Alarm data processing method and device
By grouping and correlating alarm data, new alarm data containing positioning information is generated, which solves the operation and maintenance difficulties caused by a large amount of alarm data in the network system, and achieves rapid and accurate fault positioning and improved processing efficiency.
Patent Information
- Application Number
- CN202510729730.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-09-05
AI Technical Summary
In existing technologies, the large amount of alarm data in network systems makes it difficult for operation and maintenance personnel to quickly and accurately locate faults, increasing the pressure and complexity of operation and maintenance, affecting enterprise business operations and potentially causing economic losses.
By obtaining the alarm data to be processed, grouping them based on the value or range of the target correlation attribute, filtering out the alarm data that needs to be correlated and analyzed, and determining the location information through the time window and fault ratio threshold, new alarm data is generated and sent to the information notification platform.
It reduces the amount of alarm data received by operation and maintenance personnel, improves the accuracy of fault location and processing efficiency, helps operation and maintenance personnel quickly identify the source of the fault, and improves operation and maintenance work efficiency.
Smart Images

Figure CN120602300A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network management technology, and in particular to an alarm data processing method and device. Background Art
[0002] In today's digital age, with the continuous expansion of enterprise businesses and the rapid development of information technology, network systems are becoming increasingly large. With the increasing number of network devices in these systems, each of which runs different business systems, the amount of alarm data generated by various network devices and business systems is also increasing, increasing the actual operation and maintenance pressure and complexity.
[0003] Currently, many equipment manufacturers' built-in operations and maintenance management systems directly forward alarm data to operations and maintenance personnel. Due to the high volume of alarm data generated by numerous network devices, field maintenance personnel face a complex and chaotic flow of alarm data, making it difficult to quickly and accurately locate faults, which delays the development of solutions. They must analyze and troubleshoot alarm data individually, consuming significant time and effort and resulting in lengthy troubleshooting. This not only impacts normal business operations but can also lead to unnecessary financial losses and reputational damage due to prolonged business interruptions or instability.
[0004] Therefore, there is an urgent need for an alarm data processing method that can quickly locate the source of the fault. Summary of the Invention
[0005] The present application provides an alarm data processing method and device, which can reduce the number of alarms received by operation and maintenance personnel, help operation and maintenance personnel quickly and accurately locate the source of the fault, and improve the work efficiency of operation and maintenance personnel.
[0006] In a first aspect, a method for processing alarm data is provided, comprising:
[0007] Obtaining at least one first alarm data to be processed;
[0008] grouping the at least one first alarm data item based on a value of at least one target association attribute or at least one target range, where the target range specifies a range of values of the target association attribute, and the target association attribute is used to associate different alarm data items in terms of hardware, business system, or network;
[0009] Acquire at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window;
[0010] If the proportion of alarm data indicating a fault in the at least one piece of second alarm data exceeds a preset threshold, determining positioning information according to a target association attribute or a target range corresponding to the at least one piece of second alarm data;
[0011] Generate new alarm data based on positioning information;
[0012] Send new alarm data to the information notification platform.
[0013] In a feasible design, new alarm data is sent to the information notification platform, including:
[0014] Acquire at least one third alarm data in the same time window as the at least one second alarm data, where the type of each third alarm data is a recovery alarm;
[0015] For each piece of third alarm data, determining whether at least one piece of second alarm data includes source alarm data corresponding to the corresponding third alarm data;
[0016] If at least one piece of the second alarm data includes one or more pieces of source alarm data, deleting the one or more pieces of source alarm data and the corresponding third alarm data;
[0017] If the second alarm data indicating the fault associated with the new alarm data has not been completely deleted as the source alarm data, the new alarm data is sent to the information notification platform.
[0018] In a feasible design, determining the positioning information according to the target association attribute or target range corresponding to at least one piece of second alarm data includes:
[0019] Determine the name and value of the target-related attribute corresponding to at least one piece of second alarm data as positioning information, or,
[0020] Determine the name of the target association attribute and the target range as positioning information, or,
[0021] On the basis of the structure tree formed by each target association attribute, the name and value of the upper-layer association attribute of the target association attribute corresponding to at least one piece of second alarm data are determined as the positioning information.
[0022] In a feasible design, the types of target association attributes for associating different alarm data in the business system are: business module information, function information, service level information, service instance information, transaction information, service call information or configuration environment information.
[0023] In a feasible design, the type of target correlation attribute for correlating different alarm data in the network aspect includes any one of the following: network topology information, network session information, and network device information.
[0024] In a feasible design, the type of the target correlation attribute for correlating different alarm data in hardware includes any one of the following: device information and location information.
[0025] In one possible design, the method further includes:
[0026] If the at least one piece of second alarm data does not include source alarm data corresponding to any piece of third alarm data, at least one piece of third alarm data is sent to the information notification platform.
[0027] In one possible design, the method further includes:
[0028] If the second alarm data indicating the fault associated with the new alarm data are all deleted as source alarm data, the new alarm data is deleted.
[0029] In a feasible design, grouping the at least one first alarm data based on a value of at least one target-related attribute or at least one target range includes:
[0030] Filtering out first alarm data that meets the correlation analysis condition from at least one first alarm data;
[0031] At least one piece of first alarm data meeting the association analysis condition is grouped based on a value of at least one target association attribute or at least one target range.
[0032] In a second aspect, an alarm data processing device is provided, comprising:
[0033] An alarm data acquisition module, configured to acquire at least one first alarm data to be processed;
[0034] an alarm data association analysis module, configured to group at least one first alarm data item based on a value of at least one target association attribute or at least one target range, wherein the target range is used to define a range of values of the target association attribute, and the target association attribute is used to associate different alarm data items in terms of hardware, business system, or network;
[0035] The alarm data association analysis module is further configured to obtain at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window;
[0036] The alarm data association analysis module is further configured to determine positioning information based on a target association attribute or a target range corresponding to the at least one piece of second alarm data if a proportion of the alarm data indicating a fault in the at least one piece of second alarm data exceeds a preset threshold;
[0037] The alarm data association analysis module is also used to generate new alarm data based on the positioning information;
[0038] The alarm data transmission module is used to send new alarm data to the information notification platform.
[0039] In an embodiment of the present application, after obtaining at least one piece of first alarm data to be processed, the at least one piece of first alarm data is grouped based on the value of at least one target association attribute, or at least one target range for specifying the value of the target association attribute. Because the target association attribute is used to associate different alarm data with respect to hardware, business system, or network, different types of alarm data belonging to the same hardware, business system, or network can be grouped into the same group, thereby enabling correlation analysis of complex device relationships, business logic relationships, or network relationships between different types of alarm data.
[0040] For at least one second alarm data of the same group of non-recovery alarm type and in the same time window, determine whether the at least one second alarm data meets the generation conditions of new alarm data by determining whether the proportion of alarm data indicating faults in the at least one second alarm data exceeds a preset threshold. If it exceeds the preset threshold, it means that the fault of the network device, service or network to which the at least one second alarm data belongs is relatively serious and requires special attention from the operation and maintenance personnel. Therefore, the present application determines the positioning information based on the target association attribute or target range corresponding to the at least one second alarm data, and then generates new alarm data based on the positioning information, and sends the new alarm data to the information notification platform. It can be seen that the content of the new alarm data is a summary and induction based on the correlation analysis of the complex device relationships, business logic relationships or network relationships between various types of alarm data. The generation of new alarm data realizes the compression and merging of different types of alarm data based on device relationships, business logic relationships or network relationships, which greatly reduces the amount of alarm data sent to the information notification platform. Moreover, since the content of the new alarm data contains positioning information, the operation and maintenance personnel can quickly and accurately locate the source of the fault based on the positioning information after receiving the new alarm data, which is conducive to the rapid formulation of solutions and improves the efficiency of operation and maintenance personnel in handling serious faults. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0042] Figure 1 This is a schematic flow chart of an alarm data processing method provided by an exemplary embodiment of the present application;
[0043] Figure 2 This is a schematic flow chart of another alarm data processing method provided by an exemplary embodiment of the present application;
[0044] Figure 3This is a schematic diagram of an alarm data processing device provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0045] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0046] In order to quickly and accurately determine the location information of the fault corresponding to the alarm data, such as Figure 1 As shown, the present application provides an alarm data processing method, comprising:
[0047] S110: Obtain at least one piece of first alarm data to be processed.
[0048] Exemplarily, the alarm data processing method provided in this application is deployed on a network equipment monitoring platform.
[0049] S120: Group at least one piece of first alarm data based on a value of at least one target-related attribute or at least one target range.
[0050] The target range is used to define the value range of the target association attribute, and the target association attribute is used to associate different alarm data in terms of hardware, business system or network.
[0051] It should be noted that the association attributes in this application refer to the names and values of the association attributes of the alarm data. The target range is used to specify the value range of the target association attribute. Therefore, the target range includes the name of the target association attribute and the value range of the target association attribute.
[0052] In other words, the name and value of the target-related attribute are used as conditions for grouping alarm data, and the target range to which the name and value of the target-related attribute belong is also used as conditions for grouping alarm data. The first alarm data in the same group must have the same target-related attribute value, or the value of the target-related attribute is within the target range.
[0053] During the alarm data management process, not all alarm data requires correlation analysis. For example, low-level alarm data (such as prompts and information) generally does not require urgent processing or correlation analysis because they may not directly affect the normal operation of the system. Another example is alarm data manually triggered by users (such as test alarm data and simulation alarm data) that generally does not require correlation analysis because they are manually operated.
[0054] Furthermore, from the perspective of the scope of operation and maintenance work, operation and maintenance personnel may only need to manage and analyze alarm data for a target province or city, alarm data for a target network address, alarm data for a target name, or alarm data for a target monitored object, etc. Therefore, in a feasible design, at least one first alarm data item is grouped based on the value of at least one target-related attribute or at least one target range in the following manner:
[0055] Filtering out first alarm data that meets the correlation analysis condition from at least one first alarm data;
[0056] The at least one first alarm data is grouped based on a value of at least one target-related attribute or at least one target range.
[0057] Among them, the correlation analysis conditions can be set according to actual needs.
[0058] Illustratively, the association analysis conditions include one or more of the following conditions:
[0059] (1) The level of the alarm data is other than the low level, for example, the emergency level, the high level, and the medium level.
[0060] (2) The alarm data is not manually triggered by the user.
[0061] (3) The province or city to which the alarm data belongs is the target province or city.
[0062] (4) The network address of the alarm data is the target network address.
[0063] (5) The name of the alarm data is the target name.
[0064] (6) The monitoring object of the alarm data is the target monitoring object.
[0065] It should be understood that alarm data that does not meet the correlation analysis conditions can be sent to the information notification platform for operation and maintenance personnel to handle.
[0066] This application filters alarm data by setting correlation analysis conditions, which can screen out alarm data that requires subsequent correlation analysis in advance and improve the efficiency of alarm data processing.
[0067] In a feasible design, the types of target association attributes for associating different alarm data in the business system are: business module information, function information, service level information, service instance information, transaction information, service call information or configuration environment information.
[0068] For example, the name of the target association attribute of the business module information type is the business module name or the unique identifier of the business module, wherein the name of the business module is, for example, order system, payment system, user center, etc.
[0069] For example, the name of the target association attribute of the function information type is function type, wherein the function type is the type of a specific function of the business module, such as order placement, payment, logistics tracking, etc.
[0070] For example, the name of the target association attribute of the service level information type is the service level name, where the service level is the level of the business module in the business system, and the service level name is, for example, front-end service, back-end service, database service, etc.
[0071] Exemplarily, the name of the target association attribute of the service instance information type is the service instance identifier corresponding to the business module.
[0072] Exemplarily, the name of the target association attribute of the transaction information type is a unique identifier of the transaction.
[0073] Exemplarily, the target association attribute name of the service call information type is a unique identifier of the service call chain, a caller service name, or a callee service name.
[0074] Exemplarily, the target-associated attribute name of the configuration environment information type is a configuration file version used by the business system or an environment variable for the business system to run.
[0075] It should be noted that, in the business system, the name of the target correlation attribute for associating different alarm data may also be set according to actual needs.
[0076] The above examples are based on target association attributes of types such as business module information, function information, service level information, service instance information, transaction information, service call information, and configuration environment information. They can associate various alarm data belonging to the same business system to form the same group, or associate various alarm data belonging to the same business module, the same function type, the same service level, the same service instance, the same transaction, or the same service call chain of the same business system to form the same group, thereby realizing the analysis of the association relationship of complex business logic between alarm data, so that operation and maintenance personnel can quickly locate the source of the fault in the business system.
[0077] In a feasible design, the type of target correlation attribute for correlating different alarm data in the network aspect includes but is not limited to any one of the following: network topology information, network session information, or network device information.
[0078] Exemplarily, the name of the associated attribute of the network topology information type is the network address of the network node.
[0079] Exemplarily, the name of the associated attribute of the network session information type is a unique identifier of the network session or a port number used by the network session.
[0080] For example, the names of the associated attributes of the network device information type are the device type of the network device, the unique identifier of the network device, the name of the network device, the network address of the network device, the physical address of the network device, the number of the virtual local area network to which the network device belongs, or the subnet mask of the network device. A network device refers to a hardware device used to connect a computer network, such as a router or switch.
[0081] It should be noted that the name of the target correlation attribute for associating different alarm data in the network aspect can also be set according to actual needs.
[0082] The above examples are based on association attributes of types such as network topology information, network session information, and network device information. They can associate various alarm data belonging to the same network to form the same group, or associate various alarm data belonging to the same network node, the same network session, and the same network device in the same network to form the same group, thereby realizing the analysis of the association relationship between alarm data on the network, so that operation and maintenance personnel can quickly locate the network source of the fault.
[0083] In a feasible design, the type of target correlation attribute for correlating different alarm data in hardware includes but is not limited to any one of the following: device information or location information.
[0084] Exemplarily, the name of the associated attribute of the device information type is the unique identifier of the network device to which the alarm data belongs, the network device name, the network device type, the network device model, or the network device vendor.
[0085] Exemplarily, the name of the associated attribute of the location information type is the physical location, geographical location, rack number, or cabinet number of the network device to which the alarm data belongs.
[0086] It should be noted that the name of the target correlation attribute for correlating different alarm data in hardware can also be set according to actual needs.
[0087] By setting a target range, this application can associate alarm data from different network devices whose target association attribute values fall within the same range and group them together. For example, alarm data from rack numbers 001-010 are grouped together, indicating that these alarm data come from network devices in the same computer room.
[0088] The above examples are based on association attributes such as network device information and location information. They can associate the alarm data belonging to the same network device to classify them into the same group, or associate the alarm data of different network devices belonging to the same location range (different network devices in the same location range can constitute a network device set) to classify them into the same group, thereby realizing the analysis of the association relationship between the alarm data in the hardware or the space where the hardware is located, so that operation and maintenance personnel can quickly locate the faulty network device or network device set.
[0089] S130: Obtain at least one piece of second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window.
[0090] The time window is a preset length of time used to determine which alarms were generated at similar times. By setting a time window, you can filter out alarms that occurred within the same time window, allowing you to further analyze whether there are any correlations between these alarms. The time window setting can be adjusted based on actual needs to accommodate different application scenarios and alarm data processing requirements.
[0091] Common alarm data is classified according to content. The types of alarm data are:
[0092] Hardware alarms: such as power failure, fan failure, memory failure, etc.
[0093] Network alarms: such as network connection interruption, excessive bandwidth utilization, protocol anomalies, etc.
[0094] Software alarms: such as operating system failure, application failure, configuration file error, etc.
[0095] Performance alarms: such as high CPU utilization, high memory utilization, and frequent disk I / O operations.
[0096] Security alerts: such as intrusion detection alerts, virus alerts, and firewall rule triggering.
[0097] Recovery alarm: Triggered when the system or network device recovers from a faulty state to a normal state, such as a successful server restart or network connection recovery.
[0098] The type of the second alarm data is a type other than the recovery alarm.
[0099] S140: If the proportion of alarm data indicating faults in the at least one piece of second alarm data exceeds a preset threshold, determine positioning information according to a target association attribute or a target range corresponding to the at least one piece of second alarm data.
[0100] The preset threshold can be set according to actual needs, for example, it can be 30%.
[0101] Exemplarily, whether the alarm data indicates a fault is determined by identifying the name of the alarm data.
[0102] For example, if the name of an alarm data item includes words such as "fault," "interruption," "error," or "abnormal," the alarm data item is determined to be alarm data indicating a fault. The number of alarm data items indicating a fault and the total number of alarm data items are then counted to determine the proportion of alarm data items indicating a fault.
[0103] Exemplarily, the name and value of the target-related attribute corresponding to at least one piece of second alarm data are determined as the positioning information.
[0104] For example, the name of the target association attribute is the unique identifier of the business module, and the value is A. Then, the positioning information can be determined to be the business module identifier A.
[0105] Exemplarily, the name of the target-related attribute and the target range are determined as the positioning information.
[0106] For example, if the name of the target association attribute is rack number and the range is E to G, then the positioning information can be determined to be rack numbers E to G. Furthermore, the location of the computer room can be further located by using the stored association between the rack number and the computer room number.
[0107] The location information determined through the above example is relatively accurate, making it easier for operation and maintenance personnel to accurately locate the fault.
[0108] Exemplarily, based on a structure tree composed of each target-related attribute, the name and value of the upper-level related attribute of the target-related attribute corresponding to at least one piece of second alarm data are determined as the positioning information. In this structure tree, each related attribute corresponds to a node, and a node of an upper-level related attribute corresponds to one or more nodes of a lower-level related attribute.
[0109] In the structure tree composed of each target association attribute, if the target association attribute corresponding to the second alarm data has a parent node, the association attribute corresponding to the parent node is called the upper-layer association attribute. If the target association attribute corresponding to the second alarm data has a child node, the association attribute corresponding to the child node is called the lower-layer association attribute.
[0110] For example, business module A and business module B are both business modules of business system C. In the structure tree, the node corresponding to business module A and the node corresponding to business module B have the same association attribute as business system C. Therefore, the location information determined based on the alarm data with the target association attribute of business module A is business system C. The location information determined based on the alarm data with the target association attribute of business module B is also business system C. When operations personnel see that the location information of two new alarm data is both business system C, they can realize that there is a high probability that there is a problem with business system C.
[0111] Therefore, the location information determined through the above example can help operation and maintenance personnel understand the source of the fault from a macro perspective.
[0112] S150: Generate new alarm data according to the positioning information.
[0113] Exemplarily, determining new alarm data based on positioning information is achieved in the following manner:
[0114] Obtain a content template for generating new alarm data;
[0115] Use the location information to fill in the content template to obtain new alarm data.
[0116] For example, if the content template is "The health status of _ has seriously deteriorated" and the location information is "Network device A", then the location information is used to fill in the content template, and the new alarm data obtained is "The health status of network device A has seriously deteriorated".
[0117] As can be seen, the new alarm data is used to provide location information to operations and maintenance personnel when the faults reflected by the alarm data reach a certain level of severity, allowing them to quickly and accurately locate the source of the fault. This also significantly reduces the amount of alarm data received by operations and maintenance personnel, thus saving human resources.
[0118] Exemplarily, the method further includes:
[0119] If the proportion of alarm data indicating faults in the at least one piece of second alarm data does not exceed a preset threshold, the at least one piece of second alarm data is sent to the information notification platform.
[0120] In the above example, if the proportion of fault-indicating alarm data in at least one second alarm data item does not exceed the preset threshold, the probability of a fault is low. There is no need to generate new alarm data to specifically alert the operations and maintenance personnel; instead, the alarm data can be directly sent to the information notification platform. The operations and maintenance personnel can then choose a response plan for the at least one second alarm data item as needed.
[0121] S160: Send new alarm data to the information notification platform.
[0122] Exemplarily, the information notification platform may be a short message center, an email service center, or a work order processing center, which is used to send information to the terminal devices of the operation and maintenance personnel.
[0123] In a feasible design, new alarm data is sent to the information notification platform in the following way:
[0124] Acquire at least one third alarm data in the same time window as the at least one second alarm data, where the type of each third alarm data is a recovery alarm;
[0125] For each piece of third alarm data, determining whether at least one piece of second alarm data includes source alarm data corresponding to the corresponding third alarm data;
[0126] If at least one piece of the second alarm data includes one or more pieces of source alarm data, deleting the one or more pieces of source alarm data and the corresponding third alarm data;
[0127] If the second alarm data indicating the fault associated with the new alarm data has not been completely deleted as the source alarm data, the new alarm data is sent to the information notification platform.
[0128] Further illustratively, the remaining third alarm data is also sent to the information notification platform.
[0129] The source alarm data indicates that a problem has occurred, and the corresponding third alarm data of the recovery alarm type is used to indicate that the problem has been resolved.
[0130] In one possible design, the method further includes:
[0131] If the at least one piece of second alarm data does not include source alarm data corresponding to any piece of third alarm data, at least one piece of third alarm data is sent to the information notification platform.
[0132] In this case, new alarm data is still sent to the information notification platform.
[0133] Because the third alarm data of the recovery alarm type indicates that the corresponding issue has been resolved, after analyzing whether new alarm data can be generated, or after generating new alarm data, it is necessary to determine whether at least one second alarm data item contains the resolved source alarm data. If not, it means that the second alarm data within the time window is unrelated to any third alarm data item, and at least one third alarm data item is sufficient to send to the information notification platform.
[0134] If included, the source alarm data and the corresponding third alarm data must be deleted to avoid disrupting the operations and maintenance personnel's subsequent fault diagnosis and solution development. However, since the source alarm data may be the second alarm data associated with the new alarm data, to improve the accuracy of the new alarm data, it is necessary to further determine whether the second alarm data associated with the new alarm data has been deleted as the source alarm data. If not, the new alarm data must be sent to the information notification platform to draw the special attention of the operations and maintenance personnel.
[0135] It should be understood that if the proportion of alarm data indicating faults in at least one second alarm data does not exceed the preset threshold, the source alarm data and the corresponding third alarm data are deleted, and the remaining second alarm data and the remaining third alarm data are sent to the information notification platform.
[0136] In one possible design, the method further includes:
[0137] If the second alarm data indicating the fault associated with the new alarm data are all deleted as source alarm data, the new alarm data is deleted.
[0138] Further illustratively, the remaining third alarm data is sent to the information notification platform.
[0139] Considering that if all the secondary alarm data indicating a fault associated with the new alarm data is deleted, this means that the problem corresponding to the new alarm data has been completely resolved, and there is no need to notify the operation and maintenance personnel. Therefore, deleting the new alarm data can save human resources. It should be noted that although the generated new alarm data is deleted in this embodiment, the operation and maintenance personnel are not notified. However, since the generated new alarm data retains a generation record, the operation and maintenance personnel can use this record to fully understand the fault alarm status of the network equipment during regular maintenance.
[0140] On the contrary, if there is no need to view the generation record of new alarm data, in order to improve computing efficiency, you can first judge the source alarm data and then determine whether to generate new alarm data. Specifically, the following are included:
[0141] Obtaining at least one first alarm data to be processed;
[0142] grouping the at least one first alarm data item based on a value of at least one target association attribute or at least one target range, where the target range specifies a range of values of the target association attribute, and the target association attribute is used to associate different alarm data items in terms of hardware, business system, or network;
[0143] Acquire at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window;
[0144] Acquire at least one third alarm data in the same time window as the at least one second alarm data, where the type of each third alarm data is a recovery alarm;
[0145] For each piece of third alarm data, determining whether at least one piece of second alarm data includes source alarm data corresponding to the corresponding third alarm data;
[0146] If at least one piece of the second alarm data includes one or more pieces of source alarm data, deleting the one or more pieces of source alarm data and the corresponding third alarm data;
[0147] If, after deletion, the proportion of fault-indicating alarm data in at least one piece of second alarm data does not exceed a preset threshold, the remaining fault-indicating second alarm data and the remaining third alarm data are sent to the information notification platform. If all fault-indicating alarm data in at least one piece of second alarm data has been deleted, only the remaining third alarm data is sent to the information notification platform. It should be understood that if all third alarm data has been deleted, there is no need to send the alarm data to the information notification platform.
[0148] If, after deletion, the proportion of alarm data indicating faults in at least one piece of the second alarm data exceeds a preset threshold, the positioning information is determined based on the target association attribute or target range corresponding to the at least one piece of the second alarm data; new alarm data is generated based on the positioning information; and the new alarm data is sent to the information notification platform.
[0149] For other implementation methods and effects, please refer to S110-S150 and will not be repeated here.
[0150] In a feasible design, the above solution is implemented based on the Flink technology framework and deployed in the monitoring platform. Figure 2 This article introduces the alarm data processing method based on Flink technology.
[0151] S210: The Flink cluster receives at least one first alarm data sent by a network device.
[0152] S220: The Flink cluster uses Spring SPEL's expression matching technology to filter out first alarm data that meets the correlation analysis condition from at least one piece of first alarm data according to the correlation analysis condition.
[0153] At step S230 , the Flink cluster uses the Flink KeyBy function to group at least one first alarm data item that meets the association analysis criteria, using the values of each target-related attribute or each target range as a grouping condition. The first alarm data item in the same group is then sent to the same Flink association analysis task. Multiple Flink association analysis tasks can be performed simultaneously.
[0154] S240: In each Flink association analysis task, if the time window is not enabled, after receiving the first alarm data of the non-recovery alarm type, the time window is enabled, and the first alarm data is determined as the second alarm data, and the second alarm data is then stored in the first partition of the cache. During this time window, the first alarm data of the non-recovery alarm type is determined as the second alarm data and stored in the first partition of the cache; the first alarm data of the recovery alarm type is determined as the third alarm data, and the third alarm data is then stored in the second partition of the cache.
[0155] S250: After the time window ends, the Flink association analysis task determines whether the proportion of alarm data indicating faults in at least one piece of second alarm data in the first partition exceeds a preset threshold.
[0156] If it exceeds, the positioning information is determined according to the target association attribute or target range corresponding to the at least one second alarm data, and then new alarm data is generated according to the positioning information.
[0157] If not exceeded, determine not to generate new alarm data.
[0158] After the analysis is completed, obtain at least one third alarm data in the second partition that is in the same time window as at least one second alarm data, and the type of each third alarm data is a recovery alarm; for each third alarm data, determine whether at least one second alarm data contains source alarm data corresponding to the corresponding third alarm data.
[0159] If at least one piece of second alarm data does not include source alarm data corresponding to any piece of third alarm data, at least one piece of third alarm data is sent to the information notification platform. Furthermore, if no new alarm data is generated, at least one piece of second alarm data is also sent to the information notification platform; if new alarm data is generated, the new alarm data is also sent to the information notification platform, so that operation and maintenance personnel can quickly and accurately locate the source of the fault based on the new alarm data and view the corresponding second alarm data based on the source on the network equipment monitoring platform.
[0160] If at least one second alarm data contains one or more source alarm data, delete one or more source alarm data and the corresponding third alarm data; further, if no new alarm data is generated, send the remaining second alarm data in the first partition and the remaining third alarm data in the second partition to the information notification platform. If new alarm data is generated, further determine whether the second alarm data indicating the fault associated with the new alarm data has been deleted as the source alarm data. If the second alarm data indicating the fault associated with the new alarm data in the first partition has not been deleted as the source alarm data, that is, the second alarm data indicating the fault associated with the new alarm data still exists in the first partition, send the new alarm data and the remaining third alarm data in the second partition to the information notification platform. If the second alarm data indicating the fault associated with the new alarm data has been deleted as the source alarm data, delete the new alarm data and send the remaining third alarm data in the second partition to the information notification platform.
[0161] The above example uses the Flink technology framework to implement real-time processing of large-scale alarm data streams and can perform multiple correlation analysis tasks simultaneously, which helps improve the processing efficiency of large-scale alarm data.
[0162] In an embodiment of the present application, after obtaining at least one piece of first alarm data to be processed, the at least one piece of first alarm data is grouped based on the value of at least one target association attribute, or at least one target range for specifying the value of the target association attribute. Because the target association attribute is used to associate different alarm data with respect to hardware, business system, or network, different types of alarm data belonging to the same hardware, business system, or network can be grouped into the same group, thereby enabling correlation analysis of complex device relationships, business logic relationships, or network relationships between different types of alarm data.
[0163] For at least one second alarm data of the same group of non-recovery alarm type and in the same time window, determine whether the at least one second alarm data meets the generation conditions of new alarm data by determining whether the proportion of alarm data indicating faults in the at least one second alarm data exceeds a preset threshold. If it exceeds the preset threshold, it means that the fault of the network device, service or network to which the at least one second alarm data belongs is relatively serious and requires special attention from the operation and maintenance personnel. Therefore, the present application determines the positioning information based on the target association attribute or target range corresponding to the at least one second alarm data, and then generates new alarm data based on the positioning information, and sends the new alarm data to the information notification platform. It can be seen that the content of the new alarm data is a summary and induction based on the correlation analysis of the complex device relationships, business logic relationships or network relationships between various types of alarm data. The generation of new alarm data realizes the compression and merging of different types of alarm data based on device relationships, business logic relationships or network relationships, which greatly reduces the amount of alarm data sent to the information notification platform. Moreover, since the content of the new alarm data contains positioning information, the operation and maintenance personnel can quickly and accurately locate the source of the fault based on the positioning information after receiving the new alarm data, which is conducive to the rapid formulation of solutions and improves the efficiency of operation and maintenance personnel in handling serious faults.
[0164] like Figure 3 As shown, the present application also provides an alarm data processing device, comprising:
[0165] An alarm data acquisition module, configured to acquire at least one first alarm data to be processed;
[0166] an alarm data association analysis module, configured to group at least one first alarm data item based on a value of at least one target association attribute or at least one target range, wherein the target range is used to define a range of values of the target association attribute, and the target association attribute is used to associate different alarm data items in terms of hardware, business system, or network;
[0167] The alarm data association analysis module is further configured to obtain at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window;
[0168] The alarm data association analysis module is further configured to determine positioning information based on a target association attribute or a target range corresponding to the at least one piece of second alarm data if a proportion of the alarm data indicating a fault in the at least one piece of second alarm data exceeds a preset threshold;
[0169] The alarm data association analysis module is also used to generate new alarm data based on the positioning information;
[0170] The alarm data transmission module is used to send new alarm data to the information notification platform.
[0171] In a feasible design, the alarm data correlation analysis module is implemented in the following way to send new alarm data to the information notification platform:
[0172] Acquire at least one third alarm data in the same time window as the at least one second alarm data, where the type of each third alarm data is a recovery alarm;
[0173] For each piece of third alarm data, determining whether at least one piece of second alarm data includes source alarm data corresponding to the corresponding third alarm data;
[0174] If at least one piece of the second alarm data includes one or more pieces of source alarm data, deleting the one or more pieces of source alarm data and the corresponding third alarm data;
[0175] If the second alarm data indicating the fault associated with the new alarm data has not been completely deleted as the source alarm data, the new alarm data is sent to the information notification platform.
[0176] In a feasible design, the alarm data association analysis module is implemented in the following manner to determine the positioning information based on the target association attribute or target range corresponding to at least one piece of second alarm data:
[0177] Determine the name and value of the target-related attribute corresponding to at least one piece of second alarm data as positioning information, or,
[0178] Determine the name of the target association attribute and the target range as positioning information, or,
[0179] On the basis of the structure tree formed by each target association attribute, the name and value of the upper-layer association attribute of the target association attribute corresponding to at least one piece of second alarm data are determined as the positioning information.
[0180] In a feasible design, the types of target association attributes for associating different alarm data in the business system are: business module information, function information, service level information, service instance information, transaction information, service call information or configuration environment information.
[0181] In a feasible design, the type of target correlation attribute for correlating different alarm data in the network aspect includes any one of the following: network topology information, network session information, and network device information.
[0182] In a feasible design, the type of the target correlation attribute for correlating different alarm data in hardware includes any one of the following: device information and location information.
[0183] In a feasible design, the alarm data association analysis module is also used to:
[0184] If the at least one piece of second alarm data does not include source alarm data corresponding to any piece of third alarm data, at least one piece of third alarm data is sent to the information notification platform.
[0185] In a feasible design, the alarm data association analysis module is also used to:
[0186] If the second alarm data indicating the fault associated with the new alarm data are all deleted as source alarm data, the new alarm data is deleted.
[0187] In a feasible design, the alarm data association analysis module is further configured to group the at least one first alarm data based on the value of at least one target association attribute or at least one target range in the following manner:
[0188] Filtering out first alarm data that meets the correlation analysis condition from at least one first alarm data;
[0189] At least one piece of first alarm data meeting the association analysis condition is grouped based on a value of at least one target association attribute or at least one target range.
[0190] For other implementations and effects of the above-mentioned device, please refer to the description in the embodiment of the alarm data processing method, which will not be repeated here.
[0191] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this application are merely illustrative and not restrictive, and it should not be assumed that these advantages, strengths, and effects are required of each embodiment of this application. In addition, the specific details disclosed above are merely illustrative and facilitating understanding, and are not restrictive. The above details do not limit this application to necessarily being implemented using the above specific details.
[0192] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0193] The block diagrams of the devices, devices, equipment, and systems involved in this application are intended only as illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0194] It should also be noted that in the apparatus, device, and method of the present application, each component or each step can be decomposed and / or recombined, and such decomposition and / or recombination should be regarded as equivalent solutions of the present application.
[0195] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0196] The above description has been provided for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A method for processing alarm data, characterized in that: include: Obtaining at least one first alarm data to be processed; grouping the at least one first alarm data based on a value of at least one target association attribute or at least one target range, the target range being used to specify a range of values of the target association attribute, the target association attribute being used to associate different alarm data in terms of hardware, business system, or network; Acquire at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window; If the proportion of the alarm data indicating a fault in the at least one second alarm data exceeds a preset threshold, determining positioning information according to a target association attribute or a target range corresponding to the at least one second alarm data; generating new alarm data according to the positioning information; Send the new alarm data to the information notification platform.
2. The method according to claim 1, characterized in that The sending of the new alarm data to the information notification platform includes: Acquire at least one third alarm data in the same time window as the at least one second alarm data, where the type of each third alarm data is a recovery alarm; For each piece of the third alarm data, determining whether the at least one piece of the second alarm data includes source alarm data corresponding to the corresponding third alarm data; If the at least one second alarm data includes one or more source alarm data, deleting the one or more source alarm data and the corresponding third alarm data; If the second alarm data indicating the fault associated with the new alarm data has not been completely deleted as the source alarm data, the new alarm data is sent to the information notification platform.
3. The method according to claim 1 or 2, characterized in that The determining the positioning information according to the target association attribute or target range corresponding to the at least one piece of second alarm data includes: Determine the name and value of the target-related attribute corresponding to the at least one second alarm data as positioning information, or, Determine the name of the target association attribute and the target range as positioning information, or, On the basis of the structure tree formed by each target association attribute, the name and value of the upper-layer association attribute of the target association attribute corresponding to the at least one second alarm data are determined as the positioning information.
4. The method according to claim 1 or 2, characterized in that The types of target correlation attributes that correlate different alarm data in terms of business systems include: business module information, function information, service level information, service instance information, transaction information, service call information, or configuration environment information.
5. The method according to claim 1 or 2, characterized in that The types of target correlation attributes for correlating different alarm data in the network aspect include: network topology information, network session information, and network device information.
6. The method according to claim 1 or 2, characterized in that Types of target correlation attributes for correlating different alarm data in hardware include: device information and location information.
7. The method according to claim 2, characterized in that The method further comprises: If the at least one piece of second alarm data does not include source alarm data corresponding to any piece of third alarm data, the at least one piece of third alarm data is sent to the information notification platform.
8. The method according to claim 2, characterized in that The method further comprises: If the second alarm data indicating the fault associated with the new alarm data are all deleted as source alarm data, the new alarm data is deleted.
9. The method according to claim 1 or 2, characterized in that The grouping of the at least one first alarm data based on a value of at least one target association attribute or at least one target range includes: Filtering out first alarm data that meets the correlation analysis condition from the at least one first alarm data; At least one piece of first alarm data meeting the association analysis condition is grouped based on a value of at least one target association attribute or at least one target range.
10. An alarm data processing device, characterized in that: include: An alarm data acquisition module, configured to acquire at least one first alarm data to be processed; an alarm data association analysis module, configured to group the at least one first alarm data based on a value of at least one target association attribute or at least one target range, wherein the target range is used to define a range of values of the target association attribute, and the target association attribute is used to associate different alarm data in terms of hardware, business system, or network; The alarm data association analysis module is further configured to obtain at least one second alarm data of the same group, which is of the non-recovery alarm type and is in the same time window; The alarm data association analysis module is further configured to determine positioning information based on a target association attribute or a target range corresponding to the at least one second alarm data if a proportion of the alarm data indicating a fault in the at least one second alarm data exceeds a preset threshold; The alarm data association analysis module is further used to generate new alarm data according to the positioning information; The alarm data transmission module is used to send the new alarm data to the information notification platform.
Citation Information
Patent Citations
Alarm correlation analysis method and system for cloud center operation and maintenance
CN110493065A
Fault work order generation method, device and equipment
CN111814999A
Alarm processing method, device and equipment
CN115809262A
Cluster anomaly detection method and device, electronic equipment and storage medium
CN118170617A
Alarm correlation analysis method and device, electronic equipment and storage medium
CN118555187A