Cloud service anomaly detection method and device, monitoring server, storage medium and program product

By obtaining multi-dimensional service fusion data or anomaly retrieval information of cloud services and using preset anomaly detection models to perform anomaly detection, the problems of false detection and missed detection in cloud service monitoring are solved, and the accuracy of anomaly detection and the efficiency of operation and maintenance are improved.

CN120602303APending Publication Date: 2025-09-05CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510824115.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In existing technologies, abnormal monitoring of cloud services is prone to false detection or missed detection, making it difficult to detect potential problems in a timely manner, resulting in low operation and maintenance efficiency.

Method used

By obtaining multi-dimensional service fusion data or anomaly retrieval information of the target business server, anomaly detection is performed using a preset anomaly detection model, including a preset retrieval sub-model and a generation sub-model. Combined with a dynamic knowledge base and business impact analysis, anomaly detection information is generated and an alarm prompt message is output.

Benefits of technology

It achieves accurate and timely detection of cloud service anomalies, improves the accuracy and efficiency of operation and maintenance, and enables timely and targeted operation and maintenance processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602303A_ABST
    Figure CN120602303A_ABST
Patent Text Reader

Abstract

The invention relates to a cloud service anomaly detection method and device, a monitoring server, a storage medium and a program product. The method comprises the steps of inputting obtained target query information of a target service server into a preset anomaly detection model, determining anomaly detection information of the target service server according to output of the preset anomaly detection model, and outputting an alarm prompt message including the anomaly detection information and alarm prompt information; wherein the exception detection information is used for indicating a target exception condition existing in the target business server, a target exception reason corresponding to the target exception condition, business influence prediction corresponding to the target exception condition and a target maintenance suggestion. It can be seen that compared with a mode that operation and maintenance personnel inspect according to a fixed period in the related technology, the method can improve the accuracy of anomaly detection, and is also beneficial for improving the operation and maintenance accuracy and efficiency of the service server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing technology, and in particular to a cloud service anomaly detection method, device, monitoring server, storage medium, and program product. Background Art

[0002] Cloud services are a model for delivering computing resources (such as servers, storage, databases, and software) over the internet. Users can access and use these resources on demand to perform business operations. Monitoring and alerting for cloud services are crucial for ensuring business continuity and service quality.

[0003] In related technologies, operations and maintenance personnel conduct anomaly monitoring through regular inspections. However, related technologies are prone to false detection or missed detection, making it difficult to detect potential problems in a timely manner. Summary of the Invention

[0004] Based on this, it is necessary to provide an anomaly detection method, device, monitoring server, storage medium and program product that can improve the accuracy of anomaly detection in response to the above technical problems.

[0005] In a first aspect, the present application provides a cloud service anomaly detection method, which is applied to a monitoring server and includes:

[0006] Obtaining target query information of a target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormality retrieval information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multi-dimensional data of server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server;

[0007] Input the target query information into a preset anomaly detection model, and determine anomaly detection information of the target business server based on the output of the preset anomaly detection model; wherein the anomaly detection information is used to indicate the target anomaly condition existing in the target business server, the target anomaly cause corresponding to the target anomaly condition, the business impact prediction corresponding to the target anomaly condition, and the target maintenance suggestion;

[0008] Output alarm prompt message; wherein the alarm prompt message includes abnormality detection information and alarm prompt information.

[0009] In one embodiment, the preset anomaly detection model includes a preset retrieval sub-model and a preset generation sub-model. Target query information is input into the preset anomaly detection model, and anomaly detection information of the target business server is determined based on the output of the preset anomaly detection model, including:

[0010] Input the target query information into a preset retrieval sub-model, and determine the target historical anomaly detection information corresponding to the target query information in the dynamic knowledge base according to the output of the preset retrieval sub-model;

[0011] The target historical anomaly detection information is input into a preset generation sub-model, and the anomaly detection information of the target business server is determined according to the output of the preset generation sub-model.

[0012] In one embodiment, when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the target historical anomaly detection information is input into a preset generation sub-model, and the anomaly detection information of the target business server is determined based on the output of the preset generation sub-model, including:

[0013] The multi-dimensional service fusion data and the target historical anomaly detection information are input into a preset generation sub-model, and the anomaly detection information is determined according to the output of the preset generation sub-model.

[0014] In one embodiment, when the target query information includes multi-dimensional service fusion data corresponding to the target service server, obtaining the target query information of the target service server includes:

[0015] Acquire multidimensional original service data of the target business server from the target business server; perform data cleaning processing, data format processing and data fusion processing on the multidimensional original service data to obtain multidimensional service fusion data corresponding to the target business server.

[0016] In one embodiment, when the target query information includes abnormal search information corresponding to the target service server, obtaining the target query information of the target service server includes:

[0017] Receive abnormal search information sent by the first terminal device; wherein the abnormal search information is NLP search information, or preset custom view search information.

[0018] In one embodiment, outputting an alarm prompt message includes:

[0019] Determine a second terminal device corresponding to the target service server;

[0020] Send an alarm message to the second terminal device.

[0021] In a second aspect, the present application further provides a cloud service anomaly detection device, which is applied to a monitoring server and includes:

[0022] An acquisition module is configured to acquire target query information of a target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormality retrieval information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multi-dimensional data of server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server;

[0023] A detection module is configured to input target query information into a preset anomaly detection model and determine anomaly detection information of a target business server based on the output of the preset anomaly detection model; wherein the anomaly detection information is configured to indicate a target anomaly condition existing in the target business server, a target anomaly cause corresponding to the target anomaly condition, a predicted business impact corresponding to the target anomaly condition, and a target maintenance recommendation;

[0024] The output module is used to output alarm prompt messages; wherein the alarm prompt messages include abnormality detection information and alarm prompt information.

[0025] In a third aspect, the present application further provides a monitoring server comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method of any embodiment of the first aspect when executing the computer program.

[0026] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the method of any embodiment of the first aspect when the computer program is executed by a processor.

[0027] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which implements the steps of the method of any embodiment of the first aspect when the computer program is executed by a processor.

[0028] The above-mentioned cloud service anomaly detection method, device, monitoring server, storage medium and program product, by inputting the target query information of the target business server into a preset anomaly detection model, determines the anomaly detection information of the target business server according to the output of the preset anomaly detection model, and outputs an alarm prompt message including the anomaly detection information and an alarm prompt information; wherein the anomaly detection information is used to indicate the target anomaly situation existing in the target business server, the target anomaly cause corresponding to the target anomaly situation, the business impact prediction corresponding to the target anomaly situation, and the target maintenance suggestion. It can be seen that compared with the related art operation and maintenance personnel according to the fixed periodic inspection method, the embodiment of the present application obtains the anomaly detection information of the target business server by performing anomaly detection based on the acquired target query information and the preset anomaly detection model, which can detect the anomaly detection information of the target business server more accurately and timely, thereby improving the accuracy of anomaly detection. Furthermore, by outputting an alarm prompt message based on the anomaly detection information, the operation and maintenance personnel can timely perform targeted operation and maintenance processing on the target business server according to the alarm prompt information, which is conducive to improving the operation and maintenance accuracy and efficiency of the business server. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 1 is a flowchart of a method for detecting anomalies in a cloud service according to an embodiment;

[0031] Figure 2 1 is a flow chart of a method for determining abnormality detection information of a target business server in one embodiment;

[0032] Figure 3 A flowchart of a method for outputting an alarm prompt message in one embodiment is shown;

[0033] Figure 4 A flowchart of a method for detecting anomalies in a cloud service according to another embodiment;

[0034] Figure 5 A flowchart of a method for detecting anomalies in a cloud service according to another embodiment;

[0035] Figure 6 A schematic diagram of the architecture of an anomaly detection system for a cloud service in one embodiment;

[0036] Figure 7 A schematic diagram of an anomaly detection process for a cloud service in one embodiment;

[0037] Figure 8 A schematic diagram of an anomaly detection process for a cloud service in another embodiment;

[0038] Figure 9 A schematic diagram of the structure of an anomaly detection device for a cloud service in one embodiment;

[0039] Figure 10 FIG. 1 is a schematic diagram of the structure of a monitoring server in an embodiment. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0041] With the widespread application of cloud computing services, cloud service monitoring and alarming have become key links in ensuring business continuity and service quality.

[0042] In related technologies, operations and maintenance personnel conduct anomaly monitoring through regular inspections. However, related technologies are prone to false detection or missed detection, making it difficult to detect potential problems in a timely manner.

[0043] To address the above technical issues, the present application proposes a method for obtaining anomaly detection information of a target business server by performing anomaly detection based on acquired target query information and a preset anomaly detection model. This method can more accurately and timely detect anomaly detection information of the target business server, thereby improving the accuracy of anomaly detection. Furthermore, by outputting an alarm prompt message based on the anomaly detection information, operation and maintenance personnel can promptly perform targeted operation and maintenance processing on the target business server based on the alarm prompt information, which is conducive to improving the accuracy and efficiency of the operation and maintenance of the business server.

[0044] For example, any server involved in the embodiments of the present application (for example, a monitoring server, or a business server, etc.) can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0045] For example, any terminal device involved in the embodiments of this application (e.g., the first terminal device or the second terminal device) may be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart TVs, smart car devices, and projection devices. Portable wearable devices may include smart watches, smart bracelets, head-mounted devices, and the like. Head-mounted devices may include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, and the like.

[0046] In an exemplary embodiment, Figure 1 FIG. 1 is a flow chart of an abnormality detection method for cloud services in an embodiment. The embodiment of the present application takes the application of the method to a monitoring server as an example for explanation. Figure 1 As shown, the cloud service anomaly detection method of the embodiment of the present application may include the following steps:

[0047] Step S101, obtain target query information of the target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormal retrieval information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multiple data including server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server.

[0048] Exemplarily, the multi-dimensional service fusion data in the embodiment of the present application may be fusion data calculated based on multi-dimensional data (belonging to multi-source heterogeneous data) such as server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server.

[0049] The server performance indicator can be used to indicate the performance indicators of the target service server. For example, the server performance indicator may include, but is not limited to, at least one of the following: computing performance, memory performance, network performance, application programming interface (API) response time, and database access performance. Computing performance may include, but is not limited to, CPU performance, and network performance may include, but is not limited to, network latency performance.

[0050] The business indicator data may be used to indicate business indicators involved in the business processing of the target business server. For example, the business indicator data may include but is not limited to a business logic error rate.

[0051] The user behavior indicator data may be used to indicate user behavior indicators involved in the target service server's service processing. For example, the user behavior indicator data may include but is not limited to the number of times an API is requested.

[0052] For example, the abnormality search information in the embodiments of the present application can be used to indicate abnormality prompt information of the target business server that the user needs to search. For example, the abnormality search information may include, but is not limited to, any of the following: whether business server A has abnormality a, whether abnormality b in business server B will affect user satisfaction, and whether there is a business server C whose configuration changes may cause increased response time.

[0053] In this step, the monitoring server may obtain target query information of the target service server to be detected, wherein the target query information may include but is not limited to multi-dimensional service fusion data corresponding to the target service server, or abnormality search information corresponding to the target service server.

[0054] Exemplarily, the monitoring server may obtain target query information of the target business server from the database or target business server at preset time intervals, or when an abnormal detection instruction is detected, or may obtain the target query information after performing data processing based on the initial query information of the target business server obtained from the database or target business server (for example, multi-dimensional original service data, etc.).

[0055] In another exemplary embodiment, the monitoring server may receive target query information of a target service server sent by the terminal device.

[0056] For ease of understanding, the following embodiments of this application take the target query information including the multi-dimensional service fusion data corresponding to the target business server, or the abnormal retrieval information corresponding to the target business server as an example to further introduce and explain the relevant content of the method of obtaining the target query information of the target business server.

[0057] In one possible implementation, when the target query information includes multidimensional service fusion data corresponding to the target business server, the multidimensional original service data of the target business server is obtained from the target business server; the multidimensional original service data is subjected to data cleaning processing, data format processing and data fusion processing to obtain the multidimensional service fusion data corresponding to the target business server.

[0058] Illustratively, the multi-dimensional original service data in the embodiments of the present application may include, but is not limited to, at least two-dimensional data: server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server.

[0059] In this implementation, the monitoring server can obtain the target service server's multi-dimensional raw service data from the target service server and perform data cleansing on the multi-dimensional raw service data to obtain cleansed multi-dimensional raw service data. The data cleansing process can include, but is not limited to, at least one of the following: missing value processing, deduplication, abnormal data processing, and data type conversion.

[0060] For example, the monitoring server can perform data cleaning processing by utilizing message queues such as distributed stream processing platforms (such as Kafka) or distributed publish-subscribe messaging systems (such as Pulsar), which is beneficial to improving the real-time performance and reliability of data stream processing.

[0061] Furthermore, the monitoring server performs data format processing on the cleaned multi-dimensional original service data to obtain the format-processed multi-dimensional original service data, wherein the data format processing is used to unify the data format.

[0062] For example, the monitoring server may perform data format processing by utilizing a message queue method such as a distributed stream processing platform or a distributed publish-subscribe message system, which is beneficial to improving the real-time performance and reliability of data stream processing.

[0063] Furthermore, the monitoring server performs data fusion processing on the formatted multi-dimensional raw service data to obtain multi-dimensional service fusion data corresponding to the target business server. Data fusion processing can be used to integrate data from different sources, formats, and structures into unified and usable fused data. Exemplarily, data fusion processing may include, but is not limited to, time series analysis and / or association rule mining to extract key performance indicators (KPIs) that have a direct impact on the business.

[0064] For example, the monitoring server can perform data fusion processing by utilizing a real-time computing framework (such as Spark Streaming, etc.), which is beneficial to improving the real-time performance and reliability of data stream processing.

[0065] It should be understood that the target service server can collect multi-dimensional raw service data of the target service server by using a distributed tracing system (e.g., Jaeger) and / or API integration, so as to comprehensively and real-timely collect various types of service data. Of course, the target service server can also collect multi-dimensional raw service data of the target service server by other means.

[0066] In this implementation, by obtaining the multidimensional original service data of the target business server from the target business server, and performing data cleaning processing, data format processing and data fusion processing on the multidimensional original service data, the multidimensional service fusion data corresponding to the target business server is obtained. This method can not only compress the amount of data subsequently input into the preset anomaly detection model to improve the detection efficiency of the preset anomaly detection model, but also realize the fusion processing of the multidimensional service data to obtain the multidimensional service fusion data, so that more accurate and timely anomaly detection can be performed based on the multidimensional service fusion data.

[0067] In another possible implementation, when the target query information includes exception retrieval information corresponding to the target business server, the exception retrieval information sent by the first terminal device is received; wherein the exception retrieval information is natural language processing (NLP) retrieval information, or preset custom view retrieval information.

[0068] In this implementation, the monitoring server may receive the abnormal search information sent by the first terminal device; wherein the abnormal search information may be used to indicate abnormal prompt information of the target service server that the user needs to retrieve.

[0069] Exemplarily, the abnormal search information may be NLP abnormal search information input by the user to the first terminal device through an NLP query method.

[0070] In another exemplary embodiment, the abnormality search information may be preset custom view abnormality search information input by the user to the first terminal device through a preset custom view query method.

[0071] Of course, the monitoring server can also obtain the target query information of the target business server through other methods.

[0072] Step S102: Input the target query information into a preset anomaly detection model, and determine the anomaly detection information of the target business server based on the output of the preset anomaly detection model; wherein the anomaly detection information is used to indicate the target anomaly condition existing in the target business server, the target anomaly cause corresponding to the target anomaly condition, the business impact prediction corresponding to the target anomaly condition, and the target maintenance suggestion.

[0073] The preset anomaly detection model in the embodiment of the present application may be a detection model trained based on target query sample information and corresponding anomaly detection sample information of multiple groups of business servers.

[0074] In recent years, with the development of artificial intelligence (AI), particularly natural language processing (NLP) and machine learning (ML), the industry has begun exploring more intelligent surveillance solutions. Retrieval-Augmented Generation (RAG) models, a representative of the next generation of AI technologies, combine the capabilities of information retrieval and text generation. When processing large amounts of data, they can not only retrieve relevant historical records and documents but also generate contextually appropriate explanations and recommendations.

[0075] Exemplarily, the preset anomaly detection model in the embodiments of the present application may include but is not limited to a RAG model.

[0076] In this step, the monitoring server may input the target query information of the target business server obtained in step S101 into a preset anomaly detection model and determine anomaly detection information of the target business server based on the output of the preset anomaly detection model. The preset anomaly detection model may be used to perform anomaly detection based on the target query information of the target business server in combination with business logic and business impact, thereby outputting corresponding anomaly detection information (including business impact predictions and targeted maintenance recommendations).

[0077] It should be noted that the preset anomaly detection model of the embodiment of the present application can be combined with business logic and business impact to perform deep mining, correlation analysis and anomaly screening on cross-source data to quickly locate deep anomaly detection information.

[0078] For example, the anomaly detection information in the embodiments of the present application can be used to indicate a target anomaly condition existing in a target service server, a target anomaly cause corresponding to the target anomaly condition, a predicted business impact corresponding to the target anomaly condition (i.e., a predicted business issue that may be affected), and a target repair recommendation. Of course, the anomaly detection information can also be used to indicate other anomaly information about the target service server.

[0079] In a possible implementation, the monitoring server may input the target query information of the target business server into a preset anomaly detection model, and thereby obtain the anomaly detection information of the target business server output by the preset anomaly detection model.

[0080] For example, when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the monitoring server can obtain the anomaly detection information of the target business server output by the preset anomaly detection model by inputting the multi-dimensional service fusion data of the target business server into the preset anomaly detection model.

[0081] As another example, when the target query information includes abnormality retrieval information corresponding to the target business server, the monitoring server can obtain the abnormality detection information of the target business server output by the preset abnormality detection model by inputting the abnormality retrieval information corresponding to the target business server into the preset abnormality detection model.

[0082] In another possible implementation, the preset anomaly detection model includes a preset retrieval sub-model and a preset generation sub-model. The monitoring server can obtain the anomaly detection information of the target business server output by the preset anomaly detection model by inputting the target query information of the target business server into the preset retrieval sub-model and / or the preset generation sub-model in the preset anomaly detection model.

[0083] Step S103: output an alarm prompt message; wherein the alarm prompt message includes abnormality detection information and alarm prompt information.

[0084] In this step, the monitoring server may output an alarm prompt message based on the abnormality detection information of the target business server; wherein, the alarm prompt message may include but is not limited to abnormality detection information and alarm prompt information, so that the operation and maintenance personnel can perform targeted operation and maintenance processing on the target business server in a timely manner according to the alarm prompt information, which is conducive to improving the operation and maintenance accuracy and efficiency of the business server.

[0085] Exemplarily, the warning prompt information may include but is not limited to at least one of the following: sound warning prompt information, text warning prompt information, and image warning prompt information.

[0086] In summary, in the embodiment of the present application, the target query information of the target business server is input into the preset anomaly detection model, the anomaly detection information of the target business server is determined according to the output of the preset anomaly detection model, and an alarm prompt message including the anomaly detection information and the alarm prompt information is output; wherein the anomaly detection information is used to indicate the target anomaly situation of the target business server, the target anomaly cause corresponding to the target anomaly situation, the business impact prediction corresponding to the target anomaly situation, and the target maintenance suggestion. It can be seen that compared with the operation and maintenance personnel in the related art who conduct an inspection according to a fixed period, the embodiment of the present application obtains the anomaly detection information of the target business server by performing anomaly detection based on the acquired target query information and the preset anomaly detection model. This can detect the anomaly detection information of the target business server more accurately and timely, thereby improving the accuracy of anomaly detection. Further, by outputting an alarm prompt message according to the anomaly detection information, the operation and maintenance personnel can perform targeted operation and maintenance processing on the target business server in a timely manner according to the alarm prompt information, which is conducive to improving the accuracy and efficiency of the operation and maintenance of the business server.

[0087] In an exemplary embodiment, Figure 2 This is a flow chart of a method for determining abnormality detection information of a target business server in one embodiment. In this embodiment of the application, the relevant content of "inputting the target query information into a preset abnormality detection model, and determining the abnormality detection information of the target business server according to the output of the preset abnormality detection model" in the above step S102 is further introduced and explained. For example, the preset abnormality detection model in the embodiment of the application may include but is not limited to a preset retrieval sub-model and a preset generation sub-model. Figure 2 As shown, the method of the embodiment of the present application may include the following steps:

[0088] Step S1021: Input the target query information into a preset retrieval sub-model, and determine the target historical anomaly detection information corresponding to the target query information in the dynamic knowledge base according to the output of the preset retrieval sub-model.

[0089] The preset retrieval sub-model in the embodiments of the present application can be used to perform semantic similarity matching between the target query information and the historical anomaly detection information set in the dynamic knowledge base to quickly locate the target historical anomaly detection information related to the target query information. Exemplarily, the preset retrieval sub-model can include, but is not limited to, a Bidirectional Encoder Representations from Transformers (BERT) model.

[0090] The dynamic knowledge base in the embodiments of the present application includes multiple historical anomaly detection information corresponding to different business servers. Any historical anomaly detection information can be used to indicate historical anomaly conditions, historical anomaly causes corresponding to these anomaly conditions, and historical repair recommendations. Of course, historical anomaly detection information can also be used to indicate other historical anomaly information (such as links to technical documents corresponding to the historical anomaly detection information).

[0091] In this step, the monitoring server can input the target query information into a preset retrieval sub-model, and determine the target historical anomaly detection information corresponding to the target query information in the dynamic knowledge base according to the output of the preset retrieval sub-model.

[0092] For example, the target history anomaly detection information in the embodiment of the present application can be used to indicate the target history anomaly situation, the target history anomaly cause corresponding to the target history anomaly situation, and the target history maintenance suggestion.

[0093] It should be understood that the preset retrieval sub-model can be helpful in early warning performance bottlenecks and failure trends by searching based on a dynamic knowledge base to determine the target historical anomaly detection information, so as to promote the transformation of operation and maintenance to a preventive strategy.

[0094] Step S1022: Input the target historical anomaly detection information into the preset generation sub-model, and determine the anomaly detection information of the target business server according to the output of the preset generation sub-model.

[0095] The preset generation sub-model in the embodiment of the present application can be used to perform detection and analysis based on the target historical anomaly detection information combined with business impact, etc. to generate corresponding anomaly detection information. Exemplarily, the preset generation sub-model can include but is not limited to sequence models such as Transformer network models.

[0096] In this step, the monitoring server may input the target historical anomaly detection information into a preset generation sub-model, and may determine the anomaly detection information of the target business server according to the output of the preset generation sub-model.

[0097] Illustratively, the anomaly detection information of the target business server in the embodiment of the present application may be in the form of an anomaly detection report; of course, it may also be in other forms.

[0098] It's important to note that when generating anomaly detection information for target business servers, the pre-defined generation sub-model not only incorporates business impact analysis (for example, predicting the potential for decreased customer satisfaction or resource loss caused by an anomaly), but also provides technical explanations for the anomaly. Furthermore, the pre-defined generation sub-model's generation logic is more flexible, allowing it to adjust the structure and content of anomaly detection information based on business context, thereby enhancing the relevance of recommendations.

[0099] In an exemplary embodiment, when the target query information includes multidimensional service fusion data corresponding to the target business server, the monitoring server can input the multidimensional service fusion data and the target historical anomaly detection information into a preset generation sub-model, and determine the anomaly detection information based on the output of the preset generation sub-model.

[0100] In an embodiment of the present application, the monitoring server inputs the multi-dimensional service fusion data and the target historical anomaly detection information into the preset generation sub-model, so that the preset generation sub-model can further combine the multi-dimensional service fusion data corresponding to the target business server during the detection and analysis process, thereby facilitating the preset generation sub-model to output more accurate anomaly detection information of the target business server.

[0101] In an exemplary embodiment, the monitoring server may input an anomaly detection scenario and target historical anomaly detection information into a preset generation sub-model and determine anomaly detection information based on the output of the preset generation sub-model. The anomaly detection scenario indicates the content and format of the generated anomaly detection information. Exemplarily, the anomaly detection scenario may be a preset detection scenario or a detection scenario transmitted by the receiving first terminal device.

[0102] In an embodiment of the present application, by inputting the anomaly detection scenario and the target historical anomaly detection information into a preset generation sub-model, and determining the method of anomaly detection information according to the output of the preset generation sub-model, the preset generation sub-model can further combine the anomaly detection scenario during the detection and analysis process, so that the content and form of the anomaly detection information can be adaptively adjusted according to different user roles and detection requirements, thereby realizing personalized and adaptive generation of anomaly detection information, which is conducive to improving the efficiency of users' understanding of anomaly detection information.

[0103] It should be understood that when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the monitoring server can also input the anomaly detection scenario, multi-dimensional service fusion data and target historical anomaly detection information into the preset generation sub-model, and determine the anomaly detection information based on the output of the preset generation sub-model.

[0104] In summary, in the embodiments of the present application, the target historical anomaly detection information corresponding to the target query information can be located based on the preset retrieval sub-model, and the method of determining the anomaly detection information based on the preset generation sub-model according to the target historical anomaly detection information can refer to the relevant target historical anomaly detection information to generate anomaly detection information, which is not only conducive to improving the accuracy of the anomaly detection information of the target business server, but also conducive to warning performance bottlenecks and failure trends, so as to promote the transformation of operation and maintenance to a preventive strategy.

[0105] In an exemplary embodiment, Figure 3 FIG. 1 is a flow chart of a method for outputting an alarm prompt message in an embodiment. In the embodiment of the present application, the relevant contents of “outputting an alarm prompt message” in the above step S103 are further introduced and explained. Figure 3 As shown, the method of the embodiment of the present application may include the following steps:

[0106] Step S1031: Determine the second terminal device corresponding to the target service server.

[0107] In this step, the monitoring server may determine the second terminal device corresponding to the target service server in order to send an alarm prompt message.

[0108] In one possible implementation, when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the monitoring server can query the correspondence between the preset business server identifier and the operation and maintenance terminal device identifier based on the identifier of the target business server, determine the target operation and maintenance terminal device identifier corresponding to the identifier of the target business server, and determine the second terminal device based on the target operation and maintenance terminal device identifier. The correspondence between the preset business server identifier and the operation and maintenance terminal device identifier is used to indicate the correspondence between different business server identifiers and the corresponding operation and maintenance terminal device identifiers.

[0109] In another possible implementation, when the target query information includes abnormality retrieval information corresponding to the target service server, the monitoring server may use the first terminal device that sends the abnormality retrieval information as the second terminal device.

[0110] Furthermore, the monitoring server can also query the correspondence between the preset business server identifier and the operation and maintenance terminal device identifier based on the identifier of the target business server, determine the target operation and maintenance terminal device identifier corresponding to the identifier of the target business server, and determine the second terminal device based on the target operation and maintenance terminal device identifier.

[0111] Of course, the monitoring server may also determine the second terminal device corresponding to the target service server in other ways.

[0112] Step S1032: Send an alarm prompt message to the second terminal device.

[0113] In this step, the monitoring server can send an alarm prompt message to the second terminal device so that the operation and maintenance personnel can perform targeted operation and maintenance processing on the target business server in a timely manner according to the alarm prompt information, which is conducive to improving the operation and maintenance accuracy and efficiency of the business server.

[0114] In summary, in the embodiments of the present application, by determining the second terminal device corresponding to the target business server and sending an alarm prompt message to the second terminal device, it is possible to accurately send an alarm prompt message to the second terminal device that needs to be notified, so that the operation and maintenance personnel can perform targeted operation and maintenance processing on the target business server in a timely manner according to the alarm prompt information, which is conducive to improving the operation and maintenance accuracy and efficiency of the business server.

[0115] In an exemplary embodiment, Figure 4 This is a flow chart of an anomaly detection method for cloud services in another embodiment. For ease of understanding, in this embodiment, the target query information includes multi-dimensional service fusion data corresponding to the target business server as an example, and the overall process of the anomaly detection method for cloud services is further described in combination with the monitoring server, the target business server and the second terminal device. Figure 4As shown, the method of the embodiment of the present application may include the following steps:

[0116] Step S401: The monitoring server may obtain multi-dimensional original service data of the target service server from the target service server at preset intervals or when an abnormality detection instruction is detected.

[0117] Step S402: The monitoring server may perform data cleaning, data formatting, and data fusion processing on the multi-dimensional original service data to obtain multi-dimensional service fusion data corresponding to the target business server.

[0118] Step S403: The monitoring server inputs the multi-dimensional service fusion data corresponding to the target business server into a preset retrieval sub-model, and determines the target historical anomaly detection information corresponding to the multi-dimensional service fusion data in the dynamic knowledge base according to the output of the preset retrieval sub-model.

[0119] Step S404: The monitoring server inputs the multi-dimensional service fusion data, the target historical anomaly detection information and the anomaly detection scenario into a preset generation sub-model, and determines the anomaly detection information of the target business server according to the output of the preset generation sub-model.

[0120] Step S405: The monitoring server determines the second terminal device corresponding to the target service server.

[0121] Step S406: The monitoring server sends an alarm prompt message to the second terminal device.

[0122] In an exemplary embodiment, the monitoring server may also output multi-dimensional original service data and / or multi-dimensional service fusion data to facilitate real-time data monitoring of cloud services.

[0123] It should be noted that the implementation methods of each step in the embodiments of the present application can refer to the relevant contents in the above embodiments of the present application and will not be repeated here.

[0124] In an exemplary embodiment, Figure 5 This is a flow chart of an anomaly detection method for cloud services in another embodiment. For ease of understanding, in this embodiment of the application, the target query information includes the anomaly retrieval information corresponding to the target business server as an example, and the overall process of the anomaly detection method for cloud services is further described in combination with the monitoring server, the target business server and the first terminal device. Figure 5 As shown, the method of the embodiment of the present application may include the following steps:

[0125] Step S501: The monitoring server receives abnormality search information corresponding to the target service server sent by the first terminal device.

[0126] Step S502: The monitoring server inputs the abnormal search information into a preset search sub-model, and determines the target historical abnormality detection information corresponding to the abnormal search information in the dynamic knowledge base according to the output of the preset search sub-model.

[0127] Step S503: The monitoring server inputs the target historical anomaly detection information and the anomaly detection context into a preset generation sub-model, and determines the anomaly detection information of the target business server according to the output of the preset generation sub-model.

[0128] Step S504: The monitoring server sends an alarm prompt message to the first terminal device.

[0129] It should be noted that the implementation methods of each step in the embodiments of the present application can refer to the relevant contents in the above embodiments of the present application and will not be repeated here.

[0130] In an exemplary embodiment, Figure 6 This is an architectural diagram of an anomaly detection system for a cloud service in one embodiment. The anomaly detection system for a cloud service in this embodiment of the present application fully considers the complexity of cross-business line and multi-dimensional data processing, as well as the universal applicability of anomaly detection and the friendliness of user interaction.

[0131] like Figure 6 As shown, the architectural diagram of the anomaly detection system of the cloud service in an embodiment of the present application may include: a data acquisition module 601, a real-time processing module 602, an anomaly alarm and notification module 603, a model core processing module 604, a knowledge base module 605, and a user interface and interaction module 606.

[0132] Exemplarily, the data collection module 601 may be deployed on different service servers respectively.

[0133] Exemplarily, the real-time processing module 602 , the abnormal alarm and notification module 603 and the model core processing module 604 may be deployed on a monitoring server.

[0134] Exemplarily, the knowledge base module 605 may be deployed on a monitoring server, or may be deployed on a data storage server.

[0135] Exemplarily, the terminal-side portion of the user interface and interaction module 606 may be deployed on a terminal device, and the server-side portion of the user interface and interaction module 606 may be deployed on a monitoring server.

[0136] The following embodiments of the present application further describe the relevant contents of each step.

[0137] The data collection module 601 in the embodiment of the present application can cover various business scenarios in cloud services and can span different business lines. Data collection is not limited to server performance indicators (for example, computing performance, memory performance, API response time, database access performance, etc.), but also extends to business indicators (for example, business logic error rate, etc.) and user behavior indicators, etc., and can widely collect multi-source and multi-dimensional service data.

[0138] For example, data collection module 601 can collect data by utilizing a distributed tracing system and / or API integration technology, thereby capturing comprehensive service data in real time. Furthermore, data collection module 601's data collection strategy can be flexibly adjusted based on different business scenarios, supporting on-demand adjustments to sampling rates and frequencies for different businesses. This balances monitoring accuracy and resource consumption, ensuring efficient and comprehensive data capture.

[0139] In addition to performing real-time processing such as data cleaning and data formatting, the real-time processing module 602 in the present embodiment can also implement multi-dimensional data fusion processing. For example, the real-time processing module 602 can utilize message queue technologies such as Kafka or Pulsar to perform data cleaning and data formatting, thereby improving the real-time and reliability of data stream processing. The real-time processing module 602 can also utilize a real-time computing framework to perform data fusion processing, such as time series analysis and association rule mining, to extract key performance indicators that have a direct impact on the business.

[0140] The core of the model core processing module 604 in this embodiment of the present application is a preset anomaly detection model (e.g., a RAG model), which can be composed of two parts: a preset retrieval sub-model and a preset generation sub-model. The preset retrieval sub-model can perform semantic similarity matching between the input target query information and the historical anomaly detection information set in the dynamic knowledge base to quickly locate the target historical anomaly detection information related to the target query information. The preset retrieval sub-model is also integrated with the business rule engine to understand the meaning of data in different business scenarios.

[0141] The preset generation sub-model can generate corresponding anomaly detection information based on the retrieval results (i.e., the target historical anomaly detection information) output by the preset retrieval sub-model. Exemplarily, the preset generation sub-model can further integrate multi-dimensional service fusion data and / or anomaly detection context when generating anomaly detection information. Furthermore, when generating anomaly detection information for the target business server, the preset generation sub-model not only incorporates business impact analysis (e.g., predicting the potential decrease in customer satisfaction or resource loss caused by the anomaly), but also provides technical explanations for the anomaly.

[0142] In addition, the model core processing module 604 can also consider business cyclicality, seasonal changes, and / or the impact of external factors (such as promotional activities, etc.) on indicators, and dynamically adjust the indicator thresholds to improve the intelligence level of threshold setting, thereby helping to further improve the accuracy of anomaly detection information of the preset anomaly detection model.

[0143] The knowledge base module 605 in the embodiment of the present application constructs an extensible dynamic knowledge graph (or a dynamic knowledge base), which stores multiple historical anomaly detection information corresponding to different business servers (historical anomalies, historical anomaly causes corresponding to historical anomalies, historical maintenance suggestions, technical document links corresponding to historical anomaly detection information, etc.).

[0144] For example, the dynamic knowledge base in the embodiment of the present application not only supports text information, but is also compatible with multimedia content such as charts and code snippets to provide more intuitive and practical guidance. At the same time, the knowledge base module 605 can regularly update and maintain the dynamic knowledge base to ensure the timeliness and accuracy of the knowledge base.

[0145] On the one hand, the user interface and interaction module 606 in the embodiment of the present application supports interactive query, allowing users to trigger detection by the model core processing module 604 by inputting anomaly search information (for example, NLP search information or preset custom view anomaly search information), which facilitates efficient problem troubleshooting. On the other hand, the user interface and interaction module 606 in the embodiment of the present application adopts responsive design principles, allowing users to conveniently view monitoring status and anomaly detection information, whether on desktop or mobile devices.

[0146] Illustratively, the interface of the user interface and interaction module 606 provides a visual dashboard so as to clearly display a real-time performance overview, anomaly alarm list, anomaly detection information, and the like.

[0147] The abnormal alarm and notification module 603 in the embodiment of the present application can be used to determine the terminal device corresponding to the target service server that needs to be notified, and send an alarm prompt message to the terminal device.

[0148] For ease of understanding, the following embodiments of this application take multi-dimensional business performance monitoring and optimization as an example to briefly introduce and explain the anomaly detection process of cloud services.

[0149] Figure 7 A schematic diagram of anomaly detection process of cloud services in one embodiment, combined with Figure 6 and Figure 7As shown, assume that an e-commerce platform discovers a significant increase in order processing time during a major sales event. Data collection module 601 collects multi-dimensional raw service data, including API request latency, database query time, and inventory system response. Real-time processing module 602 performs stream processing and analysis on the multi-dimensional raw service data to generate multi-dimensional service fusion data. Model core processing module 604 performs anomaly detection based on the multi-dimensional service fusion data to quickly locate target historical anomaly detection information related to the multi-dimensional service fusion data. It also conducts anomaly analysis and business impact analysis based on user purchasing behavior patterns during peak business periods to generate anomaly detection information. This anomaly detection information indicates the target anomaly condition on the target business server, the target anomaly cause (e.g., database query bottleneck), the predicted business impact (e.g., the potential risk of order loss), and target troubleshooting recommendations (e.g., recommendations for optimizing database indexes and increasing database resources). User interface and interaction module 606 displays anomaly detection information in real time and notifies relevant operations and maintenance personnel via multiple channels, such as email and text messages, to ensure a prompt response.

[0150] For ease of understanding, the following embodiments of this application use cross-business impact analysis and proactive prevention as an example to briefly introduce the anomaly detection process for cloud services.

[0151] Figure 8 A schematic diagram of anomaly detection process of cloud services in another embodiment, combined with Figure 6 and Figure 8 As shown, assuming that a large enterprise cloud platform contains multiple subsystems, the model core processing module 604 can be used for cross-business impact analysis. If an exception occurs in a subsystem, the operation and maintenance personnel enter the exception retrieval information through interactive query, for example, "Will the existence of this exception in the subsystem affect user satisfaction?" The model core processing module 604 can be used to perform exception analysis and business impact analysis based on multiple historical exception detection information in the dynamic knowledge base to determine the exception detection information, and return an interactive query response (including but not limited to exception detection information). Among them, the exception detection information is used to indicate the target exception situation existing in the subsystem, the target exception cause corresponding to the target exception situation, the business impact prediction corresponding to the target exception situation (such as the impact of upstream system delays on downstream order processing), and target maintenance suggestions (such as notifying affected customers in advance and starting backup processing processes, etc.).

[0152] In summary, the cloud service anomaly detection system of the embodiment of the present application, by introducing a data acquisition module, a real-time processing module, a model core processing module, a knowledge base module and a user interface and interaction module, can transcend the scope of traditional performance monitoring, deeply understand business logic, and provide accurate anomaly detection, business impact assessment and intelligent optimization suggestions. It not only achieves the real-time and accuracy of cloud service performance monitoring, but also greatly improves the accuracy of anomaly detection and the efficiency of problem solving, thereby significantly improving the response speed and problem-solving ability of the operation and maintenance team. In addition, through the model core processing module, the system can analyze and self-learn based on historical anomaly detection information and / or real-time input data, and can better understand the business context to provide more accurate anomaly detection information, which is conducive to enterprises to efficiently respond to challenges in complex business environments, improve operational efficiency, and ensure customer service quality and business continuity. It brings significant intelligent progress to cloud service monitoring and is conducive to ensuring the healthy operation of cloud services and business continuity.

[0153] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0154] Based on the same inventive concept, embodiments of the present application also provide an anomaly detection device for implementing the aforementioned cloud service anomaly detection method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of the embodiments of the anomaly detection device for one or more cloud services provided below can be found in the limitations of the cloud service anomaly detection method described above and will not be repeated here.

[0155] In an exemplary embodiment, Figure 9 FIG. 1 is a schematic diagram of the structure of an abnormality detection device for a cloud service in one embodiment. The abnormality detection device for a cloud service in the embodiment of the present application can be applied to a monitoring server. Figure 9 As shown, the cloud service anomaly detection device of the embodiment of the present application may include: an acquisition module 901, a detection module 902 and an output module 903.

[0156] Acquisition module 901 is used to acquire target query information of a target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormality search information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multi-dimensional data of server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server;

[0157] Detection module 902 is configured to input the target query information into a preset anomaly detection model and determine anomaly detection information of the target business server based on the output of the preset anomaly detection model; the anomaly detection information indicates the target anomaly condition of the target business server, the target anomaly cause corresponding to the target anomaly condition, the predicted business impact corresponding to the target anomaly condition, and a target maintenance recommendation;

[0158] The output module 903 is used to output an alarm prompt message; wherein the alarm prompt message includes abnormality detection information and alarm prompt information.

[0159] In an exemplary embodiment, the preset anomaly detection model includes a preset retrieval sub-model and a preset generation sub-model, and the detection module 902 includes:

[0160] a retrieval unit, configured to input target query information into a preset retrieval sub-model, and determine target historical anomaly detection information corresponding to the target query information in a dynamic knowledge base according to an output of the preset retrieval sub-model;

[0161] The first determining unit is configured to input the target historical anomaly detection information into a preset generation sub-model, and determine the anomaly detection information of the target business server according to the output of the preset generation sub-model.

[0162] In an exemplary embodiment, when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the first determining unit is specifically configured to:

[0163] The multi-dimensional service fusion data and the target historical anomaly detection information are input into a preset generation sub-model, and the anomaly detection information is determined according to the output of the preset generation sub-model.

[0164] In an exemplary embodiment, when the target query information includes multi-dimensional service fusion data corresponding to the target business server, the acquisition module 901 is specifically configured to:

[0165] Acquire multidimensional original service data of the target business server from the target business server; perform data cleaning processing, data format processing and data fusion processing on the multidimensional original service data to obtain multidimensional service fusion data corresponding to the target business server.

[0166] In an exemplary embodiment, when the target query information includes abnormal search information corresponding to the target service server, the acquisition module 901 is specifically configured to:

[0167] Receive abnormal search information sent by the first terminal device; wherein the abnormal search information is NLP search information, or preset custom view search information.

[0168] In an exemplary embodiment, the output module 903 includes:

[0169] A second determining unit, configured to determine a second terminal device corresponding to the target service server;

[0170] The sending unit is used to send an alarm prompt message to the second terminal device.

[0171] The cloud service anomaly detection device provided in the embodiments of the present application can be used to execute the technical solution in any of the above-mentioned cloud service anomaly detection method embodiments of the present application. Its implementation principles and technical effects are similar and will not be repeated here.

[0172] Each module in the aforementioned cloud service anomaly detection device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in the monitoring server as hardware, or may be stored in a memory in the monitoring server as software, allowing the processor to call and execute the corresponding operations of each module.

[0173] In an exemplary embodiment, Figure 10 FIG. 1 is a schematic diagram of the structure of a monitoring server in an embodiment. Figure 10 As shown, the monitoring server of an embodiment of the present application may include a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, memory, and input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. The processor of the monitoring server is used to provide computing and control capabilities. The memory of the monitoring server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the monitoring server is used to store data and information during the anomaly detection processing of the cloud service. The input / output interface of the monitoring server is used to exchange information between the processor and external devices. The communication interface of the monitoring server is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the technical solution of any of the above-mentioned cloud service anomaly detection method embodiments of the present application is implemented.

[0174] Those skilled in the art will understand that Figure 10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the monitoring server to which the solution of the present application is applied. The specific monitoring server may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0175] In an exemplary embodiment, a monitoring server is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps in any of the above-mentioned cloud service anomaly detection method embodiments are implemented.

[0176] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned cloud service anomaly detection method embodiments are implemented.

[0177] In an exemplary embodiment, a computer program product is provided, including a computer program, which, when executed by a processor, implements the steps of any of the above-mentioned cloud service anomaly detection method embodiments.

[0178] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.

[0179] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0180] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A cloud service anomaly detection method, characterized in that: The method is applied to a monitoring server and includes: Obtaining target query information of a target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormality retrieval information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multi-dimensional data of server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server; Inputting the target query information into a preset anomaly detection model, and determining anomaly detection information of the target business server based on the output of the preset anomaly detection model; wherein the anomaly detection information is used to indicate a target anomaly condition existing in the target business server, a target anomaly cause corresponding to the target anomaly condition, a business impact prediction corresponding to the target anomaly condition, and a target maintenance suggestion; Output an alarm prompt message; wherein the alarm prompt message includes the abnormality detection information and the alarm prompt information.

2. The method according to claim 1, characterized in that The preset anomaly detection model includes a preset retrieval sub-model and a preset generation sub-model. Inputting the target query information into the preset anomaly detection model and determining the anomaly detection information of the target business server according to the output of the preset anomaly detection model include: Inputting the target query information into the preset retrieval sub-model, and determining the target historical anomaly detection information corresponding to the target query information in the dynamic knowledge base according to the output of the preset retrieval sub-model; The target historical anomaly detection information is input into the preset generation sub-model, and the anomaly detection information of the target business server is determined according to the output of the preset generation sub-model.

3. The method according to claim 2, characterized in that In a case where the target query information includes multi-dimensional service fusion data corresponding to the target business server, inputting the target historical anomaly detection information into the preset generation sub-model, and determining the anomaly detection information of the target business server according to the output of the preset generation sub-model, includes: The multi-dimensional service fusion data and the target historical anomaly detection information are input into the preset generation sub-model, and the anomaly detection information is determined according to the output of the preset generation sub-model.

4. The method according to any one of claims 1 to 3, characterized in that In a case where the target query information includes the multi-dimensional service fusion data corresponding to the target service server, obtaining the target query information of the target service server includes: Acquire multidimensional original service data of the target business server from the target business server; perform data cleaning processing, data format processing and data fusion processing on the multidimensional original service data to obtain multidimensional service fusion data corresponding to the target business server.

5. The method according to any one of claims 1 to 3, characterized in that In a case where the target query information includes abnormal search information corresponding to the target service server, obtaining the target query information of the target service server includes: Receive the abnormal search information sent by the first terminal device; wherein the abnormal search information is NLP search information, or preset custom view search information.

6. The method according to any one of claims 1 to 3, characterized in that The output alarm prompt message includes: Determining a second terminal device corresponding to the target service server; Send the alarm message to the second terminal device.

7. A cloud service anomaly detection device, characterized in that: The device is applied to a monitoring server and includes: an acquisition module, configured to acquire target query information of a target business server; wherein the target query information includes multi-dimensional service fusion data corresponding to the target business server, or abnormality retrieval information corresponding to the target business server; wherein the multi-dimensional service fusion data is fusion data calculated based on multi-dimensional data of server performance indicator data, business indicator data, and user behavior indicator data corresponding to the target business server; a detection module, configured to input the target query information into a preset anomaly detection model, and determine anomaly detection information of the target business server based on the output of the preset anomaly detection model; wherein the anomaly detection information is used to indicate a target anomaly condition existing in the target business server, a target anomaly cause corresponding to the target anomaly condition, a business impact prediction corresponding to the target anomaly condition, and a target maintenance suggestion; The output module is used to output an alarm prompt message; wherein the alarm prompt message includes the abnormality detection information and the alarm prompt information.

8. A monitoring server comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.