Statistical method and system for system events and application events

Through predefined event strings and local processes communication, efficient statistics of system and business events on embedded devices are realized, the accuracy of event statistics on resource-limited devices is solved, and real-time monitoring and exception alarm functions are provided.

CN120578698AActive Publication Date: 2025-09-02ZHEJIANG LNXALL IOT TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511080274.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-09-02
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

On embedded devices with limited resources, the prior art cannot efficiently count systems and business events, and log records are prone to loss, affecting statistical accuracy.

Method used

Using predefined event strings and local processes to communicate between processes, receive event messages through sockets, split and map into main type and sub-scene segments, accumulate the number based on statistical groups, and use timers to clear and record, design a statistical method for system events and application events.

Benefits of technology

High-speed statistics on embedded devices with resource-constrained resources, reduce resource usage, improve statistical accuracy, support real-time data requests and exception alarms, and adapt to device operation status monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120578698A_ABST
    Figure CN120578698A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer event statistics, in particular to a system event and application event statistical method and system, and the method comprises the steps: presetting event character strings based on an event definition rule, and integrating the event character strings into an event list; receiving a local socket to collect an event message, and splitting the event message to obtain a plurality of event sub-strings; performing first mapping and second mapping on the event sub-character strings in an event list to obtain matched main type segments and sub-scene segments; event statistics is carried out after mapping is matched, and quantity accumulation is carried out in statistical groups corresponding to different statistical time periods based on event message segments; performing zero clearing and / or recording on counts in the statistical groups based on the timers in the statistical groups; and responding to the real-time data request, and outputting the current statistical information according to the time period requirement of the real-time data request. The method and the device have the effect of performing high-speed statistics on the event occurrence condition in the embedded equipment with limited resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of computer event statistics, and in particular to a method and system for counting system events and application events. Background Art

[0002] In the energy storage field, on resource-limited embedded devices, changes in the external environment may generate a large number of system and business events (in a short period of time), such as network disconnection and connection, peripheral device operation timeouts, energy storage device power on and off, and off-grid operation.

[0003] These events are time-related and are very important for observing the operating status of embedded devices. Quantified and centralized information can help on-site engineers quickly determine whether any equipment anomalies occur.

[0004] Currently, statistics on system and business application events are collected by searching the system's operation logs for field information related to the event. This method requires a large amount of resources and is not suitable for embedded devices with limited resources. In addition, logs cannot be written directly to Flash and require compression. However, if an abnormal situation such as power outage occurs during the compression process, the logs will be lost, which will affect the accuracy of the event statistics. Summary of the Invention

[0005] In order to achieve high-speed statistics of event occurrences in resource-limited embedded devices, the present application provides a method and system for counting system events and application events.

[0006] In a first aspect, the present application provides a method for counting system events and application events, which adopts the following technical solutions: A statistical method for system events and application events includes the following steps: Presetting event character strings based on event definition rules and integrating them into an event list, wherein the event character strings at least include a main type segment, a sub-scene segment, and a separator; receiving a local socket to collect event messages, and splitting the event messages to obtain a plurality of event substrings; Performing a first mapping on the event substring in the event list to obtain a matching main type segment, and performing a second mapping on the main type segment to obtain a matching sub-scene segment; After all mappings are matched, event statistics are performed to accumulate the number of events in corresponding statistical groups based on the event message segments, wherein different statistical groups are distinguished based on statistical time periods; clearing and / or recording the counts in the statistical groups based on the timers in the statistical groups; Respond to real-time data requests and output current statistical information according to the time period requirements of the real-time data requests.

[0007] In some embodiments, presetting event strings based on event definition rules and integrating them into an event list further includes the following steps: Separating the main type segment and the sub-scene segment by the separator; Determine whether the event corresponding to the event string is a periodic state, and add a state prefix to the event string based on the determination result, wherein the state prefix is ​​used to distinguish between a continuous event and a one-time event; An attribute segment is added to the event character string, wherein the attribute segment is used to add context attribute content corresponding to the event, and the attribute segment and the sub-scenario segment are separated by an attribute suffix.

[0008] In some embodiments, presetting event strings based on event definition rules and integrating them into an event list further includes the following steps: Format verification rules are configured in the event list, and format checks are performed on the event strings in the event list regularly based on the format verification rules. If the event strings fail the format check, an abnormal alarm is generated and the corresponding event strings and counts in the event list and the statistical group are marked.

[0009] In some embodiments, when the first mapping or the second mapping does not match, the event is defined as an unknown event and statistics of the unknown event are not collected.

[0010] In some embodiments, the event message is a structure including an event string and a system startup time, and receiving a local socket to collect event messages and splitting the event message to obtain a plurality of event substrings includes the following steps: Synchronously obtaining the current system action time when splitting the event information; The difference between the current system action time and the system startup time in the event information is calculated, and the event information is discarded when the difference is greater than a preset value.

[0011] In some embodiments, after all mappings are matched, event statistics are performed to accumulate the number of event message segments in corresponding statistical groups, including the following steps: Obtaining the statistical time periods corresponding to the statistical groups and arranging them in sequence; For each event message that has a mapping match, the number of the event message in the statistical group with the shortest statistical time period is increased by one; If the statistical time reaches the shortest statistical time period, the statistical quantity in the statistical group is added to the statistical group with a longer and adjacent statistical time period, and the statistical quantity in the current statistical group is cleared after the addition.

[0012] In some embodiments, after all mappings are matched, event statistics are performed to accumulate the number of event message segments in corresponding statistical groups, including the following steps: Obtaining the statistical time period corresponding to each statistical group; For each event message that has a mapping match, the number of events in all statistical groups is increased by one; When the statistical time reaches each statistical time period, the statistical quantity in the corresponding statistical group is cleared.

[0013] In some embodiments, the statistical time period includes a minute system, an hour system, and a daily system, and clearing and / or recording the counts in the statistical group based on the timer in each statistical group includes the following steps: Obtain the statistical time period n in minute format, and obtain the statistical time period m in hour format, where n is less than 60 and m is greater than or equal to 60; The timer is triggered every time a preset time passes so that each statistical group performs a time condition comparison. Specifically, For the minute-based statistical group: Obtaining minute information of the current time, and determining whether the minute information can divide n, and if so, clearing all the statistical quantities in the statistical group to zero; For the statistical group of the hourly system: Calculate whether m / 60 is an integer; If yes, then obtain the minute information of the current time and determine whether it is zero; if it is zero, then obtain the hour information of the current time and determine whether it can be divided by m / 60; if so, then clear all the statistical quantities in the statistical group to zero; If not, obtain the minute information of the current time and determine whether the remainder can be divided evenly by m / 60; if so, obtain the hour information of the current time and determine whether the quotient can be divided evenly by m / 60; if so, clear all the statistical quantities in the statistical group; For the statistical group of the current day: Obtain the minute information and hour information of the current time and determine whether both are 0; if so, record all the statistical quantities in the statistical group into a statistical file, and clear the statistical quantities after recording.

[0014] In some embodiments, when the event corresponding to the event string is a periodic state, the method further includes the following steps: Obtaining and recording the system startup time corresponding to the event character string, and stopping recording the system startup time when the event in the periodic state ends; A plurality of the system startup events corresponding to the event are integrated to form a duration and associated with the event.

[0015] In a second aspect, the present application provides a statistical system for system events and application events, which adopts the following technical solutions: A statistical system for system events and application events, comprising: An event predefinition module, configured to predefine event character strings based on event definition rules and integrate them into an event list, wherein the event character strings at least include a main type segment, a sub-scene segment, and a separator; An event receiving module, configured to receive a local socket to collect event messages, and split the event messages to obtain a plurality of event substrings; Performing a first mapping on the event substring in the event list to obtain a matching main type segment, and performing a second mapping on the main type segment to obtain a matching sub-scene segment; An event statistics module, configured to perform event statistics after all mappings are matched, so as to accumulate the number of event message segments in corresponding statistical groups, wherein different statistical groups are distinguished based on a statistical time period; A timer, configured to trigger at regular intervals to clear and / or record the counts in the statistical group; The output module is used to respond to real-time data requests and output current statistical information according to the time period requirements of the real-time data requests.

[0016] The technical solutions provided by the embodiments of this application have the following technical effects: Define various known events in the form of predefined strings; design a local inter-process communication method and communication protocol to quickly forward events generated by other services or applications to the statistical service. The statistical service will record the time and number of events. This process will not use too much system resources as a large number of events are generated. It can quickly count various system and business events over a period of time on resource-constrained embedded devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 This is a schematic diagram of the steps of a method for counting system events and application events provided by this embodiment.

[0018] Figure 2This is a module connection diagram of a statistical system for system events and application events provided by this application. DETAILED DESCRIPTION

[0019] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments. However, it should be understood by those skilled in the art that the present application can be implemented without these details. In some cases, in order to avoid unnecessary descriptions that make various aspects of the present application obscure, the well-known methods, processes, systems, components and / or circuits that have been described at a higher level will not be described in detail. It is obvious to those skilled in the art that various changes can be made to the embodiments disclosed in the present application, and the general principles defined in the present application can be applied to other embodiments and application scenarios without departing from the principles and scope of the present application. Therefore, the present application is not limited to the embodiments shown, but conforms to the broadest scope consistent with the scope claimed for protection in the present application.

[0020] It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0021] In the description of this application, "several" means one or more, "many" means more than two, "greater than," "less than," and "exceed" are understood to exclude the number itself, while "above," "below," and "within" are understood to include the number itself. The use of "first" and "second" in the description is solely for the purpose of distinguishing technical features and should not be construed as indicating or implying relative importance, implicitly specifying the number of the indicated technical features, or implicitly specifying the order of the indicated technical features.

[0022] In the description of this application, reference to the terms "one embodiment," "some embodiments," "illustrative embodiments," "examples," "specific examples," or "some examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any combination in one or more embodiments or examples.

[0023] like Figure 1 As shown, the embodiment of the present application discloses a method for counting system events and application events, comprising the following steps: S100: Preset event character strings based on event definition rules and integrate them into an event list.

[0024] When an abnormality occurs in a normally operating embedded device, these abnormalities are known and can be predefined. Then, such known abnormalities can be classified and grouped by counting.

[0025] This application does not focus on unknown anomalies. Since the attributes of such anomalies are unknown, they cannot and do not need to be counted.

[0026] First, it is necessary to predefine various known events based on naming rules, so as to refine a type of event and assign an event string that can be read and judged by the system.

[0027] An event string consists of at least a main type segment, a sub-scenario segment, and a separator. The main type segment represents the overall category name of the event type, such as "network4g" for abnormal events related to the 4G network, while the sub-scenario segment represents the detailed event scenario name, such as "nosimcard" for the 4G network module not detecting a SIM card. The separator is located between the main type segment and the sub-scenario segment to separate the two different string components.

[0028] Through the above event definition rules, different events can be subdivided and defined based on type and scenario, generating event strings with the following event definition meanings: network4g.nosimcard - "The 4G network module did not detect the SIM card", network4g.signallow - "The 4G network module detected a low 4G signal (and thus could not register with the base station)", network4g.registerfail - "Registration with the 4G base station failed (possibly due to a locked SIM card)" For example, if there is an application on the device that reads ModBus data, then its main type segment is predefined as: "modbus", and its corresponding event strings may include: modbus.tty1openerror - "failed to open the first serial port", modbus.tty2openerror - "failed to open the second serial port", and modbus.tty3nodata - "no data can be read after the third serial port is opened".

[0029] Integrate several event strings to obtain an event list, which contains the event string names corresponding to various main types and sub-scenes.

[0030] The content of the configuration file of the event list is relatively concise. In the embodiment of the present application, it is organized in json format. The event list is used to statically determine which events should be recorded (events included in the event list) and which events do not need to be recorded (events not included in the event list) when subsequent event statistics are performed.

[0031] The event list does not contain the complete string of an event definition, but is stored by grouping and splicing. Specifically: { "events" : { "network4g" : [ "nosimcard", "signallow", "registerfail" ], "modbus" : [ "tty1openerror", "tty2openerror", "tty3nodata" ] } } Events are represented by events, with network4g and modbus both being main type segments. Each main type segment can be followed by a matching sub-scenario segment. This eliminates the need to store the entire string for each event when storing the event list. When a new event is added, only the string corresponding to the sub-scenario segment is stored. This facilitates adding and removing events from an embedded device, accelerating the development of business functions.

[0032] S200: Receive a local socket to collect event messages, and split the event messages to obtain a number of event substrings.

[0033] Receive event information sent by other applications and services, and split the received event information, so as to split the received complete event string into substrings that match the main type segment and sub-scene segment in the event string.

[0034] S300 , performing a first mapping on the event substring in the event list to obtain a matching main type segment, and performing a second mapping on the main type segment to obtain a matching sub-scene segment.

[0035] Map and compare several substrings of the received event to the main type segment and sub-scenario segment, and determine whether there are fields in the event list that match all of them successfully. If all of them match, the event is considered a known event and subsequent statistics are performed. However, if there is any mismatch during the matching, such as a mismatch in the first mapping, it is considered that there is no matching event type in the event list. If the first mapping matches but the second mapping does not match, it is considered that there is no event scenario subdivided under this type in the event list. In any case, the received event is characterized as an unknown event and is not counted.

[0036] Among them, as the data input interface of the event statistics service, it receives events generated by other services and applications through the "UNIX" local data message socket when receiving events. The socket is characterized by low system resource usage, automatic subpackaging, and high receiving efficiency, which is suitable for application scenarios with frequent initial launches.

[0037] S400 , after all mappings are matched, event statistics are performed to accumulate the number in corresponding statistical groups based on event message segments, wherein different statistical groups are distinguished based on statistical time periods.

[0038] Set up several statistical groups. The statistical groups are differentiated based on different statistical time periods. For example, events received within tens of minutes correspond to one statistical group, events received within several hours correspond to one statistical group, and events received within one day correspond to one statistical group.

[0039] When there is event information that is confirmed as a known event through mapping and matching, the number of the corresponding occurrence events is accumulated in the corresponding statistical group.

[0040] S500: Clear and / or record the counts in each statistical group based on the timer in each statistical group.

[0041] There is a timer in the module corresponding to event statistics. The timer is set to trigger once every 60 seconds. When triggered, the counts in each statistical group that meets the time requirements will be cleared and / or recorded. Clearing means deleting all statistical counts in the statistical group and returning them to zero. Recording means recording the numerical value of the current statistical counts in the statistical group.

[0042] Regularly clearing the counts in each statistical group prevents the occurrence of events in a statistical group from exceeding the corresponding statistical period. For example, if a statistical group counts events within ten minutes, without regular clearing, the group will contain events that occurred more than ten minutes ago, resulting in errors and exceptions in subsequent statistical queries. It also reduces memory usage and avoids the increased consumption of content resources due to excessive events.

[0043] S600: respond to the real-time data request and output current statistical information according to the time period requirement of the real-time data request.

[0044] The user uses the command line tool to enable the system module to output event statistics records within a period of time. The system module responds to real-time data requests and outputs the statistical information that currently meets the time period requirements.

[0045] Specifically, the command-line tool establishes a connection with the main event statistics module via a TCP socket to retrieve statistics for all current events. The output format is identical to the statistical data written to the file daily, corresponding at least to the event string and occurrence count for each event. This data can also include maintenance events for some events.

[0046] For example, the specific format is: network4g.nosimcard: 20; modbus.tty1openerror: 25.

[0047] In this way, operation and maintenance personnel who access the system can learn the count of known events that have occurred in the past tens of minutes, hours, or a day, which greatly facilitates understanding the operating status of embedded devices with limited system resources.

[0048] Through the above scheme, various known events are defined in the form of predefined strings; a local inter-process communication method and communication protocol are designed to quickly forward events generated by other services or applications to the statistical service. The statistical service will record the time and number of events. This process does not consume too much system resources as a large number of events are generated. It can quickly count various system and business events within a period of time on resource-constrained embedded devices.

[0049] After testing, on an embedded device with 128MB of memory, the event statistics method based on this application can achieve an event statistics effect of more than 1,000 events per second.

[0050] In some other embodiments, presetting event strings based on event definition rules and integrating them into an event list further includes the following steps: S110 , separating the main type segment and the sub-scene segment by a separator.

[0051] S120 , determining whether the event corresponding to the event character string is a periodic state, and adding a state prefix to the event character string based on the determination result. The state prefix is ​​used to distinguish between a continuous event and a one-time event.

[0052] A persistent event is characterized by the persistence of the data or service corresponding to an event. For example, "nosimcard" means that the 4G network module does not detect the SIM card, and this event is a persistent state of the device's 4G network. For example, registration behavior is a single operation attempt, and a failed registration corresponds to a failure event. For this type of event, it corresponds to a one-time event.

[0053] Because there should be certain differences in the way of counting the number of continuous events and one-time events, for example, a one-time event is recorded once each time it occurs, but for continuous events, it is necessary to consider information such as the triggering method, triggering frequency, and maintenance time of the event. Therefore, this application judges the specific type of an event based on whether it has a periodic state in time, and adds a status prefix to the event string based on the judgment result.

[0054] The function of the state prefix is ​​to distinguish the specific type of an event. In this application, the state prefix is ​​"@state". If the state prefix exists in the event string, it corresponds to a persistent event. If the state prefix does not exist, it corresponds to a one-time event.

[0055] For example, for the "4G network module does not detect a SIM card" event, the corresponding event string is network4g.nosimcard@state.

[0056] S130: Add an attribute segment to the event character string. The attribute segment is used to add context attribute content corresponding to the event. The attribute segment and the sub-scenario segment are separated by an attribute suffix.

[0057] In an embodiment of the present application, an attribute segment may be added to the event character string. The attribute segment represents additional context attributes corresponding to the event, which may be used to obtain a detailed scenario corresponding to the cause of an event based on attribute extraction.

[0058] The attribute segment contains the context attribute content corresponding to the event, which is mainly presented in the form of characters + numbers. At the same time, the attribute segment is at the end of the event string, and is separated from the sub-scene segment by an attribute suffix symbol. The attribute suffix symbol is "#" in the embodiment of this application.

[0059] For example, in an application that reads ModBus data on a device, if the first serial port fails to open and the attribute status of the event indicates that the serial port failed to open at a baud rate of 9600, this attribute can be contextually associated with the event string to generate an attribute segment of "baud9600" separated by "#". The final event string is: "modbus.tty1openerror#baud9600".

[0060] Through the above method, personalized customization of custom fields can be achieved. Different character definitions can be made for different data information based on usage scenarios, usage requirements, and usage accuracy. While counting the number of event occurrences, other attributes and types of events can be further reflected in the string. This does not affect the original technical logic, but can also add other additional content to the event. Subsequently, more detailed scenarios can be queried through filtering tools.

[0061] In other embodiments, the event definition rules may also include other personalized customization solutions. For example, when the event definition rules need to be iterated (such as interface changes, scenario upgrades), version numbers (such as V1, V2) can be added to the character string. The statistical service can not only count events of different versions separately, but also achieve summary statistics through fuzzy matching, which is compatible with the transition scenarios of old and new systems. For devices deployed in multiple regions, language identifiers (such as zh, en) can also be added to the event character string. Multiple language versions can be stored in the event list at the same time. When the statistical results are output, they automatically match the event character string of the corresponding language according to the region where the device is located, and output the event description in the corresponding language, thereby improving the usability of the operation and maintenance tool.

[0062] In other embodiments, format verification rules are configured in the event list, and the format of the event strings in the event list are regularly checked based on the format verification rules. If there are event strings that fail the format check, an abnormal alarm is generated and the corresponding event strings in the event list and the statistical group are marked.

[0063] The above custom rules are selected and configured based on actual scenarios. However, no matter which event definition method is used, it must match the standardization requirements. For example, each string must be a predefined module name, custom string names are not allowed, the total length of the event string must not exceed 64 characters, and excessively long strings must not occupy content.

[0064] If there is an event string that is not defined in a standard way, the system will generate an alarm to remind the operation and maintenance personnel to check whether there are any errors in the event definition rules. At the same time, the abnormal string in the event list will be marked, and the count value related to the abnormal string in the statistical group will also be marked to facilitate the operation and maintenance personnel to check.

[0065] In other embodiments, when the first mapping or the second mapping does not match, the event is defined as an unknown event and statistics of the unknown event are not collected.

[0066] If any mapping fails, the event corresponding to the event string is defined as an unknown event. Unknown events do not fall within the scope of the event statistics process to be performed in this application, so unknown events are not counted.

[0067] In other embodiments, the event message is a structure including an event string and a system startup time, and receiving a local socket to collect the event message and splitting the event message to obtain a plurality of event substrings includes the following steps: S210, synchronously obtaining the current system action time when splitting the event information.

[0068] When receiving events, the format of the obtained event information is also defined. In order to improve the efficiency of data parsing, instead of using JSON or other data serialization message format encapsulation, a simple structure is directly defined: struct event_message { char eventid

[128] ; time_t uptime; } Among them, the eventid in the structure is the event string of a certain event, such as "network4g.nosimcard",

[128] represents the character length of the event string, and "uptime" represents the system startup time that generated the event, in seconds.

[0069] S220: Calculate the difference between the current system action time and the system startup time in the event information, and discard the event information if the difference is greater than a preset value.

[0070] The system startup time is mainly used to prevent too much event information from being generated in a short period of time, causing the statistical service to process it in a timely manner and mistakenly taking the time generated a few minutes ago as the current time.

[0071] In other words, when receiving an event, not only the system time corresponding to the event generation time must be obtained, but also the current system time must be obtained and compared. If the difference with the "uptime" in a certain event information is too large (for example, three minutes), then the event will be discarded and not included in the statistical count.

[0072] Because different statistical groups have corresponding statistical cycle time requirements, if the time when an event occurs is obtained incorrectly, the target statistical group for the final count of the event will have a certain deviation, resulting in a certain impact on the accuracy of the final count number.

[0073] In other embodiments, after all mappings are matched, event statistics are performed to accumulate the number of events in corresponding statistical groups based on event message segments, including the following steps: S410, obtaining the statistical time periods corresponding to the statistical groups and arranging them in sequence.

[0074] Several statistical groups are arranged in sequence based on the length of the statistical time period corresponding to each statistical group. In this application, the arrangement is from short to long.

[0075] S420: For every event message that matches a mapping, the number of events in the statistical group with the shortest statistical time period is increased by one.

[0076] Whenever a known event is received, the number in the statistical group with the shortest statistical time period is increased by one, and statistical groups of other lengths are not counted.

[0077] S430: If the statistical time reaches the shortest statistical time period, the statistical quantity in the statistical group is added to a statistical group with a longer and adjacent statistical time period, and the statistical quantity in the current statistical group is cleared after the addition.

[0078] When the statistical time reaches the shortest statistical time period, for example, the statistical time period of statistical group A is 10 minutes, the number of events that occurred ten minutes before the current time will be counted in this statistical group. When the statistical time exceeds 10 minutes, the corresponding time of the newly received events will not match this statistical group A. In this case, the statistical quantity in statistical group A must be added to the next statistical group B with a longer statistical time period. For example, if the statistical time period of statistical group B is 1 hour, even if the statistical time exceeds 10 minutes, it still belongs to the time range corresponding to statistical group B.

[0079] At the same time, the statistics in statistics group A are cleared to start the next 10 minutes of event statistics, and the current event statistics are added to statistics group B every ten minutes.

[0080] Similarly, when the statistical time reaches one hour, the statistical quantity in statistical group B is added to statistical group C with a statistical time period of one day.

[0081] Through the above method, the incremental snapshot mechanism of the counter is realized. The accumulation of event values ​​only acts on one statistical group at a time, and an incremental recording function is provided. The data in the statistical group with a long statistical period is independently appended in batches at regular intervals by the statistical group with a short statistical period, avoiding abnormal deviations in the counting of all data caused by the loss of events at the moment of timer triggering, thereby improving statistical accuracy. At the same time, because the data increment of each statistical group is carried out independently, less memory is occupied on the embedded device.

[0082] In other embodiments, after all mappings are matched, event statistics are performed to accumulate the number of events in corresponding statistical groups based on event message segments, including the following steps: S440: Obtain the statistical time period corresponding to each statistical group.

[0083] S450: For every event message that matches the mapping, the number in all statistical groups is increased by one.

[0084] S460: When the statistical time reaches each statistical time period, the statistical quantity in the corresponding statistical group is cleared.

[0085] In the embodiment of the present application, in addition to the above-mentioned incremental snapshot mechanism, a synchronous incremental mechanism can also be adopted.

[0086] Under the synchronous increment mechanism, the event statistics service will synchronously perform multiple statistics on an event after monitoring an event information, that is, each event will increase the statistical count in multiple statistical groups.

[0087] For example, after event information is monitored, the count is synchronously incremented by one in statistical group A with a statistical period of ten minutes, statistical group B with a statistical period of one hour, and statistical group C with a statistical period of one day.

[0088] Under the synchronous increment mechanism, redundant counting of events can be achieved, so that when statistical anomalies occur in a statistical group, it will not affect the statistical accuracy of other statistical groups.

[0089] In some other embodiments, the statistical time period includes a minute system, an hour system, and a daily system, and clearing and / or recording the counts in each statistical group based on a timer in each statistical group includes the following steps: S510 , obtaining a statistical time period n in minute format and a statistical time period m in hour format, wherein n is less than 60 and m is greater than or equal to 60.

[0090] All times in the timer are in minutes. Therefore, different statistical groups in the embodiment of the present application are classified based on minute measurement, hour measurement, and day measurement. The overall statistical time for the statistical group with minute measurement is the shortest, less than 60 minutes. The overall statistical time for the statistical group with hour measurement is longer, exceeding 60 minutes. The statistical group with day measurement is generally in units of one day.

[0091] S520: The timer is triggered every time a preset time passes so that each statistical group performs a time condition comparison.

[0092] The main function of the timer is to determine whether the current statistical time meets the matching conditions of each statistical time period through regular triggering. For example, if you count the number of times an event occurs in the past 10 minutes, it needs to be reset every 10 minutes to start the statistical work of the next 10-minute period.

[0093] Therefore, the timer will trigger once within the trigger period (every 60 seconds) to compare the event conditions of each statistical group to determine whether the statistical values ​​in one or more statistical groups need to be cleared and / or recorded.

[0094] Specifically, Minute-based statistical groups: S530, obtaining the minute information of the current time, and determining whether the minute information can divide n evenly. If so, clearing all statistical quantities in the statistical group to zero.

[0095] For minute-based statistical groups, the statistical time will not exceed 1 hour, so the day and hour are always 0, so you only need to pay attention to the minute information.

[0096] The timer is triggered once every minute. As long as it is determined that the current minute information can divide n, it means that the statistical group has reached the time to be cleared. At this time, all current statistical quantities in the statistical group are cleared.

[0097] For example, if statistical group A counts the number of times an event occurs within ten minutes, then n=10. As long as the minute information of the current time can be divided by 10, it is represented as the current time being 10 or an integer multiple of 10. However, since the condition is met and the time is directly cleared when the minute information is 10, the minute information will not exceed 10 minutes.

[0098] Statistics group for hourly system: S540, calculate whether m / 60 is an integer.

[0099] S541, if yes, then obtain the minute information of the current time and determine whether it is zero. If it is zero, then obtain the hour information of the current time and determine whether it can be divided by m / 60. If it can, then clear all statistical quantities in the statistical group to zero.

[0100] S542, if not, obtain the minute information of the current time and determine whether the remainder can be divided evenly by m / 60. If so, obtain the hour information of the current time and determine whether the quotient can be divided evenly by m / 60. If so, clear all statistical quantities in the statistical group to zero.

[0101] For hourly statistical groups, the default unit of the timer is minutes, while the current time format is "hours, minutes, and seconds." Therefore, the two units are inconsistent. Therefore, it is necessary to first determine whether the statistical time period m corresponding to a statistical group is divisible by 60. If it is, it indicates that the corresponding statistical time period is an integer number of hours. If it is not, it indicates that the corresponding statistical time period is x hours and xx minutes.

[0102] For integer hours, you first need to determine whether the minute information of the current time is zero. If it is not equal to zero, it means that the current statistical time is not an hour and does not meet the requirements. In this case, there is no need to compare the hour information.

[0103] If it is equal to zero, it indicates that the current statistical time is an hour. Then, it is determined whether the time information of the current time can be divided by m / 60, that is, an integer hour. If it can, the statistical count in the statistical group is cleared.

[0104] If it's not equal to zero, the corresponding hours and minutes are determined based on m. When m is divided by 60, the quotient represents the hours, and the remainder represents the minutes. For example, if m is 150 minutes, the quotient is 2 and the remainder is 30, which corresponds to 2 hours and 30 minutes.

[0105] Therefore, we first determine whether the minute information of the current time can be divided evenly into the remainder after m / 60, and analyze whether the minute information of the current time matches the minute value corresponding to m. If they match, we compare the hour information to determine whether the hour information can be divided evenly into the quotient after m / 60 to compare whether the hour information matches the hour value corresponding to m.

[0106] If all match, all existing statistics counts in the statistics group will be cleared to zero.

[0107] For the statistics group of the day: S550, obtaining the minute information and hour information of the current time and determining whether both are 0, if so, recording all statistical quantities in the statistical group into a statistical file, and clearing the statistical quantities after recording.

[0108] The current representation is the number of all events counted in a day. It only needs to determine whether the hour information and minute information of the current time are both 0.

[0109] As for time information, while clearing the statistical quantity, it is also necessary to record all the currently counted data in the statistical file for storage. Furthermore, the system will regularly delete the record files before 15 days to reduce the storage content.

[0110] It should also be noted that when event statistics are just started, the counts of various events are zero, and memory will be allocated for each event. At the same time, after initialization, no content will be allocated when performing event statistics, because the consumption of content resources will not increase due to too many events.

[0111] In some other embodiments, when the event corresponding to the event string is in a periodic state, the following steps are further included: S121, obtaining the system startup time corresponding to the event character string and recording it, and stopping recording the system startup time when the event of the periodic state ends.

[0112] When an event corresponds to a persistent event, in order to facilitate operation and maintenance personnel to view and analyze the status information corresponding to the event, this application will count the number of events and the duration of the event.

[0113] For example, the "4G network module does not detect a SIM card" status is a persistent state of the 4G network. Therefore, how can we analyze the number of occurrences and duration of this event? The 4G network's dial-up service reads the 4G module status at regular intervals (for example, two minutes). If no SIM card is detected during a read, an event is generated.

[0114] S122 , integrating several system startup times corresponding to the event to form a duration and associating it with the event.

[0115] The number of times the event occurs is counted as the statistical number, and the system startup time corresponding to each event is obtained and recorded until the event ends to calculate the maintenance time.

[0116] After calculating the duration, associate it with the event. This allows users to generate the number of occurrences and duration of persistent events when querying them from the command line.

[0117] This application also discloses a statistical system for system events and application events, including: An event pre-definition module, configured to pre-define event strings based on event definition rules and integrate them into an event list, wherein the event strings include at least a main type segment, a sub-scene segment, and a separator; An event receiving module is used to receive a local socket to collect event messages and split the event messages to obtain several event substrings; Mapping the event substring in the event list for the first time to obtain the matching main type segment, and mapping it for the second time in the main type segment to obtain the matching sub-scene segment; An event statistics module is used to perform event statistics after all mappings are matched, so as to accumulate the number of events in corresponding statistical groups based on event message segments, wherein different statistical groups are distinguished based on the statistical time period; A timer, used for timing triggering to clear and / or record counts in a statistical group; The output module is used to respond to real-time data requests and output current statistical information according to the time period requirements of the real-time data requests.

[0118] The implementation principle is: Define various known events in the form of predefined strings; design a local inter-process communication method and communication protocol to quickly forward events generated by other services or applications to the statistical service. The statistical service will record the time and number of events. This process will not use too much system resources as a large number of events are generated. It can quickly count various system and business events over a period of time on resource-constrained embedded devices.

[0119] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps and they may be performed in other orders.

[0120] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.

Claims

1. A statistical method for system events and application events, characterized in that: The following steps are involved: Presetting event character strings based on event definition rules and integrating them into an event list, wherein the event character strings at least include a main type segment, a sub-scene segment, and a separator; receiving a local socket to collect event messages, and splitting the event messages to obtain a plurality of event substrings; Performing a first mapping on the event substring in the event list to obtain a matching main type segment, and performing a second mapping on the main type segment to obtain a matching sub-scene segment; After all mappings are matched, event statistics are performed to accumulate the number of events in corresponding statistical groups based on the event message segments, wherein different statistical groups are distinguished based on statistical time periods; clearing and / or recording the counts in the statistical groups based on the timers in the statistical groups; Respond to real-time data requests and output current statistical information according to the time period requirements of the real-time data requests.

2. The statistical method for system events and application events according to claim 1, characterized in that: Presetting event strings based on event definition rules and integrating them into an event list also includes the following steps: Separating the main type segment and the sub-scene segment by the separator; Determine whether the event corresponding to the event string is a periodic state, and add a state prefix to the event string based on the determination result, wherein the state prefix is ​​used to distinguish between a continuous event and a one-time event; An attribute segment is added to the event character string, wherein the attribute segment is used to add context attribute content corresponding to the event, and the attribute segment and the sub-scenario segment are separated by an attribute suffix.

3. The statistical method for system events and application events according to claim 2, characterized in that: Presetting event strings based on event definition rules and integrating them into an event list also includes the following steps: Format verification rules are configured in the event list, and format checks are performed on the event strings in the event list regularly based on the format verification rules. If the event strings fail the format check, an abnormal alarm is generated and the corresponding event strings and counts in the event list and the statistical group are marked.

4. The statistical method for system events and application events according to claim 1, characterized in that: When the first mapping or the second mapping does not match, the event is defined as an unknown event and statistics of the unknown event are not collected.

5. The method for counting system events and application events according to claim 2, characterized in that: The event message is a structure containing an event string and system startup time. The local socket is received to collect the event message, and the event message is split to obtain several event substrings, including the following steps: Synchronously obtaining the current system action time when splitting the event information; The difference between the current system action time and the system startup time in the event information is calculated, and the event information is discarded when the difference is greater than a preset value.

6. The method for counting system events and application events according to claim 1, characterized in that: After all mappings are matched, event statistics are performed to accumulate the number of event message segments in the corresponding statistical groups, including the following steps: Obtaining the statistical time periods corresponding to the statistical groups and arranging them in sequence; For each event message that has a mapping match, the number of the event message in the statistical group with the shortest statistical time period is increased by one; If the statistical time reaches the shortest statistical time period, the statistical quantity in the statistical group is added to the statistical group with a longer and adjacent statistical time period, and the statistical quantity in the current statistical group is cleared after the addition.

7. The method for counting system events and application events according to claim 1, characterized in that: After all mappings are matched, event statistics are performed to accumulate the number of event message segments in the corresponding statistical groups, including the following steps: Obtaining the statistical time period corresponding to each statistical group; For each event message that has a mapping match, the number of events in all statistical groups is increased by one; When the statistical time reaches each statistical time period, the statistical quantity in the corresponding statistical group is cleared.

8. The method for counting system events and application events according to claim 6 or 7, characterized in that: The statistical time period includes a minute system, an hour system, and a daily system, and clearing and / or recording the counts in the statistical group based on the timer in each statistical group includes the following steps: Obtain the statistical time period n in minute format, and obtain the statistical time period m in hour format, where n is less than 60 and m is greater than or equal to 60; The timer is triggered every time a preset time passes so that each statistical group performs a time condition comparison. Specifically, For the minute-based statistical group: Obtaining minute information of the current time, and determining whether the minute information can divide n, and if so, clearing all the statistical quantities in the statistical group to zero; For the statistical group of the hourly system: Calculate whether m / 60 is an integer; If yes, then obtain the minute information of the current time and determine whether it is zero; if it is zero, then obtain the hour information of the current time and determine whether it can be divided by m / 60; if so, then clear all the statistical quantities in the statistical group to zero; If not, obtain the minute information of the current time and determine whether the remainder can be divided evenly by m / 60; if so, obtain the hour information of the current time and determine whether the quotient can be divided evenly by m / 60; if so, clear all the statistical quantities in the statistical group; For the statistical group of the current day: Obtain the minute information and hour information of the current time and determine whether both are 0; if so, record all the statistical quantities in the statistical group into a statistical file, and clear the statistical quantities after recording.

9. The method for counting system events and application events according to claim 5, characterized in that: When the event corresponding to the event string is a periodic state, the following steps are also included: Obtaining and recording the system startup time corresponding to the event character string, and stopping recording the system startup time when the event in the periodic state ends; A plurality of the system startup events corresponding to the event are integrated to form a duration and associated with the event.

10. A statistical system for system events and application events, characterized in that: include: An event predefinition module, configured to predefine event character strings based on event definition rules and integrate them into an event list, wherein the event character strings at least include a main type segment, a sub-scene segment, and a separator; An event receiving module, configured to receive a local socket to collect event messages, and split the event messages to obtain a plurality of event substrings; The event substring is first mapped in the event list to obtain a matching main type segment, and a second mapping is performed in the main type segment to obtain a matching sub-scene segment. An event statistics module, configured to perform event statistics after all mappings are matched, so as to accumulate the number of event message segments in corresponding statistical groups, wherein different statistical groups are distinguished based on a statistical time period; A timer, configured to trigger at regular intervals to clear and / or record the counts in the statistical group; The output module is used to respond to real-time data requests and output current statistical information according to the time period requirements of the real-time data requests.

Citation Information

Patent Citations

  • Event detection method and system fusing hierarchical category information

    CN113468333A

  • Method and device for identifying alarm event type, equipment and storage medium

    CN115033688A

  • DTU remote monitoring method and system

    CN119001298A

  • Business data processing method and system, computer equipment and storage medium

    CN119166637A

  • Semantic deduplication of event logs

    US12093230B1