Alarm rule configuration method of distributed system and related device
By generating configuration tasks in a distributed system and monitoring log changes in multiple data centers, the problems of high network bandwidth and low configuration efficiency are solved, and efficient and accurate alarm rule configuration is achieved.
Patent Information
- Application Number
- CN202511094308.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-09-19
AI Technical Summary
When monitoring and alarming logs of multiple data centers in a distributed system, the existing technology has the problems of high network bandwidth requirements and low efficiency in configuring alarm rules.
By generating configuration tasks, including reference modules for forming log change trend diagrams and simulation monitoring results, users configure alarm rules on the interactive end and monitor changes in the logs to be monitored in multiple data centers, and uniformly configure alarm rules.
It improves the configuration efficiency and accuracy of alarm rules, reduces network bandwidth requirements, and ensures the comprehensiveness and accuracy of monitoring.
Smart Images

Figure CN120675865A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer application technology, and in particular to an alarm rule configuration method and related devices for a distributed system. Background Art
[0002] Distributed systems typically utilize multiple data centers to ensure business system stability. To ensure the reliable operation of distributed systems, it is necessary to monitor their operational status and generate alerts for any faults discovered during monitoring. Distributed systems implement monitoring and alerting based on logs, which directly reflect the operational status of applications, middleware, databases, and operating systems, enabling full-stack alerting capabilities.
[0003] However, for distributed systems, monitoring and alerting only the logs of one data center can easily lead to monitoring loopholes. To avoid monitoring loopholes, it is necessary to monitor and alert the logs of all data centers. However, the logs of distributed systems are stored in situ. For example, the logs of data center d are stored in data center d, the logs of data center e are stored in data center e, and so on. Therefore, to achieve monitoring and alerting of the logs of all data centers, some existing technologies use the solution of merging the logs of multiple data centers for monitoring and alerting. Merging the logs of multiple data centers requires a large amount of network bandwidth, and it is also necessary to ensure the real-time transmission of logs across long distances across data centers, which is very costly.
[0004] In order to overcome the drawbacks of the above-mentioned solution of merging logs of multiple data centers for monitoring and alarming, some other existing technologies adopt a solution of configuring alarm rules for each data center separately to achieve monitoring and alarming of logs of all data centers. However, under this solution, the efficiency of configuring alarm rules is low. Summary of the Invention
[0005] The embodiment of the present invention provides an alarm rule configuration method and related devices for a distributed system to solve the problem of low efficiency in configuring alarm rules in the prior art, which adopts a solution of configuring alarm rules for each data center individually.
[0006] In order to solve the above-mentioned technical problems, the present invention is achieved as follows:
[0007] In a first aspect, an embodiment of the present invention provides a method for configuring alarm rules in a distributed system, comprising:
[0008] Determine a log to be monitored, generate a configuration task for configuring an alarm rule for the log to be monitored, and send the configuration task to an interactive terminal associated with a user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rule, the first reference module is used to form a log change trend diagram based on historical log data of the log to be monitored, and the second reference module is used to obtain a simulation monitoring result based on the historical log data and the alarm rule input by the user;
[0009] Receiving the configured alarm rule sent by the interaction terminal;
[0010] According to the configured alarm rules, changes of the logs to be monitored are monitored in multiple data centers of the distributed system.
[0011] Optionally, the alarm rule includes at least one of the following alarm conditions: rule type, time range, and alarm threshold.
[0012] Optionally, determine the logs to be monitored, including:
[0013] Determine the log information of the user-specified application to be monitored in multiple data centers of the distributed system;
[0014] The log to be monitored is determined according to the log information.
[0015] Optionally, determining log information of a user-specified application to be monitored in multiple data centers of a distributed system includes:
[0016] Obtain mapping information between applications, data centers, and logs from the distributed system's configuration management information database (CMDB) platform, and generate application-data center-log mapping relationships based on the mapping information.
[0017] Determining, based on the application-data center-log mapping relationship, multiple target data centers where the application to be monitored is deployed, and obtaining the log information in the multiple target data centers;
[0018] According to the configured alarm rules, the changes of the logs to be monitored are monitored in multiple data centers of the distributed system, including:
[0019] According to the configured alarm rules, changes of the logs to be monitored are monitored in the multiple target data centers.
[0020] Optionally, determine the logs to be monitored, including:
[0021] Generate a designated task specifying the log to be monitored, and send the designated task to the interactive terminal;
[0022] Receiving the log to be monitored specified by the interactive terminal;
[0023] The configuration task also includes: selecting a plurality of target data centers;
[0024] According to the configured alarm rules, the changes of the logs to be monitored are monitored in multiple data centers of the distributed system, including:
[0025] receiving the plurality of target data centers selected by the interactive terminal;
[0026] According to the configured alarm rules, changes of the logs to be monitored are monitored in the multiple target data centers.
[0027] Optionally, according to the configured alarm rules, changes of the log to be monitored are monitored in multiple data centers of the distributed system, and then the following steps are included:
[0028] Obtaining the number of alarms generated after the change of the to-be-monitored log on each of the data centers triggers the alarm rule, and determining whether the sum of the number of alarms for all the data centers exceeds a preset total threshold of the number of alarms;
[0029] If the sum of the alarm quantities of all the data centers exceeds the total alarm quantity threshold, sending a total alarm and the alarm quantity of each data center to the interaction terminal;
[0030] If the sum of the alarm numbers of all the data centers does not exceed the total alarm number threshold, determine whether the alarm number of each data center exceeds the preset alarm number threshold of the data center. If the alarm number of any data center exceeds the alarm number threshold, send an alarm for the data center to the interactive end.
[0031] In a second aspect, an embodiment of the present invention provides an alarm rule configuration device for a distributed system, comprising:
[0032] A determination module, configured to determine a log to be monitored, generate a configuration task for configuring an alarm rule for the log to be monitored, and send the configuration task to an interactive terminal associated with a user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rule, the first reference module being configured to form a log change trend diagram based on historical log data of the log to be monitored, and the second reference module being configured to obtain a simulation monitoring result based on the historical log data and the alarm rule input by the user;
[0033] A receiving module, configured to receive the configured alarm rules sent by the interaction terminal;
[0034] An execution module is used to monitor changes in the logs to be monitored in multiple data centers of a distributed system according to the configured alarm rules.
[0035] In a third aspect, an embodiment of the present invention provides an electronic device comprising a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps in the method for configuring alarm rules for a distributed system as described in any one of the first aspects.
[0036] In a fourth aspect, an embodiment of the present invention provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps in the alarm rule configuration method for a distributed system as described in any one of the first aspects are implemented.
[0037] In a fifth aspect, an embodiment of the present invention provides a computer program product, comprising computer instructions, which, when executed by a processor, implement the steps of the distributed system alarm rule configuration method as described in any one of the first aspects.
[0038] In an embodiment of the present invention, by determining the log to be monitored, a configuration task for configuring alarm rules for the log to be monitored is generated, and the configuration task is sent to the interactive terminal associated with the user; wherein, the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rules, the first reference module is used to form a log change trend diagram based on the historical log data of the log to be monitored, and the second reference module is used to obtain a simulation monitoring result based on the historical log data and the alarm rules input by the user; the configured alarm rules sent by the interactive terminal are received; according to the configured alarm rules, the changes of the log to be monitored are monitored in multiple data centers of the distributed system. The embodiment of the present invention realizes the unified configuration of alarm rules for multiple data centers, thereby improving the efficiency of configuring alarm rules. In addition, by including the first reference module and / or the second reference module for the user to refer to when configuring the alarm rules in the configuration task, the user experience is improved, and it also helps to improve the accuracy of the user configuration of the alarm rules. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0040] Figure 1 A schematic diagram of a flow chart of a method for configuring alarm rules in a distributed system according to an embodiment of the present invention;
[0041] Figure 2 This is a schematic diagram of log change trends;
[0042] Figure 3a This is a diagram of the alarm rule configuration page in template configuration mode;
[0043] Figure 3b This is a diagram of the alarm rule configuration page in custom mode;
[0044] Figure 4a This is a schematic diagram of the total alarm;
[0045] Figure 4b This is a diagram of a separate alarm for a data center;
[0046] Figure 5 A diagram of the system architecture for configuring the alarm rules system;
[0047] Figure 6 A diagram of the multi-data center alarm rule configuration page;
[0048] Figure 7 This is a functional block diagram of an alarm rule configuration device for a distributed system according to an embodiment of the present invention;
[0049] Figure 8 This is a principle block diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0051] The terms "first", "second", etc. in the embodiments of the present invention are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present invention can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "or" in the embodiments of the present invention represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0052] In addition, the technical features involved in the different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0053] It should be noted that the collection, collection, updating, analysis, processing, use, transmission, and storage of personal information involved in the technical solutions of the embodiments of the present invention all comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. Necessary measures are taken with respect to personal information to prevent unauthorized access to personal information data and maintain personal information security and network security.
[0054] The embodiment of the present invention provides a method for configuring alarm rules in a distributed system. Figure 1 As shown, Figure 1 This is a flow chart of a method for configuring alarm rules for a distributed system according to an embodiment of the present invention, including:
[0055] Step 11: Determine the log to be monitored, generate a configuration task for configuring alarm rules for the log to be monitored, and send the configuration task to the interactive terminal associated with the user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rules, the first reference module is used to form a log change trend diagram based on the historical log data of the log to be monitored, and the second reference module is used to obtain a simulated monitoring result based on the historical log data and the alarm rules entered by the user;
[0056] Step 12: Receive the configured alarm rules sent by the interaction end;
[0057] Step 13: Based on the configured alarm rules, monitor changes in the logs to be monitored in multiple data centers of the distributed system.
[0058] In some embodiments of the present invention, the log change trend diagram formed by the first reference module can be a display of log changes within a historical time period from the current moment back to a preset time, for example, the log change trend within 30 minutes before the current moment. In some embodiments, it can also be a display of log changes within at least one historical time period selected by the user, determined according to the user's specific selection, for example, the user pre-selects or selects in the first reference module to display log changes within the hour from 8:00 to 9:00 on the previous natural day, or the user pre-selects or selects in the first reference module to display log changes within the hour from 9:00 to 10:00 on the previous natural day.
[0059] It is understood that one axis of the log change trend diagram represents time, while the other axis represents an indicator associated with an alarm rule. For example, if the number of logs is used as the control indicator for an alarm rule, that is, if the number of logs exceeds a certain preset value, an alarm is triggered. The number of logs is the indicator associated with the alarm rule, and accordingly, the other axis represents the number of logs. The log change trend diagram thus represents the trend of the number of logs changing over time within a historical period. It should be noted that other indicators can also be used as the control indicator for the alarm rule, and this is not limited to this aspect of the present invention.
[0060] In a distributed system, business applications are fully deployed in multiple data centers. The system can determine the application processing instructions of one data center according to the processing rules set by the user. For example, based on real-time traffic, response rate or other indicators, multiple data centers will generate log data to be monitored. Therefore, in actual applications, users can set the first reference module to display a log change trend diagram of historical log data in at least one data center. For example, see Figure 2 As shown, Figure 2 The log change trend of the monitored log titled "log-lemon-access-" within 30 minutes before the current time is displayed, including the log changes of data center A, data center B, and the total log changes of the two data centers.
[0061] Users can refer to the log change trend diagram to configure alarm policies.
[0062] In some embodiments of the present invention, the simulation monitoring results formed by the second reference module are used to display the effect of the alarm rules input by the user on the historical log data. The user can evaluate the alarm rules input by himself based on the effect, and thus adjust the alarm rules input by himself. It can be understood that the simulation monitoring results will also display the effect of the adjusted alarm rules on the historical log data, and this cycle will be repeated until the effect that satisfies the user is obtained, and the alarm rules corresponding to the effect that satisfies the user are determined to be the configured alarm rules. It should also be noted that, similar to the first reference module, in actual applications, the user can set the second reference module to display the historical log data and alarm rules in at least one data center to obtain simulation monitoring results.
[0063] The embodiment of the present invention improves user experience and helps to improve the accuracy of user configuration of alarm rules by including the first reference module and / or the second reference module in the configuration task for the user to refer to when configuring the alarm rule.
[0064] In some embodiments, an alarm rule may include at least one alarm condition.
[0065] In some embodiments, at the interactive end, the configuration task can be presented in the form of a configuration page, which has an interface linking the first reference module and / or the second reference module. The user can open the corresponding first reference module and / or the second reference module by clicking on the interface to reference when configuring the alarm rules.
[0066] For example, see Figure 3a and Figure 3b As shown, users can choose two modes to configure alarm rules on the configuration page. One mode is "template configuration", see Figure 3a As shown, after selecting the template configuration, the page will display the template for configuring the alarm rule. In this example, it is a configuration template composed of log fields, field configuration methods, and field values. Users can enter parameters in the input boxes under the log fields, field configuration methods, and field value templates, or select parameters from the parameter list pre-configured in the input boxes. After filling in the parameters in all three input boxes, click "Add" to complete the configuration of an alarm condition. The other mode is "Custom", see Figure 3b As shown, the user can enter the alarm condition in the input box that prompts "Directly fill in the lucene expression". In this example, there are also selection buttons (interfaces) for "first reference module" and "second reference module". The user can choose to open the first reference module and / or the second reference module according to their own needs to assist the user in completing the configuration of the alarm rules. It can be understood that the "first reference module" and "second reference module" in this example can be other names. For example, the first reference module can be named trend chart and the second reference module can be named real-time log. As long as the first reference module and the second reference module can be linked and the functions of the first reference module and the second reference module can be realized after clicking.
[0067] In a distributed system, business applications are fully deployed across multiple data centers. The system can determine which data center's application processes business instructions based on user-defined processing rules, such as real-time traffic, response rate, or other metrics. Consequently, log data is generated across multiple data centers. This embodiment of the present invention monitors changes in logs to be monitored across multiple data centers in the distributed system based on configured alarm rules, avoiding omissions and ensuring that all changes in the logs to be monitored are monitored, thereby improving the accuracy of alarms.
[0068] In an embodiment of the present invention, by determining the log to be monitored, a configuration task for configuring alarm rules for the log to be monitored is generated, and the configuration task is sent to the interactive terminal associated with the user; wherein, the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rules, the first reference module is used to form a log change trend diagram based on the historical log data of the log to be monitored, and the second reference module is used to obtain a simulation monitoring result based on the historical log data and the alarm rules input by the user; the configured alarm rules sent by the interactive terminal are received; according to the configured alarm rules, the changes of the log to be monitored are monitored in multiple data centers of the distributed system. The embodiment of the present invention realizes the unified configuration of alarm rules for multiple data centers, thereby improving the efficiency of configuring alarm rules. In addition, by including the first reference module and / or the second reference module for the user to refer to when configuring the alarm rules in the configuration task, the user experience is improved, and it also helps to improve the accuracy of the user configuration of the alarm rules.
[0069] In some embodiments, the alarm rule includes at least one of the following alarm conditions: rule type, time range, and alarm threshold.
[0070] In some embodiments, the rule types may include: trigger on occurrence, upper deviation, lower deviation, sudden increase or decrease, and percentage.
[0071] For example, "trigger if there is any control indicator of the log to be monitored that meets the early warning rule, an alarm will be triggered. Upper deviation can mean that the control indicator of the log to be monitored shows an increasing or rising trend, which will trigger an alarm. Lower deviation can mean that the control indicator of the log to be monitored shows a decreasing or falling trend, which will trigger an alarm. Sudden increase or decrease can mean that when the rising rate of the control indicator of the log to be monitored exceeds the preset rising rate threshold, or the falling rate exceeds the preset falling rate threshold, an alarm will be triggered. Among them, the rising rate threshold and the falling rate threshold are the definitions of sudden increase and sudden decrease determined by the user according to actual needs. Percentage can mean that the proportion of the change in the control indicator of the log to be monitored to itself exceeds the preset percentage threshold, triggering an alarm. Among them, the percentage threshold is determined by the user according to actual needs.
[0072] In some embodiments, a time range may refer to a time range within which changes in the monitored log data are used to control whether an alarm rule is triggered. A user-defined time range (after the alarm rule configuration is complete) monitors changes in the monitored log data within the user-defined time range across multiple data centers in the distributed system.
[0073] In some embodiments, an alarm threshold may refer to a limit threshold for a control metric. That is, when a control metric meets the alarm threshold, an alarm is triggered. For example, if the number of logs is used as the control metric for an alarm rule, the user may set a log number threshold as the alarm threshold. When the number of monitored logs exceeds the log number threshold, an alarm is triggered. It is understood that users can set the alarm threshold according to their specific needs, and this is not a limitation of the present invention.
[0074] In the embodiment of the present invention, the alarm rule includes at least one of the following alarm conditions: rule type, time range, and alarm threshold. The embodiment of the present invention enables users to set alarm rules in a refined manner, thereby improving the accuracy and precision of alarms.
[0075] In some embodiments, determining the logs to be monitored includes:
[0076] Determine the log information of the user-specified application to be monitored in multiple data centers of the distributed system;
[0077] Determine the logs to be monitored based on the log information.
[0078] In the embodiment of the present invention, the user only needs to specify the application to be monitored, and the method execution subject of the embodiment of the present invention can determine the log information of the application to be monitored specified by the user in multiple data centers of the distributed system, and determine the log to be monitored based on the log information, thereby avoiding the heavy operational burden on the user when the user specifies the log to be monitored, and improving the efficiency of determining the log to be monitored. It can be understood that the amount of background data in the distributed system is huge and the data structure is complex. If the user specifies the log to be monitored, on the one hand, it is easy to cause omissions in the log to be monitored, forming a monitoring loophole; on the other hand, it is inefficient. Therefore, the application of the embodiment of the present invention can avoid omissions in the log to be monitored, improve the accuracy of monitoring, and also improve efficiency.
[0079] In some embodiments, determining log information of a user-specified application to be monitored in multiple data centers of a distributed system includes:
[0080] Obtain mapping information between applications, data centers, and logs from the distributed system's configuration management information database (CMDB) platform, and generate application-data center-log mapping relationships based on the mapping information.
[0081] Based on the application-data center-log mapping relationship, determine multiple target data centers where the application to be monitored is deployed, and obtain log information from multiple target data centers;
[0082] Among them, according to the configured alarm rules, the changes of the monitored logs are monitored in multiple data centers of the distributed system, including:
[0083] Based on the configured alarm rules, changes in the logs to be monitored are monitored in multiple target data centers.
[0084] Configuration Management Database (CMDB) is an important component of IT service management, mainly used to store and manage configuration information related to IT infrastructure.
[0085] The present invention utilizes a CMDB platform to construct an application-data center-log mapping relationship. Furthermore, based on the application-data center-log mapping relationship, multiple target data centers are determined for deploying the application to be monitored, and log information is obtained in the multiple target data centers. This improves the efficiency of determining the logs to be monitored, reduces the probability of omissions in the determined logs to be monitored, and improves the accuracy of monitoring. Furthermore, by determining multiple target data centers for deploying the application to be monitored and monitoring changes in the logs to be monitored in the multiple target data centers based on configured alarm rules, accurate monitoring of the data centers is achieved, the computing resources required for monitoring the data centers are reduced, and monitoring efficiency is improved.
[0086] In some embodiments, determining the logs to be monitored includes:
[0087] Generate a specified task for the specified log to be monitored and send the specified task to the interactive end;
[0088] Receive the logs to be monitored specified by the interaction end;
[0089] The configuration tasks also include: selecting tasks for selecting multiple target data centers;
[0090] Among them, according to the configured alarm rules, the changes of the monitored logs are monitored in multiple data centers of the distributed system, including:
[0091] receiving multiple target data centers selected by the interaction terminal;
[0092] Based on the configured alarm rules, changes in the logs to be monitored are monitored in multiple target data centers.
[0093] In the embodiment of the present invention, the logs to be monitored are determined by the user's designation, and the user can independently select the logs to be monitored according to monitoring needs, thereby improving the flexibility of monitoring.
[0094] On this basis, the configuration tasks also include: selecting multiple target data centers; monitoring changes in the logs to be monitored in multiple data centers of the distributed system according to the configured alarm rules, including: receiving multiple target data centers selected by the interactive end; monitoring changes in the logs to be monitored in multiple target data centers according to the configured alarm rules, so as to monitor the target data centers selected by the user, thereby improving the flexibility of monitoring, realizing accurate monitoring of the data center, reducing the computing power resources required to monitor the data center, and improving the monitoring efficiency.
[0095] In some embodiments, according to the configured alarm rules, changes in the logs to be monitored are monitored in multiple data centers of the distributed system, and then the following steps are included:
[0096] Obtain the number of alarms generated after the changes in the monitored logs on each data center trigger the alarm rules, and determine whether the sum of the alarm numbers of all data centers exceeds the preset total alarm number threshold;
[0097] If the sum of the alarm counts for all data centers exceeds the total alarm count threshold, a summary alarm and the alarm counts for each data center are sent to the interaction client.
[0098] If the sum of the alarm numbers of all data centers does not exceed the total alarm number threshold, determine whether the alarm number of each data center exceeds the preset alarm number threshold of the data center. If the alarm number of a data center exceeds the alarm number threshold, send an alarm for the data center to the interactive end.
[0099] For example, see the following for aggregate alarms: Figure 4a As shown, the alarm information displays the total alarm, and each data center will not generate a separate alarm. Figure 4a It can be seen that in the AAA management system as a distributed system, the query result of data center A is 1869 data items, and the query result of data center B is 326 data items. The total result after merging is 2195 data items. 2195 data items meet the threshold of 60 set in the alarm rule (that is, the alarm quantity threshold), meet the aggregate alarm conditions, and issue an aggregate alarm.
[0100] In an embodiment of the present invention, when the sum of the number of alarms of all data centers exceeds the total threshold of the number of alarms, an aggregate alarm and the number of alarms of each data center are sent to the interactive end, ensuring that the interactive end obtains complete and accurate alarm information, thereby improving the convenience for users to determine the root cause of the alarm.
[0101] For example, see the alarm for the data center. Figure 4b As shown, an alarm is sent to data center A alone.
[0102] In an embodiment of the present invention, when the sum of the number of alarms of all data centers does not exceed the total alarm number threshold, it is determined whether the number of alarms of each data center exceeds the preset alarm number threshold of the data center. If the number of alarms of a data center exceeds the alarm number threshold, an alarm for the data center is sent to the interactive end, ensuring that the interactive end obtains complete and accurate alarm information, thereby improving the convenience for users to determine the root cause of the alarm.
[0103] The following is described with reference to specific embodiments:
[0104] See also Figure 5 As shown, Figure 5 This section shows the system architecture diagram of the alarm rule configuration system. In this system, the methods for configuring alarm policies include:
[0105] Step 1: Obtain the log information of the computer room (center) where the business system application is deployed and the application by connecting to the Configuration Management Database (CMDB) platform, forming an application-data center-log mapping relationship. This allows the business to automatically identify the information of the computer room (center) where it is deployed when configuring multi-center alarms. It should be noted that the center refers to the data center.
[0106] If the CMDB platform does not have this corresponding relationship, the user will select the computer room (center) by himself when configuring the alarm rules. After the selection is completed, the system will automatically use the same log name in the selected computer room (center) as the log data source for multi-center alarms and provide it to the user for log alarm rule configuration.
[0107] For example, based on the following Figure 6 In the multi-data center alarm rule configuration page shown, after the user configures and selects static information such as "Alarm Title", "Maintenance Type", "Group", and "Alarm Level", it is necessary to configure the multi-center related information:
[0108] In the "Application" field, select the application for which you want to configure an alarm. The system automatically obtains the application from the deployed data center based on the (Application-Data Center-Log) mapping relationship and automatically selects the corresponding computer room (center) in the "Region Name" field.
[0109] If there is no such mapping relationship, the user can manually select the computer room (center) for which alarms need to be configured in the "Area Name" field.
[0110] After the center confirms, the system will automatically obtain its log information based on the (application-data center-log) mapping relationship and provide users with a drop-down selection in the "Monitoring Log" (i.e., the log to be monitored) field;
[0111] If there is no such mapping relationship, the system will automatically provide the user with a drop-down selection in the "Monitoring Log" field based on the same log file of the selected computer room (center);
[0112] Step 2: After confirming the "Area Name" and "Monitoring Log", see Figure 6 In the "Condition Type" section, users need to configure specific alarm conditions. Alarm conditions are divided into two types: "Template Configuration" and "Custom".
[0113] User selects template configuration: The system will search for the corresponding index mapping (table structure) in the ES of the corresponding computer room (center) based on the selected log, and provide the fields of the same table structure in multiple computer rooms (centers) for the user to select from the drop-down list. Figure 6 In the "Log Field" section, users manually fill in the field matching method and content.
[0114] If the user chooses custom configuration: the system will provide a custom input box for the user to enter the alarm conditions to be configured.
[0115] After the user fills in the specific alarm conditions, the user can click the "Trend Chart (i.e. the first reference module)" and "Real-time Log (i.e. the second reference module)" buttons to view the data matched by the specified log in the corresponding computer room (center) based on the filled-in alarm conditions.
[0116] The principle of the historical curve chart is as follows: after determining the specific content in the "area name", "monitoring log" and "condition type", the log source of each computer room (center) is queried for the corresponding matching situation in the last 30 minutes, forming a result curve chart of the last 30 minutes of each computer room (center) and the overall total. Users can also pull down to change the time range to provide reference data for setting alarm thresholds.
[0117] The principle of matching real-time logs is as follows: after determining the specific content in the "area name", "monitoring log" and "condition type", the log source of each computer room (center) is queried for the latest 10 log information that meets the alarm conditions in the last 30 minutes, and the information is displayed to the user to assist the user in judging whether the alarm conditions they have filled in are accurate through the real log information.
[0118] Step 3: The user sets the "Rule Type" (e.g., trigger immediately, upper deviation, lower deviation, sudden increase, sudden decrease, percentage) and "Time Range" as well as the alarm threshold for each center and the total alarm threshold for multiple centers;
[0119] The principle is as follows: After the user determines the alarm conditions, the log text can be converted into an indicator value that can be used for high and low judgment based on the number of matches in the query results within the specified time range. Since the traffic carried by different centers may not be evenly distributed, different thresholds can be configured for each center. The alarm threshold for the entire business cannot be roughly processed by simply adding or averaging the thresholds of each center, so the overall alarm threshold also needs to be configured.
[0120] Step 4: After the user configures the alarm rules, the background polling phase will begin. The polling phase will perform concurrency optimization to ensure that each alarm rule can be triggered on time. The principles are as follows: 1. The background will group according to the polling frequency configured by the user; 2. Each group will aggregate the conditions of the same computer room (center) and the same log in each rule into one query, so as to reduce the concurrency pressure of executing each rule separately under a large number of rules; 3. Set a timeout for each query. If the query times out and no result is obtained, it will be initiated again after the default interval time (configurable) until the next polling starts. If no query result is obtained, the current round of query will be stopped and an error log will be recorded.
[0121] Step 5: Since the query in the fifth step is a single-center dimension, after obtaining the query results, first merge (sum) the query results of each computer room (center), calculate whether the overall alarm total threshold meets the conditions, and if so, issue an overall total alarm and display the query result values of each computer room (center); if the overall total value does not meet the total threshold, then determine whether each center meets the independent threshold. If each computer room (center) meets the alarm threshold, issue an alarm for each computer room (center).
[0122] Step 6: After the alarm is issued, you can push the alarm to the work order system by connecting to an external platform, or connect to an email server to send the alarm by email, or connect to an SMS gateway to send the alarm SMS, etc.
[0123] The embodiment of the present invention also provides an alarm rule configuration device for a distributed system, see Figure 7 As shown, Figure 7 This is a principle block diagram of an alarm rule configuration device for a distributed system according to an embodiment of the present invention. The alarm rule configuration device 70 for a distributed system includes:
[0124] A determination module 71 is configured to determine a log to be monitored, generate a configuration task for configuring an alarm rule for the log to be monitored, and send the configuration task to an interactive terminal associated with a user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rule, the first reference module being configured to form a log change trend diagram based on historical log data of the log to be monitored, and the second reference module being configured to obtain a simulated monitoring result based on the historical log data and the alarm rule input by the user;
[0125] A receiving module 72 is configured to receive the configured alarm rule sent by the interaction terminal;
[0126] The execution module 73 is configured to monitor changes in the logs to be monitored in multiple data centers of the distributed system according to the configured alarm rules.
[0127] In some embodiments, the alarm rule includes at least one of the following alarm conditions: rule type, time range, and alarm threshold.
[0128] In some embodiments, the determining module 71 is further configured to determine log information of a user-specified application to be monitored in multiple data centers of a distributed system;
[0129] The determining module 71 is further configured to determine the log to be monitored according to the log information.
[0130] In some embodiments, the determining module 71 is further configured to obtain mapping information between applications, data centers, and logs from a configuration management information database CMDB platform of the distributed system, and generate an application-data center-log mapping relationship based on the mapping information;
[0131] The determining module 71 is further configured to determine, based on the application-data center-log mapping relationship, multiple target data centers where the application to be monitored is deployed, and obtain the log information in the multiple target data centers;
[0132] The execution module 73 is further configured to monitor changes in the logs to be monitored in the multiple target data centers according to the configured alarm rules.
[0133] In some embodiments, the determining module 71 is further configured to generate a designated task specifying the log to be monitored, and send the designated task to the interactive terminal;
[0134] The determining module 71 is further configured to receive the log to be monitored specified by the interaction terminal;
[0135] The configuration task also includes: selecting a plurality of target data centers;
[0136] The execution module 73 is further configured to receive the multiple target data centers selected by the interaction terminal;
[0137] The execution module 73 is further configured to monitor changes in the logs to be monitored in the multiple target data centers according to the configured alarm rules.
[0138] In some embodiments, the execution module 73 is further configured to obtain the number of alarms generated after the change of the monitored log on each of the data centers triggers the alarm rule, and determine whether the sum of the number of alarms for all the data centers exceeds a preset total alarm number threshold;
[0139] The execution module 73 is further configured to send a total alarm and the number of alarms of each data center to the interaction terminal if the sum of the number of alarms of all the data centers exceeds the total alarm number threshold;
[0140] The execution module 73 is also used to determine whether the number of alarms of each data center exceeds the preset alarm number threshold of the data center if the sum of the number of alarms of all the data centers does not exceed the total alarm number threshold; if the number of alarms of any data center exceeds the alarm number threshold, an alarm for the data center is sent to the interactive end.
[0141] The distributed system alarm rule configuration device provided by the embodiment of the present invention can realize Figures 1 to 6 The various processes implemented by the method embodiment achieve the same technical effect and are not described here again to avoid repetition.
[0142] An embodiment of the present invention provides an electronic device 80, see Figure 8 As shown, Figure 8 This is a principle block diagram of an electronic device 80 according to an embodiment of the present invention, including a processor 81, a memory 82, and a program or instruction stored in the memory 82 and executable on the processor 81. When the program or instruction is executed by the processor, the steps in the alarm rule configuration method of any distributed system according to the present invention are implemented.
[0143] An embodiment of the present invention provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the embodiment of the alarm rule configuration method of a distributed system such as any of the above-mentioned items are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0144] The readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0145] An embodiment of the present invention also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the various processes of the alarm rule configuration method for a distributed system described above are implemented, and the same technical effects can be achieved. To avoid repetition, they will not be described here.
[0146] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are protected by the present invention.
Claims
1. A distributed system alarm rule configuration method, characterized in that: include: Determine a log to be monitored, generate a configuration task for configuring an alarm rule for the log to be monitored, and send the configuration task to an interactive terminal associated with a user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rule, the first reference module is used to form a log change trend diagram based on historical log data of the log to be monitored, and the second reference module is used to obtain a simulation monitoring result based on the historical log data and the alarm rule input by the user; Receiving the configured alarm rule sent by the interaction terminal; According to the configured alarm rules, changes of the logs to be monitored are monitored in multiple data centers of the distributed system.
2. The distributed system alarm rule configuration method according to claim 1, characterized in that: The alarm rule includes at least one of the following alarm conditions: rule type, time range, and alarm threshold.
3. The distributed system alarm rule configuration method according to claim 1, characterized in that: Identify the logs to be monitored, including: Determine the log information of the user-specified application to be monitored in multiple data centers of the distributed system; The log to be monitored is determined according to the log information.
4. The distributed system alarm rule configuration method according to claim 3, characterized in that: Determine the log information of the user-specified application to be monitored in multiple data centers of the distributed system, including: Obtain mapping information between applications, data centers, and logs from the distributed system's configuration management information database (CMDB) platform, and generate application-data center-log mapping relationships based on the mapping information. Determining, based on the application-data center-log mapping relationship, multiple target data centers where the application to be monitored is deployed, and obtaining the log information in the multiple target data centers; According to the configured alarm rules, the changes of the logs to be monitored are monitored in multiple data centers of the distributed system, including: According to the configured alarm rules, changes of the logs to be monitored are monitored in the multiple target data centers.
5. The distributed system alarm rule configuration method according to claim 1, characterized in that: Identify the logs to be monitored, including: Generate a designated task specifying the log to be monitored, and send the designated task to the interactive terminal; Receiving the log to be monitored specified by the interactive terminal; The configuration task also includes: selecting a plurality of target data centers; According to the configured alarm rules, the changes of the logs to be monitored are monitored in multiple data centers of the distributed system, including: receiving the plurality of target data centers selected by the interactive terminal; According to the configured alarm rules, changes of the logs to be monitored are monitored in the multiple target data centers.
6. The distributed system alarm rule configuration method according to claim 1, characterized in that: According to the configured alarm rules, the changes of the logs to be monitored are monitored in multiple data centers of the distributed system, and then the following steps are included: Obtaining the number of alarms generated after the change of the to-be-monitored log on each of the data centers triggers the alarm rule, and determining whether the sum of the number of alarms for all the data centers exceeds a preset total threshold of the number of alarms; If the sum of the alarm quantities of all the data centers exceeds the total alarm quantity threshold, sending a total alarm and the alarm quantity of each data center to the interaction terminal; If the sum of the alarm numbers of all the data centers does not exceed the total alarm number threshold, determine whether the alarm number of each data center exceeds the preset alarm number threshold of the data center. If the alarm number of any data center exceeds the alarm number threshold, send an alarm for the data center to the interactive end.
7. An alarm rule configuration device for a distributed system, characterized in that: include: A determination module, configured to determine a log to be monitored, generate a configuration task for configuring an alarm rule for the log to be monitored, and send the configuration task to an interactive terminal associated with a user; wherein the configuration task includes a first reference module and / or a second reference module for the user to refer to when configuring the alarm rule, the first reference module being configured to form a log change trend diagram based on historical log data of the log to be monitored, and the second reference module being configured to obtain a simulation monitoring result based on the historical log data and the alarm rule input by the user; A receiving module, configured to receive the configured alarm rules sent by the interaction terminal; An execution module is used to monitor changes in the logs to be monitored in multiple data centers of a distributed system according to the configured alarm rules.
8. An electronic device, characterized in that: It includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps in the alarm rule configuration method for a distributed system as described in any one of claims 1 to 6.
9. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps in the alarm rule configuration method for a distributed system according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the steps of the alarm rule configuration method for a distributed system according to any one of claims 1 to 6.