505", the knowledge base automatically limits the query scope to the "Financial System" business domain to avoid misjudgments caused by cross-domain matching.

[0043] In step S130, based on the service topology and data lineage information in the service and resource knowledge base, upstream and downstream components directly associated with the focus component before and after the anomaly occurred are identified, and key contextual information about the anomaly event is extracted from these upstream and downstream components. It should be understood that when an anomaly in an industry indicator is localized to a specific focus component, focusing solely on that component itself is often insufficient to reveal the full picture and root cause of the problem. Modern IT systems are intricate networks composed of a large number of interdependent and interacting services and resources. A component's abnormal behavior may be a direct result of an upstream service failure or data input issue, and may also have a knock-on impact on its downstream dependent services and business processes. Traditional management methods, lacking the ability to perceive this global service topology and data flow, make it difficult to trace the true source of anomalies when faced with them, nor can they accurately assess their potential spread risk. Therefore, in the technical solution of the present application, based on the service topology and data lineage information in the service and resource knowledge base, upstream and downstream components directly associated with the focus component before and after the anomaly occurred are identified, and key contextual information about the anomaly event is extracted from these upstream and downstream components.

[0044] Specifically, a directed graph model is first constructed, with the focal component as the central node, based on service topology data stored in the service and resource knowledge base (such as REST API call relationships, message queue subscription relationships, and database table associations). The service topology explicitly records the call direction and dependency strength between components. For example, if component A calls component B's interface to obtain data, A is the downstream component and B is the upstream component. Parameters such as call frequency and timeout threshold serve as edge weights. When an abnormal event occurs, a sliding time window (e.g., 30 minutes before and after) is opened in the service topology graph based on the event's timestamp (e.g., 2025-05-15 14:30:00). All upstream and downstream components that directly interact with the focal component within this window are retrieved. For example, the topology of the focal component "Payment Service" shows that its upstream components include "User Authentication Service" and "Inventory Query Service," and its downstream component is "Transaction Log Service." Within the time window, these three components are automatically identified as directly connected components.

[0045] Data lineage information is used to supplement the data flow paths between components. For example, in an ETL operation, data is cleaned by component X and then transferred to component Y for storage. By analyzing the lineage relationships in the service and resource knowledge base, the system can identify the position of the focus component in the data production, processing, and consumption chain. For example, an abnormal indicator may be caused by quality issues at the upstream data source (such as missing fields in data source A) or a write bottleneck in the downstream data storage (such as abnormal disk IO in component Y). This dual association (service call + data flow) ensures comprehensive identification of upstream and downstream components, avoiding the omission of hidden fault sources caused by data dependencies.

[0046] After identifying upstream and downstream components, the key context information collection process is automatically triggered. The collection scope includes: the performance indicators of upstream components within the abnormal time window (such as response time, error rate, and throughput), for example, whether the authentication failure rate of the "User Authentication Service" increased sharply between 14:25 and 14:35; the operation logs of downstream components, such as whether the "Transaction Log Service" recorded batch write failure information during the abnormal period; the alarm events of related components, such as whether the middleware management platform issued a "message queue backlog" alarm at the same time; and configuration change records, such as whether the upstream database of the focus component was upgraded before the abnormality. This information is pulled in real time from the monitoring agent, log server, and configuration management system of each component through a unified data collection interface to ensure the timeliness and integrity of the context.

[0047] To avoid data overload, we filter information using the following strategies: First, we prioritize data from components that frequently interact with the focal component (e.g., call counts >100 times / minute) or are on critical paths, based on topological dependency strength. Second, we use time series anomaly detection algorithms (such as isolation forests and LSTM prediction models) to automatically identify abnormal fluctuations in the metrics of upstream and downstream components, retaining only contextual data that coincides with the focal component's anomaly. For example, if the response time of the "Inventory Query Service" suddenly increases by three times during an abnormal period and perfectly matches the abnormal timestamp of the focal component, its related data is marked as high-priority context. Conversely, if a downstream component's log anomaly occurs outside the abnormal time window, it is considered irrelevant and filtered out.

[0048] Structuring contextual information is another key step in this process. Unstructured logs (such as JSON-formatted error logs) are converted to a unified format using the LogSchema standardization tool. Performance metric data is then associated with component metadata in the knowledge base (such as component ID and cluster), forming key-value pairs with timestamps. For example, the performance data for the upstream component "User Authentication Service - Instance02" is structured as: {component_id: "US-02", metric: "authentication_failure_rate", value: 15%, timestamp: "2025-05-15 14:28:00"}. This structured data is stored in a distributed time series database, supporting subsequent correlation analysis and visualization.

[0049] In addition, the dynamically maintained knowledge base ensures the adaptability of the process. When the service topology changes (such as the addition of a new microservice node) or the data lineage relationship is adjusted (such as the reconstruction of the ETL process), the knowledge base updates the association relationship through an automated synchronization mechanism to ensure the accuracy of upstream and downstream component identification. For example, a government system added a "face recognition service" as an upstream component for user authentication. After receiving the change notification from the CMDB, the knowledge base automatically updates the topology of the "user authentication service" so that subsequent abnormality diagnosis can incorporate the context information of the new component.

[0050] In step S140, the associated log set is obtained by querying from the unified log query platform based on the key context information of the abnormal event. It is understandable that although the focus components and their upstream and downstream dependencies related to the abnormal indicators are identified through the service topology and context information, this is mainly still at the structured and semi-structured metadata level, such as component status, performance indicators, etc. This information can outline the general outline and propagation path of the impact of the abnormal event, but in order to reveal the specific cause of the abnormality, internal error details and precise fault triggering mechanism, deeper, unstructured evidence is often required, and system and application logs are the key carriers of such detailed information. For this reason, the present application obtains the associated log set from the unified log query platform based on the key context information of the abnormal event.

[0051] Specifically, the key context information extracted in the previous step is first deeply parsed and broken down into executable query elements. For example, the context extracts the unique identifiers of the focus component and its upstream and downstream components (e.g., component ID: SVC-001, IP address: 192.168.1.101), the time range of the exception (e.g., 2025-05-15 14:25:00 to 14:35:00), characteristic error codes (e.g., HTTP 500, ERROR CODE: E001), and process names (e.g., java.exe, nginx.conf). These elements form multidimensional query conditions, which are combined through logical operators (e.g., "component ID = SVC-001 AND timestamp BETWEEN '14:25' AND '14:35' AND error code = E001") to form a precise log retrieval expression.

[0052] The unified log query platform serves as a cross-data source retrieval hub. It connects to various enterprise / government log systems through standardized interfaces, including application logs (such as Spring Boot service logs), middleware logs (such as Kafka consumption logs), infrastructure logs (such as Linux system logs), and security logs (such as firewall access records). The platform uses distributed search engines (such as Elasticsearch) to build log indexes, supporting full-text search, structured field filtering, and time range aggregation of log content. When a query request is initiated, the platform decomposes the search expression into multiple subquery tasks, distributes them in parallel to each data source node, and uses an inverted index to quickly locate eligible log entries.

[0053] To improve query efficiency, a "priority tiering" strategy is adopted to process different types of contextual information. For example, timestamp ranges are used as mandatory conditions for strict filtering to ensure that returned logs are within the anomaly time window; component IDs and IP addresses are used as core positioning conditions to narrow the search scope to specific component clusters; error codes and process names are used as feature matching conditions to identify anomaly-related log patterns. This tiered strategy enables the query engine to first filter out over 90% of irrelevant logs using the time and component dimensions, and then accurately match key evidence in the remaining logs using feature conditions, keeping the average response time for a single query to within seconds.

[0054] When processing log result sets, we first normalize logs across data sources. Because log formats vary significantly across systems (e.g., microservice logs in JSON format versus database slow query logs in CSV format), the platform uses predefined log parsers (e.g., Logstash filters) to convert raw logs into a unified structured format, containing fields such as timestamp, component name, log level, message content, and associated business ID. For example, we parse the binary logs of a particular middleware into readable text, extracting transaction IDs and associating them with business IDs to ensure that subsequent analysis can trace the path of anomalies across components.

[0055] To avoid missing potential evidence, a "context expansion query" mechanism is introduced. When the initial query result set is small or the key information is insufficient, derivative query conditions are automatically generated based on the existing context. For example, if "connection timeout" errors frequently appear in the upstream component logs of the focus component, query conditions for the downstream component logs of the upstream component will be automatically added to check whether there are cascading failures; or based on the third-party service address mentioned in the log (such as an external API endpoint), the access log of the service will be expanded to confirm whether the exception is caused by external dependencies.

[0056] In step S150, semantic embedding coding is performed on each original log in the associated log set to obtain a set of original log semantic embedding coding vectors, including: LogBERT-based semantic embedding coding is performed on each original log in the associated log set to obtain a set of original log semantic embedding coding vectors. Accordingly, considering that the original logs usually contain a large amount of free text, mixed with timestamps, component names, code snippets, error descriptions and other information, their formats are diverse and their semantics are complex. Traditional log analysis methods, such as rules based on keyword matching or regular expressions, can extract information from logs to a certain extent, but they are often very sensitive to the expression form of the logs and have difficulty capturing semantic nuances, synonymous expressions or implicit correlations. This shallow text processing method cannot truly gain insight into the deep meaning and patterns behind the logs, resulting in the accuracy and intelligence of diagnosis being greatly limited when faced with massive, heterogeneous, and dynamically changing log data, and cannot meet the needs of in-depth root cause analysis of complex abnormal events. In order to enable the machine to understand and utilize log information at a deeper level, the present application performs LogBERT-based semantic embedding encoding on each original log in the associated log set to obtain a set of semantic embedding encoding vectors of the original log. Specifically, the present application uses a LogBERT-based model to perform this conversion. LogBERT is a Transformer model that is pre-trained and optimized specifically for the characteristics of log data. It can better capture the patterns, templates and semantic information unique to logs. Through LogBERT, the semantic content of each log is condensed and mapped to a point (vector) in a high-dimensional space, so that semantically similar logs are closer in the vector space, while logs with large semantic differences are farther apart, so that the understanding of the logs leaps from literal matching to the semantic level, greatly improving the quality and depth of information extraction.

[0057] In step S160, the abnormal events of industry indicators are structured and embedded into coding vectors to obtain structured embedded coding vectors of abnormal events of industry indicators. It should be understood that, considering that abnormal events of industry indicators usually contain multi-dimensional structured attributes (such as indicator name, business ID, timestamp, etc.), key correlation characteristics of service health status are hidden between these attributes. Traditional analysis methods often only focus on the numerical deviation of a single indicator, while ignoring the semantic association between the indicator and the business scenario and service component. For example, when the "API request success rate" indicator is abnormal, the specific service version, dependent middleware cluster or associated business process corresponding to the indicator cannot be revealed by threshold comparison alone, resulting in subsequent diagnosis requiring manual backtracking of contextual information from multiple isolated systems, which is inefficient and easy to miss key clues. Based on this, in the technical solution of the present application, the abnormal events of industry indicators are structured and embedded into coding vectors to obtain structured embedded coding vectors of abnormal events of industry indicators. By building an embedding model that includes fields such as event ID, indicator name, and business ID, the system can capture implicit features such as the potential mapping relationship between indicator names and business scenarios (such as the "payment transaction delay" indicator automatically associated with the payment core service cluster), the dynamic association between timestamps and service call peaks and valleys, and so on. For example, when the order processing service corresponding to a certain business ID experiences an abnormal response time, structured embedding coding not only retains the numerical characteristics of the indicator, but also associates it with the corresponding database sharding, message queue configuration, and other topological information through the embedding vector of the business ID, forming a vector expression of multi-dimensional feature fusion.

[0058] In step S170, the set of the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded coding vector is input into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report. Figure 2 Flowchart of step S170 in the integrated management method of brain services for enterprises and governments according to an embodiment of the present application. Specifically, in the embodiment of the present application, Figure 2 As shown, step S170, inputs the set of the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded coding vector into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report, including: S171, inputs the set of the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded coding vector into the abnormal event-log semantic dynamic query module to obtain the abnormal event-log information semantic association query response coding vector; S172, based on the abnormal event-log information semantic association query response coding vector, obtains the intelligent diagnosis report.

[0059] Specifically, step S171 inputs the structured embedded coding vector of the industry indicator anomaly event and the semantic embedded coding vector of the raw log into the anomaly event-log semantic dynamic query module to obtain an anomaly event-log information semantic association query response coding vector. Furthermore, while structured indicator events and raw log data are both key inputs for anomaly analysis, they share a significant modality gap: structured events contain precise numerical attributes and business labels but lack service runtime context; unstructured logs record rich operational details but contain fragmented semantic clues. Traditional methods for processing such cross-modal associations typically employ time window matching or keyword hard association, making it difficult to capture the nonlinear causal relationship between indicator fluctuations and log anomalies. For example, when a database master-slave switch causes an anomaly in a business indicator, the relevant logs may be distributed across multiple components, such as the database connection pool and transaction manager, and the log content may include different semantic fragments, such as connection timeouts and transaction rollbacks. Traditional rule engines are unable to automatically identify these cross-component and cross-semantic correlation patterns, resulting in root cause inference remaining at the superficial level of alarm overlay. To this end, the present application inputs the set of the industry indicator abnormal event structured embedded coding vector and the original log semantic embedded coding vector into the abnormal event-log semantic dynamic query module to obtain the abnormal event-log information semantic association query response coding vector.

[0060] Specifically, the team first performs information condensation and topological modeling on the collection of raw log semantic embedding vectors, identifying the underlying semantic manifold structure between log events (e.g., mapping "connection pool exhaustion" and "thread blocking alarm" logs to the same resource contention subgraph). A gated masking mechanism is then used to extract key topological connections and eliminate noise interference. Finally, a graph convolutional network is used to generate a structured encoding matrix that incorporates global context. Based on this graph-like model, the structured event vectors are used as dynamic query inputs. An attention mechanism interacts with the log feature manifold, enabling anomalous events to adaptively focus on related log node clusters in the topological space (e.g., semantically binding order service response delay events with database slow query logs and cache breakdown logs). This enables automated reasoning and context enhancement of cross-modal evidence chains.

[0061] Figure 3 Flowchart of step S171 in the integrated management method of brain services for enterprises and governments according to an embodiment of the present application. Specifically, in the embodiment of the present application, Figure 3As shown, step S171, inputs the set of the industrial indicator abnormal event structured embedding coding vector and the original log semantic embedding coding vector into the abnormal event-log semantic dynamic query module to obtain the abnormal event-log information semantic association query response coding vector, including: S1711, performing bionic graph semantic encoding based on dynamic gated sparse topology on the set of the original log semantic embedding coding vector to obtain the original log semantic embedding imitation graph coding matrix; S1712, performing feature query response on the industrial indicator abnormal event structured embedding coding vector and the original log semantic embedding imitation graph coding matrix to obtain the abnormal event-log information semantic association query response coding vector.

[0062] Specifically, in the embodiment of the present application, step S1711, performing bionic graph semantic encoding based on dynamic gated sparse topology on the set of the original log semantic embedding coding vectors to obtain the original log semantic embedding bionic graph encoding matrix, includes:

[0063] Information condensation is performed on each original log semantic embedding coding vector in the set of original log semantic embedding coding vectors to obtain a set of original log semantic embedding condensed coding vectors, which is expressed in formula form as follows:

[0064] S={s1,s2,...,s i ,...,s n}

[0065] H={h1,h2,...,h i ,...,h n}

[0066]

[0067] Among them, S is the set of original log semantic embedding coding vectors, s1, s2, s i and s n are the first, second, i-th and n-th original log semantic embedding encoding vectors in the set of original log semantic embedding encoding vectors, n is the number of vectors in S, ||s i || 2 To calculate s i The square of the Euclidean norm, ReLU is the ReLu activation function, W c is the weight matrix, b c is the bias term, h1, h2, h i and h n are the first, second, i-th and n-th original log semantic embedding condensed coding vectors in the set of original log semantic embedding condensed coding vectors, and H is the set of original log semantic embedding condensed coding vectors;

[0068] The semantic correlation between any two original log semantic embedding condensed coding vectors in the set of the original log semantic embedding condensed coding vectors is calculated to obtain the original log semantic embedding node correlation topology matrix, which is expressed in formula form as follows:

[0069]

[0070] Among them, h i and h j are the i-th and j-th original log semantic embedding condensed coding vectors in the set of original log semantic embedding condensed coding vectors, [·||·] is the vector splicing operation, W r Splicing weight matrix, b r is the splicing bias term, r i,j It is h i and h j The original log semantic embedding association vector between r i,j The number of eigenvalues in r i,jz is r i,j The eigenvalue at the zth position in A i,j The original log semantics is embedded in the node association topology matrix h i and h j The semantic relevance between

[0071] The original log semantic embedding inter-node correlation topology matrix is subjected to gated mask sparsification to obtain the original log semantic embedding inter-node sparse correlation topology matrix, which is expressed in formula form as follows:

[0072]

[0073] A i,j ′=M i,j ·A i,j

[0074] in, is the mask weight vector, b g is the mask bias weight parameter, Sigmoid is the Sigmoid activation function, M i,j is the original log semantic embedding in the association mask matrix h i and h j The mask value between i,j ' is the original log semantics embedded in the sparse correlation topology matrix h between nodes i and h j Sparse correlation value between ;

[0075] The set of the original log semantic embedding concentrated coding vectors and the original log semantic embedding inter-node sparse correlation topology matrix are subjected to graph convolution to obtain the original log semantic embedding graph-like coding matrix, which is expressed in formula form as follows:

[0076]

[0077] Among them, A' is the sparse correlation topology matrix between nodes of the original log semantic embedding, GCN is the graph convolutional coding, and G is the original log semantic embedding graph-like coding matrix.

[0078] It should be understood that while the vectors generated after semantic embedding encoding of raw logs can capture the semantic features of the text, they often carry a large amount of redundant information and noise interference. For example, different instances of the same service may produce log entries with similar content but different expressions. The distribution of their raw embedding vectors in high-dimensional space may be discrete due to differences in wording. At the same time, logs often contain semantically irrelevant details such as timestamps and process IDs. This noise dilutes the expression strength of the core semantics, making it difficult for subsequent cross-modal association analysis to focus on the true abnormal patterns. Therefore, in order to refine the core representation of log semantics, information condensation is performed on each raw log semantic embedding encoding vector to obtain a set of raw log semantic condensed embedding encoding vectors. The information condensed log vector not only reduces the computational complexity brought by the feature dimension, but more importantly, constructs a denoised semantic foundation, allowing the graph-like encoding engine to more clearly identify the potential correlation structure between log events (such as establishing a causal link between resource contention logs and performance degradation indicator anomalies).

[0079] Accordingly, there are often implicit semantic associations and causal chains between massive log events, but traditional analysis methods can only identify explicit time series overlaps or keyword matching relationships. For example, when a database master node failure triggers a cascading exception, the timeout log of the front-end service, the retry log of the middleware, and the heartbeat loss log of the database are strongly associated at the semantic level. However, due to reasons such as service component isolation and differences in log templates, their intrinsic connections are difficult to be captured by rule-based engines. This fragmented log analysis model requires the restoration of the abnormal propagation path to rely on the subjective experience of operation and maintenance personnel to piece together clues, and it is very easy to miss key evidence nodes across components. This application breaks through the limitations of isolated log analysis by calculating the semantic correlation between any two original log semantic embedding condensed encoding vectors to explicitly define the semantic coupling strength between log events, weaves discrete abnormal clues into an evidence network with business explanatory power, and obtains a correlation topology matrix between original log semantic embedding nodes.

[0080] It should be understood that the initial correlation topology between original log events often contains a large number of redundant connections and noise interference. For example, when a microservice cluster experiences network jitter, hundreds of log entries involving thread blocking, timeout retries, and heartbeat anomalies may be generated at the same time, and its initial correlation matrix will form dense but low-value edge connections. These redundant connections not only mask the key links that truly reflect the fault propagation path (such as the causal chain from database connection failure to transaction rollback), but also cause information over-smoothing during the graph convolution process, resulting in the dilution of abnormal features by the noise of irrelevant nodes, seriously affecting the accuracy of root cause reasoning. To this end, the original log semantic embedding node correlation topology matrix is gated masked to obtain the original log semantic embedding node sparse correlation topology matrix. This refined graph structure not only reduces the training complexity of the graph neural network, but also enables the subsequent graph-like encoding to focus on the real abnormal pattern by eliminating the noise propagation path.

[0081] Correspondingly, the correlation between log events often presents multi-level, nonlinear topological structural characteristics, while traditional time series analysis or keyword matching methods can only capture local linear correlations. For example, when a cache service failure causes a cascading exception, the relevant logs may be distributed in the cache node, load balancer, and upstream business services that rely on the cache, and the exception propagation path needs to span multiple service levels. Although the initial sparse association topology can identify directly associated nodes, it cannot reveal the implicit impact chain across multi-hop nodes (such as cache breakdown causing a surge in database pressure, which in turn causes business interface timeouts). The lack of such high-order relationships makes root cause inference prone to falling into local optimal traps. To this end, the present application performs graph convolution on the set of the original log semantic embedding concentrated encoding vectors and the sparse association topology matrix between the original log semantic embedding nodes to obtain the original log semantic embedding imitation graph encoding matrix. That is, each vector in the encoding matrix carries the context-aware features of the log node in the global topology, such as establishing an implicit association between the seemingly isolated "message queue backlog" log and the remote "consumer thread blocking" log.

[0082] Specifically, in the embodiment of the present application, step S1712 performs a feature query response on the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedding imitation graph coding matrix to obtain the abnormal event-log information semantic association query response coding vector, including:

[0083] The topology-invariant optimization based on dynamic integral measure and multi-order statistical coupling is performed on each row vector in the original log semantic embedding graph-like encoding matrix to obtain the original log semantic embedding graph-like optimized encoding matrix composed of multiple optimized row vectors, which is expressed in formula form as follows:

[0084]

[0085] g″ i =r i g i

[0086] Among them, g i is the i-th row vector in the original log semantic embedding spectral encoding matrix, g u are all row vectors g i The mean vector is obtained by averaging the corresponding positions, |·| is the absolute value calculation, π is the circumference, g' i It is g i The corresponding original log semantic embedding local rigid transformation vector, ln is the logarithmic function value with the natural constant e as the base, g' ij It's g' i The eigenvalue of the j-th position, r i It is g i The corresponding original log semantic embedding dynamic integral measure, g″ i It's g' i The optimized row vector after optimization is the i-th row vector in the original log semantic embedding graph-like optimized encoding matrix;

[0087] The structural embedding coding vector of the abnormal event of the industrial indicator and the original log semantic embedding imitation graph optimization coding matrix are subjected to dynamic query semantic weighting based on the response contribution weight value to obtain the abnormal event-log information semantic association query response coding vector, which is expressed in formula form as follows:

[0088] α i =softmax(u T g″ i )

[0089] v r =∑ i α i (u⊙g″ i )

[0090] Among them, u T is the transposed vector of the structured embedding coding vector of abnormal events of industry indicators, softmax is the softmax normalization function, α i It is g i The corresponding abnormal event-log information semantic association response contribution weight value, ⊙ is the position point multiplication, v i It is the encoding vector of the abnormal event-log information semantic association query response.

[0091] In particular, although the graph neural network has extracted high-order interaction features and system-level structural features in the topological association space relative to each original log semantic embedding condensed encoding vector, due to the sparsity characteristics introduced by the gated mask mechanism to the network topology, for each row vector g in the original log semantic embedding imitation graph encoding matrix i , it is still necessary to ensure that it maintains consistent statistical characteristics in the macroscopic distribution dimension of the topological extension, that is, it is necessary to realize the row vector g i High-order comprehensive association consistency.

[0092] First, construct each row vector g based on the semicircular distribution model i Local rigid transformation mapping of :

[0093]

[0094] The original log semantic embedding local rigid transformation vector g ' i Able to capture higher-order nonlinear dependencies in the context of supercovariance matrices.

[0095] Then, calculate the g ' i The original log semantic embedding dynamic integral measure:

[0096]

[0097] Finally, the dynamic integral measure r is embedded through the original log semantics i For the original row vector g i Perform weighted optimization: g″ i =r i g i .

[0098] This design is based on the macroscopic distribution law dominated by high-order statistical moments. To ensure the consistency of the macroscopic distribution across eigenvectors, a dynamic integral measure within a rigid constraint domain is used to maintain the system-level symmetry characteristics, thereby ensuring the stable propagation of the macroscopic statistical law within the topological architecture and effectively avoiding the statistical mismatch caused by correlation failure.

[0099] In other words, the association between structured indicator events and log semantic graphs is often dynamic and asymmetric. Traditional static weight distribution methods are difficult to adapt to changes in the importance of evidence in different abnormal scenarios. For example, when a business interface timeout indicator is abnormal, logs with similar timing may contain various types such as slow database queries, cache failures, network jitters, etc., but only some logs truly constitute a causal chain. If all related logs are treated with equal weights, key evidence will be submerged in noise, and the interference of minor logs may cause the diagnosis engine to deviate from the true root cause path. Based on this, the present application performs dynamic query semantic weighting based on the response contribution weight value on the structured embedded coding vector of the industry indicator abnormal event and the original log semantic embedded imitation graph optimization coding matrix to obtain the abnormal event-log information semantic association query response coding vector. This weight distribution is not driven by preset rules, but is learned through the model to learn the implicit association strength between log nodes and indicator events in different semantic scenarios, so that in the gateway current limiting abnormal scenario, the weight of the network bandwidth monitoring log will be adaptively improved.

[0100] Specifically, step S172, based on the abnormal event-log information semantic association query response coding vector, obtains the intelligent diagnosis report, including: embedding the abnormal event-log information semantic association query response coding vector into the preset Propmt and then inputting it into the abnormal pattern diagnosis engine based on the large model to obtain the intelligent diagnosis report. In particular, the intelligent diagnosis report here includes the task ID, original event information, Top-N candidate root cause details, relevant log evidence and recommended solutions. In other words, although the abnormal event-log information semantic association query response coding vector is obtained through the previous steps, the vector is only a characterization expression of the abnormality-related information, and lacks clear task orientation and structured output requirements. Although the large model itself has powerful language understanding and reasoning capabilities, if the original vector is directly input, it is difficult to ensure that the output result meets the business needs of abnormal diagnosis, and it is impossible to provide a clear and structured diagnostic conclusion. Therefore, it is necessary to use the preset Prompt to convert the vector information into an input form that meets the requirements of the diagnostic task, and guide the large model to generate valuable diagnostic results. By pre-setting prompts, the semantic association query response encoding vector is restructured to meet the input requirements of the large-scale model-based anomaly pattern diagnosis engine, driving the large-scale model to generate complete and standardized intelligent diagnostic reports. The preset prompt contains key information such as a detailed description of the diagnostic task and the expected output content structure. Embedding the encoding vector within it gives the vector clear diagnostic task semantics, guiding the large-scale model to extract key elements from the information contained in the vector based on its own knowledge and reasoning capabilities, analyze the possible causes of the anomaly, screen relevant log evidence, and propose targeted solutions. Ultimately, a structured report is generated that includes the task ID, original event information, top-N candidate root cause details, relevant log evidence, and recommended solutions.

[0101] Specifically, the encoding vector serves as a high-dimensional feature that integrates structured metrics and log semantics (for example, the correlation weights for the metric "30% order creation failure rate" and "inventory service timeout log" and "payment gateway connection interruption log" are 0.85 and 0.72, respectively). Feature extraction is required to generate an input summary suitable for the large model, such as "Metric = Order Creation Failure Rate, Current Value = 30% / Threshold = 5%, Timestamp = 2025-05-15 16:00, Business ID = ORD-20250515001, Associated Log Keywords = 'Inventory Lock Failed', 'Payment API Returns 404'." The pre-set prompt must clearly define the diagnostic objective and output specifications, for example: "You are an e-commerce system operation and maintenance expert and need to analyze the cause of order creation failures. The inventory service has the highest correlation weight in the input vector, followed by the payment gateway. The output must include the top two candidate root causes, corresponding log evidence, and e-commerce scenario solutions. The language must be concise and the technology must be feasible."

[0102] The Prompt embedding vector summary is then fed into a larger model (such as a fine-tuned GPT-4). The engine uses an attention mechanism to identify core features (such as the "inventory lock failure" log) and infer the root cause based on the e-commerce system failure knowledge base. For example, the model extracts the log "2025-05-15 16:02:18 Inventory service returned 'Insufficient inventory for product SKU-1001'" as evidence and generates a candidate root cause of "Insufficient inventory of popular products leads to interrupted order creation" (with a confidence level of 78%). Simultaneously, based on the "Payment API returns 404" log, it infers "Temporary routing error in the payment gateway" (with a confidence level of 20%). The solution is proposed for the root cause: "1. Start pre-sale mode for SKU-1001 and replenish inventory; 2. Check the payment gateway API routing configuration and restart the abnormal node." The final generated intelligent diagnostic report is structured and includes: 1. Task: DIAG-20250515-007. 2. Original event: Order creation failure rate 30% (threshold 5%) occurred at 2025-05-15 16:00, affecting business ID: ORD-20250515001. 3. Top-2 candidate root causes: Insufficient inventory of popular products (confidence 78%) - log evidence: Inventory service returns "Insufficient inventory of product SKU-1001"; Payment gateway API routing error (confidence 20%) - log evidence: Payment gateway log "API path / PayV2 not found". 4. Recommended solution: Urgently allocate SKU-1001 inventory to the target warehouse, and simultaneously launch the pre-sale page to guide users to queue; call the gateway management tool to detect the routing configuration, restart the load balancing node and monitor the API response.

[0103] To improve diagnostic efficiency, the report simultaneously triggers a visualization module. The anomaly propagation map, centered on the order service, highlights the inventory service node in red and the payment gateway in orange. Line thickness represents correlation weight, visually demonstrating the propagation path of anomalies originating from the inventory service. The log timeline arranges key logs at minute-level granularity, such as inventory lock failure at 16:02 and order service retry timeout at 16:05, with arrows indicating causal relationships. The root cause confidence dashboard compares candidate root cause probabilities using a bar chart, with insufficient inventory accounting for 78% of the root cause. Click to view detailed log evidence. The solution action card breaks down recommendations into two cards: "Inventory Action" and "Gateway Troubleshooting," each labeled with priority (high / medium), estimated completion time (4 hours / 2 hours), and responsible person (warehouse administrator / middleware team). Quick links are embedded between the inventory management system and the gateway monitoring page. This allows abstracted cross-modal correlation data to be transformed into a complete diagnostic package encompassing business impact, root cause analysis, evidence chain, and action plan. This allows operations personnel to quickly complete the entire process from "indicator alert" to "remediation execution." For example, after receiving a report, the e-commerce team can immediately confirm that inventory issues are the main root cause through a visual map. Clicking the solution card will directly jump to the inventory management interface to replenish the stock, while notifying the middleware team to check the payment gateway.

[0104] In summary, the integrated management method of brain services for enterprises and governments based on the embodiment of the present application is explained. It obtains abnormal events of industrial indicators containing multi-dimensional features in real time, locates the focus components and their upstream and downstream related nodes in the service topology, and extracts key contexts in combination with data lineage information to break through the data island limitations of traditional monitoring tools; then semantic embedding encoding is performed on the original logs to convert the unstructured log text into a computable vector space representation, eliminating the inefficiency of manual analysis; finally, through the feature manifold search engine driven by a large model, the structured abnormal event features are cross-modally correlated and matched with the log semantic vectors, and an intelligent report containing root cause location, evidence chain and solution is automatically generated. This system effectively solves the pain points of service link fault analysis, difficulty in associating heterogeneous data, and high dependence on manual experience in traditional solutions, and upgrades abnormal diagnosis from discrete alarms to a causal reasoning process with service topology perception capabilities, greatly improving the efficiency of handling abnormal events in complex systems and the reliability of decision-making.

[0105] Figure 4 FIG is a block diagram of an integrated management system for brain services for enterprises and governments according to an embodiment of the present application. Figure 4As shown, according to the embodiment of the present application, the brain service integrated management system 100 for enterprises and governments includes: an industry indicator abnormal event acquisition module 110, which is used to obtain industry indicator abnormal events, and the industry indicator abnormal events include event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID; a focus component query module 120, which is used to extract the indicator name from the industry indicator abnormal event, and query the focus component from the service and resource knowledge base according to the indicator name; an abnormal event extraction module 130, which is used to identify the upstream components and downstream components that are directly related to the focus component before and after the abnormality occurs based on the service topology and data lineage information in the service and resource knowledge base, and query the focus component from the upstream components and the downstream components. The downstream components extract key context information of abnormal events; the query module 140 is used to query the unified log query platform based on the key context information of the abnormal events to obtain a set of related logs; the associated log encoding module 150 is used to perform semantic embedding encoding on each original log in the associated log set to obtain a set of original log semantic embedding encoding vectors; the abnormal event encoding module 160 is used to perform structured embedding encoding vectors on the industrial indicator abnormal events to obtain structured embedding encoding vectors of industrial indicator abnormal events; the diagnosis report generation module 170 is used to input the set of structured embedding encoding vectors of industrial indicator abnormal events and the original log semantic embedding encoding vectors into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report.

[0106] Here, those skilled in the art will understand that the specific operations of each step in the above-mentioned brain service integrated management system for enterprises and governments have been referred to above. Figures 1 to 3 It has been introduced in detail in the description of the integrated management method of brain services for enterprises and governments, and therefore, its repeated description will be omitted.

[0107] As described above, the integrated management system 100 for brain services for enterprises and governments according to the embodiment of the present disclosure can be implemented in various wireless terminals, such as a server with an integrated management algorithm for brain services for enterprises and governments. In one possible implementation, the integrated management system 100 for brain services for enterprises and governments according to the embodiment of the present disclosure can be integrated into a wireless terminal as a software module and / or a hardware module. For example, the integrated management system 100 for brain services for enterprises and governments can be a software module in the operating system of the wireless terminal, or can be an application developed for the wireless terminal; of course, the integrated management system 100 for brain services for enterprises and governments can also be one of the many hardware modules of the wireless terminal.

[0108] Alternatively, in another example, the integrated management system 100 for brain services for enterprises and governments and the wireless terminal may also be separate devices, and the integrated management system 100 for brain services for enterprises and governments may be connected to the wireless terminal via a wired and / or wireless network and transmit interactive information in accordance with an agreed data format.

[0109] Various embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments.

Claims

1. A brain service integrated management method for enterprises and governments, characterized by: include: Obtain industry indicator abnormal events, including event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID; Extracting an indicator name from the abnormal event of the industry indicator, and querying a focus component from a service and resource knowledge base according to the indicator name; Based on the service topology and data lineage information in the service and resource knowledge base, identifying upstream components and downstream components that are directly associated with the focus component before and after the abnormality occurs, and extracting key context information of the abnormal event from the upstream components and the downstream components; Obtaining a related log set from a unified log query platform based on the key context information of the abnormal event; Performing semantic embedding coding on each original log in the associated log set to obtain a set of original log semantic embedding coding vectors; Performing structured embedding coding on the abnormal events of the industry indicators to obtain structured embedding coding vectors of abnormal events of the industry indicators; The set of the structured embedded coding vector of the abnormal event of the industrial indicator and the semantic embedded coding vector of the original log is input into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report.

2. The integrated management method for brain services for enterprises and governments according to claim 1 is characterized in that: The intelligent diagnosis report includes the task ID, original event information, Top-N candidate root cause details, relevant log evidence and recommended solutions.

3. The integrated management method of brain services for enterprises and governments according to claim 2 is characterized in that: Performing semantic embedding coding on each original log in the associated log set to obtain a set of original log semantic embedding coding vectors, including: performing LogBERT-based semantic embedding coding on each original log in the associated log set to obtain the set of original log semantic embedding coding vectors.

4. The integrated management method of brain services for enterprises and governments according to claim 1 is characterized in that: Inputting the set of the structured embedded coding vector of the abnormal event of the industrial indicator and the semantic embedded coding vector of the original log into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnosis report, including: Inputting the set of the industrial indicator abnormal event structured embedded coding vector and the original log semantic embedded coding vector into the abnormal event-log semantic dynamic query module to obtain the abnormal event-log information semantic association query response coding vector; The intelligent diagnosis report is obtained based on the abnormal event-log information semantic association query response encoding vector.

5. The integrated management method of brain services for enterprises and governments according to claim 4 is characterized in that: Inputting the set of the industry indicator abnormal event structured embedded coding vector and the original log semantic embedded coding vector into the abnormal event-log semantic dynamic query module to obtain the abnormal event-log information semantic association query response coding vector, including: Performing bionic graph semantic encoding based on dynamic gated sparse topology on the set of original log semantic embedding coding vectors to obtain an original log semantic embedding bionic graph encoding matrix; A feature query response is performed on the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded graph-like coding matrix to obtain the abnormal event-log information semantic association query response coding vector.

6. The integrated management method of brain services for enterprises and governments according to claim 5 is characterized in that: The set of the original log semantic embedding coding vectors is subjected to bionic graph semantic coding based on dynamic gated sparse topology to obtain an original log semantic embedding imitation graph coding matrix, including: performing information condensation on each original log semantic embedding coding vector in the set of original log semantic embedding coding vectors to obtain a set of original log semantic embedding condensed coding vectors; Calculating the semantic association between any two original log semantic embedding condensed coding vectors in the set of original log semantic embedding condensed coding vectors to obtain an original log semantic embedding inter-node association topology matrix; Performing gated mask sparsification on the original log semantic embedding inter-node correlation topology matrix to obtain the original log semantic embedding inter-node sparse correlation topology matrix; A graph convolution-like graph construction is performed on the set of the original log semantic embedding concentrated coding vectors and the original log semantic embedding inter-node sparse association topology matrix to obtain the original log semantic embedding imitation graph coding matrix.

7. The integrated management method of brain services for enterprises and governments according to claim 6 is characterized in that: Performing a feature query response on the structured embedded coding vector of the abnormal event of the industrial indicator and the original log semantic embedded imitation graph coding matrix to obtain the abnormal event-log information semantic association query response coding vector, including: Performing topological invariant optimization based on dynamic integral measure and multi-order statistical coupling on each row vector in the original log semantic embedding graph-like encoding matrix to obtain an original log semantic embedding graph-like optimized encoding matrix composed of multiple optimized row vectors; The structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded graph-optimized coding matrix are dynamically query semantically weighted based on the response contribution weight value to obtain the abnormal event-log information semantic association query response coding vector.

8. The integrated management method of brain services for enterprises and governments according to claim 7 is characterized in that: Based on the abnormal event-log information semantic association query response coding vector, the intelligent diagnosis report is obtained, including: embedding the abnormal event-log information semantic association query response coding vector into a preset Propmt and then inputting it into the large model-based abnormal pattern diagnosis engine to obtain the intelligent diagnosis report.

9. An integrated brain service management system for enterprises and governments, characterized by: include: An industry indicator abnormal event acquisition module is used to acquire industry indicator abnormal events, wherein the industry indicator abnormal event includes event ID, indicator name, indicator current value, indicator threshold, occurrence timestamp and related business ID; A focus component query module is used to extract the indicator name from the abnormal event of the industry indicator, and query the focus component from the service and resource knowledge base according to the indicator name; An abnormal event extraction module is used to identify upstream components and downstream components that are directly related to the focus component before and after the abnormality occurs based on the service topology and data lineage information in the service and resource knowledge base, and extract key context information of the abnormal event from the upstream components and the downstream components; A query module, configured to query and obtain a set of related logs from a unified log query platform based on the key context information of the abnormal event; An associated log encoding module, configured to perform semantic embedding encoding on each original log in the associated log set to obtain a set of original log semantic embedding encoding vectors; An abnormal event coding module, configured to perform structured embedding coding on the abnormal event of the industry indicator to obtain a structured embedded coding vector of the abnormal event of the industry indicator; The diagnostic report generation module is used to input the set of the structured embedded coding vector of the industrial indicator abnormal event and the original log semantic embedded coding vector into the abnormal pattern diagnosis engine based on the large model to obtain an intelligent diagnostic report.

Citation Information

Cited By

  • Intelligent image comparison method and system based on machine learning

    CN120599295A

  • Large model-based multi-dimensional index abnormal reason generation and intervention path recommendation method

    CN121543746A