Root cause positioning method and system based on time series decomposition and multi-agent cooperation
By performing multidimensional component time-series decomposition and multi-agent collaborative parallel analysis on the time-series data of the target system, the problem of difficulty in locating the root cause of faults caused by the coupling of multidimensional time-series variables in the existing technology is solved, and fast and accurate fault root cause location is achieved, improving the efficiency of operation and maintenance decision-making and user experience.
Patent Information
- Application Number
- CN202510550291.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-04-29
AI Technical Summary
Existing root cause localization methods struggle to quickly pinpoint the root cause of a fault when multiple time-series variables are coupled together, resulting in long troubleshooting times, significant system delays during maintenance, economic losses for enterprises, and poor user experience.
By performing multidimensional component time-series decomposition on the time-series data of the target system, a multidimensional independent component time-series dataset is constructed. Then, by using a multi-agent collaborative parallel analysis strategy combined with a root cause fusion analysis strategy, the abnormal indicator localization information set is determined, and a root cause analysis report is output.
Rapidly pinpointing the root cause of faults in situations where multidimensional time-series variables are coupled together significantly improves the accuracy of fault location in complex systems and the efficiency of operation and maintenance decisions, reduces economic losses for enterprises, and enhances user experience.
Smart Images

Figure CN120670197B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intelligent operation and maintenance, and in particular to a root cause positioning method and system based on time series decomposition and multi-agent cooperation. BACKGROUND
[0002] In modern information systems, with the continuous increase of system complexity and scale, fault root cause positioning has become a key problem to ensure stable operation of the system. Rapid and accurate positioning of system fault root cause can significantly improve the fault resolution speed, thereby reducing downtime and economic losses of enterprises, and ensuring the reliability and response efficiency of the system.
[0003] However, the existing root cause positioning methods are usually based on statistical or machine learning methods, which analyze the system time series variables as a whole. Although this method can capture the overall trend of system abnormal behavior, it is difficult to quickly locate the fault root cause in the case of mutual coupling of multi-dimensional time series variables, resulting in long fault troubleshooting time, obvious system delay in operation and maintenance process, and poor user experience. SUMMARY
[0004] The present application provides a root cause positioning method and system based on time series decomposition and multi-agent cooperation to solve the above technical problems.
[0005] In a first aspect, the present application provides a root cause positioning method based on time series decomposition and multi-agent cooperation, which comprises:
[0006] Obtaining a target system time series dataset, analyzing the target system time series dataset, and determining a multi-dimensional independent component time series dataset; based on a multi-agent cooperative parallel analysis strategy, performing multi-agent cooperative parallel anomaly analysis on the multi-dimensional independent component time series dataset to determine an abnormal index positioning information set; according to a root cause fusion analysis strategy, performing fusion decision analysis on the abnormal index positioning information set to determine and output a root cause analysis report.
[0007] Optionally, the analysis of the target system time series dataset to determine the multi-dimensional independent component time series dataset comprises:
[0008] Based on the target system time series dataset, missing value imputation and time series alignment are performed on each target system time series dataset within the target system time series dataset to determine the preprocessed time series dataset. Based on a preset sliding time window span and a preset periodic time window span, the preprocessed time series dataset is analyzed, and time series decomposition is performed on each preprocessed time series data point to determine the corresponding trend component, periodic component, and burst component of each preprocessed time series data point at different time points. A trend component data sequence is constructed based on the corresponding trend component of each preprocessed time series data point at different time points; a periodic component data sequence is constructed based on the corresponding periodic component of each preprocessed time series data point at different time points; a burst component data sequence is constructed based on the corresponding burst component of each preprocessed time series data point at different time points; and a multidimensional independent component time series dataset is constructed based on the trend component data sequence, the periodic component data sequence, and the burst component data sequence.
[0009] Optionally, based on a preset sliding time window span and a preset periodic time window span, the preprocessed time series dataset is analyzed, and time series decomposition processing is performed on each preprocessed time series data in the preprocessed time series dataset to determine the corresponding trend component, periodic component, and burst component of each preprocessed time series data at different time points, specifically as follows:
[0010] ;
[0011] in, At the current time point The trend components mentioned below, The preset sliding time window span, For the currently described preprocessed time series data at time points The data value at that location, For time points The periodic components mentioned below, The preset periodic time window span, For the preprocessed time series data, This is the timestamp corresponding to the current period's time point. For time points The aforementioned burst components.
[0012] Optionally, the multi-agent collaborative parallel analysis strategy, which performs multi-agent collaborative parallel anomaly analysis on the multi-dimensional independent component time-series dataset to determine the anomaly indicator localization information set, includes:
[0013] The multi-agent includes a performance monitoring agent, an index tracking agent and a question and answer agent; based on the performance monitoring agent, the trend component data sequence in the multi-dimensional independent component time series data set is analyzed, and a trend change mapping index corresponding to each trend component data is determined; according to the numerical positive and negative properties of each trend change mapping index, it is judged whether there is a trend type fault of the operation and maintenance index corresponding to different trend component data, and if there is, the corresponding trend type abnormal operation and maintenance index is extracted; based on the index tracking agent, the cycle component data sequence in the multi-dimensional independent component time series data set is analyzed, and a cycle component amplitude corresponding to each cycle component data is determined; each cycle component amplitude is compared with a preset cycle amplitude threshold, it is judged whether there is a cycle type fault of the operation and maintenance index corresponding to different cycle component data, and if there is, the corresponding cycle type abnormal operation and maintenance index is extracted; based on the question and answer agent, the burst component data sequence in the multi-dimensional independent component time series data set is analyzed, according to the burst fault judgment condition, it is judged whether there is a burst type fault of the operation and maintenance index corresponding to different burst component data, and if there is, the corresponding burst type abnormal operation and maintenance index is extracted; according to the trend type abnormal operation and maintenance index, the cycle type abnormal operation and maintenance index and the burst type abnormal operation and maintenance index, the abnormal index positioning information set is constructed.
[0014] Optionally, based on the performance monitoring agent, the trend component data sequence in the multi-dimensional independent component time series data set is analyzed, and a trend change mapping index corresponding to each trend component data is determined, which is specifically the following formula:
[0015] ;
[0016] Wherein, is a trend change mapping index, is the total number of time points corresponding to the current trend component data in the trend component data sequence, is a time point index, is a time point under the trend component.
[0017] Optionally, based on the index tracking agent, the cycle component data sequence in the multi-dimensional independent component time series data set is analyzed, and a cycle component amplitude corresponding to each cycle component data is determined, which is specifically the following formula:
[0018] ;
[0019] Wherein, is the cycle component amplitude of the current cycle component data sequence under the first cycle time window, is the cycle component amplitude of the current cycle component data sequence under the second a sub-data sequence under a cycle time window, for the preset cycle time window span, for the total number of cycle time windows.
[0020] Optionally, the burst failure judgment condition is specifically the following formula:
[0021]
[0022] wherein, is the burst component at the time point is the burst component at the time point is the burst component at the time point is the standard deviation of the change amount between each burst component in the current burst component data sequence, is the average value of the burst component in the current burst component data sequence, is the standard deviation of the burst component in the current burst component data sequence.
[0023] Optionally, the fusion decision analysis of the abnormal index positioning information set according to the root cause fusion analysis strategy, the determination and output of the root cause analysis report, include:
[0024] obtaining a real-time operation and maintenance optimization target, based on the real-time operation and maintenance optimization target, determining the root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set according to the abnormal index positioning information set; analyzing the root cause evaluation coefficient corresponding to each abnormal index, performing significant difference evaluation on each root cause evaluation coefficient, and determining a plurality of root cause abnormal operation and maintenance indexes; according to a plurality of root cause abnormal operation and maintenance indexes, constructing and outputting the root cause analysis report.
[0025] Optionally, the determination of the root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set according to the abnormal index positioning information set based on the real-time operation and maintenance optimization target is specifically the following formula:
[0026] ;
[0027] wherein, is the real-time operation and maintenance optimization target, is the i-th abnormal index in the abnormal index positioning information set, is the abnormal index positioning information set, is the data sub-set after removing the corresponding abnormal index in the abnormal index positioning information set, is the root cause evaluation coefficient corresponding to the current abnormal index, is the i-th root cause evaluation coefficient, is the i-th root cause evaluation coefficient. conditional covariance between abnormal indicators, variance corresponding to the current operation and maintenance optimization target, variance corresponding to the current abnormal indicator.
[0028] In a second aspect, the application provides a root cause positioning system based on time series decomposition and multi-agent cooperation, comprising:
[0029] a time series decomposition module for obtaining a target system time series dataset, analyzing the target system time series dataset, and determining a multi-dimensional independent component time series dataset; a parallel analysis module for performing multi-agent cooperative parallel anomaly analysis on the multi-dimensional independent component time series dataset based on a multi-agent cooperative parallel analysis strategy, and determining an abnormal indicator positioning information set; and a fusion decision module for performing fusion decision analysis on the abnormal indicator positioning information set according to a root cause fusion analysis strategy, and determining and outputting a root cause analysis report.
[0030] Optionally, the time series decomposition module is specifically configured to: based on the target system time series dataset, perform missing value supplement processing and time series alignment processing on each target system time series dataset in the target system time series dataset, and determine a preprocessed time series dataset; based on a preset sliding time window span and a preset periodic time window span, analyze the preprocessed time series dataset, perform time series decomposition processing on each preprocessed time series data in the preprocessed time series dataset, and determine corresponding trend components, periodic components and burst components of each preprocessed time series data at different time points; construct a trend component data sequence according to the corresponding trend components of each preprocessed time series data at different time points; construct a periodic component data sequence according to the corresponding periodic components of each preprocessed time series data at different time points; construct a burst component data sequence according to the corresponding burst components of each preprocessed time series data at different time points; and construct a multi-dimensional independent component time series dataset according to the trend component data sequence, the periodic component data sequence and the burst component data sequence.
[0031] Optionally, when the time series decomposition module analyzes the preprocessed time series dataset based on the preset sliding time window span and the preset periodic time window span, performs time series decomposition processing on each preprocessed time series data in the preprocessed time series dataset, and determines corresponding trend components, periodic components and burst components of each preprocessed time series data at different time points, the time series decomposition module specifically performs the following formula:
[0032] ;
[0033] wherein, is the trend component at the current time point a preset sliding time window span, a data value of the preprocessed time series data at a time point , a periodic component at a time point , a preset periodic time window span, the preprocessed time series data, a corresponding timestamp of a current periodic time point, a burst component at a time point .
[0034] Optionally, the parallel analysis module is specifically configured to:
[0035] The multiple agents include a performance monitoring agent, an index tracking agent, and a question and answer agent; based on the performance monitoring agent, the trend component data sequence in the multi-dimensional independent component time series dataset is analyzed to determine a trend change mapping index corresponding to each trend component data; according to the numerical positive and negative properties of each trend change mapping index, it is determined whether there is a trend type fault of the operation and maintenance index corresponding to different trend component data, and if so, the corresponding trend type abnormal operation and maintenance index is extracted; based on the index tracking agent, the periodic component data sequence in the multi-dimensional independent component time series dataset is analyzed to determine a periodic component amplitude corresponding to each periodic component data; each periodic component amplitude is compared with a preset periodic amplitude threshold value respectively to determine whether there is a periodic type fault of the operation and maintenance index corresponding to different periodic component data, and if so, the corresponding periodic type abnormal operation and maintenance index is extracted; based on the question and answer agent, the burst component data sequence in the multi-dimensional independent component time series dataset is analyzed, and according to a burst fault judgment condition, it is determined whether there is a burst type fault of the operation and maintenance index corresponding to different burst component data, and if so, the corresponding burst type abnormal operation and maintenance index is extracted; and according to the trend type abnormal operation and maintenance index, the periodic type abnormal operation and maintenance index, and the burst type abnormal operation and maintenance index, the abnormal index positioning information set is constructed.
[0036] Optionally, when the parallel analysis module analyzes the trend component data sequence in the multi-dimensional independent component time series dataset based on the performance monitoring agent to determine a trend change mapping index corresponding to each trend component data, the following formula is specifically used:
[0037] ;
[0038] wherein, the trend change mapping index is, a total number of time points corresponding to the current trend component data in the trend component data sequence, a time point index, is the trend component at time point .
[0039] Optionally, when the parallel analysis module determines the periodic component amplitude corresponding to each periodic component data by analyzing the periodic component data sequence in the multi-dimensional independent component time series data set based on the index tracking agent, the specific formula is as follows:
[0040] ;
[0041] wherein, is the periodic component amplitude of the current periodic component data sequence at the th periodic time window, is the sub-data sequence of the current periodic component data sequence at the th periodic time window, is the preset periodic time window span, is the total number of periodic time windows.
[0042] Optionally, the burst failure judgment condition in the parallel analysis module is specifically as follows:
[0043]
[0044] wherein, is the burst component at time point is the burst component at time point is the standard deviation of the change amount between each burst component in the current burst component data sequence, is the average value of the burst component in the current burst component data sequence, is the standard deviation of the burst component in the current burst component data sequence.
[0045] Optionally, the fusion decision module is specifically configured to: acquire a real-time operation and maintenance optimization target, determine a root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set based on the real-time operation and maintenance optimization target and the abnormal index positioning information set, analyze the root cause evaluation coefficient corresponding to each abnormal index, perform significant difference evaluation on each root cause evaluation coefficient, and determine a plurality of root cause abnormal operation and maintenance indexes; and construct and output the root cause analysis report according to the plurality of root cause abnormal operation and maintenance indexes.
[0046] Optionally, the fusion decision module determines a root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set based on the real-time operation and maintenance optimization target and the abnormal index positioning information set, and the specific formula is as follows:
[0047] ;
[0048] wherein, is the real-time operation and maintenance optimization target, is the i-th abnormal index in the abnormal index positioning information set, is the abnormal index positioning information set, is a data sub-set after eliminating the corresponding abnormal index in the abnormal index positioning information set, is a root cause evaluation coefficient corresponding to the current abnormal index, is the conditional covariance between the current operation and maintenance optimization target and the i-th abnormal index, is the variance corresponding to the current operation and maintenance optimization target, is the variance corresponding to the current abnormal index. The above technical solutions have the following beneficial effects:
[0049] Through the scheme, the target system time series data is subjected to multi-dimensional component time series decomposition, noise interference is effectively stripped and a meaningful feature component is extracted, a multi-dimensional independent component time series data set is constructed, on the basis of which, through a multi-agent collaborative parallel analysis mode, abnormal operation and maintenance indexes corresponding to different types of system faults are subjected to positioning analysis, an abnormal index positioning information set is obtained, and then, based on a root cause fusion analysis strategy, through fusion decision analysis of the abnormal index positioning information set, positioning of a system fault root cause is realized, and a corresponding root cause analysis report is provided to an operation and maintenance team, so that the fault root cause is quickly positioned under the condition that multi-dimensional time series variables are mutually coupled, the accuracy of complex system fault positioning and operation and maintenance decision efficiency are significantly improved, enterprise economic losses are reduced, and user experience is improved.
[0050] The target system time series data set is preprocessed to obtain a preprocessed time series data set, on the basis of which, in combination with a preset sliding time window span and a preset periodic time window span, corresponding trend components, periodic components and burst components of each preprocessed time series data at different time points are respectively analyzed, trend component data sequences, periodic component data sequences and burst component data sequences are constructed, and then a multi-dimensional independent component time series data set is constructed, through a three-stage processing procedure of "data preprocessing-feature decoupling-component reconstruction", the original complex target system time series data set is decomposed into independent component sequences in three orthogonal feature spaces, structured input data is provided for subsequent multi-agent parallel analysis, and the accuracy and interpretability of root cause positioning are effectively improved.
[0051] The target system time series data set is preprocessed to obtain a preprocessed time series data set, on the basis of which, in combination with a preset sliding time window span and a preset periodic time window span, corresponding trend components, periodic components and burst components of each preprocessed time series data at different time points are respectively analyzed, trend component data sequences, periodic component data sequences and burst component data sequences are constructed, and then a multi-dimensional independent component time series data set is constructed, through a three-stage processing procedure of "data preprocessing-feature decoupling-component reconstruction", the original complex target system time series data set is decomposed into independent component sequences in three orthogonal feature spaces, structured input data is provided for subsequent multi-agent parallel analysis, and the accuracy and interpretability of root cause positioning are effectively improved.
[0052] The pre-processed time series data set is analyzed by using mathematical analysis means based on a preset sliding time window span and a preset periodic time window span, feature decoupling is performed on the pre-processed time series data set through a double sliding window mechanism, trend components, periodic components and burst components are quantified respectively, and the scientificity and accuracy of component features are improved;
[0053] Different types of anomalies are analyzed by using multi-agent division and cooperation, and the operation and maintenance indexes corresponding to different types of anomalies are used as corresponding trend type anomaly operation and maintenance indexes, periodic type anomaly operation and maintenance indexes and burst type anomaly operation and maintenance indexes, respectively, to construct anomaly index positioning information set, so that the analysis process is decoupled while the data features are decoupled, so as to prevent different types of feature components from producing cross interference in the analysis process and causing some anomalies to be covered, and improve the accuracy and comprehensiveness of the anomaly operation and maintenance index analysis process;
[0054] The trend component data sequence in the multi-dimensional independent component time series data set is analyzed by using mathematical analysis means, and the trend change mapping index reflecting the change trend of the operation and maintenance index is quantified, so as to accurately capture the change trend of different operation and maintenance indexes and improve the accuracy and scientificity of the trend type anomaly analysis;
[0055] The periodic component data sequence in the multi-dimensional independent component time series data set is analyzed by using mathematical analysis means, and the maximum fluctuation of the periodic component data in different periodic time windows is quantified as the periodic component amplitude corresponding to the corresponding periodic component data, providing a reliable data standard for the evaluation of periodic type anomalies;
[0056] Starting from the instantaneous fluctuation characteristics and numerical deviation characteristics of burst type anomalies, a mathematical condition for judging whether there is a burst type anomaly is constructed to determine the burst fault judgment condition, and the comprehensiveness and accuracy of the burst type anomaly analysis process are improved;
[0057] Based on the real-time operation and maintenance optimization target and the anomaly index positioning information set, the multi-dimensional independent component time series data set is analyzed, the root cause evaluation coefficient reflecting the causal correlation degree between each anomaly index and the real-time operation and maintenance optimization target is quantified, and on this basis, the root cause anomaly operation and maintenance indexes causing the current system anomaly are determined through significant difference evaluation of each root cause evaluation coefficient, to construct and output the root cause analysis report, and through unified decision convergence, the anomaly indexes corresponding to different component features are fused and analyzed under the clear real-time operation and maintenance optimization target, so as to improve the comprehensiveness and accuracy of the root cause anomaly operation and maintenance index analysis process;
[0058] By means of mathematical analysis, based on the real-time operation optimization target, according to the abnormal index positioning information set, the independent contribution of each abnormal index to the real-time operation optimization target is measured, and the root cause evaluation coefficient corresponding to the abnormal index is quantitatively obtained, so that the root cause evaluation coefficient can accurately reflect the causal correlation degree between the abnormal index and the real-time operation optimization target, and the accuracy and scientificity of root cause positioning are improved. BRIEF DESCRIPTION OF DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0060] Figure 1 An application scenario schematic diagram provided by an embodiment of the present application;
[0061] Figure 2 A flowchart of a root cause positioning method based on time series decomposition and multi-agent cooperation provided by an embodiment of the present application;
[0062] Figure 3 A structural schematic diagram of a root cause positioning system based on time series decomposition and multi-agent cooperation provided by an embodiment of the present application. DETAILED DESCRIPTION
[0063] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0064] In addition, the term "and / or" in this paper is only a description of the association relationship between the associated objects, which means that there may be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper, unless otherwise specified, generally represents an "or" relationship between the associated objects before and after it.
[0065] The embodiments of the present application will be further described in detail below in combination with the drawings of the specification.
[0066] Existing root cause positioning methods are usually based on statistical or machine learning methods, and perform overall analysis on system time series variables. Although this method can capture the overall trend of system abnormal behavior, it is difficult to quickly locate the fault root cause in the case of mutual coupling of multi-dimensional time series variables, resulting in long fault troubleshooting time, obvious system delay in operation and maintenance process, causing economic loss of enterprises and poor user experience.
[0067] Based on this, the application provides a root cause positioning method and system based on time series decomposition and multi-agent cooperation. The target system time series data is subjected to multi-dimensional component time series decomposition, the noise interference is effectively stripped and the feature component with clear meaning is extracted, and a multi-dimensional independent component time series dataset is constructed. On this basis, through the multi-agent cooperative parallel analysis method, the abnormal operation and maintenance indicators corresponding to different types of system faults are positioned and analyzed, and the abnormal indicator positioning information set is obtained. Then, based on the root cause fusion analysis strategy, the abnormal indicator positioning information set is fused and decision analyzed, the system fault root cause is positioned, and the corresponding root cause analysis report is provided to the operation and maintenance team. In the case of mutual coupling of multi-dimensional time series variables, the fault root cause is quickly located, the accuracy of complex system fault positioning and the operation and maintenance decision efficiency are significantly improved, the economic loss of enterprises is reduced, and the user experience is improved.
[0068] Figure 1 An application scenario provided by the application is shown in the figure. In the automatic operation and maintenance process, the method provided by the application is applied to quickly locate the fault root cause in the case of mutual coupling of multi-dimensional time series variables, and the accuracy of complex system fault positioning and the operation and maintenance decision efficiency are significantly improved.
[0069] Specifically, the method of the application is applied to any server, which communicates with a log recording component. The target system time series dataset provided by the log recording component is acquired and analyzed through the server, the target system time series data is subjected to multi-dimensional component time series decomposition, the noise interference is effectively stripped and the feature component with clear meaning is extracted, and a multi-dimensional independent component time series dataset is constructed. On this basis, through the multi-agent cooperative parallel analysis method, the abnormal operation and maintenance indicators corresponding to different types of system faults are positioned and analyzed, and the abnormal indicator positioning information set is obtained. Then, based on the root cause fusion analysis strategy, the abnormal indicator positioning information set is fused and decision analyzed, the system fault root cause is positioned, and the corresponding root cause analysis report is provided to the operation and maintenance team. In the case of mutual coupling of multi-dimensional time series variables, the fault root cause is quickly located, the accuracy of complex system fault positioning and the operation and maintenance decision efficiency are significantly improved, the economic loss of enterprises is reduced, and the user experience is improved. The specific implementation mode can refer to the following embodiments.
[0070] Figure 2A flowchart of a root cause positioning method based on time series decomposition and multi-agent collaboration provided for an embodiment of the present application. The method of the present embodiment can be applied to the server in the above scenario. As shown in Figure 2 the method includes:
[0071] S201, obtaining a target system time series dataset, analyzing the target system time series dataset, and determining a multi-dimensional independent component time series dataset.
[0072] The target system time series dataset can be a time series dataset generated by the target operation and maintenance system during operation, such as time series data of indicators such as CPU usage, memory occupancy, network delay, and device temperature. The target system time series dataset can be obtained by a system built-in log recording component.
[0073] The multi-dimensional independent component time series dataset can be a collection of several independent component data sequences obtained by time series decomposition of the target system time series dataset, such as trend components, periodic components, and burst components.
[0074] Specifically, in the complex system operation and maintenance scenario, the difficulty of root cause positioning lies in the fact that system failures are often caused by multiple interrelated indicator abnormalities. Traditional single-dimensional analysis methods cannot effectively distinguish potential failure modes. Existing technologies usually directly perform correlation analysis on raw time series data, but do not consider the independent characteristics of different components (trend, periodic, and burst), resulting in serious noise interference in the analysis results. Different component characteristics can map different potential problems in the system, such as the trend component reflecting the development trend characteristics of the operation and maintenance indicators, which can map persistent system vulnerabilities such as memory leaks. The present solution uses mathematical analysis methods to target different component characteristics, performs time series decomposition of different component types on the target system time series dataset, and determines a multi-dimensional independent component time series dataset reflecting the operation and maintenance indicator change characteristics from different component directions. The above time series decomposition operation can clearly divide the mixed characteristics in the original time series data into dimensions, providing a structured data basis for subsequent multi-dimensional root cause analysis.
[0075] S202, based on a multi-agent collaborative parallel analysis strategy, performing multi-agent collaborative parallel anomaly analysis on the multi-dimensional independent component time series dataset to determine an abnormal indicator positioning information set.
[0076] The multi-agent collaborative parallel analysis strategy can be a distributed analysis architecture containing different agents, such as performance monitoring agents, indicator tracking agents, and question and answer agents.
[0077] The multi-agent collaborative parallel anomaly analysis can be a parallel analysis of time series data by different agents to determine the analysis process of abnormal indicators in the time series data.
[0078] The abnormal index positioning information set can be a set of information containing all abnormal operation and maintenance indexes in the current system.
[0079] Specifically, the traditional operation and maintenance abnormality analysis method uses a single algorithm model for full data analysis, which has the defects of low calculation efficiency and incomplete feature capture. The present scheme uses a different intelligent agent collaborative parallel abnormality analysis strategy, captures different types of abnormalities existing in the system through targeted parallel analysis of different intelligent agents, such as analyzing the burst component features in the multi-dimensional independent component time series data set through the question and answer intelligent agent, extracting the operation and maintenance indexes that map the system burst abnormality, to capture the burst type abnormality in the system, using different types of intelligent agents to process abnormality capture tasks in a distributed computing framework, integrating the abnormal operation and maintenance indexes obtained by each analysis, obtaining an abnormal index positioning information set, which significantly improves the abnormality analysis efficiency while ensuring the accuracy of the abnormality analysis.
[0080] S203, according to the root cause fusion analysis strategy, performing fusion decision analysis on the abnormal index positioning information set, and determining and outputting a root cause analysis report.
[0081] The fusion decision analysis strategy can be an analysis method for quantifying the causal relationship strength between different abnormal indexes and system failures.
[0082] The root cause analysis report can be a visual report containing root cause indexes corresponding to the current system failure and corresponding repair suggestions.
[0083] Specifically, after determining the abnormal index positioning information set, the causal relationship between the abnormal indexes is quantitatively analyzed by mathematical analysis means to determine a number of root cause indexes causing the current system failure, and then through a large language model or an operation and maintenance knowledge graph, operation and maintenance suggestions for solving the current system failure from the number of root cause indexes are obtained. Through data visualization technology, the number of root cause indexes and the corresponding operation and maintenance suggestions are data visualized to construct a root cause analysis report, and the root cause analysis report is provided to the operation and maintenance team to support operation and maintenance personnel to quickly locate the core fault point and develop repair strategies.
[0084] By the scheme, the target system time series data is subjected to multi-dimensional component time series decomposition, noise interference is effectively stripped and a meaningful feature component is extracted, and a multi-dimensional independent component time series dataset is constructed. On this basis, through a multi-agent collaborative parallel analysis mode, abnormal operation and maintenance indexes corresponding to different types of system faults are positioned and analyzed, an abnormal index positioning information set is obtained, and then based on a root cause fusion analysis strategy, the abnormal index positioning information set is subjected to fusion decision analysis, the positioning of the system fault root cause is realized, and the corresponding root cause analysis report is provided to the operation and maintenance team, so that the fault root cause is quickly positioned under the condition that multi-dimensional time series variables are coupled with each other, the accuracy of complex system fault positioning and the operation and maintenance decision efficiency are significantly improved, the economic loss of enterprises is reduced, and the user experience is improved.
[0085] In some embodiments, according to the target system time series dataset, each target system time series dataset in the target system time series dataset is subjected to missing value supplementing processing and time series alignment processing to determine a preprocessed time series dataset; based on a preset sliding time window span and a preset periodic time window span, the preprocessed time series dataset is analyzed, each preprocessed time series data in the preprocessed time series dataset is subjected to time series decomposition processing to determine the corresponding trend component, periodic component and burst component of each preprocessed time series data at different time points; according to the corresponding trend component of each preprocessed time series data at different time points, a trend component data sequence is constructed; according to the corresponding periodic component of each preprocessed time series data at different time points, a periodic component data sequence is constructed; according to the corresponding burst component of each preprocessed time series data at different time points, a burst component data sequence is constructed; and according to the trend component data sequence, the periodic component data sequence and the burst component data sequence, a multi-dimensional independent component time series dataset is constructed.
[0086] The missing value supplementing processing can be a processing process of interpolating and supplementing the missing values in the target system time series dataset.
[0087] The time series alignment processing can be a processing process of time series alignment of multi-source data in the target system time series dataset.
[0088] The preprocessed time series dataset can be a standardized dataset obtained through data cleaning and time series normalization processing.
[0089] The preset sliding time window span can be a time span parameter for extracting data trend features, which can be determined by the trend change period statistical value in the historical data.
[0090] The preset periodic time window span can be a reference period parameter for identifying data periodicity features, which can be obtained by Fourier transform analysis of data frequency spectrum features.
[0091] The trend component can be a feature component reflecting the long-term change direction of data.
[0092] Periodic component can be a characteristic component reflecting the periodic fluctuation law of data.
[0093] Sudden component can be a characteristic component representing the sudden abnormal fluctuation of data.
[0094] Trend component data sequence can be a data set containing trend components corresponding to different operation and maintenance indicators.
[0095] Periodic component data sequence can be a data set containing periodic components corresponding to different operation and maintenance indicators.
[0096] Sudden component data sequence can be a data set containing sudden components corresponding to different operation and maintenance indicators.
[0097] Specifically, in the distributed system operation and maintenance scenario, the original collected time series data usually has missing values caused by failure of collection equipment, and time series misalignment problem caused by inconsistent collection frequency of multi-source data. Through missing value interpolation algorithm such as cubic spline interpolation method, the missing values are supplemented, and time series alignment algorithm such as dynamic time warping algorithm is used to align the time series of multi-source data, to generate a preprocessed time series data set with integrity and consistency. Further, since different characteristic components in operation and maintenance data time series can map different types of anomalies existing in the system, trend component mainly maps potential continuous anomalies in the system, such as memory leakage, periodic component mainly maps potential periodic anomalies in the system, such as periodic high load, and sudden component mainly maps sudden anomalies in the system. Considering that the trend, periodicity and suddenness of system operation indicators are often coupled and superimposed, a double sliding window mechanism is used for component feature decoupling. Through mathematical analysis means, the data is processed by moving average using a preset sliding time window span, and the trend component after removing short-term fluctuations is extracted. At the same time, based on the preset periodic time window span, the data is processed by periodic residual quantization to separate the periodic component. Then, the sudden component is obtained by total residual quantization. Through the three-stage processing flow of "data preprocessing-feature decoupling-component reconstruction", the original complex time series data is decomposed into independent component sequences in three orthogonal feature spaces, providing structured input data for subsequent multi-agent parallel analysis, effectively improving the accuracy and explainability of root cause positioning.
[0098] This approach preprocesses the target system's time-series dataset to obtain a preprocessed time-series dataset. Based on this, and combining a preset sliding time window span and a preset periodic time window span, the trend component, periodic component, and burst component of each preprocessed time-series data at different time points are analyzed. Trend component data sequences, periodic component data sequences, and burst component data sequences are constructed, thereby creating a multidimensional independent component time-series dataset. Through a three-stage processing flow of "data preprocessing - feature decoupling - component reconstruction," the original complex target system time-series dataset is decomposed into independent component sequences in three orthogonal feature spaces. This provides structured input data for subsequent multi-agent parallel analysis, effectively improving the accuracy and interpretability of root cause localization.
[0099] In some embodiments, based on a preset sliding time window span and a preset periodic time window span, the preprocessed time series dataset is analyzed, and each preprocessed time series data in the preprocessed time series dataset is subjected to time series decomposition processing to determine the corresponding trend component, periodic component and burst component of each preprocessed time series data at different time points, specifically as shown in the following formula (1):
[0100] (1)
[0101] in, At the current time point The downward trend component, To preset the sliding time window span, For the current preprocessed time series data at time points The data value at that location, For time points The periodic components below, To preset the periodic time window span, To preprocess time series data, This is the timestamp corresponding to the current period's time point. For time points The sudden component below.
[0102] Specifically, the trend component is a smoothed trend that reflects the long-term development direction of time series data, as shown in formula (1). The data is smoothed using a sliding time window, and the trend value at each time point is calculated as the trend component; the periodic component is used to represent the recurring periodic fluctuation characteristics in the time series data, through... ,use Residuals are extracted, and the periodicity of the data is extracted by calculating the mean of the residual values over a preset periodic time window, quantifying the periodic components. Sudden components are parts of the time series that cannot be explained by trends and periods; these are addressed through... Quantify the burst components.
[0103] By the present solution, the pre-processed time series dataset is analyzed based on the preset sliding time window span and the preset periodic time window span by using mathematical analysis means, and the feature decoupling of the pre-processed time series dataset is performed through a double sliding window mechanism to quantize the trend component, the periodic component and the burst component respectively, thereby improving the scientificity and accuracy of the component features.
[0104] In some embodiments, the multi-agent includes a performance monitoring agent, an index tracking agent and a question and answer agent; based on the performance monitoring agent, trend component data sequences in the multi-dimensional independent component time series dataset are analyzed to determine a trend change mapping index corresponding to each trend component data; according to the numerical positive and negative properties of each trend change mapping index, it is judged whether the operation and maintenance index corresponding to different trend component data exists a trend type fault, if exists, the corresponding trend type abnormal operation and maintenance index is extracted; based on the index tracking agent, periodic component data sequences in the multi-dimensional independent component time series dataset are analyzed to determine a periodic component amplitude corresponding to each periodic component data; each periodic component amplitude is compared with a preset periodic amplitude threshold respectively to judge whether the operation and maintenance index corresponding to different periodic component data exists a periodic type fault, if exists, the corresponding periodic type abnormal operation and maintenance index is extracted; based on the question and answer agent, burst component data sequences in the multi-dimensional independent component time series dataset are analyzed, and according to a burst fault judgment condition, it is judged whether the operation and maintenance index corresponding to different burst component data exists a burst type fault, if exists, the corresponding burst type abnormal operation and maintenance index is extracted; according to the trend type abnormal operation and maintenance index, the periodic type abnormal operation and maintenance index and the burst type abnormal operation and maintenance index, an abnormal index positioning information set is constructed.
[0105] The performance monitoring agent can be an agent module for analyzing trend component data sequences to detect trend type abnormalities. The index tracking agent can be an agent module for analyzing periodic component data sequences to detect periodic type abnormalities. The question and answer agent can be an agent module for analyzing burst component data sequences to detect burst type faults. The trend change mapping index can be a quantitative value for characterizing the trend change direction and strength in the trend component data sequence.
[0106] The numerical positive and negative properties can be an index for characterizing whether the trend change mapping index is a positive number or a negative number, when the trend change mapping index is a positive number, it means that the corresponding operation and maintenance index presents a continuous upward trend, and when the trend change mapping index is a negative number, it means that the corresponding operation and maintenance index presents a continuous downward trend.
[0107] The trend type abnormal operation and maintenance index can be an operation and maintenance index that maps a trend type abnormality existing in the current system.
[0108] The periodic component amplitude can be a quantitative value representing the fluctuation intensity of the periodic component data sequence within a single cycle window. The preset periodic amplitude threshold can be a critical value for determining whether the periodic fluctuation is abnormal, which can be obtained by statistical analysis of historical periodic component data.
[0109] The periodic abnormal operation indicator can be an operation indicator that reflects the periodic abnormality of the current system.
[0110] The burst failure judgment condition can be a mathematical condition for determining whether a burst-type abnormality exists.
[0111] The burst-type abnormal operation indicator can be an operation indicator that reflects the burst-type abnormality of the current system.
[0112] Specifically, in the process of analyzing system abnormalities, the trend component data sequence, the periodic component data sequence, and the burst component data sequence in the multi-dimensional independent component time series data set are respectively subjected to abnormal indicator positioning analysis by the performance monitoring agent responsible for continuous indicator monitoring, the indicator tracking agent responsible for indicator feature tracking, and the question and answer agent responsible for burst abnormality evaluation. In the process of decoupling data features, the analysis process is decoupled to prevent cross interference between different types of feature components during the analysis process, which may cause some abnormalities to be masked, such as periodic fluctuations that may mask the trend deterioration, resulting in an inability to accurately identify long-term deterioration trends. The performance monitoring agent uses mathematical analysis methods to quantitatively analyze the trend component data sequence and determine the trend change mapping index. Then, according to the positive or negative nature of the trend change mapping index value, when the current trend change mapping index is a significantly higher positive number than the mean or a significantly lower negative number than the mean, it represents that the current operation indicator has a long-term growth or long-term decline trend, indicating that there is a trend-type abnormality. The corresponding operation indicator is taken as a trend-type abnormal operation indicator. The indicator tracking agent uses mathematical analysis methods to quantitatively analyze the periodic component data sequence and determine the periodic component amplitude. Each of the periodic component amplitudes is compared with the preset periodic amplitude threshold. When there is a periodic component amplitude greater than the preset periodic amplitude threshold and the abnormal amplitude continuously appears in different cycle windows, it indicates that the corresponding operation indicator has a periodic abnormal fluctuation. The corresponding operation indicator is taken as a periodic abnormal operation indicator. The burst failure judgment condition constructed by the question and answer agent is used to conditionally compare and judge the burst component data sequence. The operation indicator reflecting the existence of a burst-type abnormality is taken as a burst-type abnormal operation indicator. Then, the trend-type abnormal operation indicator, the periodic abnormal operation indicator, and the burst-type abnormal operation indicator are integrated to obtain the abnormal indicator positioning information set.
[0113] By the scheme, multi-agent division of labor and cooperation is utilized, special abnormality analysis is respectively performed on the trend component, the periodic component and the burst component, and the operation and maintenance indexes corresponding to different types of abnormality are respectively taken as the corresponding trend-type abnormality operation and maintenance index, the periodic-type abnormality operation and maintenance index and the burst-type abnormality operation and maintenance index, so as to construct the abnormality index positioning information set, decouple the data feature at the same time, realize decoupling of the analysis process, prevent cross interference of different types of feature components in the analysis process from causing some abnormality to be covered, and improve the accuracy and comprehensiveness of the abnormality operation and maintenance index analysis process.
[0114] In some embodiments, based on the performance monitoring agent, trend component data sequences in the multi-dimensional independent component time series data set are analyzed, a trend change mapping index corresponding to each trend component data is determined, and the following formula (2) is used:
[0115] (2)
[0116] wherein, is the trend change mapping index, is the total number of time points corresponding to the current trend component data in the trend component data sequence, is the time point index, is the time point trend component.
[0117] Specifically, the deviation of each time point relative to the time mean is described in formula (2) to eliminate the overall translation effect in the time series data, so that the quantization process of the trend change mapping index focuses on the trend change of the data, and is not affected by the time position information; by the deviation of each trend component relative to the average of the overall trend component is described, so as to eliminate the average value in the trend component sequence, and thus the change mode of the trend data itself is concerned; and then by the linear relationship between time and trend component is reflected, if the value corresponding to this part is positive, the time and the trend component are positively correlated (i.e. the trend component increases with the increase of time), if the value corresponding to this part is negative, the time and the trend component are negatively correlated (i.e. the trend component decreases with the increase of time); further, by , the variance corresponding to the time point deviation is used to eliminate the influence of the time series scale, so that the quantized trend change mapping index presents a dimensionless standardized trend change index.
[0118] This solution utilizes mathematical analysis to analyze the trend component data sequence within a multidimensional independent component time series dataset, quantifies the trend change mapping index that reflects the changing trends of operation and maintenance indicators, thereby accurately capturing the changing trends of different operation and maintenance indicators and improving the accuracy and scientific nature of trend anomaly analysis.
[0119] In some embodiments, based on the index tracking agent, the periodic component data sequence in the multidimensional independent component time series dataset is analyzed to determine the periodic component amplitude corresponding to each periodic component data, specifically as shown in the following formula (3):
[0120] (3)
[0121] in, For the current periodic component data sequence in the th... The periodic component amplitude within a periodic time window For the current periodic component data sequence in the th... Sub-data sequences within a periodic time window To preset the periodic time window span, This represents the total number of time windows in the cycle.
[0122] Specifically, the periodic component data sequence is divided into segments based on a preset periodic time window span. A periodic data segment with the same time span, through The difference between the maximum and minimum values in the periodic component data within each periodic time window is quantified to reflect the maximum fluctuation of the periodic component data within the current periodic time window. This is used as the corresponding periodic component amplitude to provide a reliable data standard for the assessment of periodic anomalies.
[0123] This scheme utilizes mathematical analysis to analyze the periodic component data sequences within a multidimensional independent component time series dataset, quantifies the maximum fluctuation of the periodic component data within different periodic time windows, and uses this as the amplitude of the corresponding periodic component data, thus providing a reliable data standard for the assessment of periodic anomalies.
[0124] In some embodiments, the sudden failure judgment condition is specifically the following formula (4):
[0125] (4)
[0126] in, For time points The sudden weight below, For time points The sudden weight below, This represents the standard deviation of the variation among the burst components within the current burst component data sequence. an average value of the burst component within a current burst component data sequence, a standard deviation of the burst component within the current burst component data sequence.
[0127] Specifically, in the system operation process, the performance of the burst type anomaly on the operation and maintenance index mainly has two characteristics: one is the instantaneous sharp fluctuation of the operation and maintenance index, and the operation and maintenance index value changes abruptly in a short time (such as network instantaneous interruption), and the other is that the operation and maintenance index value deviates from the normal fluctuation range (such as disk bad track leading to high load); in order to capture the above two characteristics, two conditions need to be combined in the burst fault judgment condition: one is that the burst component change rate exceeds the normal fluctuation range, and the other is that the absolute value of the burst component exceeds the global anomaly threshold; through the capture the absolute change value of the burst component at different time points (corresponding to the instantaneous fluctuation of the operation and maintenance index), compare the absolute change value with the change amount standard deviation (representing the average dispersion degree of normal change), and when the above absolute change value exceeds 2 times the change amount standard deviation, it means that the current value fluctuation has significant abrupt anomaly; at the same time, since the time series of the burst component is normally distributed, the mean value of the sequence represents the central tendency, and the standard deviation of the sequence represents the normal fluctuation range, based on the normal distribution principle, 99.7% of the data points will fall within the range of , and when the burst component exceeds , it means that the corresponding operation and maintenance index value deviates from the normal fluctuation range.
[0128] Through the scheme, starting from the instantaneous fluctuation characteristics and numerical deviation characteristics of the burst type anomaly, a mathematical condition for judging whether there is a burst type anomaly is constructed to determine the burst fault judgment condition, and the comprehensiveness and accuracy of the burst type anomaly analysis process are improved.
[0129] In some embodiments, a real-time operation and maintenance optimization target is obtained, based on the real-time operation and maintenance optimization target and the multi-dimensional independent component time series data set, according to the abnormal index positioning information set, the root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set is determined; the root cause evaluation coefficient corresponding to each abnormal index is analyzed, and each root cause evaluation coefficient is evaluated for significant difference to determine a plurality of root cause abnormal operation and maintenance indexes; and a root cause analysis report is constructed and output according to the plurality of root cause abnormal operation and maintenance indexes.
[0130] The real-time operation and maintenance optimization target can be a quantitative index that needs to be prioritized in the current system operation process, and the real-time operation and maintenance optimization target is obtained through dynamic configuration of the operation and maintenance management platform.
[0131] The root cause evaluation coefficient can be a quantitative value for measuring the influence degree of the abnormal index on the operation and maintenance optimization target, and the larger the root cause evaluation coefficient, the greater the probability that the corresponding abnormal index is a root cause index.
[0132] Significant difference assessment can be an assessment process used to determine whether the root cause assessment coefficient deviates significantly from the normal range.
[0133] Root cause anomaly indicators can be the root cause indicators that cause the current system anomaly.
[0134] Specifically, in complex system operation and maintenance, the ultimate goal of root cause analysis needs to be aligned with real-time business requirements. Based on the real-time operation and maintenance goals corresponding to the current system, mathematical analysis is used to jointly analyze the causal relationships between different abnormal indicators within the abnormal indicator location information set and the real-time operation and maintenance goals. This quantifies the root cause evaluation coefficient corresponding to each abnormal indicator, which characterizes the degree of causal association. When there is at least one root cause evaluation coefficient that is significantly larger than other root cause evaluation coefficients, it indicates that there is a significant causal association between the corresponding partial root cause evaluation coefficients and the real-time operation and maintenance goals. These partial abnormal indicators are the root cause abnormal operation and maintenance indicators that caused the current anomaly. Based on these root cause abnormal operation and maintenance indicators, the actual operation and maintenance process required to optimize each root cause abnormal operation and maintenance indicator is analyzed using methods such as large language model analysis or operation and maintenance knowledge graph retrieval. This integrates the operation and maintenance suggestions corresponding to the current root cause abnormal operation and maintenance indicators. Through data visualization toolsets, the abnormal operation and maintenance indicators and corresponding operation and maintenance suggestions are integrated and visualized to obtain a root cause analysis report. The root cause analysis report is then provided to the operation and maintenance team through human-computer interaction devices, such as high-definition displays.
[0135] This solution analyzes multidimensional independent component time-series datasets based on real-time operation and maintenance optimization goals and anomaly indicator location information sets. It quantifies the root cause evaluation coefficient, reflecting the degree of causal correlation between each anomaly indicator and the real-time operation and maintenance optimization goal. Based on this, by evaluating the significant differences of each root cause evaluation coefficient, several root cause anomaly operation and maintenance indicators that trigger the current system anomaly are identified. A root cause analysis report is then constructed and output. Through a unified decision convergence method, under a clear real-time operation and maintenance optimization goal, a fusion root cause analysis is performed on anomaly indicators corresponding to different component characteristics to improve the comprehensiveness and accuracy of the root cause anomaly operation and maintenance indicator analysis process.
[0136] In some embodiments, based on the real-time operation and maintenance optimization goal, the root cause evaluation coefficient corresponding to each abnormal indicator in the abnormal indicator location information set is determined according to the abnormal indicator location information set, specifically by the following formula:
[0137] ;
[0138] in, To achieve the goal of real-time operation and maintenance optimization, For the location of abnormal indicators within the information set One abnormal indicator, an abnormal index positioning information set, a data sub-set after removing the corresponding abnormal index in the abnormal index positioning information set, a root cause evaluation coefficient corresponding to the current abnormal index, a conditional covariance between the current operation and maintenance optimization target and the first abnormal index, a variance corresponding to the current operation and maintenance optimization target, a variance corresponding to the current operation and maintenance optimization target, a variance corresponding to the current abnormal index.
[0139] Specifically, by using the conditional covariance to describe the linear correlation degree between the real-time operation and maintenance optimization target and the abnormal index after removing the corresponding abnormal index in the multi-dimensional independent component time series data set, and by describing the comprehensive residual fluctuation between the real-time operation and maintenance optimization target and the abnormal index after removing the current abnormal index from the abnormal index positioning information set, and by implementing the standardization processing of the conditional covariance, and measuring the independent contribution degree of the current abnormal index to the real-time operation and maintenance optimization target in the absolute value, the root cause evaluation coefficient corresponding to the abnormal index is quantitatively obtained. By the scheme, the independent contribution degree of each abnormal index to the real-time operation and maintenance optimization target is measured based on the real-time operation and maintenance optimization target according to the abnormal index positioning information set by using mathematical analysis means, so that the root cause evaluation coefficient corresponding to the abnormal index is quantitatively obtained, which can accurately reflect the causal correlation degree between the abnormal index and the real-time operation and maintenance optimization target, thereby improving the accuracy and scientificity of root cause positioning.
[0140]
[0141] A structural schematic diagram of a root cause positioning system based on time series decomposition and multi-agent cooperation provided by an embodiment of the present application is shown in Figure 3 As shown in the structural schematic diagram, the root cause positioning system 300 based on time series decomposition and multi-agent cooperation of the embodiment includes a time series decomposition module 301, a parallel analysis module 302 and a fusion decision module 303. Figure 3 The time series decomposition module 301 is configured to acquire a target system time series data set, analyze the target system time series data set, and determine a multi-dimensional independent component time series data set; the parallel analysis module 302 is configured to perform multi-agent cooperative parallel abnormal analysis on the multi-dimensional independent component time series data set based on a multi-agent cooperative parallel analysis strategy, and determine an abnormal index positioning information set; and the fusion decision module 303 is configured to perform fusion decision analysis on the abnormal index positioning information set according to a root cause fusion analysis strategy, and determine and output a root cause analysis report.
[0142]
[0143] Optionally, the time series decomposition module 301 is specifically configured to: according to the target system time series dataset, perform missing value supplementing processing and time series alignment processing on each target system time series dataset in the target system time series dataset to determine a preprocessed time series dataset; based on a preset sliding time window span and a preset periodic time window span, analyze the preprocessed time series dataset, perform time series decomposition processing on each preprocessed time series data in the preprocessed time series dataset to determine a corresponding trend component, a periodic component and a burst component of each preprocessed time series data at different time points; according to the corresponding trend component of each preprocessed time series data at different time points, construct a trend component data sequence; according to the corresponding periodic component of each preprocessed time series data at different time points, construct a periodic component data sequence; according to the corresponding burst component of each preprocessed time series data at different time points, construct a burst component data sequence; and according to the trend component data sequence, the periodic component data sequence and the burst component data sequence, construct a multi-dimensional independent component time series dataset.
[0144] Optionally, when the time series decomposition module 301 analyzes the preprocessed time series dataset based on the preset sliding time window span and the preset periodic time window span, performs time series decomposition processing on each preprocessed time series data in the preprocessed time series dataset, and determines a corresponding trend component, a periodic component and a burst component of each preprocessed time series data at different time points, the time series decomposition module 301 is specifically configured to use the following formula:
[0145] ;
[0146] wherein, is the trend component at the current time point , is the preset sliding time window span, is the data value of the current preprocessed time series data at time point , is the periodic component at time point , is the preset periodic time window span, is the preprocessed time series data, is the current periodic time point corresponding timestamp, is the burst component at time point .
[0147] Optionally, the parallel analysis module 302 is specifically configured to: the plurality of intelligent agents include a performance monitoring intelligent agent, an index tracking intelligent agent, and a question and answer intelligent agent; based on the performance monitoring intelligent agent, analyze the trend component data sequence in the multi-dimensional independent component time series data set, and determine a trend change mapping index corresponding to each trend component data; according to the numerical positive and negative properties of each trend change mapping index, judge whether there is a trend type fault of the operation and maintenance index corresponding to different trend component data, and if there is, extract the corresponding trend type abnormal operation and maintenance index; based on the index tracking intelligent agent, analyze the periodic component data sequence in the multi-dimensional independent component time series data set, and determine a periodic component amplitude corresponding to each periodic component data; compare each periodic component amplitude with a preset periodic amplitude threshold, respectively, to judge whether there is a periodic type fault of the operation and maintenance index corresponding to different periodic component data, and if there is, extract the corresponding periodic type abnormal operation and maintenance index; based on the question and answer intelligent agent, analyze the burst component data sequence in the multi-dimensional independent component time series data set, and according to a burst fault judgment condition, judge whether there is a burst type fault of the operation and maintenance index corresponding to different burst component data, and if there is, extract the corresponding burst type abnormal operation and maintenance index; and according to the trend type abnormal operation and maintenance index, the periodic type abnormal operation and maintenance index, and the burst type abnormal operation and maintenance index, construct the abnormal index positioning information set.
[0148] Optionally, when the parallel analysis module 302 analyzes the trend component data sequence in the multi-dimensional independent component time series data set based on the performance monitoring intelligent agent, and determines a trend change mapping index corresponding to each trend component data, the following formula is specifically used:
[0149] ;
[0150] wherein, is a trend change mapping index, is a total number of time points corresponding to the current trend component data in the trend component data sequence, is a time point index, is a trend component at the time point.
[0151] Optionally, when the parallel analysis module 302 analyzes the periodic component data sequence in the multi-dimensional independent component time series data set based on the index tracking intelligent agent, and determines a periodic component amplitude corresponding to each periodic component data, the following formula is specifically used:
[0152] ;
[0153] wherein, is a periodic component amplitude of the current periodic component data sequence in the m-th periodic time window, a sub-data sequence of the current periodic component data sequence in a first periodic time window, a preset periodic time window span, a total number of periodic time windows.
[0154] Optionally, the burst failure judgment condition in the parallel analysis module 302 is specifically the following formula:
[0155]
[0156] wherein, b t is the burst component at the time point t, b t+1 is the burst component at the time point t+1, σ b is the standard deviation of the variation amount between each burst component in the current burst component data sequence, μ b is the average value of the burst component in the current burst component data sequence, and σ b t is the standard deviation of the burst component in the current burst component data sequence.
[0157] Optionally, the fusion decision module 303 is specifically configured to: acquire a real-time operation and maintenance optimization target, determine a root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set based on the real-time operation and maintenance optimization target and the abnormal index positioning information set; analyze the root cause evaluation coefficient corresponding to each abnormal index, perform significant difference evaluation on each root cause evaluation coefficient, and determine a plurality of root cause abnormal operation and maintenance indexes; and construct and output the root cause analysis report according to the plurality of root cause abnormal operation and maintenance indexes.
[0158] Optionally, the fusion decision module 303 determines the root cause evaluation coefficient corresponding to each abnormal index in the abnormal index positioning information set based on the real-time operation and maintenance optimization target and the abnormal index positioning information set, and is specifically the following formula:
[0159]
[0160] wherein, the real-time operation and maintenance optimization target is t, the abnormal index in the abnormal index positioning information set is i, the abnormal index positioning information set is S, the data sub-set after the corresponding abnormal index is removed in the abnormal index positioning information set is S i, the root cause evaluation coefficient corresponding to the current abnormal index is r i, and the current operation and maintenance optimization target and the i th abnormal index are t and i, respectively. conditional covariance between the abnormal indicators, variance corresponding to the current operation and maintenance optimization target, variance corresponding to the current abnormal indicator.
[0161] The system of the embodiment can be used to execute the method of any of the above embodiments, and has similar implementation principles and technical effects, which are not described here again.
Claims
1. A root cause localization method based on time series decomposition and multi-agent cooperation, characterized in that, include: Obtain the time series dataset of the target system, analyze the time series dataset of the target system, and determine the time series dataset of the multidimensional independent components; Based on a multi-agent collaborative parallel analysis strategy, multi-agent collaborative parallel anomaly analysis is performed on the multi-dimensional independent component time series dataset to determine the anomaly index localization information set. Based on the root cause fusion analysis strategy, the abnormal indicator location information set is fused and analyzed to determine and output a root cause analysis report. The analysis of the target system time series dataset to determine the multidimensional independent component time series dataset includes: The target system time series dataset is a collection of time series data generated during the operation of the target operation and maintenance system, including time series data of CPU utilization, memory usage, network latency, and device temperature. The target system time series dataset is obtained from the log recording component of the target operation and maintenance system. Based on the target system time series dataset, missing value imputation and time series alignment are performed on each target system time series dataset within the target system time series dataset to determine the preprocessed time series dataset; Based on a preset sliding time window span and a preset periodic time window span, the preprocessed time series dataset is analyzed. Time series decomposition is performed on each preprocessed time series data point within the dataset to determine the corresponding trend component, periodic component, and burst component of each preprocessed time series data point at different time points, specifically using the following formula: ; in, The current time point The trend components mentioned below, The preset sliding time window span, For the currently described preprocessed time series data at time points The data value at that location, For time points The periodic components mentioned below, The preset periodic time window span, For the preprocessed time series data, This is the timestamp corresponding to the current period's time point. For time points The following burst components; Based on the trend components corresponding to each preprocessed time series data at different time points, a trend component data sequence is constructed. Based on the corresponding periodic components of each preprocessed time series data at different time points, a periodic component data sequence is constructed. Based on the burst components corresponding to each preprocessed time series data at different time points, a burst component data sequence is constructed. A multidimensional independent component time series dataset is constructed based on the trend component data sequence, the periodic component data sequence, and the burst component data sequence.
2. The method according to claim 1, characterized in that, The multi-agent collaborative parallel analysis strategy performs multi-agent collaborative parallel anomaly analysis on the multi-dimensional independent component time-series dataset to determine the anomaly indicator localization information set, including: The multi-agent system includes a performance monitoring agent, an indicator tracking agent, and a question-answering agent. Based on the performance monitoring agent, the trend component data sequence in the multidimensional independent component time series dataset is analyzed, and the trend change mapping index corresponding to each trend component data is determined. Based on the positive or negative value of each trend change mapping index, determine whether there are trend-type faults in the operation and maintenance indicators corresponding to different trend component data. If so, extract the corresponding trend-type abnormal operation and maintenance indicators. Based on the index tracking agent, the periodic component data sequence in the multidimensional independent component time series dataset is analyzed to determine the periodic component amplitude corresponding to each periodic component data. The amplitude of each periodic component is compared with a preset periodic amplitude threshold to determine whether there are periodic faults in the operation and maintenance indicators corresponding to different periodic component data. If so, the corresponding periodic abnormal operation and maintenance indicators are extracted. Based on the question-answering agent, the burst component data sequence in the multidimensional independent component time series dataset is analyzed. According to the burst fault judgment conditions, it is determined whether there is a burst fault in the operation and maintenance indicators corresponding to different burst component data. If there is, the corresponding burst abnormal operation and maintenance indicators are extracted. Based on the trend-type abnormal operation and maintenance indicators, the periodic abnormal operation and maintenance indicators, and the sudden abnormal operation and maintenance indicators, the abnormal indicator location information set is constructed.
3. The method according to claim 2, characterized in that, Based on the performance monitoring agent, the trend component data sequence within the multidimensional independent component time-series dataset is analyzed to determine the trend change mapping index corresponding to each trend component data, specifically using the following formula: ; in, An index that maps trend changes. The total number of time points corresponding to the current trend component data within the trend component data sequence. For time point indexing, For time points The trend components described below.
4. The method according to claim 2, characterized in that, The intelligent agent based on the index tracking analyzes the periodic component data sequence within the multidimensional independent component time-series dataset to determine the periodic component amplitude corresponding to each periodic component data, specifically using the following formula: ; in, For the current periodic component data sequence in the th... The periodic component amplitude within a periodic time window For the current periodic component data sequence in the th... Sub-data sequences within a periodic time window The preset periodic time window span, This represents the total number of time windows in the cycle.
5. The method according to claim 2, characterized in that, The criteria for determining sudden failures are specifically defined by the following formula: ; in, For time points The aforementioned burst components, For time points The aforementioned burst components, The standard deviation of the variation among the burst components within the current burst component data sequence. This represents the average value of the burst components within the current burst component data sequence. This represents the standard deviation of the burst component within the current burst component data sequence.
6. The method according to claim 5, characterized in that, The step of performing fusion decision analysis on the abnormal indicator location information set according to the root cause fusion analysis strategy, and determining and outputting a root cause analysis report, includes: Obtain real-time operation and maintenance optimization goals, and based on the real-time operation and maintenance optimization goals, determine the root cause evaluation coefficient corresponding to each abnormal indicator in the abnormal indicator location information set according to the abnormal indicator location information set. Analyze the root cause evaluation coefficient corresponding to each abnormal indicator, evaluate the significant differences of each root cause evaluation coefficient, and determine several root cause abnormal operation and maintenance indicators. Based on several of the aforementioned root cause anomaly operation and maintenance indicators, construct and output the root cause analysis report.
7. The method according to claim 6, characterized in that, Based on the real-time operation and maintenance optimization goals, and according to the abnormal indicator location information set, the root cause evaluation coefficient corresponding to each abnormal indicator in the abnormal indicator location information set is determined, specifically by the following formula: ; in, The goal of the real-time operation and maintenance optimization is... The first one in the abnormal indicator location information set One abnormal indicator, To locate the abnormal indicator information set. This is the subset of data after removing the corresponding abnormal indicators from the abnormal indicator location information set. This is the root cause assessment coefficient corresponding to the current abnormal indicator. For the current operation and maintenance optimization goals and the first Conditional covariance among the outliers Let Variance be the variance corresponding to the current operation and maintenance optimization objective. This represents the variance corresponding to the current abnormal indicator.
8. A root cause localization system based on time series decomposition and multi-agent cooperation, characterized in that, Applied to the method as described in any one of claims 1-7, comprising: The time series decomposition module is used to acquire the time series dataset of the target system, analyze the time series dataset of the target system, and determine the multidimensional independent component time series dataset. The parallel analysis module is used to perform multi-agent collaborative parallel anomaly analysis on the multi-dimensional independent component time series dataset based on a multi-agent collaborative parallel analysis strategy, and to determine the anomaly index location information set. The fusion decision module is used to perform fusion decision analysis on the abnormal indicator location information set according to the root cause fusion analysis strategy, and to determine and output the root cause analysis report.
Citation Information
Patent Citations
Adaptive operation and maintenance root cause positioning method and system based on deep learning
CN119691576A